Home Case Studies

How Celigo Brought SOC 2 Posture for 84 SaaS and AI Apps into One Severity-Ordered View

How Celigo Brought SOC 2 Posture for 84 SaaS and AI Apps into One Severity-Ordered View

“Proving SOC 2 posture across 84 apps used to take weeks before every audit. Now it all sits in one view, sorted by severity, with evidence and a note on every control. When the auditors asked a question, the answer was already in the audit log, and the audit wrapped without our team chasing app owners.”

~ Jessica Mifflin, Senior Director, Cybersecurity & Compliance; DPO, Celigo

‍

31
failing controls found
84
apps under SOC 2 posture tracking
Zero
apps flagged in the SOC 2 audit

31

failing controls found

84

apps under SOC 2 posture tracking

Zero

apps flagged in the SOC 2 audit
Problems
Challenge
  • As the SaaS and AI stack grew to 84 in-scope apps, Celigo's compliance team tracked SOC 2 posture app by app in a spreadsheet.
  • Critical identity controls sat in the same list as low-severity ones, so the team worked them in app order.
  • Some apps could not technically support a control, and those gaps looked the same as failures.
  • The internal 15-minute session-timeout policy was stricter than SOC 2 and was not measured anywhere.

‍

Solutions
Solution
  • SaaS Security Posture Management (SSPM) applied a SOC 2 Type II framework to all 84 apps in one setup.
  • Every control carries a severity and category, and Top Applications by Risk shows where to start.
  • A Not Supporting status records the limitation separately, with a note explaining the compensating control.
  • A custom control measures the internal policy on every app alongside the framework controls.

‍

Profit
Result
  • Pre-audit posture review dropped from seven weeks to nine days.
  • 31 failing Critical controls across 12 apps were found and closed before the audit began.
  • 9 apps were documented as Not Supporting, and the auditors flagged none of them.
  • 14 apps were brought into line with the session-timeout policy within the quarter.

‍

Challenge

Celigo, the integration platform company, runs an annual SOC 2 Type II audit. As its stack grew to 84 in-scope applications, including the AI tools the business had approved, the cybersecurity and compliance team assessed security posture through a manual pass before each audit. 

Analysts checked each app for MFA, SSO, access removal on termination, and privileged access, then recorded the results in a spreadsheet, with evidence collected separately. 

Two gaps made each audit harder to prepare for. Some apps could not support a control at all, such as tools without SSO, and in the spreadsheet those looked identical to failures, so each one had to be explained to the auditors again. 

Ahead of the next audit cycle, Celigo needed one place to measure posture by severity, record why each status was set, and keep the evidence attached to the control.

‍

Solution
  • The team created a framework from the SOC 2 Type II base template, added the controls in scope, and applied it to all 84 applications in a three-step setup.
  • Each control on each app shows Passed, Failed, Need Verification, or Not Supporting, so a control nobody has checked yet, a failure, and a technical limitation each look different.
  • Every control carries a category, such as Identity and Access or Data Protection, and a severity from Critical to Low. Top Applications by Risk shows which apps to open first.
  • The Update Posture panel sets a control's status, accepts an evidence file, and records a note in the control's audit log along with who made the change.
  • One view shows the global pass rate, active Critical and High risks with the change since the previous day, and the pass percentage for each framework.
Why CloudEagle.ai?

Celigo evaluated several options and chose CloudEagle.ai because it could prove SOC 2 posture without adding another tool to the stack.

  • A natural extension of the SaaS management platform already in place. CloudEagle.ai was already a leader there, so posture tracking ran on the same app inventory and one setup covered all 84 apps.
  • Ready-made SOC 2 Type II controls, so there was no control list to build from scratch, and internal policies like the 15-minute session timeout sit on the same scorecard.
  • Nothing hidden. EagleIQ's seven telemetries find apps even when they never go through SSO, so the apps in scope match the real stack.
  • Audit answers without the chase. Evidence and a note sit on every control, so an auditor's question is answered from the audit log.
  • One product for two pressing problems. SOC 2 posture and AI tool governance were both urgent, and CloudEagle.ai covered both with the same controls and no separate review.
Impact

Audit-Ready Posture Evidence

  • All 84 in-scope SaaS and AI apps are tracked against one SOC 2 Type II framework, with a pass rate for every app and for the framework as a whole.
  • Auditor questions are now answered directly from each control's audit log, with the evidence and the reason for every status already attached.
  • The SOC 2 Type II pass rate is a standing line in Celigo's audit committee reporting, so posture is tracked all year instead of rebuilt before each audit.

‍

Immediate Security Improvements

  • 31 failing Critical controls across 12 apps were found and closed before the audit began.
  • The team starts each week from the severity-ordered list, so new Critical gaps are worked first rather than discovered during the next audit.
  • Active Critical and High risks are tracked day over day in the Security Posture Summary, and the approved AI tools sit under the same SOC 2 controls as the rest of the stack.

‍

Sustained Posture Governance

  • The SOC 2 Type II audit closed with zero apps flagged by the auditors.
  • Apps that can't support a control are marked Not Supporting with the compensating control recorded, so those decisions carry forward to every future audit.
  • Internal policies like the 15-minute session timeout are measured on every app as custom controls, and new apps are added to the framework as they come into scope.

‍

The Transformation

Before CloudEagle
The team tracked SOC 2 posture app by app in a spreadsheet before each audit.
Critical identity controls sat in the same list as low-severity ones.
Evidence was collected separately and pieced together when auditors asked.
Apps that couldn't support a control looked like unexplained failures.
The internal session-timeout policy was written down but never measured.
After CloudEagle
Check box
One SOC 2 Type II framework shows posture and pass rate across all 84 apps.
Check box
Controls are sorted by severity, so Critical identity controls were closed first.
Check box
Every status update carries an evidence file and a note in the control's audit log.
Check box
Not Supporting status records the limitation and the compensating control behind it.
Check box
A custom control measures the 15-minute timeout policy on every app.

Achieve similar success with CloudEagle!