How Tovuti LMS Runs SOC 2 & FedRAMP Compliance in a Single Platform

Industry Type
Commercial: Software / EdTech (Learning Management System)
Use Cases
SOC 2 Type II, FedRAMP continuous compliance, automated evidence collection, single source of truth
Frameworks
SOC 2, FedRAMP
Impact
Challenge: Managing full-scope SOC 2 and FedRAMP compliance across spreadsheets, email, and Word Docs with slow, manual processes.
Solution: RegScale centralized both frameworks into a single pane of glass and automated policy alignment via APIs with AI.
Results: Saved 800+ hours in a single quarter by eliminating spreadsheets and manual policy overhauls, and saved $190k for the business with RegScale.
Customer Outcomes
hours saved in a single quarter reported to leadership
SOC 2 Type II + FedRAMP SSPs
Spreadsheets, emails, Word Docs
Summary
Tovuti LMS is an AI-powered, all-in-one learning management platform used by government agencies, healthcare organizations, manufacturers, nonprofits, and software companies to create courses, train teams, and manage compliance training at scale. As a FedRAMP Authorized (IL2) and SOC 2 Type II platform serving the public sector, Tovuti has to continuously prove the strength of its security controls. Meeting that bar meant managing two demanding frameworks across spreadsheets, email, and Word Docs — slow, manual processes that couldn’t keep pace with the scrutiny both frameworks demand.
With RegScale’s continuous controls monitoring (CCM) platform, Tovuti consolidated its SOC 2 and FedRAMP System Security Plans into a single source of truth, automated evidence collection with integrations and AI, and turned compliance from a manual scramble into a repeatable, automated program, while saving 800+ hours and $190k in a way leadership could see.
Challenge: Two frameworks, three disconnected tools
The compliance workload challenge
Tovuti’s compliance program started as a function embedded within engineering. Over time, the company recognized the critical need to fully separate the security and compliance function from core engineering. Dennis Shewmaker transitioned from his role as CTO to become the company’s dedicated CISO. For a small company, that meant Dennis was accountable for the documentation, evidence, and audit readiness behind two of the most scrutinized frameworks in the industry.
Spreadsheets, email, and Word Docs couldn’t scale
Before RegScale, the program ran on spreadsheets, email threads, and Word documents. Policy drafts and control mappings lived in multiple places, were manually updated, and had to be re-tracked every cycle. By centralizing these components into RegScale, both policies and active evidence were much more easily tracked, managed, and updated in one unified location, eliminating the slow, error-prone manual overhead that used to eat up hours every cycle.
SOC 2 carried the heaviest load
Because Tovuti’s FedRAMP authorization runs through Knox Systems’ approved cloud infrastructure, the FedRAMP lift is comparatively contained. SOC 2 Type II, by contrast, is full-scope and ongoing with continuous evidence and control validation — a heavy, disproportionate workload to manage manually. RegScale’s automation handled the policy and evidence work at the center of that load.
Solution: One platform for documentation, evidence, and AI-driven automation
A single source of truth for SOC 2 and FedRAMP
Tovuti fully documented and now maintains both its FedRAMP and SOC 2 System Security Plans inside RegScale. RegScale’s modern, easy-to-use platform and built-in SOC control catalog gave Dennis one place to centralize the communication and management of the entire assessment process while replacing the patchwork of spreadsheets and documents with a true system of record. Both policies and active evidence could be updated in tandem, establishing a solid, audit-ready compliance foundation.
FedRAMP was also new territory. Leading his first FedRAMP effort, Dennis leaned on RegScale’s control dashboard and its mapping from the SOC 2 work Tovuti had already completed, turning overlapping requirements into a running start instead of a duplicate project.
“This was my first time leading a FedRAMP effort. Having RegScale’s control dashboard, and the mapping from the SOC 2 work we’d already done, was hugely valuable. The mapping worked beautifully.”
Dennis Shewmaker, Former CTO/CISO of Tovuti LMS & Founder of Panjiea
Automating the busywork with RegScale and AI
By programmatically extracting live control implementation statements directly from RegScale’s system of record, Dennis used AI to cross-reference them against corporate policy templates. This pipeline instantly performed gap analyses and generated updated compliance language automatically. Instead of wasting entire weeks manually drafting text and hunting down document version history, this automation instantly aligned Tovuti’s policies with active operational realities. Freeing himself from the manual policy grind allowed Dennis to shift his focus from administrative busywork to higher-value security work.
“RegScale became my source of truth. I’d pull the control implementation statements, run them against our existing policies with AI, and it surfaced every gap I had.”
Dennis Shewmaker, Former CTO/CISO of Tovuti LMS & Founder of Panjiea
Connecting the security stack
In November 2024, Tovuti built on RegScale’s APIs and integrations to deepen automation by adding Wiz to its stack to feed control and evidence data directly into the platform.
Results: A scalable, leadership-ready compliance program
Spreadsheets and the manual processes behind them were eliminated
With everything consolidated in RegScale, Tovuti eliminated its compliance spreadsheets and the manual policy overhauls that came with them. Documentation, controls, and active evidence now live in one platform instead of being scattered across files and inboxes.
800+ hours and $190k saved with RegScale
The biggest payoff was time. With RegScale and AI, Dennis was able to quantify the hours and cost that were saved and present that ROI directly to leadership. That turned compliance from an invisible cost center into a measurable efficiency story. The $190,000 figure was concrete: it came from a contractor’s quote to manually rebuild Tovuti’s FedRAMP policies and procedures, an expense Dennis had taken to the board while under pressure to stand up federal compliance quickly. RegScale replaced that manual effort, and the return landed inside the first quarter.
“On paper, RegScale might look expensive, but the ROI was there. There’s simply no way I could have tracked all those policy changes across spreadsheets and Word Docs. RegScale made it possible.”
Dennis Shewmaker, Former CTO/CISO of Tovuti LMS & Founder of Panjiea
Looking ahead
With both frameworks maintained in a single source of truth and more integration underway, Tovuti is positioned to sustain continuous compliance as it grows. And with partners like Knox Systems continuing to support its FedRAMP footprint, that foundation is built to last.
“Before RegScale, running SOC 2 and FedRAMP out of spreadsheets, email, and Word Docs meant a massive, manual policy and documentation workload. Moving from CTO to CISO let us fully separate security from engineering, but that workload didn’t go away on its own. By using RegScale’s APIs to feed our live controls into AI, we automated the manual policy overhauls, saving over 800 hours. For the first time, I could walk into a leadership conversation and show that we avoided a $190,000 contractor engagement to manually rebuild our FedRAMP policies. At Panjiea, this is the exact type of automation we build to keep organizations secure and hyper-efficient.”
Dennis Shewmaker, Former CTO/CISO of Tovuti LMS & Founder of Panjiea
Read more success stories
See what RegScale can streamline for you
Book a demo now for a quick walkthrough of how our continuous controls monitoring can solve your compliance, risk, and cybersecurity challenges.


