Support Case #1993 - Forge Industries Comply v2 Early Access Question
43 turns · 8 min captured of 26 min stated?Only the captured portion exists in the database. The remaining 17 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 43 of 43 turns · 19 turns were used as evidence for at least one fact.
- David KimAegisCloud0:06turn 0ASR 96%
Alright, I think we've got everyone on now — Gerald, Dana, can you hear us okay?
- Gerald HutchinsCustomer0:12turn 1ASR 93%
Yep, loud and clear, David.
- Dana MorettiCustomer0:15turn 2ASR 95%
Same here, good connection today.
- David KimAegisCloud0:17turn 3ASR 92%
Great, and I also wanted to introduce Elena Vasquez, she's a senior support engineer here, she's been really deep in the Comply module so I pulled her in for this one.
- Elena VasquezAegisCloud0:29turn 4ASR 93%
Hi everyone, really happy to be on this call — Forge Industries is actually one of the accounts I've been keeping an eye on, so this is a great chance to connect directly.
- Gerald HutchinsCustomer0:42turn 5ASR 90%
Oh great, well we appreciate that, Elena. So yeah, I'm Gerald Hutchins, VP of IT here at Forge, and Dana is our Security Manager, she's really the one in the weeds on this.
- Dana MorettiCustomer0:54turn 6ASR 88%
Yeah, hi — and honestly thank you guys for making time on short notice, I know we submitted the case just yesterday.
- David KimAegisCloud1:02turn 7ASR 91%
Of course, that's what we're here for. So let me just pull up case 1993 real quick — okay, so it looks like the question is around Comply v2 and specifically early access. Dana, do you want to just walk us through what you're looking to do?
- Dana MorettiCustomer1:19turn 8ASR 96%
Sure, yeah. So, um, we've been on Aegis Comply for about eight months now and it's been really solid for us. But our compliance team — we report across multiple frameworks, we do SOC 2, we're getting into HIPAA because we've got a new healthcare adjacent part of the business, and then we have PCI requirements for some of our vendor payment processing. And right now, pulling reports for each of those is just... it's a lot of manual work.
- Elena VasquezAegisCloud1:48turn 9ASR 92%
Right, yeah, that totally makes sense, especially juggling three frameworks at once.
- Dana MorettiCustomer1:53turn 10ASR 92%
Exactly. So we heard through, uh, I think it was a webinar or something, that there's a version two of Comply coming that has on-demand reporting across multiple frameworks. And we just — we really want to know if there's any way to get early access before the general release because our SOC 2 audit window is coming up and the timing would be really helpful.
- Elena VasquezAegisCloud2:18turn 11ASR 96%
Yeah that's — and honestly I want to say, your timing on asking about this is really good.
- Gerald HutchinsCustomer2:25turn 12ASR 89%
Oh yeah?
- Elena VasquezAegisCloud2:28turn 13ASR 96%
Yeah so, um, I can share — and David correct me if I'm misstating anything here — but Comply v2 is essentially locked and going through final QA right now. The GA launch is actually scheduled for April 7th, so that's like, what, four days from now.
- David KimAegisCloud2:44turn 14ASR 90%
That's right, April 7th is the date we have, it's been on the roadmap for a little while and the team is feeling really good about it.
- Gerald HutchinsCustomer2:54turn 15ASR 94%
Oh wow, okay, four days — Dana did you catch that?
- Dana MorettiCustomer2:59turn 16ASR 97%
Yeah I — that's honestly better than I expected. So it's a full GA release, not just like a limited beta?
+1Dana says the GA release is better than she expected. · product capability
- Elena VasquezAegisCloud3:07turn 17ASR 89%
Full GA, available to all existing Comply customers. And the on-demand reporting piece — that's going to cover SOC 2, PCI DSS, HIPAA, and ISO 27001 right out of the gate. So your use case, Dana, honestly checks every box.
- Dana MorettiCustomer3:23turn 18ASR 90%
That's — okay, that's really exciting actually. Because we were almost starting to look at whether we needed a separate point solution just for the HIPAA piece and this would obviously be way cleaner to keep it all in one platform.
+2Dana says v2 is really exciting and avoids needing a separate HIPAA point solution. · product capability
- Elena VasquezAegisCloud3:38turn 19ASR 94%
Yeah absolutely, and that's kind of the whole vision behind v2 — consolidating that audit prep workflow so you're not bouncing between tools or doing a ton of manual exports. You essentially set up your framework mappings and then you can generate a report on demand whenever your auditor asks for it.
- Gerald HutchinsCustomer3:58turn 20ASR 96%
Can I ask a kind of dumb question — when you say on-demand, does that mean like, real-time? Or is there still some processing lag?
- Elena VasquezAegisCloud4:08turn 21ASR 90%
That's not a dumb question at all, it's actually a really common one. So the underlying data is continuously synced, so when you generate a report it's pulling from current state. There may be, you know, a minute or two of rendering time depending on the scope of what you're pulling, but it's not like a 24-hour batch job or anything like that.
- Gerald HutchinsCustomer4:31turn 22ASR 94%
Okay great, that's what I was hoping to hear.
+1Gerald says that is what he was hoping to hear about report lag. · compliance reporting
- David KimAegisCloud4:35turn 23ASR 97%
And just to add to that — one of the things that came with v2 is also better evidence collection. So it's not just generating the summary report, it's actually attaching the relevant log references and control evidence inline, which is something auditors have been asking for.
- Dana MorettiCustomer4:52turn 24ASR 93%
Oh that is huge. Our last SOC 2 audit, we spent — I don't even want to say how many hours just pulling evidence artifacts together manually.
+1Dana says inline evidence collection would be huge after a painful manual SOC 2 audit. · compliance reporting
- Elena VasquezAegisCloud5:03turn 25ASR 94%
Yeah that's one of the biggest pain points we hear from compliance teams honestly.
- Dana MorettiCustomer5:09turn 26ASR 90%
So okay, back to the original question — since we're only four days out, is there anything we should be doing to prepare, or does the upgrade happen automatically for our tenant?
- Elena VasquezAegisCloud5:21turn 27ASR 94%
Good question. So the v2 update will roll out automatically for existing customers, but there are a few configuration steps you'll want to do on your side to take full advantage of the multi-framework features. Specifically you'll need to go into the Comply settings and, um, map your existing controls to the new framework templates — v2 has a migration assistant for this that'll try to auto-map based on your current setup, but you'll want to review it.
- Dana MorettiCustomer5:49turn 28ASR 90%
Is there documentation for that process, or like a walkthrough?
- Elena VasquezAegisCloud5:54turn 29ASR 89%
Yes, there's going to be a full v2 migration guide published in the knowledge base on the 7th alongside the release, and we're also planning a customer webinar — David, what's the date on that?
- David KimAegisCloud6:07turn 30ASR 92%
I believe it's April 10th, a Thursday, I can send you both the invite after this call if that's helpful.
- Dana MorettiCustomer6:15turn 31ASR 88%
Please do, yeah. And actually can you send it to a couple people on my team? I've got two compliance analysts who are going to be the primary users on this.
- David KimAegisCloud6:27turn 32ASR 96%
Absolutely, just shoot me an email with their addresses and I'll get them added.
- Dana MorettiCustomer6:32turn 33ASR 93%
Perfect. Okay and — sorry, one more thing, this might be a little out of scope for this call but — we had been thinking about requesting some features around, um, custom control labeling within the reports. Like being able to tag controls with our internal policy numbers. Is that something v2 supports or is that more of a future roadmap item?
- Elena VasquezAegisCloud6:55turn 34ASR 91%
Ooh, that's a good one. So, um, v2 does have a custom metadata field option for controls — I don't want to overcommit on exactly how flexible it is but I believe you can add custom tags and labels. I'd want to double-check the specifics and follow up with you in writing so you know exactly what's supported.
- Dana MorettiCustomer7:17turn 35ASR 94%
Yeah that would be great, even if it's partial support that would be a huge improvement for us.
+1Dana says even partial custom-label support would be a huge improvement. · product capability
- Elena VasquezAegisCloud7:25turn 36ASR 91%
And if it turns out there are gaps there, I'd love to formally log that as a feature request with the product team — that kind of internal policy cross-referencing is actually something I could see a lot of enterprise customers wanting.
- Gerald HutchinsCustomer7:41turn 37ASR 94%
Please do, yeah. We'd love to be part of that conversation if there's ever a beta or feedback group for that.
+1Gerald asks to join a beta or feedback group for the custom labeling feature. · product capability
- Elena VasquezAegisCloud7:49turn 38ASR 92%
Noted, and honestly Forge Industries would be a great reference customer for that kind of feature given how many frameworks you're operating across. I'll make a note of that.
- Gerald HutchinsCustomer8:00turn 39ASR 93%
Awesome. Okay I think that actually covers everything we came into this call with, and then some. David, Elena — this was super helpful, we really appreciate you both.
+1Gerald says the call was super helpful and appreciates the vendor. · other
- David KimAegisCloud8:11turn 40ASR 96%
Of course, glad we could help. I'll send over the webinar invite and follow up on the custom labeling question by end of week. Don't hesitate to reach back out through the case if anything else comes up before the 7th.
- Dana MorettiCustomer8:28turn 41ASR 90%
Will do. Thanks everyone, talk soon.
- Elena VasquezAegisCloud8:31turn 42ASR 96%
Thanks, have a good one!