Healthcare Brightwave

Brightwave passes SOC 2 Type II on the first attempt

1/1 SOC 2 attempts to pass
Brightwave passes SOC 2 Type II on the first attempt

Challenge

Brightwave handles health data and needed SOC 2 Type II to close enterprise deals. They had no dedicated security team and a three-month audit deadline.

Approach

We mapped controls to the SOC 2 framework, identified gaps, and prioritized automating repeatable controls so a small team could sustain them.

Solution

We deployed:

  • Zero-trust: mTLS, least-privilege, audit logging
  • Code and dependency scanning in CI
  • Automated compliance evidence collection

Results

1/1
attempts
12 tuần
to audit
0
critical findings
HIPAA
roadmap ready

“We passed SOC 2 Type II on the first attempt thanks to their security and DevOps work. Responsive, rigorous, and genuinely invested.”

Mei Lin Founder, Brightwave

Tech stack

AWSTerraformVaultOPASplunk

Start a similar project

Tell us about your challenge — we'll bring the team.

Talk to us