ISO 27001 without killing velocity
- Company
- Flo Health
- Role
- Security Engineering Lead
- When
- Dec 2020 – Aug 2022
- Result
- ISO 27001 certified, with Vanta
- In public
- Flo’s announcement
For a company holding health data, trust isn't a feature — it's the product. When ISO 27001 landed on Flo's roadmap, everyone knew why it mattered. Everyone also knew the horror stories: certification programmes that turn engineering into paperwork and grind shipping to a halt.
I was leading security engineering, and I made one bet early: compliance is an engineering problem pretending to be a paperwork problem. So instead of hiring a wall of consultants, I introduced Vanta — compliance automation — and made it the backbone of the programme.
Auditors want evidence. Engineers want to ship. Automation is the peace treaty.
Vanta plugged into the estate — cloud accounts, identity provider, endpoints, repos — and turned compliance from an annual archaeology dig into a continuously monitored system: every control checked automatically, every gap surfaced as a task, every fix verified the moment it shipped. The shift-left pipeline we'd already built with Terraform and Snyk meant most controls were satisfied by how engineers already worked.
Evidence collection — the part that usually eats months of screenshots — became a by-product. Vanta gathered it continuously in the background; when the auditors arrived, the audit trail already existed.
The result: ISO 27001 in nine months, with a 100% audit score — the first period tracker to get there, per Flo’s announcement — and engineers barely changed how they worked. The secure path and the easy path were the same path, and the paperwork did itself. That's the whole trick, and it's the same trick whether the auditor is ISO, a regulator, or your own future incident review.
Next story →