Aegis / Nimbus Platform - Comply v2 Preview
49 turns · 12 min captured of 54 min stated?Only the captured portion exists in the database. The remaining 42 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 49 of 49 turns · 29 turns were used as evidence for at least one fact.
- Kevin O'BrienAegisCloud0:05turn 0ASR 93%
Hey Keith, good to finally catch you — I know we've been trying to get this on the calendar for like two weeks now.
- Keith DonovanCustomer0:14turn 1ASR 89%
Yeah, no kidding, it's been a crazy couple of weeks on our end, but I'm glad we made it work — this is a call I've actually been looking forward to.
+1Says he was looking forward to the call. · other
- Kevin O'BrienAegisCloud0:27turn 2ASR 93%
Same, same. So before we jump in, how are things going at Nimbus? I saw you guys announced that new data platform partnership last week — that looked like a big deal.
- Keith DonovanCustomer0:39turn 3ASR 90%
Yeah that was — that was a long time coming, honestly. It opens up a whole new set of customers for us in the financial services space, which is exciting but also, you know, comes with its own compliance headaches, which is actually very relevant to why we're here today.
- Kevin O'BrienAegisCloud0:57turn 4ASR 90%
Oh perfect, yeah that's a great segue actually. So, um, the whole reason I wanted to get this call on the books is that we've got Comply v2 going GA on April seventh — so like a week from today — and I really wanted to get you guys in front of it early, kind of a sneak peek before the broader announcement goes out.
- Keith DonovanCustomer1:21turn 5ASR 88%
Yeah I appreciate that. And honestly, the timing is — it's almost too good, like we were literally in a board meeting two days ago where our CFO was asking about our compliance posture going into Q2 and I didn't have a great answer for him on the reporting side.
- Kevin O'BrienAegisCloud1:38turn 6ASR 89%
Okay so let's fix that. Let me share my screen here and I'll walk you through what we've built — and Keith feel free to just interrupt me whenever, this is not meant to be a one-way demo.
- Keith DonovanCustomer1:53turn 7ASR 96%
Absolutely, yeah I'm not a passive audience kind of guy so you'll hear from me.
- Kevin O'BrienAegisCloud1:59turn 8ASR 88%
Perfect, that's exactly what I want. Okay so, uh, you can see the new dashboard here — and the biggest headline with v2 is the on-demand reporting engine. So previously, as you know, generating a SOC 2 report was kind of this... painful, manual export process. That's gone.
- Keith DonovanCustomer2:18turn 9ASR 91%
Okay yeah because I remember when we went through our last SOC 2 audit and my team spent like three days just pulling data together. Three days. That's not a compliance process, that's just suffering.
-1Frustrated about the three days spent pulling SOC 2 data in a past audit. · compliance reporting
- Kevin O'BrienAegisCloud2:31turn 10ASR 96%
Ha — yeah, suffering is a good word for it. So what you're looking at now is — you click here, select your framework, and the report generates. Full audit-ready SOC 2 report, on demand.
- Keith DonovanCustomer2:45turn 11ASR 90%
Wait, how long does that actually take? Like when you click generate, what's the — what's the actual wait time?
+1Calls the four-minutes-versus-three-days difference meaningful. · compliance reporting
- Kevin O'BrienAegisCloud2:53turn 12ASR 88%
So it depends on the size of your environment, but in our testing with accounts similar to Nimbus in terms of scale, we're seeing somewhere between, uh, ninety seconds and about four minutes for a full SOC 2 Type II report.
- Keith DonovanCustomer3:07turn 13ASR 90%
Four minutes versus three days. That's — yeah, that's a meaningful difference, Kevin.
+1Says PCI DSS relevance 'changes the conversation completely.' · compliance reporting
- Kevin O'BrienAegisCloud3:12turn 14ASR 91%
Right? And it's not just SOC 2 — so v2 launches with multi-framework support out of the gate. You've got SOC 2, PCI DSS, HIPAA, and ISO 27001 all in the same interface. And given what you just said about financial services customers, PCI DSS is probably relevant now in a way it maybe wasn't six months ago.
- Keith DonovanCustomer3:34turn 15ASR 96%
That is — yeah, that is extremely relevant. We've been kind of, um, putting off the PCI conversation internally because nobody wanted to deal with the overhead of standing up a whole new reporting workflow. If this just... works, that changes the conversation completely.
+1Enthusiastic that the new reporting workflow changes the PCI conversation. · compliance reporting
- Kevin O'BrienAegisCloud3:50turn 16ASR 92%
And that's exactly the intent. Like the whole philosophy behind v2 was, compliance reporting shouldn't require a project. It should just be part of how you operate. So — let me show you the framework selector here.
- Keith DonovanCustomer4:04turn 17ASR 95%
Yeah go ahead, I'm watching.
- Kevin O'BrienAegisCloud4:07turn 18ASR 90%
So you click frameworks, you get this dropdown, and you can actually — this is something our customers have loved — you can run reports for multiple frameworks simultaneously. So if you need SOC 2 and ISO 27001 at the same time for a customer who's asking for both, you just check both boxes, hit generate, and it queues them up.
- Keith DonovanCustomer4:30turn 19ASR 94%
Okay I need to send this recording to my head of security engineering because he has been building, like, a custom internal tool to do exactly this and I think I just saved him about three months of work.
+2Says the tool just saved his head of security engineering three months of work. · compliance reporting
- Kevin O'BrienAegisCloud4:44turn 20ASR 95%
Ha, yeah — well, you know, we've heard that from a few accounts actually, people who had kind of started building something in-house and then saw v2 and were like, oh, okay, we don't need to do that anymore.
- Keith DonovanCustomer4:59turn 21ASR 95%
That's a win. Okay, so — walk me through the output. Like what does the actual report look like? Is it something I can hand directly to an auditor or is there still cleanup work to do?
+1Repeatedly calls the demo a win. · other
- Kevin O'BrienAegisCloud5:13turn 22ASR 94%
Great question and honestly this is where v2 really shines. The output is a structured PDF — it's formatted specifically for auditor consumption, so it's got your control mapping, your evidence artifacts, timestamps, everything organized by control category. We worked with a few of our customers' auditors directly in the design process to make sure the format actually worked in the real world.
- Keith DonovanCustomer5:36turn 23ASR 96%
You worked with actual auditors? That's — I mean that's the right way to do it, most vendors just guess at what auditors want and then you end up with this beautiful PDF that your auditor looks at and goes, I can't use any of this.
+1Praises Aegis for working with actual auditors to design the report format. · compliance reporting
- Kevin O'BrienAegisCloud5:52turn 24ASR 95%
Yeah exactly, we've been on the receiving end of those complaints too so we wanted to get it right from the jump. Let me actually show you a sample output — I've got one pulled up here from a test environment.
- Keith DonovanCustomer6:08turn 25ASR 88%
Yeah please.
- Kevin O'BrienAegisCloud6:10turn 26ASR 89%
So this is a SOC 2 Type II sample — you can see the trust service criteria on the left, the controls mapped to each one, and then for each control there's a linked evidence section that pulls directly from your Aegis environment. So like here, for availability, it's pulling in the uptime data, the incident logs, backup verification records from Protect — it all connects.
- Keith DonovanCustomer6:34turn 27ASR 90%
The cross-module data pull is — that's actually huge. Because right now we're stitching that together manually across three different tools and it's — it's a mess. Having it come out of a single platform is a massive operational improvement.
+1Calls the cross-module data pull a 'massive operational improvement.' · product capability
- Kevin O'BrienAegisCloud6:49turn 28ASR 92%
Yep, and that's really the power of having Protect and Comply sitting in the same ecosystem. Um, I want to ask you something actually — you mentioned you're also using Detect, right? Are you on the full suite or just Protect and Comply?
- Keith DonovanCustomer7:04turn 29ASR 94%
We're on Protect, Comply, and Detect. We're not on Identity yet — that's actually something we've been evaluating but haven't pulled the trigger on.
- Kevin O'BrienAegisCloud7:13turn 30ASR 97%
Got it, okay. I'll put a pin in Identity for now. But the reason I ask about Detect is — and this is something I wanted to mention — Detect also feeds into the compliance reports in v2. So your threat monitoring data, your detection events, your incident response logs — those surface in the relevant control sections automatically.
- Keith DonovanCustomer7:35turn 31ASR 89%
Oh that's interesting. So when an auditor asks about our incident detection and response capability, the evidence is just... already in the report.
+1Enthusiastic that audit evidence is already baked into the report. · compliance reporting
- Kevin O'BrienAegisCloud7:45turn 32ASR 88%
Exactly. You don't have to go pull it separately, it's baked in. Now — and I want to be transparent here — there was a period in March where Detect had some availability issues, you may have noticed that, the outage around March tenth through the eighteenth. We've made significant infrastructure changes since then — redundant processing nodes, circuit breaker architecture — so the reliability story is much stronger now, but I wanted to flag that proactively.
- Keith DonovanCustomer8:13turn 33ASR 95%
Yeah we did notice that, and honestly I appreciated the communication during it — your team was pretty on top of the status updates. It wasn't fun but I felt like we knew what was happening. And the fix sounds solid, the circuit breaker pattern is the right call for that kind of cascading failure scenario.
+1Appreciates the communication during the Detect outage and calls the fix sound. · support experience
- Kevin O'BrienAegisCloud8:34turn 34ASR 95%
Yeah our engineering team was — they moved fast on it and I think the architecture is genuinely better for it. Okay so — let me swing back to Comply v2, I want to make sure we cover the onboarding side of this since that's really the point of today's call.
- Keith DonovanCustomer8:52turn 35ASR 88%
Yes, yeah — let's talk about what actually getting live on v2 looks like for us. What's the migration path from current Comply?
- Kevin O'BrienAegisCloud9:01turn 36ASR 95%
So the good news is there's no big bang migration here. v2 is deployed as an upgrade to your existing Comply instance, your historical data comes with you, your custom configurations and any existing scheduled reports are preserved. The typical onboarding for an account your size is — we're looking at kind of a one to two week window to get fully configured and validated.
- Keith DonovanCustomer9:25turn 37ASR 96%
One to two weeks is very manageable. And is there a dedicated resource from your side for that, or is it more of a self-serve setup with documentation?
- Kevin O'BrienAegisCloud9:36turn 38ASR 94%
So you'd have me as your SA throughout, and we'll also loop in a dedicated onboarding specialist from our CS team — they'll run the technical setup sessions with your team. It's not self-serve, we're hands-on for the whole window.
- Keith DonovanCustomer9:51turn 39ASR 97%
That's great to hear, honestly. The last time we onboarded something new it was basically a Confluence page and good luck to you, so this is a different experience.
+1'That's great to hear' about dedicated onboarding support. · onboarding and implementation
- Kevin O'BrienAegisCloud10:02turn 40ASR 96%
Ha, yeah, we try to make it a little more human than that. Okay, so — given that v2 goes GA on April seventh, what would your ideal timeline look like? Do you want to be in the first wave of production upgrades, or do you want to let it bake for a few weeks?
- Keith DonovanCustomer10:22turn 41ASR 93%
Honestly, given the PCI angle and the board conversation I mentioned, I'd love to be in the first wave. Like if I can go back to my CFO in mid-April and say we have on-demand PCI DSS reporting live and ready, that's a very good story to tell.
+1Wants to be in the first wave to tell the CFO about on-demand PCI DSS. · compliance reporting
- Kevin O'BrienAegisCloud10:39turn 42ASR 93%
I love that. Okay, so let's talk about what we'd need to do to make that happen — I'd want to get the upgrade scheduled for the week of April seventh, kick off the onboarding sessions the week of the fourteenth, and target you being fully live and validated by April twenty-first. Does that rough timeline work for your team's bandwidth?
- Keith DonovanCustomer11:01turn 43ASR 89%
April twenty-first is — yeah, that works. I'd want to loop in my security engineering lead, Priya, she'd be the one running point on the technical side. Can I have her connect with you directly after this call to get the details?
- Kevin O'BrienAegisCloud11:17turn 44ASR 93%
Absolutely, yes — have her shoot me an email and I'll get the onboarding specialist intro'd right away. And Keith, honestly, I'm really excited about this one — I think v2 is going to genuinely change the way your team experiences compliance and I can't wait to see you use it with auditors for real.
- Keith DonovanCustomer11:37turn 45ASR 97%
Same, yeah — this has been one of those calls where I feel like I'm getting off with more than I expected to, which is a good feeling. Thanks for the early look, Kevin, really appreciate it.
+2Says he's getting off with more than he expected and appreciates the early look. · other
- Kevin O'BrienAegisCloud11:51turn 46ASR 92%
Of course, that's what we're here for. I'll send over a recap and the onboarding guide this afternoon, and I'll hold a spot for you in the April seventh first-wave rollout. Looking forward to it.
- Keith DonovanCustomer12:04turn 47ASR 91%
Perfect. Alright, I'll talk to you soon Kevin — appreciate the time.
- Kevin O'BrienAegisCloud12:10turn 48ASR 93%
You too, Keith. Take care.