Aegis / Forge Industries - PCI DSS Compliance Review
42 turns · 10 min captured of 24 min stated?Only the captured portion exists in the database. The remaining 14 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 42 of 42 turns · 27 turns were used as evidence for at least one fact.
- Maria SantosAegisCloud0:04turn 0ASR 95%
Gerald, hey, good morning! Thanks so much for making time today, I know you've got a packed schedule over there.
- Gerald HutchinsCustomer0:12turn 1ASR 90%
Maria, always good to hear from you. Yeah it's been a little crazy on our end but honestly this is one of the calls I was actually looking forward to so, no complaints.
+1Gerald opens positively, saying he was looking forward to the call. · other
- Maria SantosAegisCloud0:25turn 2ASR 94%
That's great to hear! And I also have Ananya Sharma on the line with me today — she's one of our senior engineers on the Comply side of things, she's going to be super helpful for the more technical questions you might have.
- Ananya SharmaAegisCloud0:40turn 3ASR 91%
Hi Gerald, really glad to be here. I've been looking forward to this one actually.
- Gerald HutchinsCustomer0:46turn 4ASR 89%
Great, great. Yeah, Ananya, nice to meet you. So Maria filled me in a little bit on — on what you all just launched, and I have to say the timing is honestly almost too good to be true.
+1Gerald says timing of the new launch is almost too good to be true. · product capability
- Maria SantosAegisCloud1:01turn 5ASR 94%
Ha, well we'll take that! So just to set the stage for today — we wanted to walk you through what's new in Aegis Comply v2, specifically around the PCI DSS reporting capabilities, and then really hear from you about where Forge Industries is in your compliance journey and see how we can help. Does that agenda work for you?
- Gerald HutchinsCustomer1:22turn 6ASR 95%
Yeah absolutely, that's exactly what I need. So, uh, a little context from my side — we've been going through our PCI DSS audit prep and honestly it has been a nightmare. Like, our current process is... it's very manual. Spreadsheets, a lot of back and forth with our QSA, it's just — it eats up weeks of engineering time.
-1Gerald describes PCI audit prep as a nightmare with manual spreadsheets. · compliance reporting
- Maria SantosAegisCloud1:44turn 7ASR 90%
Yeah, that's such a common pain point, especially in manufacturing where you've got all these different systems touching cardholder data flows and it's not always obvious where the scope boundaries are.
- Gerald HutchinsCustomer1:56turn 8ASR 95%
Exactly, exactly. And we've got, you know, we've got our OT systems, our ERP, we've got point-of-sale on the distribution side — so the scope is, it's not small.
-1Gerald highlights the large compliance scope across OT, ERP, and POS as a burden. · compliance reporting
- Ananya SharmaAegisCloud2:08turn 9ASR 89%
Right, so that's actually a perfect segue for me to jump in on the product side if that's okay. So with Comply v2 — and this just went GA two days ago, April 7th — we've built out on-demand reporting that's fully mapped to PCI DSS controls. And what that means in practice is you're not waiting for a quarterly export or anything like that. You can pull a report at any point in time that shows your current control posture mapped directly to the PCI DSS requirements.
- Gerald HutchinsCustomer2:39turn 10ASR 88%
Wait, so when you say on-demand — like, same day? Or is there some processing lag?
- Ananya SharmaAegisCloud2:46turn 11ASR 89%
Same day, yeah. It's — so the underlying data is being collected continuously from your environment, and the report generation itself is pretty much near real-time. We're talking minutes, not hours.
- Gerald HutchinsCustomer2:58turn 12ASR 89%
Okay. Okay that's — yeah, that's significant. Because right now we're like, we're going back and forth with our QSA and they'll ask for evidence on a specific control and it takes us sometimes two, three days just to pull it together.
-1Gerald says evidence requests take two to three days to pull together. · compliance reporting
- Ananya SharmaAegisCloud3:13turn 13ASR 91%
And that's exactly the use case we designed for. You can actually share report outputs directly with your QSA — there's an export format that's structured specifically to make auditor review easier. Like the evidence artifacts are organized by control number, so they don't have to go hunting through a zip file of random screenshots.
- Gerald HutchinsCustomer3:33turn 14ASR 90%
Oh, that — honestly that alone would save us so much time. Our QSA basically — I mean, I love them, but they charge by the hour and every time I send them a messy evidence package I can just feel the invoice getting bigger.
-1Gerald notes QSA hourly charges rise with messy evidence packages. · pricing and billing
- Maria SantosAegisCloud3:50turn 15ASR 97%
Ha! I mean, we can't promise to fix your QSA relationship but we can definitely make the evidence package a lot cleaner.
- Gerald HutchinsCustomer3:59turn 16ASR 96%
That works for me. So, uh, what about multi-framework? Maria had mentioned something about that — we're also starting to look at SOC 2 this year so I'm curious if there's overlap.
- Ananya SharmaAegisCloud4:10turn 17ASR 91%
Yeah, so this is one of the things I'm most excited about with v2. We support PCI DSS, SOC 2, HIPAA, and ISO 27001, and the way we've built it is — the underlying control evidence is mapped across frameworks. So if you have a control that satisfies a PCI DSS requirement and it also maps to a SOC 2 criteria, you're not collecting evidence twice. It's the same artifact, surfaced in both reports.
- Gerald HutchinsCustomer4:37turn 18ASR 93%
That's — okay, I was not expecting that. So we wouldn't have to like, re-instrument everything when we start our SOC 2 push?
+1Gerald is pleasantly surprised that SOC 2 won't require re-instrumentation. · compliance reporting
- Ananya SharmaAegisCloud4:46turn 19ASR 93%
Correct. You'd be surprised how much of your PCI work carries over. Logging, access controls, encryption at rest — a lot of those controls are shared. We surface that overlap in the dashboard so you can see, okay, I've already got coverage here because of my PCI program.
- Maria SantosAegisCloud5:05turn 20ASR 90%
Gerald, I know you mentioned earlier in the year that you were worried about the SOC 2 prep running in parallel with the PCI audit cycle. This kind of addresses that directly, right?
- Gerald HutchinsCustomer5:18turn 21ASR 91%
It absolutely does. Yeah. I mean, honestly I was kind of dreading telling my team we had to spin up a whole separate program for SOC 2. This — this changes the math on that conversation significantly.
+1Gerald says the shared-control approach changes the math on the SOC 2 conversation. · compliance reporting
- Ananya SharmaAegisCloud5:32turn 22ASR 93%
I'm really glad to hear that. Can I ask — on the PCI side specifically, where are you in your audit cycle right now? Like, are you in active audit, prep, or...?
- Gerald HutchinsCustomer5:45turn 23ASR 92%
We're in prep. Our QSA assessment is scheduled for, uh, end of June. So we've got about — what, two and a half months? Which sounds like a lot but it really isn't when you factor in all the evidence gathering and the remediation items we still have open.
- Maria SantosAegisCloud6:04turn 24ASR 93%
Okay, that's actually a really workable timeline. Two and a half months is enough to get you meaningfully set up in Comply and have real, audit-ready reports by the time your QSA comes in.
- Gerald HutchinsCustomer6:16turn 25ASR 91%
And from an onboarding standpoint — like, what does that actually look like? How long does it take to get connected and start seeing real data?
- Ananya SharmaAegisCloud6:25turn 26ASR 95%
So typically for an environment like yours — and I'm making some assumptions based on what Maria has shared with me, but assuming you're running in a hybrid cloud setup with some on-prem — we're usually looking at one to two weeks for the initial integration and data ingestion to be in a solid state. Then maybe another week to tune the control mappings to your specific environment. So call it two to three weeks before you're getting meaningful report output.
- Gerald HutchinsCustomer6:54turn 27ASR 90%
That's — yeah, that's faster than I thought honestly. I was assuming it would be like a two month implementation just based on past experiences with other tools.
+1Gerald says two to three week onboarding is faster than expected. · onboarding and implementation
- Maria SantosAegisCloud7:06turn 28ASR 90%
We've put a lot of work into making the onboarding experience less painful. And you'd have dedicated support through that process — not just documentation, like actual humans.
- Gerald HutchinsCustomer7:17turn 29ASR 93%
Ha, that's refreshing. Okay so — and I don't want to get too far ahead of ourselves here but — are we talking about this as like a standalone Comply add-on, or is this tied to expanding the broader Aegis footprint with us? Because we're already using Protect and I've had some conversations internally about Detect.
- Ananya SharmaAegisCloud7:38turn 30ASR 96%
It can be either, honestly. Comply v2 is available as a standalone module, but there are some really nice synergies if you're running it alongside Detect especially — because Detect feeds security event data into the compliance evidence chain automatically. So your threat monitoring logs become part of your audit trail without any extra work.
- Gerald HutchinsCustomer7:58turn 31ASR 91%
Okay I'm going to be honest with you both — that's kind of the pitch that makes Detect interesting to me again. We had some concerns earlier this year about reliability.
-1Gerald voices lingering reliability concerns about Detect despite renewed interest. · service reliability
- Maria SantosAegisCloud8:11turn 32ASR 92%
Yeah, I — I was going to bring that up actually, I didn't want to gloss over it. The March outage was a real issue and I completely understand if that shook your confidence. We've made significant architectural changes since then — redundant processing nodes, circuit breaker patterns on the ingestion pipeline — and I'm happy to share the full post-incident review with you if that would be helpful.
- Gerald HutchinsCustomer8:37turn 33ASR 89%
Yeah, I'd actually appreciate that. My team flagged it and it came up in our last steering committee so I want to be able to address it with some substance, not just take it on faith that it's fixed.
+1Gerald appreciates the offer of the post-incident review to address steering committee concerns. · support experience
- Maria SantosAegisCloud8:51turn 34ASR 89%
Totally fair. I'll get that over to you today. And look — I think it's actually a sign of where we want this relationship to go that you're asking the hard questions. That's exactly what I want.
- Gerald HutchinsCustomer9:05turn 35ASR 93%
I appreciate that. Alright so — next steps. What are you thinking?
- Maria SantosAegisCloud9:10turn 36ASR 97%
So I'd love to set up a technical deep-dive with your team and Ananya — maybe a week from now — where we can actually walk through a demo environment and look at what PCI DSS reporting would look like for your specific setup. And in the meantime I'll send over the Detect post-incident review and a Comply v2 product brief. Does that sound right?
- Gerald HutchinsCustomer9:35turn 37ASR 95%
Yeah, that works. Can you also include something on the multi-framework overlap — like, even just a one-pager that shows the PCI to SOC 2 control mapping? That would be great for my internal conversations.
+1Gerald agrees to next steps and asks for a multi-framework one-pager, calling it great. · other
- Ananya SharmaAegisCloud9:48turn 38ASR 97%
Absolutely, I can put that together. We actually have a pretty clean mapping document I can customize for you.
- Gerald HutchinsCustomer9:55turn 39ASR 92%
Perfect. Alright — I'm genuinely excited about this. Like, I came into this call a little skeptical just because we've had some bumps, but this is — yeah, this is looking really promising.
+2Gerald says he is genuinely excited and that the call is looking really promising. · other
- Maria SantosAegisCloud10:09turn 40ASR 95%
That means a lot to hear, Gerald. We really do want to be a long-term partner for Forge, not just a vendor. Alright, we'll get everything over to you by end of day and we'll get that technical session on the calendar. Thanks so much for your time today.
- Gerald HutchinsCustomer10:27turn 41ASR 95%
Thanks both of you. Talk soon.