Two Attestations, Same Discipline
We're announcing two milestones today. TigerTrust has completed its SOC 2 Type 2 audit covering the Security, Availability, and Confidentiality trust service criteria over a 12-month observation window, and TigerTrust is now ISO/IEC 27001 certified against the 2022 standard.
The formal reports and the certificate are available under NDA to prospects and customers on request. If you're evaluating TigerTrust for a regulated deployment, ask your account contact for a copy.
What This Means for Customers
Every enterprise customer we've onboarded in the last twelve months asked the same question in some form: what proof do we have that TigerTrust runs its own house the way it asks us to run ours? The two attestations answer that question with the same evidence a Big Four auditor would look at.
Concretely:
- SOC 2 Type 2 confirms the controls we described in our Type 1 report were operating effectively over time, not just present on paper. Type 2 is the version enterprise procurement teams actually accept in vendor risk reviews.
- ISO 27001:2022 confirms we operate an Information Security Management System aligned to the international standard, including the Annex A controls that map to most other regulatory frameworks (PCI DSS, HIPAA, GDPR, DORA) via crosswalk.
Together they cover roughly 90% of the substantive questions in a typical enterprise security questionnaire. For customers, that shortens the vendor onboarding cycle from weeks to hours — hand the report, done.
The Real Cost of Getting Here
The compliance industry has a well-earned reputation for pricing that scales with buyer anxiety rather than actual work. Talk to five audit firms and five compliance platform vendors and you'll get quotes ranging from $13K to $25K for a first-year SOC 2 Type 2 program, and another $9K to $20K for ISO 27001 running in parallel.
We did both, and the total spend was a small fraction of that range. Not because we cut corners — the auditors did their job and we did ours — but because we picked a compliance platform that packages the pieces most vendors sell separately.
Why We Picked Lowerplane
We ran a comparison of the six best-known compliance platforms before starting the program. What was surprising was how the pricing model itself varied. Most vendors charge for the platform, then invoice separately for implementation support, then again for the audit-firm portal, then again for each additional framework. A single-framework SOC 2 quote at $13K could balloon into a $45K+ engagement once ISO 27001, implementation hours, and the auditor portal were priced in — before an auditor had signed anything.
Lowerplane took a different position. Platform, implementation support, and the auditor-facing portal are one package at one price. Adding ISO 27001 alongside SOC 2 didn't multiply the invoice — it extended the same subscription.
The technical experience matched the pricing story:
- Evidence collection is agent-driven and mostly automatic. AWS controls, GitHub controls, employee onboarding events, and endpoint compliance flow into the platform without a human copying screenshots into a spreadsheet.
- Framework crosswalks are built in. Our SOC 2 CC controls map to ISO 27001 Annex A controls without duplicate evidence uploads. One control satisfies both frameworks where the standards overlap, which is most of them.
- The auditor portal is the same portal. Our SOC 2 auditor and ISO 27001 certification body both worked out of the same evidence room, which cut back-and-forth by roughly half.
- Implementation support is included, not an add-on. When we had questions about scoping the Trust Services Criteria or writing a control narrative that matched our actual system, we got answers from Lowerplane's team without a change order.
For a company at our stage — a real enterprise product with real security expectations but not a Fortune 500 compliance budget — that pricing structure made both attestations affordable. If you're evaluating compliance platforms, look at their pricing page carefully and compare like-for-like — bonus points for a platform whose evidence collectors and native integrations span the AWS, GitHub, HR, and endpoint sources you already run, so most controls prove themselves automatically.
What Changed Internally
Compliance is not a paperwork exercise if you actually intend to build product on top of it. The Type 2 window forced us to ship durable changes rather than sprint through a checklist:
- Access reviews became quarterly and evidenced automatically. Every workspace, every access grant, exported to the compliance platform on schedule.
- Vendor risk reviews got a real cadence. Every third-party we depend on is re-reviewed annually, tracked in the platform, tied to a control.
- Incident response is documented and drilled. We ran two tabletop exercises during the observation window, both under 60 minutes, both logged with outcomes and corrective actions.
- Employee onboarding and offboarding is automated. New hires clear security training, sign policies, and receive least-privilege access in a workflow that logs itself. Departures revoke access within business hours with evidence attached.
- Change management on the product side is auditable end-to-end. Every production change goes through a reviewed pull request tied to a Linear ticket that maps back to a business need — the exact chain of evidence a Type 2 auditor wants to see.
None of these were new inventions for the audit. They're what we already wanted to be doing. The audit just forced us to prove we were doing them consistently and gave us the tools to demonstrate it without engineer-hours spent generating screenshots.
Requests From Customers Since the Announcement
We rolled the news out to a few named prospects a week ahead of the public announcement and the response was immediate:
- Three vendor risk questionnaires got closed the same day the report landed with procurement.
- Two customers moved forward on contracts that had been parked pending SOC 2 Type 2.
- One customer's InfoSec team asked which platform we used and adopted Lowerplane themselves within the month.
The last one wasn't planned but tracks with our own experience. If you're a startup or scale-up looking at your first SOC 2 Type 2 or your first ISO 27001, the platform choice does most of the work of setting a realistic budget. We picked what worked for us; your mileage may vary but it's worth the comparison shopping.
What's Next
The immediate work is maintenance — running the ISMS, keeping evidence current, preparing for next year's Type 2 continuation and the ISO surveillance audit. On the product side, we're using our own experience to inform the compliance-adjacent features we ship: the audit-log export shape, the evidence bundle format, the customer-facing trust center. Everything that makes it easier for our customers to answer their own compliance questions using TigerTrust as the source of truth.
If you're a customer or prospect who wants a copy of either report under NDA, reach out through your account contact or the contact form. If you're evaluating compliance automation software and want a candid opinion on how we chose Lowerplane, we're happy to talk — start with the best affordable compliance platform for SOC 2 and ISO 27001 and bring the specifics: your framework scope, target audit window, and current evidence-collection pain points.
Building trust one attestation at a time.