Dmitry Yackevich
FLO HEALTH · SECURITY · 2 MIN READ

ISO 27001 without killing velocity

ISO 27001
nine months · 100% audit score
Company
Flo Health
Role
Security Engineering Lead
When
Dec 2020 – Aug 2022
Result
ISO 27001 certified, with Vanta
In public
Flo’s announcement

For a company holding health data, trust isn't a feature — it's the product. When ISO 27001 landed on Flo's roadmap, everyone knew why it mattered. Everyone also knew the horror stories: certification programmes that turn engineering into paperwork and grind shipping to a halt.

I was leading security engineering, and I made one bet early: compliance is an engineering problem pretending to be a paperwork problem. So instead of hiring a wall of consultants, I introduced Vanta — compliance automation — and made it the backbone of the programme.

Auditors want evidence. Engineers want to ship. Automation is the peace treaty.

Vanta plugged into the estate — cloud accounts, identity provider, endpoints, repos — and turned compliance from an annual archaeology dig into a continuously monitored system: every control checked automatically, every gap surfaced as a task, every fix verified the moment it shipped. The shift-left pipeline we'd already built with Terraform and Snyk meant most controls were satisfied by how engineers already worked.

Evidence collection — the part that usually eats months of screenshots — became a by-product. Vanta gathered it continuously in the background; when the auditors arrived, the audit trail already existed.

The result: ISO 27001 in nine months, with a 100% audit score — the first period tracker to get there, per Flo’s announcement — and engineers barely changed how they worked. The secure path and the easy path were the same path, and the paperwork did itself. That's the whole trick, and it's the same trick whether the auditor is ISO, a regulator, or your own future incident review.

Next story →
A delivery stream from zero

Working on the same problems? Let's talk.

✉ Email me