Reshaping SOC 2: How Audits Can Go From Onerous to Motivating

Sanro Health achieved SOC 2 compliance ahead of client deadlines, thanks to the modern audit approach from Sensiba and Vanta.

Sanro Health is a clinician-led healthcare technology provider, focused on scaling solutions that yield the most significant, real-time impact at the point of care. The company specializes in making healthcare data actionable through advanced technology solutions that enhance patient outcomes and optimize healthcare operations. Sanro Health’s core offering is a software platform combining AI image analysis with seamless integration of medical record data and imaging data to accelerate clinical trial recruitment.

  • SOC 2

Challenge

Sanro Health decided to pursue SOC 2 certification to build trust with customers, stakeholders, and investors, and demonstrate their commitment to data security, privacy, and operational excellence.

After going through a comprehensive request for proposal (RFP) process with external consultants, Sanro Health was presented with various manual solutions. Chief of Staff Lucy McCarthy expressed concerns about the traditional approach and her team’s capacity, prompting her to explore alternative solutions. “I was worried about the competing priorities, and the team’s bandwidth to be able to support a remote process of documentation, as well as continue to support our enterprise clients and product development,” she says.

“The way both companies (Sensiba and Vanta) work together it was like they were just meant to be.”

Lucy McCarthyChief of Staff, Sanro Health
Sanro Health

Solution

Further research into SOC 2 led the team at Sanro Health to discover the compliance automation platform Vanta. After initial discussions, the benefits quickly became apparent. “The ease of those first conversations, their responsiveness, competitive pricing, comprehensive visibility, the Trust Center, and especially the continuous monitoring, all ticked the boxes for Sanro Health,” said Karthigeyan Gunaseelan, Head of Engineering.

After onboarding with Vanta, Sanro Health was introduced to several audit partners. However, these firms did not fully align with Sanro Health’s delivery timeframe, time zone compatibility, or budget. After some discussions, they were connected with Sensiba, which had recently announced its partnership with Vanta. By leveraging Vanta’s continuous monitoring, Sanro Health gained clear visibility into where their attention was needed during the audit. Vanta’s support and the ticket-raising feature ensured that any platform-related queries were swiftly resolved, keeping Sanro Health on track.

Aware of Sanro Health’s client deadline, the Sensiba team promptly initiated the audit, providing a Vanta Velocity knowledge base guide. This step-by-step guide offered all the necessary resources for the audit. “It’s very intuitive, easy to access and understandable—even for someone without a technical background like myself,” McCarthy says.

Sensiba’s real-time, responsive feedback made the entire process— from uploading evidence to addressing queries and finalizing the audit—seamless. Behind the scenes, Sensiba’s AI-audit model powered the process, allowing both teams to focus their efforts where they were most needed.

“Partnering with a company that understood our bandwidth and resourcing needs, and approached everything with a pragmatic perspective, made all the difference for us. I think we would have struggled if we had taken the traditional audit route,” McCarthy says.

Result

What initially seemed like a daunting task for Sanro Health turned into a success as they achieved their SOC 2 Type 1 Attestation ahead of schedule, meeting client expectations. By leveraging Vanta’s compliance platform alongside Sensiba’s expertise, transparent support and real-time guidance, Sanro Health reported that they “could not have anticipated a better experience.” Buoyed by this success, Sanro Health is now setting its sights on achieving Type 2 attestation and HIPAA compliance.

Ready to get started?

Find out how our GRC team can help you with your compliance. Contact us to learn more about how we can work together toward your goals.

Ready for more inspiration? Dive into additional client success stories where we showcase diverse projects, innovative solutions, and the transformative impact we’ve had on businesses like yours.