CASE STUDY
ÉTUDE DE CAS

How GraniteStack earned SOC 2 Type II and ISO 27001 in 6 months

COMPANY
ENTREPRISE
GraniteStack
LOCATION
EMPLACEMENT
Melbourne, Victoria, Australia
INDUSTRY
INDUSTRIE
Technology / Enterprise SaaS Platform Development
PARTNER
PARTENAIRE
EMPLOYEES
EMPLOYÉS
25
SOLUTION
SOLUTION

Automated Compliance, SOC 2 Type II, ISO 27001

VANTA CUSTOMER SINCE
ANNÉES AVEC VANTA
2025
Near audit-ready within 2 weeks

Both frameworks completed in about 6 months

Compliance maintenance reduced from 15-20 hours per week to 3-4 hours per week

“A consultant delivers a deliverable. Vanta delivers a continuous programme. For a business pursuing dual certification and planning to maintain it year on year, that distinction matters significantly."

Shubha Shukla
Head of Operations and Compliance, GraniteStack

TL;DR

  • Challenge: GraniteStack had internal security practices but no formal framework, audit trail, or documentation, meaning it couldn’t easily satisfy enterprise procurement requirements.
  • Solution: GraniteStack deployed Vanta to pursue SOC 2 Type II and ISO 27001 simultaneously, automating AWS evidence collection against a single system of record.
  • ROI: Audit-ready within two weeks, completed both frameworks in about six months, and reduced ongoing compliance effort to 3–4 hours per week. These efforts improved enterprise sales. 

The company

Building enterprise-grade platforms without custom development

GraniteStack is an enterprise platform development company that helps businesses build and launch production-ready SaaS platforms, including web apps, mobile apps, and full business systems, without custom development or lengthy timelines. The platform combines low-code configurability with AI-assisted UX design and automatic API generation, making it a good fit for operationally complex businesses working in high-risk industries. 

The challenge

Enterprise customer procurement required proof, not promises

As enterprise procurement conversations intensified and security questionnaires became routine, the GraniteStack team found they could describe their security posture, but couldn't prove it. 

What GraniteStack tried first: GraniteStack wasn't starting from zero. Its infrastructure was already built on AWS with security controls baked in, and the team had internal documentation of its security practices, tracked across project management tools and spreadsheets. 

“We knew we were doing the right things operationally,” Shubha says, “but we had no formal framework, no audit trail, and no structured way to demonstrate our posture to a client who asked.” The gap wasn't security—it was proof.


GraniteStack's pivot point:  GraniteStack’s founders decided to pursue SOC 2 Type II and ISO 27001 at the same time: SOC 2 for US clients and ISO 27001 for international ones. This meant GraniteStack needed a solution to support both frameworks in parallel while integrating deeply with AWS to automate technical evidence collection.

Why GraniteStack chose Vanta: GraniteStack evaluated several competitors of Vanta alongside traditional consultants. Consultants quoted $30,000–$70,000 for a point-in-time engagement with no automation or ongoing maintenance included. 

Vanta stood out for:

  • Native support for running SOC 2 and ISO 27001 in parallel against a single, continuously monitored system of record
  • Deep AWS integration that automated technical evidence collection
  • Global recognition that carries weight with enterprise procurement teams

The Vanta impact

From informal practices to a continuously monitored compliance program

GraniteStack deployed Vanta to achieve SOC 2 Type II and ISO 27001 frameworks, securing proof of its security posture that enterprise customers demanded. With frameworks in hand, GraniteStack now uses Vanta to run a continuously monitored compliance program.

Here's how GraniteStack deployed Vanta:

Vanta tools and solutions ROI
Automated compliance for SOC 2 Type II and ISO 27001: GraniteStack automated AWS evidence collection and enabled its team to manage task assignments in-platform, which supported asynchronous workflows between Australia and India. Once GraniteStack achieved both certifications, it transitioned into "monitoring mode" with Vanta, reviewing alerts and confirming automated tests are still passing weekly.
  • Passing 70% of controls within a week
  • Two frameworks completed in about 6 months
  • Compliance maintenance reduced from 15-20 hours per week to 3-4 hours per week
  • Eliminated manual evidence collection and handoffs
  • Accelerated documentation by generating workable first drafts from operational context
  • Full program costs less than half what they would have paid for a once off consultant engagement
  • Directly influenced a large-scale deal with a fintech platform
Vanta Agent: GraniteStack used the agent to expedite repetitive work, such as generating policy document first drafts.
  • Human review reserved for strategic judgment calls
Seamless audits: Auditors raised queries and requested evidence directly in the Vanta platform, streamlining the overall process.
  • Eliminated email back-and-forths

Now, compliance is a value-generating asset, benefiting GraniteStack and its clients alike. Clients building on the GraniteStack platform build on infrastructure whose controls have already been audited, which reduces the evidence they have to gather for their own SOC 2, which turns GraniteStack's security posture from a question into both a sales credential and a product feature.

{{quote-2}}

“We can now complete security questionnaires with confidence and point to the certificates rather than offering assurances that have to be taken on trust. That shift changes the dynamic of the conversation entirely."

Shubha Shukla
Head of Operations and Compliance, GraniteStack
Shubha Shukla
Head of Operations and Compliance, GraniteStack