As we celebrate the company turning three, we’re proud of the powerful momentum we’ve built through relentless creativity, hard work, and excellence. From day one, we’ve been driven by a vision to be more than just another GRC solution on the marketplace: we’ve aimed to fundamentally disrupt the GRC space and transform how organizations approach security, risk, and compliance with our revolutionary Continuous Controls Monitoring (CCM) platform.
You’ve probably already heard about our recent industry recognition and milestones:
- Chosen for the prestigious Microsoft for Startups Pegasus Program.
- Mentioned by Gartner® 13 times this year, including recognition as a Sample Vendor in four Gartner® Hype Cycle™ reports.
- Used our own platform to earn FedRAMP High In Process certification at 50% the cost and in 300% less time
- Named a Trusted Cloud Provider in the CSA STAR program, following on the heels of our Cloud Security Alliance STAR Level 1 certification (shout out to Cory Henrickson our ISSO for leading the charge and completing his CCSK with a 93% score!).
And you’ve likely seen our recent spate of awards — including the SC Media Excellence Award for Best Compliance Solution, the CyberSecurity Breakthrough Award for Compliance Software Solution Provider of the Year, and the NVTC Cyber50 and Tech100 Awards.
But beyond the awards and accolades, one of our most important achievements has been building a team united by excellence and a shared purpose. Every milestone we’ve celebrated is ultimately a testament to everyone who pours their creativity, dedication, and expertise into RegScale on a daily basis.
Before we blow out the candles and cut the cake, let’s shine a spotlight on some of our top accomplishments — and on the people who have helped transform RegScale from a tiny startup into a dynamic, industry-leading organization.
The RegScale team kicks off the start of each fiscal year with a company kickoff event. This year, the team gathered in Nashville, TN, and led a community service event at Centennial Park, where they helped clean up the park before enjoying a tour of The Parthenon.
Building Tech Excellence
One of our biggest accomplishments over the past three years is how much the RegScale platform has improved and evolved. In terms of functionality, user friendliness, and appearance, our technology has grown in leaps and bounds.
“It looks a million times better than when I first came on board — it’s really matured as we’ve matured as a company,” said Anthony Belardo, Senior Technical Solutions Engineer at RegScale. “Before, you had to be a master at compliance to figure out where things belong. Now, with features like Wayfinder, anyone can go into the platform and find exactly what they need. It’s gotten so much easier to use.”
Franklin Wallace, RegScale User Experience Lead II who’s been with the company from its very early days, explains how these features bring us closer to our “walkup user-friendly” design philosophy. From Wayfinder’s step-by-step guides for completing various frameworks to Report Builder’s custom dashboards to the latest features released in RegScale 6.0, our goal is to make life easier for GRC teams everywhere.
“Essentially, we’re empowering clients to build their own paths and processes,” Franklin said. “By giving them lots of customization options and guidance, we’re allowing them to write their own success story.”
We’re empowering clients to build their own paths and processes. By giving them lots of customization options and guidance, we’re allowing them to write their own success story.Franklin Wallace
User Experience Lead II, RegScale
Some of our other tech wins are less visible to the untrained eye — but they’re no less important to our growth. Whether it’s learning to write in new coding languages, preparing to support rapid integrations, championing a new automation manager, or seamlessly building in new features, our R&D team members challenge themselves to improve daily.
“The world of tech gets antiquated very fast,” Anthony Belardo explained. “The great thing about RegScale is that we’re always evolving. Our leadership is able to empower us to make the best decisions, and we’re able to work really well together to get lots of code changes polished and pushed out. It takes a lot of collaboration to keep a platform design from becoming stagnant — but we’ve got enough skilled people to make things bulletproof and keep making our product better than it already is.”
The great thing about RegScale is that we’re always evolving. It takes a lot of collaboration to keep a platform design from becoming stagnant — but we’ve got enough skilled people to make things bulletproof and keep making our product better than it already is.Anthony Belardo
Senior Technical Solutions Engineer, RegScale
Compliance Wins — For Our Customers and the Industry
One of our biggest wins this year has been gaining rapid compliance certifications — including FedRAMP High “In Process” designation and SOC 2 Type 2 certification, both achieved in record time.
How did we get these wins? Ask Dale Hoak, our Senior Director of Information Security. In his previous RegScale roles as Customer Success Manager and Technical Account Manager, he’s listened to our customers’ struggles with compliance every single day, and he’s worked to build solutions to their pain points directly into the platform. With over 30 years of experience in cybersecurity, he understands firsthand the challenges that compliance presents — and how transformative RegScale can be.
“Let’s get one thing straight: I hate compliance,” Dale said. “Anyone who knows me knows this. By its very nature, compliance stifles innovation, becomes outdated the minute it’s published, and makes its use subjective at best. In most companies, compliance is where fun goes to die. And yet, here I am, dedicating myself to fixing it.”
Dale and the team worked tirelessly toward our FedRAMP, SOC 2, and CSA STAR certifications as a way to demonstrate that RegScale doesn’t just talk the talk; we walk the walk. We used our own platform to:
- Achieve FedRAMP High in 300% less time and 50% less cost
- Implement all 410 FedRAMP controls in 40 days
- Reduce manual effort for SOC 2 Type 2 by 94%
“We’re not just ticking boxes; we’re creating tools that turn compliance from a dreaded task into an opportunity for organizations to innovate and thrive,” Dale said. “Our mission is clear: to give compliance analysts and CISOs their weekends back. That’s not just a tagline — it’s a personal mission for me.”
We’re not just ticking boxes; we’re creating tools that turn compliance from a dreaded task into an opportunity for organizations to innovate and thrive. Our mission is clear: to give compliance analysts and CISOs their weekends back.Dale Hoak
Senior Director of Information Security, RegScale
Championing Customer Success
Although it’s not as easily encapsulated as a certification or a new feature, another key accomplishment by our team is their willingness to come together and support our customers.
Mala Marken, RegScale’s Account Executive who’s been with the company since early 2023, notes how taking the time to listen to our customers and understand their processes has allowed us to map out efficiencies that they didn’t even know were possible. With one client, for example, we were able to take a consultative approach to their program and identify a way to funnel information between two separate processes, helping them streamline their operations in a way they hadn’t even imagined.
“We’re really interdependent, with people always willing to jump on customer calls or turn around resources quickly,” Mala said. “It’s a very cohesive unit, and I don’t think any of us could be successful without each other.”
Leanne Scott, a Senior Customer Success Manager who’s been with RegScale for almost two years, emphasizes how this collaborative spirit goes beyond just solving immediate challenges; it’s about creating meaningful, long-term value for customers. In her role, she builds training decks, short demos, and walkthroughs of our platform to teach clients how to use our increasingly sophisticated application.
“RegScale is such a big and continuously growing application that getting customers proficient in their use case and excited about the next one is what I enjoy the most about working with customers,” she said. “Their ‘aha’ moments or ‘oh, that’s so cool’ responses are great to witness. It’s also been great to see RegScale change, grow in features and functionality, and mature in handling more complex business problems.”
RegScale is such a big and continuously growing application that getting customers proficient in their use case and excited about the next one is what I enjoy the most about working with customers. Their ‘aha’ moments or ‘oh, that’s so cool’ responses are great to witness.Leanne Scott
Senior Customer Success Manager, RegScale
One great example of how we address our customer needs is our Questionnaires. Greg Elin, our Principal OSCAL Engineer, worked with the Customer Success team for the better part of a year to make sure the Questionnaires hit the target — even when it became a moving target.
Initially designed with third-party risk management as the primary use case, the Questionnaires were intended to be interactive and secure for external vendors. Today, though, customers use them in custom ways to dynamically gather and review information from both external and internal parties.
“Implementing RegScale’s questionnaire system was an opportunity to build on important lessons and create something more dynamic and flexible,” Greg said. “It’s exciting to see our customers use them in ways well beyond what we imagined.”
RegScale Co-Founder & CEO Travis Howerton and CRO Eric Erston joined the Naval Information Warfare Center Pacific COSMOS team—James Curtin (AWS Cloud Solution Architect/Diode Technical Lead), Heather Heben (COSMOS Project Manager & NIWC Computer Scientist), and Jonathan Burgard (COSMOS Lead Engineer)—to celebrate their WashingtonExec Pinnacle Award win for Government Information Technology of the Year.
Employee Excellence and Internal Wins
As the first official employee of RegScale after the co-founders, Juliette Easley remembers the early days of company dinners that could be held at a table of four. As RegScale’s Software Engineer II, she’s seen the company grow tenfold from those early days, when the motion sensor lights in the office were constantly going out because she and Travis were the only two people in it.
Since then, RegScale has expanded to more than 50 employees — and counting. We’ve added global security expert and former TikTok CISO Roland Cloutier as a strategic advisor, and we’re about to announce some exciting new hires.
Mala Marken (Account Executive), Dale Hoak (Senior Director of Information Security), James Sumka (Solutions Engineer), and Shannon Williams (Solutions Advisor) at the RegScale booth during the ISACA GRC Conference in April 2024.
Much of our recent expansion was made possible by our Senior Recruiter, Javier Jennings, who was brought on to revamp the talent acquisition process and support our rapidly growing team. Since then, RegScale has successfully scaled multiple GTM teams and made critical hires across R&D — while Javier himself has expanded his skill set by creating training programs to help hiring managers navigate the hiring process with confidence.
“One of the most rewarding aspects of talent acquisition is seeing the direct impact on the business,” he said. “I’ve had the privilege of watching new RegScalers I recruited close new logos, launch marketing campaigns, build professional services functions, service our customers, redesign product front ends, and create cutting-edge AI functionality for our platform. Beyond their professional contributions, I’ve also seen them grow their careers here. Knowing I played a role — however small — in setting them on this path is incredibly fulfilling.”
“I love the culture, I love the people, and I love that there’s always a new challenge to solve with the freedom to execute it,” Juliette Easley said. “It’s great to be able to go back and look at code I wrote several years ago and then improve on it — we really have the freedom to grow and evolve here. Travis and RegScale have been supporting and facilitating my career and knowledge growth from the beginning.”
I love the culture, I love the people, and I love that there’s always a new challenge to solve with the freedom to execute it. We have the freedom to grow and evolve here.Juliette Easley
Software Engineer II, RegScale
Looking Ahead to Year Four
What’s next for RegScale? New partnerships, new deals, and new hires are all on the horizon.
- We’re actively expanding our partner ecosystem to include more integrations and tech alliances, enabling us to better serve our customers across industries.
- We’re working with some exciting companies expanding into new markets, while strategically growing our team to support this growth.
- We’re hard at work on our upcoming Department of Defense Impact Level 5 (IL5) certification, which will authorize us to store and process highly sensitive mission-critical national security data. The security controls required for DoD IL5 are among the strictest in the industry, and we’re excited to become one of a very small number of companies with the certification.
- Finally, we’re doubling down on our commitment to innovation in CCM. Our product roadmap includes exciting new features and automation tools that will help us continue to support our customers and revolutionize the industry.
Dale Hoak sums it up best: “As one of RegScale’s first ten team members, I’m incredibly proud of how far we’ve come in just three years. Together with an amazing team, supportive customers, and forward-thinking partners, I’m excited to continue pushing the boundaries of what risk and compliance can be. Here’s to three years of innovation — and to many more weekends reclaimed for compliance professionals everywhere.”
RegScale’s sales, marketing, and customer success teams came together in October 2024 to kick off the second half of the fiscal year with collaboration and strategy at the forefront.
Ready to get started?
Choose the path that is right for you!
Skip the line
My organization doesn’t have GRC tools yet and I am ready to start automating my compliance with continuous monitoring pipelines now.
Supercharge
My organization already has legacy compliance software, but I want to automate many of the manual processes that feed it.