CASE STUDY
ÉTUDE DE CAS
How GraniteStack earned SOC 2 Type II and ISO 27001 in 6 months

“A consultant delivers a deliverable. Vanta delivers a continuous programme. For a business pursuing dual certification and planning to maintain it year on year, that distinction matters significantly."
TL;DR
- Challenge: GraniteStack had internal security practices but no formal framework, audit trail, or documentation, meaning it couldn’t easily satisfy enterprise procurement requirements.
- Solution: GraniteStack deployed Vanta to pursue SOC 2 Type II and ISO 27001 simultaneously, automating AWS evidence collection against a single system of record.
- ROI: Audit-ready within two weeks, completed both frameworks in about six months, and reduced ongoing compliance effort to 3–4 hours per week. These efforts improved enterprise sales.
The company
Building enterprise-grade platforms without custom development
GraniteStack is an enterprise platform development company that helps businesses build and launch production-ready SaaS platforms, including web apps, mobile apps, and full business systems, without custom development or lengthy timelines. The platform combines low-code configurability with AI-assisted UX design and automatic API generation, making it a good fit for operationally complex businesses working in high-risk industries.
The challenge
Enterprise customer procurement required proof, not promises
As enterprise procurement conversations intensified and security questionnaires became routine, the GraniteStack team found they could describe their security posture, but couldn't prove it.
What GraniteStack tried first: GraniteStack wasn't starting from zero. Its infrastructure was already built on AWS with security controls baked in, and the team had internal documentation of its security practices, tracked across project management tools and spreadsheets.
“We knew we were doing the right things operationally,” Shubha says, “but we had no formal framework, no audit trail, and no structured way to demonstrate our posture to a client who asked.” The gap wasn't security—it was proof.
GraniteStack's pivot point: GraniteStack’s founders decided to pursue SOC 2 Type II and ISO 27001 at the same time: SOC 2 for US clients and ISO 27001 for international ones. This meant GraniteStack needed a solution to support both frameworks in parallel while integrating deeply with AWS to automate technical evidence collection.
Why GraniteStack chose Vanta: GraniteStack evaluated several competitors of Vanta alongside traditional consultants. Consultants quoted $30,000–$70,000 for a point-in-time engagement with no automation or ongoing maintenance included.
Vanta stood out for:
- Native support for running SOC 2 and ISO 27001 in parallel against a single, continuously monitored system of record
- Deep AWS integration that automated technical evidence collection
- Global recognition that carries weight with enterprise procurement teams
The Vanta impact
From informal practices to a continuously monitored compliance program
GraniteStack deployed Vanta to achieve SOC 2 Type II and ISO 27001 frameworks, securing proof of its security posture that enterprise customers demanded. With frameworks in hand, GraniteStack now uses Vanta to run a continuously monitored compliance program.
Here's how GraniteStack deployed Vanta:
Now, compliance is a value-generating asset, benefiting GraniteStack and its clients alike. Clients building on the GraniteStack platform build on infrastructure whose controls have already been audited, which reduces the evidence they have to gather for their own SOC 2, which turns GraniteStack's security posture from a question into both a sales credential and a product feature.
{{quote-2}}
.png)