As a founder, Emma Lawler felt like SOC 2 was a major distraction from building.
But when she started selling to enterprise logos, it became something that was impossible to ignore.
Now, as Product Lead at Rippling, she channeled her first-hand experience of getting SOC 2 compliant to rethink how all automated compliance frameworks are run.
It started with a retro.
Every other SOC 2 vendor works the same way:
Detect a problem
Alert your team
Fix it...somewhere else
The problem with this checklist is that "somewhere else" requires dozens of additional integrations. Because these vendors are just reporting layers on top of your stack.
Rippling is your stack.
Which means most of your compliance evidence is collected before you start AND when there's a gap in compliance, Rippling fixes it.
Unencrypted device --> encrypt it.
Wrong app access --> de-provision automatically
Incomplete security training --> gate system access until its done.
Because compliance really isn't about the report. It's about operating your company securely -- and proving it without a yearly fire drill.
Emma shares more about how her own founder journey influenced building Rippling's powerful new automated compliance product, available today for SOC 2 Type 1 and 2.
🎙️ Emma Lawler, Product Lead, Rippling on Fondo START pod
00:57 Introducing Rippling Automated Compliance
02:07 The evolution of compliance software
03:02 AI's role in compliance workflows
03:41 Understanding SOC 2 requirements
04:20 Compliance and enterprise procurement
05:03 Building secure operating practices
05:46 Product development at Rippling
06:28 Building with a lean team
07:15 Lessons from founding startups
08:55 Learning through product pivots
11:01 AI in modern product development
12:41 Planning and research with AI
16:05 Defining product-market fit
17:56 Using first-party data for compliance
21:35 Advice for early-stage founders
Check out www.rippling.com/products/it/automated-compliance