All articles
SecurityAugust 21, 2025 · 10 min read

How we got SOC 2 Type II without hiring a compliance team

EV

Elena Volkov

Head of Security

SOC 2 is mostly a documentation exercise about things good engineering teams already do: access control, change management, monitoring, incident response.

The trap is doing it manually. Screenshots of dashboards, spreadsheets of access reviews — that's how compliance becomes a full-time job.

Policies as code

We wrote every control as an automated check. Access reviews are a script that diffs IAM against the org chart. Change management evidence is generated from pull request metadata.

Our auditors got read-only dashboards instead of PDF exports. The audit itself took two weeks, and the controls keep verifying themselves every night.

Your next launch
starts here.

Spin up a workspace in under a minute and see why 100,000+ teams ship on Vantora every week.

No credit card required