Kairo is one of three security vendors partnered with Vanta, the largest SOC 2 compliance provider. The partnership puts continuous behavioral testing alongside the compliance programme a company is already running, inside the same account, rather than as a separate purchase made a year later when an enterprise deal demands it.
The number that started it
We have found critical or high-severity vulnerabilities in the applications of more than 180 SOC 2 compliant companies. Not companies that had let their compliance lapse, or that were mid-audit. Companies holding a current report, with controls evidenced and an auditor’s signature on the front page.
This is not an indictment of SOC 2. It is a statement about what the framework is for.
What SOC 2 actually proves
SOC 2 proves that you have controls, that the controls are the ones you said you had, and that they operated over a period. It asks whether access is reviewed, whether changes are approved, whether logging exists, whether a vulnerability management process is defined and followed. Those are real questions, and a company that answers them honestly is meaningfully safer than one that cannot.
What it does not ask is whether your order-lookup endpoint returns an account id the UI never displays, or whether an internal reporting tool treats a network position as an identity claim. No control in the framework has an opinion about a chain of four reasonable decisions that becomes a data breach when combined. That is not a gap in the auditor’s work; it is outside the question being asked.
Why the two belong together
- Compliance answers "can you show me your process?" Testing answers "what happens when someone tries?"
- A control can operate perfectly for twelve months while the application it governs ships four hundred changes.
- Buyers increasingly ask for both, and increasingly notice when the second one is a PDF from last year.
- The evidence a simulation produces, a reproduced finding with the request that caused it, is exactly the artefact a vulnerability-management control wants to point at.
How it works in practice
A company running its compliance programme in Vanta can add continuous testing without assembling a second vendor relationship, a second scoping exercise and a second set of security review paperwork. Testing runs continuously against a shadow environment, findings are reproduced before they are reported, and each one arrives where the work happens: on the pull request, in the issue tracker, in the report your auditor will read.
The point is not that compliance is theatre. It is that passing an audit and surviving an attacker are different tests, and a company should be able to sit both without buying two separate companies to sit them.