Midori, a platinum Atlassian Marketplace Partner known for Jira and Confluence tools, successfully prepared for and passed its SOC 2 audit within five months using Vanta's automated compliance platform, addressing key customer security expectations in the US market.

  • Midori leveraged Vanta to automate SOC 2 compliance controls.
  • Focus on US market drove selection of SOC 2 over other frameworks.
  • Audit passed with no findings after five months of preparation.

What happened

Midori, a well-established Atlassian Marketplace Partner specializing in Jira data exporting and Confluence archiving apps, embarked on a SOC 2 compliance journey to meet evolving customer security demands. Within six months, the company leveraged the Vanta compliance platform to streamline audit preparations, track progress, and manage necessary documentation and tests.

The preparation included creating new operational policies, conducting internal product tests, and technical infrastructure changes such as reorganizing AWS Virtual Private Clouds. This structured approach allowed Midori to successfully pass the SOC 2 audit without any issues identified by the auditor, receiving the final report roughly a month after completing the tests.

Why it matters

Achieving SOC 2 compliance is increasingly important for SaaS providers targeting security-conscious and enterprise customers, especially in the United States where the standard is common. Midori’s successful navigation sets a practical example for other Atlassian Marketplace Partners aiming to upgrade their security posture to meet customer expectations.

The strategic decision to focus first on SOC 2—before pursuing related frameworks like ISO 27001—demonstrates effective prioritization based on market needs and control overlap. By using an integrated platform like Vanta, Midori reduced complexity and improved visibility into compliance tasks, accelerating the audit process efficiently.

What to watch next

Midori plans to build on its SOC 2 success by targeting ISO 27001 certification next, leveraging the high degree of shared controls between these frameworks to streamline future compliance efforts. Other Atlassian Marketplace Partners may similarly adopt multi-framework strategies to maximize security assurance with minimal overhead.

With cloud security frameworks gaining importance, companies should watch how automated compliance platforms like Vanta evolve to support integration and simplification of auditing processes. Observing Midori’s experience can provide valuable lessons on overcoming common hurdles, such as technical infrastructure changes and permissions management.

Source assisted: This briefing began from a discovered source item from Atlassian Blog. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings