GoFIGR Builds Enterprise Trust with SOC 2 Compliance
TechCorp, a B2B SaaS company, needed a SOC 2 Type II report to close enterprise deals. With Johanson Group they went from kickoff to final report in 5 weeks.

Sydney-based GoFIGR is an AI talent intelligence platform helping HR and People leaders map real workforce skills and forecast how AI will change the work their people do.
The story
Before
- Security asserted, not demonstrated
- Processes lived in people's heads
- Every enterprise deal opened with convincing
After
- Four audits and three years of independent evidence
- Documented processes, enforced by controls
- Security review is a gate they walk straight through
About GoFIGR
GoFIGR is an AI talent intelligence platform built for HR and People leaders at mid-to-large organizations. Where traditional HR systems record job titles and org charts, GoFIGR maps what a workforce can genuinely do: identifying real skills, forecasting how roles shift as AI capability spreads, showing employees where they can grow, and powering an internal talent marketplace that moves people toward the work that needs doing. GoFIGR also offers a Free AI Workforce Impact Assessment that anyone can use to see how exposed their role is to AI.
The Challenge: Protecting the Most Sensitive Data an Employer Holds
GoFIGR's customers entrust the platform with verified skills, capability assessments, career aspirations, and forward-looking analysis of how individual roles may change. "We cannot deliver the value we promise without that data, which makes responsible custodianship of it a precondition for everything else we do," they explained.
Compliance had been on their minds for a while. Then, in 2024, a client asked for a SOC 2 report directly. GoFIGR treated it as the trigger to go all in.
The technical lift was smaller than expected. Encryption, access control, logging, and infrastructure-as-code were largely in place after a recent AWS Well-Architected Review. "The real work was organizational," GoFIGR shared. "We had to write a substantial body of policy and process and, the harder part, embed it into how we actually work day to day."
The Solution: A Long-Term Partnership with Johanson Group
GoFIGR evaluated ISO 27001 alongside SOC 2 and chose SOC 2, the default expectation for US enterprise buyers. They completed a SOC 2 Type I in 2024 and immediately pursued a Type II, followed by Type II audits in 2025 and 2026: four audits across three consecutive years with Johanson Group.
That continuity pays off. "They know our environment and our team, so we're not rebuilding context from scratch every year. That saves a genuine amount of time."
The first audit set the tone. "Everyone we dealt with clearly wanted us to succeed," GoFIGR recalled. "They explained what the process would actually be like rather than assuming we already knew, and they were clear about what good evidence looked like." Having a dedicated Customer Success Manager rather than a shared inbox was a large part of why that worked.
Distance never got in the way either. GoFIGR initially worried that being based in Sydney would make working with a US firm difficult, but connecting with Johanson Group's West Coast team via Slack, email, and Vanta comments meant timezones never became an issue.
For their most recent Type II, fieldwork began the day the observation window closed and the final report arrived roughly six weeks later, including two rounds of review. "The process was smooth, and the reason was preparation and communication," they noted. And it was no rubber stamp: "It was thorough, and it was a genuine audit, which is the point. A report that was easy to obtain wouldn't be worth showing anyone."
The Audit Impact: Trust That Works Faster Than Words
Achieving SOC 2 compliance has reshaped how GoFIGR operates and sells:
- A Trust Signal That Opens Doors: "There are client conversations we've had that we would not have been able to have without it. Security review is a gate, not a formality, and the report is what gets you through it." Instead of spending the opening phase of every relationship convincing stakeholders, GoFIGR gets straight to whether the product solves the problem.
- Order Where There Was Memory: Onboarding, offboarding, access provisioning, change management, and vendor review now live in clear checklists and documented processes rather than people's heads. Formal access reviews surface permissions that quietly accumulate and would otherwise never be revisited.
- Compliance That Compounds: Because evidence is generated continuously rather than assembled at audit time, each year has been less disruptive than the last. That has freed GoFIGR to move beyond the baseline into annual penetration testing, deeper vendor assurance, and tighter enforcement built into the platform itself.
Build Trust That Scales with Johanson Group
GoFIGR's story shows what compliance looks like when it's treated as a discipline rather than a checkbox: a first audit that builds the foundation, and each one after that compounds the return. If your company is preparing for its first SOC 2 report, or looking for an audit partner who stays with you year after year, connect with us today!



.png)