Vendor decision
Compliance platform vs security engineer
Compliance platforms are good products that do a specific job well: they tell you which controls are failing and they collect evidence from the systems they integrate with. What they do not do is fix anything. That gap is not a flaw in the software; it is the boundary of what software can do. The question is who covers it.
We work alongside any compliance platform, and we do not sell one. If you already pay for Vanta, Drata, Secureframe, or anything similar, keep it. Nothing on this page argues you should cancel a subscription. It argues that the subscription and the engineering work are two different line items, and that only one of them is usually on the budget.
What each one actually does
| Job | Compliance platform | Security engineer |
|---|---|---|
| Tell you which controls are failing | Yes. This is the core product and it is good at it | Yes, via a point-in-time scan |
| Continuous monitoring and drift alerts | Yes. Genuinely valuable, especially post-report | Only if they build it, which is a real project |
| Deploy logging, detection, and encryption baselines | No | Yes. Infrastructure-as-code into your account |
| Tighten IAM policies your application depends on | No | Yes, as specified fixes your engineers apply and we verify |
| Provide policy templates | Yes, generic. You customize | Yes, written to how your team actually operates |
| Collect evidence automatically | Yes, for integrated systems | Yes, including the systems with no integration |
| Run your quarterly access review | Reminds you. Does not run it | Yes, facilitated, with the record produced |
| Separate production from development | No | Yes, as an architecture engagement |
| Argue with your auditor on your behalf | No | Yes |
| Cost shape | Annual subscription, ongoing | Project cost, front-loaded, then a retainer if you want one |
Where the gap shows up
The pattern is consistent enough to predict. A team buys a platform, connects AWS and the identity provider, and gets a dashboard with a lot of red. The red items divide into three groups:
- Things a setting fixes. Enable this, turn on that. The platform's guidance is sufficient, and a competent engineer clears them in an afternoon. Maybe a fifth of the list.
- Things that need writing. Twenty-plus policies, an incident response plan, a risk register. Templates exist, but customizing them to how your company actually operates, and getting them approved and acknowledged, is real work that nobody wants to own. This is where most teams stall for months.
- Things that need engineering. The wildcard IAM policy your service depends on. The unencrypted RDS instance from 2024. The single AWS account holding production and development. These are code changes, migrations, and architecture work, and no dashboard reduces them.
Group one is easy, group two is slow, group three is where timelines die. A platform is excellent at telling you all three exist and equally unable to do any of them.
The integration boundary
Platforms collect evidence from systems they integrate with. Every startup has systems they do not integrate with, and those are exactly the ones auditors ask about.
The classic version: a data warehouse holding customer data, accessed through a mechanism the platform cannot see. The dashboard shows green across identity and access because it is reading the identity provider, and the tool with the most sensitive data is not connected to any of it. That surfaces in fieldwork rather than on the dashboard.
The fix is dull and effective: inventory every critical tool that touches customer data or production, on day one, and decide per tool whether evidence is automated or manual. The ones that are manual need an owner and a calendar entry for the entire observation window. Green dashboards measure integrated coverage, not real coverage.
The honest cost comparison
Platform pricing varies enormously by headcount and discount, so compare structure rather than list prices:
| Approach | Cash cost | Your engineering time | Elapsed time to ready |
|---|---|---|---|
| Platform alone | Subscription only | High. All remediation, writing, and evidence chasing | Open-ended. Three to six months is common |
| Platform plus your engineers | Subscription plus internal cost | High, roughly 0.25 to 0.5 FTE for 3 to 6 months | 3 to 6 months, competing with the roadmap |
| Engineer-led readiness, no platform | From $10,000 fixed with us | Low. Application-level fixes, ticketed and scheduled | 6 to 8 weeks |
| Both | Subscription plus readiness | Low | 6 to 8 weeks, with continuous monitoring afterwards |
The row that moves the number is engineering time, not the subscription. Half an engineer for four months at loaded cost is real money that never appears on the compliance budget because it appears on payroll instead.
Which to choose
| Your situation | Sensible move |
|---|---|
| A security-experienced engineer with spare capacity, no hard deadline | Platform alone. You have the scarce ingredient already |
| A blocked enterprise deal and no spare engineering capacity | Engineer-led readiness. Add a platform when the Type 2 window opens |
| Already paying for a platform, stalled after months of red | Keep the platform, add engineering. This is the most common call we take |
| Post-report, running an annual cycle | Both. Continuous monitoring plus someone owning the cadence |
| Not AWS-native, or multi-cloud | Platform plus a provider matched to your stack. We are AWS-only by design |
How they work together
When both are in play the division is clean. The platform is the shared source of truth for control status and the collector for integrated systems. We fix what it flags, cover what it cannot see, write and customize the policy program, run the cadences, and handle the auditor. The platform stays useful long after readiness ends, which is exactly when a project-shaped engagement would otherwise leave a gap.
What we do not do is duplicate it. If your platform collects an artifact well, we use its output rather than building a second pipeline for the same evidence.
Frequently asked questions
Is a compliance platform enough to get SOC 2?
It is enough to know what is wrong and to keep evidence flowing from integrated systems. It is not enough to fix anything. Whether that is sufficient depends entirely on whether you have an engineer with the time and background to do the remediation. If you do, a platform alone is a reasonable path. If you do not, the platform will accurately document your lack of progress.
Do we need a platform if we hire a readiness engineer?
Not for a first Type 1. A platform earns its cost in the Type 2 observation window and afterwards, where continuous monitoring and automated collection meaningfully reduce manual work. Many teams start without one and add it when the window opens.
We already pay for a platform. Are we wasting that money if we hire you?
No. We work alongside it and use its evidence output rather than duplicating it. The subscription covers monitoring and collection; the engagement covers remediation, the policy program, the cadences, and the auditor. Different jobs.
Which compliance platform is best?
We do not rank them and we have no referral arrangement with any of them. For a first SOC 2 on AWS the differences that matter are which of your specific tools they integrate with, and how their evidence exports line up with your auditor's request format. Ask both vendors those two questions with your actual tool list in hand and the choice usually makes itself.
Keep the platform. Get the work done.
We scan your environment against 35 controls, deploy the baseline as infrastructure-as-code you own, write the policy program, ticket the application-level fixes to your engineers, and organize the evidence for your auditor. Six to eight weeks, fixed price, quoted after the scan.
Book a 30-minute scoping callNo pitch deck. We look at your stack and tell you exactly what an audit would flag.