Systems of record never agreed
Meshly's bet isn't on systems of record, it's on systems of trust: the layer that decides whether what two systems say about the same thing can actually be believed. Systems of record never agreed with each other. Meaning got lost in the gaps, and that gap is where revenue leaks, audits stall, and diligence finds the thing nobody knew was there. Companies quietly lose 1 to 5% of EBITDA to it. Not to churn. To systems that don't agree.
The people who used to catch that by hand are being stripped out for efficiency right as agents move in to do the work. That's what we're building guardrails for. Which means the guardrails have to hold up to scrutiny first. So we asked an outside auditor to try to break ours.
Why the auditor mattered more than the platform
The question was never if we'd do SOC 2. It was sequencing: early, or once customers force the issue. We do it early, because security can't be bolted on later when you handle finance data.
I polled our Finance Advisory Board on what mattered most when evaluating a SOC 2. The auditor's reputation came first, by a wide margin, mapping to the two things I was weighing: the validity of the test (we wanted a real test, not a stamp) and our team's time (every hour on compliance is an hour not spent building).
Auditors don't design the controls they audit. Church and state. That's what makes the test real.
What the trifecta did
Vanta paired us with Workstreet, our guide through the process. Prescient Security, independent of both, ran the audit against AICPA SSAE 18 standards. Vanta monitored our systems throughout; our CTO layered on more. It was real work, and most of it fed directly into product decisions we needed to make anyway.
What this proves
For customers, the workflows touching your contracts and revenue data run on systems tested over time, not at a point in time. A Type II report is evidence the controls held up under actual use.
SOC 2 was table stakes. Table stakes doesn't mean easy. It's also not the finish line, it's the first outside party we asked to check our work, and it won't be the last.
Thank you to Prescient Security, Vanta, and Workstreet for the partnership.
