CASE STUDY
ÉTUDE DE CAS

How flaconi turned a compliance burden into a continuous security program with Vanta

COMPANY
ENTREPRISE
Flaconi
LOCATION
EMPLACEMENT
Berlin, Germany
INDUSTRY
INDUSTRIE
Beauty ecommerce / retail
PARTNER
PARTENAIRE
EMPLOYEES
EMPLOYÉS
700+
SOLUTION
SOLUTION

ISO 27001, GDPR, SOC 2, EU AI Act, Vendor Management

VANTA CUSTOMER SINCE
ANNÉES AVEC VANTA
2025
No new headcount required

~40% GDPR completion at activation

4 frameworks managed in one platform

“If you want that pain of compliance to be gone and actually turn it into something that the teams like to work with… with Vanta, this is possible … the activity becomes less of a pain and more and something valuable.”

Sven Rosemann
CTO, flaconi

TL;DR

  • Challenge: flaconi's teams were doing the right security work, but without a consistent system to document it or map it to compliance requirements.
  • Solution: flaconi chose Vanta over hiring a dedicated FTE, prioritizing deep AWS integration and multi-framework coverage. Vanta became the single platform for ISO 27001, GDPR, SOC 2, EU AI Act, risk, and vendor management.
  • ROI: flaconi avoided a dedicated compliance hire, reused evidence across frameworks to reach ~40% GDPR completion at activation, and gave DevOps teams direct AWS security signals — turning compliance from a documentation burden into ongoing security insight.

The company

Germany’s leading online beauty retailer

flaconi is a B2C beauty retailer with around 900 employees, based in Berlin. Today flaconi serves over 6 million customers across 12 European markets, cementing its position as Germany's leading online beauty retailer. 

The challenge

Scaling compliance without scaling the team

As an ecommerce business handling consumer data across its webshop, customer service, and internal systems, flaconi faced compliance obligations across multiple frameworks. Plus, as a subsidiary of a publicly listed parent company, it had to meet its parent's compliance standards on top of its own.

What flaconi tried first: That became a problem as parent-company reviews increased and internal stakeholders needed clearer proof of flaconi's information security posture. The team needed to get organized, without turning compliance into a full-time manual project.

flaconi’s pivot point: That became a problem as parent-company reviews increased and internal stakeholders asked for clearer proof of flaconi’s information security management system. The team knew it needed to get organized, but didn’t want to turn compliance into a full-time manual documentation project.

Why flaconi chose Vanta: The team initially expected European vendors to lead on privacy and compliance needs, but integration depth became the deciding factor — Vanta's AWS integration was deep and configurable enough for flaconi's advanced setup.

{{quote-2}}

The Vanta impact

Turning compliance overhead into security insight

With Vanta's integrations wired into its AWS environment and multiple frameworks mapped to a single platform, flaconi shifted from reactive documentation to continuous compliance. Evidence collected for one framework now carries across others, DevOps teams receive direct security signals from their infrastructure, and risk management has consolidated into one system, giving flaconi's lean team the visibility to stay ahead of compliance without adding headcount.

Here’s how flaconi deployed Vanta:

Vanta tools and solutions ROI
Multi-framework compliance management: flaconi manages ISO 27001, GDPR, SOC 2, and EU AI Act in Vanta, with cross-mapped evidence reducing duplicative work across frameworks. Deep AWS integration surfaces vulnerabilities directly to DevOps teams. Recent Vanta privacy enhancements are enabling flaconi to migrate GDPR documentation off a separate parent-company-mandated tool.
  • Evidence reuse across frameworks eliminates duplicate collection work
  • GDPR reached approximately 40% completion at activation, carried over from existing framework work
  • DevOps teams now receive direct, actionable vulnerability notifications and discover gaps in their own setup without manual documentation
  • No new headcount required
Risk and vendor management: flaconi is migrating all risk management—including business risks for parent company reporting—and vendor management into Vanta, replacing separate tools and consolidating its compliance infrastructure.
  • Parent company will receive risk updates and exports directly from Vanta
  • Reduced tool sprawl across risk, vendor, and compliance workflows

Today, flaconi reports compliance progress to its board every two to three months—using Vanta as the single source of truth across frameworks, risk, and vendors. Compliance is no longer something the team scrambles to explain; it's something leadership can see and act on.

{{quote-3}}

“We were about to hire a person to work on this. Then we asked: Do we hire a person, or do we buy a tool that does that automation for us?”

Sven Rosemann
CTO, flaconi

“Without Vanta, I would have to create a lot of documents again. Our security posture would be impacted, and we would have a lot more documentation work.”

Sven Rosemann
CTO, flaconi