CASE STUDY
ÉTUDE DE CAS
How flaconi turned a compliance burden into a continuous security program with Vanta
ISO 27001, GDPR, SOC 2, EU AI Act, Vendor Management

“If you want that pain of compliance to be gone and actually turn it into something that the teams like to work with… with Vanta, this is possible … the activity becomes less of a pain and more and something valuable.”
TL;DR
- Challenge: flaconi's teams were doing the right security work, but without a consistent system to document it or map it to compliance requirements.
- Solution: flaconi chose Vanta over hiring a dedicated FTE, prioritizing deep AWS integration and multi-framework coverage. Vanta became the single platform for ISO 27001, GDPR, SOC 2, EU AI Act, risk, and vendor management.
- ROI: flaconi avoided a dedicated compliance hire, reused evidence across frameworks to reach ~40% GDPR completion at activation, and gave DevOps teams direct AWS security signals — turning compliance from a documentation burden into ongoing security insight.
The company
Germany’s leading online beauty retailer
flaconi is a B2C beauty retailer with around 900 employees, based in Berlin. Today flaconi serves over 6 million customers across 12 European markets, cementing its position as Germany's leading online beauty retailer.
The challenge
Scaling compliance without scaling the team
As an ecommerce business handling consumer data across its webshop, customer service, and internal systems, flaconi faced compliance obligations across multiple frameworks. Plus, as a subsidiary of a publicly listed parent company, it had to meet its parent's compliance standards on top of its own.
What flaconi tried first: That became a problem as parent-company reviews increased and internal stakeholders needed clearer proof of flaconi's information security posture. The team needed to get organized, without turning compliance into a full-time manual project.
flaconi’s pivot point: That became a problem as parent-company reviews increased and internal stakeholders asked for clearer proof of flaconi’s information security management system. The team knew it needed to get organized, but didn’t want to turn compliance into a full-time manual documentation project.
Why flaconi chose Vanta: The team initially expected European vendors to lead on privacy and compliance needs, but integration depth became the deciding factor — Vanta's AWS integration was deep and configurable enough for flaconi's advanced setup.
{{quote-2}}
The Vanta impact
Turning compliance overhead into security insight
With Vanta's integrations wired into its AWS environment and multiple frameworks mapped to a single platform, flaconi shifted from reactive documentation to continuous compliance. Evidence collected for one framework now carries across others, DevOps teams receive direct security signals from their infrastructure, and risk management has consolidated into one system, giving flaconi's lean team the visibility to stay ahead of compliance without adding headcount.
Here’s how flaconi deployed Vanta:
Today, flaconi reports compliance progress to its board every two to three months—using Vanta as the single source of truth across frameworks, risk, and vendors. Compliance is no longer something the team scrambles to explain; it's something leadership can see and act on.
{{quote-3}}
