Although certifications for security management practices like SOC 2 and ISO 27001 have been around for some time, the number of companies now requiring their software vendors to pass (and pass) audits to be in compliance with these they continue to increase. For many companies, this is a heartbreaking process, so perhaps it's not surprising that we're also seeing an increase in startups aiming to simplify this process. Earlier this month, Strike Graph, which helps automate security audits, announced its $ 3.9 million round and today Secureframe, which also helps companies achieve and maintain SOC 2 and ISO 27001 certifications. , announces a $ 4.5 million round.
Secureframe's round was co-led by Base10 Partners and Google's Gradient Ventures fund focused on artificial intelligence. BoxGroup, Village Global, Soma Capital, Liquid2, Chapter One, Worklife Ventures and Backend Capital participated. Current customers include Stream, Hasura and Benepass.
Shrav Mehta, co-founder and CEO of the company, has spent time in several companies, but tells me that the idea for Secureframe was born mainly during his time at the Lob direct mail service.
"When I was at Lob, we faced a lot of security and compliance issues because sometimes we were dealing with very sensitive data and skipping customer calls, had to complete thousands of lines of security questionnaires, do comprehensive security reviews, and that was a lot for a startup our size at the time. But that's just what our clients needed. So I started to see that pain, "Mehta said.
After working at Pilot and Scale AI after leaving Lob in 2017, and informally helping other companies manage the certification process, he co-founded Secureframe along with the company's CTO, Natasja Nielsen.
"Because Secureframe basically adds a lot of automation to our software and makes the process so much simpler and easier, we are able to reduce costs to a point where this is something that many more companies can afford," Mehta explained. "This is something everyone can do from day one, and they don't really have to worry about, 'hey, it's going to take all our time, it's going to take a year, it's going to cost a lot of money." [...] We are trying to solve this problem to make it extremely easy for every organization to be safe from day one. "
The main idea here is to make the arcane certification process more transparent and streamline the process by automating many of the more laborious tasks of preparing for an audit (and it's pretty much always the pre-audit process that takes the most time). Secureframe does this by integrating with the most used cloud and SaaS tools (currently connecting to around 25 services) and extracting data from them to check your security status.
"It looks a lot like a QuickBooks or TurboTax-like experience, where we'll essentially ask you to fill in basic details about your business. We try to auto-populate as much as possible from third-party sources, so we ask you to link all integrations. used by your company, "Mehta explained.
The company plans to use much of the new funding to recruit and make these integrations. Over time, it will also add support for other certifications such as PCI, HITRUST, and HIPAA.
