How Floworks switched from a legacy GRC tool and fast-tracked multi-framework compliance with ComplyJet

Sales & CRM
10-50
Employees

When you're a Y Combinator-backed company with 500+ customers and growing fast, compliance can't be an afterthought. It has to move at the same speed as the product.

Floworks builds AI-powered sales agents that handle prospecting, email outreach, LinkedIn engagement, and meeting scheduling for B2B teams. Their platform processes sensitive customer data — contact information, email conversations, CRM records — at scale. Enterprise buyers expect proof that this data is protected.

Floworks had already gone through a SOC 2 engagement with a previous GRC platform. But when renewal came around, the team decided it was time for something better.

Why They Switched

Floworks had been using a popular GRC tool for their SOC 2 program. The platform got the job done, but the experience left gaps — particularly around integrations, evidence collection, and hands-on support.

At renewal, instead of re-signing, the team evaluated alternatives. What they wanted was simple:

  • A platform with strong, working integrations — not ones that looked good on a features page but didn't deliver
  • Better evidence collection that actually reduced manual work
  • A team that would stay involved, not just hand over a dashboard and disappear

Sarthak Shrivastava, Floworks' CEO, had already been in touch with the ComplyJet team. When it was time to make the switch, the decision was straightforward.

What Made It Different

Floworks signed a long term contract with ComplyJet covering SOC 2, ISO 27001, and GDPR — three frameworks under one platform, one price.

The onboarding was fast. Ritesh Kumar, Floworks' CTO, took point on the technical setup. Within the first week, he had connected the core infrastructure:

  • AWS for production and security controls
  • GitHub for source code and development workflows
  • Google Workspace for identity and team collaboration

From there, the team moved quickly through the foundational work:

  • Policies generated with AI — not blank templates, but drafts mapped to their actual environment and frameworks
  • Employee onboarding and training kicked off across the team
  • Vulnerability scanning connected through GitHub, with ComplyJet helping scope repos to filter out noise from unused code

That last point mattered. Floworks initially saw 83 open vulnerabilities flagged on the dashboard — a number that looked alarming but was inflated by old, out-of-scope repositories. ComplyJet's GitHub scoping feature let them remove unused repos from the compliance scope, bringing the real picture into focus and letting Ritesh prioritize what actually needed fixing.

The Three-Way Collaboration

One thing that stood out in Floworks' setup was how naturally the work split across the team.

Sarthak handled the organizational and business side — vendor reviews, board governance documents, and strategic decisions. Ritesh owned the engineering tasks — infrastructure hardening, vulnerability remediation, and integration setup. And ComplyJet filled the gaps — platform guidance, policy generation, MDM setup, and keeping the whole process on track.

Everything ran through a shared Slack channel. Questions got answered in hours. Blockers got cleared the same day. No tickets, no waiting.

Where Floworks Stands Today

Floworks' SOC 2, ISO 27001, and GDPR work is in progress. Here's what's in place so far:

  • All core integrations connected and monitored (AWS, GitHub, Google Workspace)
  • Security policies drafted across SOC 2, ISO 27001, and GDPR
  • Vulnerability scanning active with proper repo scoping
  • Employee training and onboarding underway

The team is working toward audit readiness across all three frameworks on one platform rather than three separate projects — the advantage being that the work compounds instead of duplicating as it progresses.

From Screenshots to Continuous Monitoring

With their previous vendor, evidence collection was largely manual — screenshots, spreadsheets, point-in-time snapshots stitched together to tell a compliance story. With ComplyJet, that evidence collection now runs continuously across their environment instead of being rebuilt by hand at each renewal.

Why This Matters

Floworks' story highlights something a lot of fast-growing startups face: your first compliance vendor might get you across the line, but that doesn't mean they're the right partner for the long run.

Switching platforms at renewal feels like a risk. But for Floworks, it was the opposite — it was a chance to upgrade from a checkbox exercise to a system that actually works with their engineering team.

For YC-backed companies scaling quickly across enterprise customers, compliance needs to be a system, not a side project. Floworks is building exactly that.

Looking Ahead

Floworks' SOC 2, ISO 27001, and GDPR work continues, on a compliance infrastructure designed for multi-framework coverage from the start — so the work compounds rather than restarting each time a new framework comes into scope.