Case study · healthcare
SOC2 Readiness for HealthSaaS
Passed SOC2 Type II first attempt - evidence generated as we built, not before the audit.
Overview
The brief.
A health SaaS had an SOC2 audit booked before evidence existed. We mapped 85 controls to engineering and generated evidence as they built, passing Type II on the first attempt.
Client
Health SaaS
Healthcare / B2B SaaS
Series B
Gallery
In the wild.



The numbers.
Results
First attempt
SOC2 Type II
100%
criticals closed
85
controls mapped
8 weeks
to evidence-ready
The challenge
What was in the way.
Audit booked, no evidence
Enterprise deals required SOC2, and the audit was already scheduled. But evidence lived in screenshots and tribal knowledge - there was no systematic trail.
Controls as paperwork
Security controls were a checklist on the wall, not wired into engineering. Nothing enforced them, so drift was invisible until the auditor asked.
The solution
How we solved it.
We ran a threat model, mapped 85 controls to SOC2, and made evidence a build artifact: DefectDojo for vulns, OpenTofu baselines for config, OpenBao for secrets, and nightly ZAP/OSV scans feeding an evidence pack per control.
“We passed first attempt. The auditor kept saying the evidence was the cleanest they'd seen - because it was generated, not assembled.”
Outcome
The bottom line.
Passed SOC2 Type II first attempt - evidence generated as we built, not before the audit.
FAQ
About this engagement.
How did you pass first attempt?
Evidence was generated by the pipeline per control, so nothing was missing at audit time.
How long to evidence-ready?
8 weeks for evidence; the auditor's own timeline is separate.
Is it sustainable?
Yes - evidence regenerates nightly; no re-assembling before each audit.
Want results like these?
We build to the outcome, then let the numbers speak.