Octopus Deploy lgo in white pill shape box
quote icon

“I love the flexibility of AssuranceLab. The entire team carries the mentality of ‘let’s set the audit over an entire window, but at various points in time, we can shift that window if needed… The personalised service AssuranceLab brings to the table is very nice, and having people in our time zone and supporting local is a huge benefit.” 

Jim Burger 1
CASE STUDY
Octopus Deploy lgo in white pill shape box

Using the best in technology and modern, agile audit services to achieve multi-standard compliance

How software development company, Octopus Deploy, streamlined compliance activities using Vanta and AssuranceLab.

INTRODUCTION TO OCTOPUS DEPLOY
Australian-born software company Octopus Deploy is on a mission to take the panic out of software deployments. 

When companies and developers deploy new features, there is a range of risks. From accidentally breaking something to the wrong configuration, this can lead to a website that doesn’t work how it should. Their platform helps developers and companies consistently deploy software features into environments, making it a repeatable and calm process.

BEGINNING THE COMPLIANCE JOURNEY

With the goal to move into the global enterprise space, Octopus Deploy began looking at the requirements of enterprises in Europe and the United States. This involved the different compliance standards, and which ones were considered world-class to these enterprises. It was quickly discovered that ISO 27001 in Europe and SOC 2 in the United States were going to be key for Octopus Deploy to win clients in each region.
 
When looking at each framework and the individual requirements, it became apparent that there was a lot of overlap between the standards. This resulted in Octopus Deploy's decision to complete both frameworks. They started with ISO 27001 and laid SOC 2 over that, with a few additional controls.
 
With their plan in place, Octopus Deploy started looking for audit firms and the most efficient way to achieve their goal.

DISCOVERING COMPLIANCE AUTOMATION

After first hearing about Vanta at a conference. Octopus Deploy’s CEO spoke with Jim Burger, Director of Information GRC at Octopus Deploy, about using the platform on their compliance journey. Wanting to ensure they had all available information, the team looked at several different platforms, ultimately signing with Vanta.

“They had the right price point and maturity for us at the time, and we wanted to use software that had an equal or better security posture to ours. The major selling point for Vanta was that the people leading their compliance function had all worked for a leading compliance standard company. This held a lot of weight for me,” said Jim.

DISCOVERING A NEW AND BETTER WAY OF AUDITING

After working with a traditional audit firm that had time zone challenges, Octopus Deploy started looking for an audit partner who was not only in a better time zone but could also meet their agile requirements. “We practice agile delivery ourselves, and there had to be a better way to do this. Because we are a remote-first company, we needed something that was really agile alongside us,” said Jim.

After conducting a search looking for the terms ‘agile’ and ‘audit’ and speaking to Vanta, AssuranceLab stood out as the preferred audit partner. 

“I was overjoyed to see that it (AssuranceLab’s approach) would save us a lot of heartache and pain,” said Jim. 

Octopus Deploy began working with AssuranceLab in 2022 and continues to work with the team today.

WORKING THROUGH THE AUDIT PROCESS

Octopus Deploy’s deadlines were driven by contractual obligations, where SOC 2 would be needed when the contract started. All three teams set their sights toward the goal, ultimately seeing Octopus Deploy achieve its compliance goals within deadlines.
 
Whilst there were some unexpected things that came up throughout the process, Jim highlighted that the overall process went well and the communication from AssuranceLab was fantastic.

“Having a Slack connect channel was a very positive thing, as it gave me a lot of confidence. The speed of delivery from both teams and the turnaround time on the report were great. The use of AI in the auditing process, particularly during the QA process really aided in this,” said Jim.

With the immense overlap between SOC 2 and ISO 27001, Octopus Deploy was able to align its teams on one goal and narrow concentration. “Completing SOC 2 and ISO 27001 together allowed for synergy within the team. Having the team focused on audits from both angles allowed us to concentrate on the activities. We found having all tasks condensed into one quarter allowed us to shift our focus to maintenance for the rest of the year,” said Jim.

KEEPING EVERYONE ON TRACK

Like most things, achieving compliance requires focus from everyone involved. This is no different for Octopus Deploy, which made it its team's goal for Q4 2024 to focus on audit readiness. There were a few aspects of the process that really helped with this.
 
“The numbers showed we had some work to do, but having those metrics was really powerful. It enabled me to not only communicate and plan with my team but also communicate progress back up the line. People love data, and having the ability to see our progress is very motivating."

“It would have been a lot harder to have the metrics and continual improvement without a tool like Vanta,” said Jim.

THE IMPACT OF VANTA

The power of Vanta’s automation, metrics, and dashboards meant that at a glance, the Octopus Deploy team knew where they stood. This was particularly helpful for app/user syncing and the ability to instantly know if something/someone had dropped out of compliance. There was no waiting or manual checking. Couple this with the ability to assign tasks to people directly in the platform, and Vanta proved to be a powerful compliance tool.
 
“Vanta really just takes the pain out of the ‘how am I going to establish the metrics/framework and address all the audit requirements?’ As a cloud-first, remote-first company, I can’t just go and look at a server rack; we rely on automation and tools that are done properly for these things. The vast array of Vanta integrations achieves this. Nearly everything is already in there.”

“Businesses who don’t use compliance automation tools don't realise how much of a problem they’ve got… if I wasn’t using Vanta, I would need a team of 30 people to do what we’ve done with 3,” said Jim

THE IMPACT OF ASSURANCELAB

Working with a local team that could provide agile audits was important to Octopus Deploy, which needed an audit firm that could keep up with them as a cloud-first, remote-first business. Whilst there was a deadline to work towards, Octopus Deploy didn’t know when they would be completely ‘audit ready’, and the flexibility and onboarding into the framework that AssuranceLab provided around this was immensely beneficial.

“I love the flexibility of AssuranceLab. The entire team carries the mentality of ‘let’s set the audit over an entire window, but at various points in time, we can shift that window if needed. An example of this is that we recently acquired a new company and needed more time to get them onboarded, and that flexibility really helped us. The personalised service AssuranceLab brings to the table is very nice, and having people in our time zone and supporting local is a huge benefit,” said Jim.

THE IMPACT OF SOC 2 AND ISO 27001

For Octopus Deploy, compliance was not another box-ticking exercise but rather an opportunity for a fresh perspective on a hard problem. In achieving compliance, they have not only bettered their systems but can reassure clients that their product is secure.
 
Octopus Deploy has continued to open doors in the enterprise space and ultimately increase its bottom line. From an internal perspective, the team now considers and uses compliance best practices for decision-making.

RECOMMENDATIONS FOR FUTURE COMPANIES

When asked if Jim would recommend compliance to other companies, he said, “Absolutely, but it does depend on their industry. ISO 27001 is relevant for a wide range of companies, but for a technology/SaaS company, SOC 2 is more relevant.” He also shared his recommendations for companies looking at Vanta and AssuranceLab: “Yes, I would recommend them and have done so in the past.”

THE FUTURE FOR OCTOPUS DEPLOY

Octopus Deploy has its sights set on a bright future. Its goal is to continue its growth over the past 10 years and find new and exciting ways to service its customers. With some exciting updates coming soon for enterprises (watch this space), they are well-positioned to achieve this.
 
From a compliance perspective, the team is working towards the goal of being compliance-ready year-round and building on evidence uploads and timeline learnings from past audits. 

If you would like to experience the AssuranceLab difference yourself, contact our team: info@assurancelab.com.au 

alab-soc2-image
GET IN CONTACT

Get started your way

We’re ready when you are
If you’re ready for a no-obligation discussion on your compliance needs and goals, our friendly team will be happy to take your call.