BlogSecurity
January 16, 2025

Pre-product security takes priority at Push

Written by
Vanta
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

THE COMPANY

Pushing the envelope in online payments

Push is a cutting-edge online payment platform dedicated to safeguarding customer data. Founded by a team with roots at Plaid, Push has embedded security into the core of its operations. In partnership with Vanta and VioletX, Push has established a foundation where security is not just a priority but a fundamental value.


THE CHALLENGE

Building trust in a competitive digital landscape

Recognizing the paramount importance of security and compliance, Push's co-founders, Eric and Andrew, understood that their platform's success hinged on reassuring users about their robust security measures. The increasing demand for transparency and compliance with standards like SOC 2 and ISO 27001 created a pressing challenge: achieving these certifications with a growing team and limited resources.

As Push grew, navigating complex security reviews and compliance attestations under tight client deadlines became a significant hurdle. They needed a solution to efficiently establish trust while maintaining their focus on innovation.

THE SOLUTION

Strategic partnerships for seamless security

To address these challenges, Push partnered with Vanta for automated compliance solutions and VioletX for hands-on strategic guidance in security and compliance.

VioletX played a pivotal role in developing and implementing a comprehensive SOC 2 framework tailored to Push's needs. By aligning security practices with the company's operations, VioletX ensured that Push's security posture met industry standards. Their expertise also helped prioritize critical security investments, working directly with engineering teams to resolve vulnerabilities, establish clear policies, and prepare for a successful SOC 2 audit.

Meanwhile, Vanta's automated compliance tools streamlined ongoing monitoring and evidence gathering, reducing the internal team's workload and enabling a proactive approach to compliance across various frameworks.

THE IMPACT

Security as a catalyst for growth

The combination of Vanta's automation and VioletX's in-depth security expertise enabled Push to achieve a SOC 2 report quickly and efficiently. VioletX’s collaborative approach not only ensured compliance but also established a culture of security across Push’s team, laying a solid foundation for future growth.

By demonstrating their commitment to security, Push has positioned itself as a trusted player in the digital payments industry. The strategic integration of advanced tools and expert guidance has not only built trust among users but also set the stage for sustainable expansion in a competitive market.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.