Case Study
From 48 Open Audit Findings to 95% Audit-Ready in 12 Weeks
How a mid-market fintech reached its SOC 2 Type II observation period with Vanta and AllCode, with every automated check green and no critical issues left open.
Segment: Mid-market | Use Case: Security and Compliance Automation, SOC 2 Type II Readiness | Industry: FinTech, B2B Payments and Embedded Lending
SOC 2 Compliance Challenge
48 Findings, One Audit Window
The client is a B2B platform that gives merchants and business buyers instant trade credit at checkout, which means handling sensitive PII and transaction data at scale. A March 2026 Vanta gap analysis surfaced 48 open items standing between the company and a clean SOC 2 Type II report: 26 engineering and technical tasks covering change management, network segmentation, penetration testing, vulnerability scanning, intrusion detection, centralized logging, and device management, plus 22 documentation and governance tasks spanning the system description, risk analysis, vendor management, incident procedures, and board oversight.
The AWS IAM layer carried the most audit risk. Seventeen access keys sat past the 90-day rotation window, the oldest more than five years old. Fourteen users had policies attached directly instead of through groups. The Admin group carried standing full-administrator access, and there was no dedicated AWS support role.
For a B2B lender, enterprise merchant and partner relationships depend on demonstrable security. Without a SOC 2 report, every partner security review becomes a bespoke questionnaire exercise, and stale credentials and standing admin access are real breach exposure, not just audit findings. The observation period was scheduled to open July 1, 2026, and the gap analysis put engineering remediation at 8 to 12 weeks. Work had to start immediately to make the window.
The solution
How AllCode + Vanta Closed the Gaps in 12 Weeks
Vanta was the compliance system of record and the engine that made a 12-week timeline possible. Its gap analysis surfaced the 48 findings and mapped each one to a SOC 2 control, its automated tests then verified every fix in real time, and its evidence automation staged the audit artifacts, replacing the traditional screenshot scramble with a live dashboard.
AllCode, an AWS Advanced Tier Services Partner, was the engineering partner that turned those findings green. We consolidated the 48 findings into a 36-task remediation plan across four phases with clear ownership, then triaged every task into non-negotiables like change management, MFA, penetration testing and vulnerability scanning, high-value automation wins, and right-sizable controls, so effort landed where auditors actually look.
Critical controls
IAM overhaul
Monitoring and data protection
Hardening and readiness
Governance and documentation
Technology
AWS-Native Controls Powering the Remediation
The remediation stayed AWS-native rather than pulling in a parallel set of compliance tools. GuardDuty handles intrusion detection, CloudTrail provides centralized logging, IAM was rebuilt around groups, roles, and federated sign-in, and vulnerability scanning runs on a quarterly cycle with remediation tracking. Datadog covers threshold-based infrastructure monitoring and GitHub branch protection enforces change management.
Vanta sits across all of it, running 196 automated tests with real-time monitoring spanning AWS, GitHub, MongoDB Atlas, and Google Workspace. The Vanta Agent covered laptop and device compliance, including encryption and screen lock, with no new MDM infrastructure to buy or manage.
Results
Before & After: From 48 Findings to Audit-Ready
| Metric | Before, March 2026 | After, July 2026 |
|---|---|---|
| Audit readiness | 48 open gap-analysis findings, audit at risk | 95% of 205 audit requests marked Ready for Audit at observation-period start |
| Time to readiness | 8 to 12 week engineering estimate, no plan in place | Delivered in 12 weeks across a four-phase, 36-task plan |
| Continuous monitoring | Manual, point-in-time checks | 196 automated Vanta tests passing across AWS, GitHub, MongoDB Atlas, and Google Workspace |
| Open critical or high issues | IAM and change-management findings open across multiple controls | Zero critical or high-priority issues open |
| Stale AWS access keys | 17 keys past the 90-day rotation window, the oldest more than 5 years old | Zero, with SSO federation and IAM roles replacing long-lived keys |
| Standing admin access | Full administrator policy attached to the Admin group | Scoped policies plus an empty break-glass group with just-in-time access |
| Policy framework | Governance documents outdated | 13 core policies refreshed and leadership-approved in June 2026 |
| New-hire security onboarding | Ad hoc | 100% of May and June 2026 hires completed background checks, training, and policy acknowledgment |
Business impact
Measurable Impact: SOC 2 Outcomes at a Glance
By the time the observation period opened, 95% of 205 audit requests were marked Ready for Audit, 196 automated Vanta tests were passing, and no critical or high-priority issues remained open. Seventeen stale access keys went to zero, standing administrator access was gone, and 13 core policies had been refreshed and approved by leadership.
Gap-analysis findings closed
%