Magazine

Strike Graph Raises $3.9M to Help Automate Security Audits – ProWellTech

Posted on the 05 October 2020 by Thiruvenkatam Chinnagounder @tipsclear

Compliance automation isn't exactly the coolest topic, but security audits are big business, and companies aiming to get SOC 2, ISO 207001, or FedRamp certified can often spend six figures to complete the process with the help from an audit service. Seattle-based Strike Graph, which launches today and announces an initial $ 3.9 million funding round, wants to automate this process as much as possible.

The company's funding round was led by Madrona Venture Group, with the participation of Amplify.LA, Revolution's Rise of the Rest Seed Fund and Green D Ventures.

Strike Graph co-founder and CEO Justin Beals tells me that the idea for the company came to him during his time as CTO to machine learning startup Koru (which had a bit of a weird release last year). To gain enterprise adoption of that service, the company needed to achieve SOC 2 security certification. "It was a real challenge, especially for a small business. Speaking to my colleagues, I just recognized how challenging it was across the board. And so when it came time for the next startup, I was just very curious, "he told me.

Together with his co-founder Brian Bero, he incubated the idea at Madrona Venture Labs, where he spent some time as an entrepreneur in residence after Koru.

Beals argues that today's process tends to be slow, inefficient and expensive. The idea behind Strike Graph, unsurprisingly, is to remove as many inefficiencies as is currently possible. The company itself, it is worth noting, does not provide the actual audit service. Companies will still have to hire an audit service for this. But Beals also argues that most of what companies pay today is pre-audit preparation.

"We do all that prep and prep work and then, after your first audit, you have to go and renew every year. So there is an important retention of this information. "

When clients turn to Strike Graph, they fill out a risk assessment. The company takes this and can then provide them with controls on how to improve their security status, both to pass the audit and to protect their data. Beals also noted that Strike Graph will soon be able to help companies automate the collection of audit evidence (e.g. your encryption settings) and will be able to enter it regularly. Certifications such as SOC 2, after all, require companies to have security practices in place and be reviewed every 12 months. Automated Evidence Collection will launch in early 2021, once the team creates the first set of integrations to collect that data.

This is where the company, which caters primarily to midsize businesses, plans to spend much of its new funding. Additionally, the company plans to focus on its marketing efforts, primarily on content marketing and educating its potential clients.

"Any business, large or small, that sells a software solution must meet a broad set of security and privacy compliance requirements. Obtaining certifications can be cumbersome, opaque and expensive. Strike Graph is applying intelligent technology to this problem: they help the company identify the appropriate risks, allow for trouble-free auditing, and then automate compliance and testing in the future, "said Hope Cochran. Managing Director at Madrona Venture Group. "These audits were a necessary issue when I was a CFO and Strike Graph's elegant solution brings teams across the company together to move the business forward faster."


Back to Featured Articles on Logo Paperblog