Bankingly builds digital banking channels for financial institutions across Latin America: the web and mobile banking that banks, credit unions and cooperatives offer their own customers runs on Bankingly’s platform.
That makes Bankingly’s security posture part of every client’s security posture. Their buyers are banks, and banks do not skim vendor reports. They read them line by line.
Every sales cycle runs through vendor risk review, and a current SOC 2 Type II report is the ticket to the table. The report has to exist, it has to be clean, and it has to renew every year without fail, because a lapsed report reads as a red flag to a bank’s risk team.
Bankingly needed the annual audit to be a routine, not a seasonal emergency that pulls engineers off the product for weeks.
Cloudacio runs Bankingly’s SOC 2 readiness end to end. The engagement started with a gap assessment against all five Trust Service Criteria, then hardened the cloud controls on Azure: least-privilege access through Entra ID and role-based access control, logging and monitoring, encryption across data stores, and the access review cadence auditors look for first.
Policies are written for how Bankingly actually operates, evidence is collected continuously and mapped to controls, and Cloudacio coordinates directly with the auditor each cycle. Between audits, continuous monitoring keeps drift from accumulating into findings.
A clean SOC 2 Type II, renewed year after year. Security questionnaires get answered with the report in hand, and the audit window stopped being an interruption to the roadmap.
"Our clients are banks, so our SOC 2 report gets read line by line. Cloudacio has kept our Type II clean year after year, and audits became routine instead of a fire drill."Pedro Crosta, VP of Delivery at Bankingly