a

Case Study

From 48 Open Audit Findings to 95% Audit-Ready in 12 Weeks

How a mid-market fintech reached its SOC 2 Type II observation period with Vanta and AllCode, with every automated check green and no critical issues left open.

Segment: Mid-market   |   Use Case: Security and Compliance Automation, SOC 2 Type II Readiness   |   Industry: FinTech, B2B Payments and Embedded Lending

Vanta compliance dashboard showing SOC 2 Type II automated test results for AWS infrastructure

SOC 2 Compliance Challenge

48 Findings, One Audit Window

The client is a B2B platform that gives merchants and business buyers instant trade credit at checkout, which means handling sensitive PII and transaction data at scale. A March 2026 Vanta gap analysis surfaced 48 open items standing between the company and a clean SOC 2 Type II report: 26 engineering and technical tasks covering change management, network segmentation, penetration testing, vulnerability scanning, intrusion detection, centralized logging, and device management, plus 22 documentation and governance tasks spanning the system description, risk analysis, vendor management, incident procedures, and board oversight.

The AWS IAM layer carried the most audit risk. Seventeen access keys sat past the 90-day rotation window, the oldest more than five years old. Fourteen users had policies attached directly instead of through groups. The Admin group carried standing full-administrator access, and there was no dedicated AWS support role.

For a B2B lender, enterprise merchant and partner relationships depend on demonstrable security. Without a SOC 2 report, every partner security review becomes a bespoke questionnaire exercise, and stale credentials and standing admin access are real breach exposure, not just audit findings. The observation period was scheduled to open July 1, 2026, and the gap analysis put engineering remediation at 8 to 12 weeks. Work had to start immediately to make the window.

The solution

How AllCode + Vanta Closed the Gaps in 12 Weeks

Vanta was the compliance system of record and the engine that made a 12-week timeline possible. Its gap analysis surfaced the 48 findings and mapped each one to a SOC 2 control, its automated tests then verified every fix in real time, and its evidence automation staged the audit artifacts, replacing the traditional screenshot scramble with a live dashboard.

AllCode, an AWS Advanced Tier Services Partner, was the engineering partner that turned those findings green. We consolidated the 48 findings into a 36-task remediation plan across four phases with clear ownership, then triaged every task into non-negotiables like change management, MFA, penetration testing and vulnerability scanning, high-value automation wins, and right-sizable controls, so effort landed where auditors actually look.

Critical controls

Branch-protection-enforced change management, restricted production deployment access, MFA on all remote production access, quarterly vulnerability scanning with remediation tracking, an isolated production network and cardholder data environment, and configuration management for consistent builds.

IAM overhaul

All 17 stale access keys rotated, human users moved to SSO and federation with temporary credentials, service accounts migrated to IAM roles or automated rotation, direct user policies folded into purpose-specific groups, and standing full-administrator access replaced with scoped policies and an empty break-glass group.

Monitoring and data protection

GuardDuty for intrusion detection, centralized CloudTrail log management, and threshold-based infrastructure monitoring in Datadog. Privileged database access restricted, encryption key access limited to business need, and device compliance satisfied through the Vanta Agent rather than a separate MDM purchase.

Hardening and readiness

Password complexity enforcement, time synchronization, environmental monitoring wired to vendor trust centers, a capacity review process, secure asset disposal, and the user support channel, closing with penetration test validation and a joint audit-readiness review in Vanta.

Governance and documentation

The client owned this track, refreshing 13 core policies in June 2026 including Risk Management, Secure Development, Access Control, Cryptography, Incident Response, and HR Security, and preparing all 205 evidence items for the auditor.

Technology

AWS-Native Controls Powering the Remediation

The remediation stayed AWS-native rather than pulling in a parallel set of compliance tools. GuardDuty handles intrusion detection, CloudTrail provides centralized logging, IAM was rebuilt around groups, roles, and federated sign-in, and vulnerability scanning runs on a quarterly cycle with remediation tracking. Datadog covers threshold-based infrastructure monitoring and GitHub branch protection enforces change management.

Vanta sits across all of it, running 196 automated tests with real-time monitoring spanning AWS, GitHub, MongoDB Atlas, and Google Workspace. The Vanta Agent covered laptop and device compliance, including encryption and screen lock, with no new MDM infrastructure to buy or manage.

Results

Before & After: From 48 Findings to Audit-Ready

Metric Before, March 2026 After, July 2026
Audit readiness 48 open gap-analysis findings, audit at risk 95% of 205 audit requests marked Ready for Audit at observation-period start
Time to readiness 8 to 12 week engineering estimate, no plan in place Delivered in 12 weeks across a four-phase, 36-task plan
Continuous monitoring Manual, point-in-time checks 196 automated Vanta tests passing across AWS, GitHub, MongoDB Atlas, and Google Workspace
Open critical or high issues IAM and change-management findings open across multiple controls Zero critical or high-priority issues open
Stale AWS access keys 17 keys past the 90-day rotation window, the oldest more than 5 years old Zero, with SSO federation and IAM roles replacing long-lived keys
Standing admin access Full administrator policy attached to the Admin group Scoped policies plus an empty break-glass group with just-in-time access
Policy framework Governance documents outdated 13 core policies refreshed and leadership-approved in June 2026
New-hire security onboarding Ad hoc 100% of May and June 2026 hires completed background checks, training, and policy acknowledgment

Business impact

Measurable Impact: SOC 2 Outcomes at a Glance

By the time the observation period opened, 95% of 205 audit requests were marked Ready for Audit, 196 automated Vanta tests were passing, and no critical or high-priority issues remained open. Seventeen stale access keys went to zero, standing administrator access was gone, and 13 core policies had been refreshed and approved by leadership.

Gap-analysis findings closed

%

Of 205 audit requests ready at observation-period start

Automated Vanta tests passing at audit time

Weeks from remediation plan to open observation window