How Amp got its SOC 2 type II pentest evidence in hours

Amp is the AI hiring team for high-volume frontline employers. Restaurants, retailers, logistics operators, hospitality groups, healthcare staffing firms. Amp screens candidates against the criteria you set, books interviews on your managers' calendars, runs candidate comms, and closes offers you approve. It works across the ATS, HRIS, calendar and job boards the customer already runs on, so there is no new system to log into.

The company is young. The founding team is not. Amp is the fourth business co-founders Shaun Ricci and Somen Mondal have started together over the last twenty years. Their second was acquired in 2021, and Shaun spent the four and a half years that followed inside the acquirer, later as SVP of Application Development, running an engineering organization across multiple countries for a global HCM platform. Their third was FairNow, an AI governance and compliance platform that mapped enterprise AI systems against more than 25 global regulations, from the EU AI Act to NYC Local Law 144. It was acquired in October 2025.

So when Shaun says compliance belongs inside the product rather than bolted on after it ships, he is not describing a principle he picked up recently.

The Problem

Amp handles job application data. Names, work history, contact details, references, I-9 documents. That data sits under different rules in every country, province, state and city Amp's customers hire in. Getting it wrong can lead to many regulatory problems.

Shaun has watched that expectation change over four companies.

"Over my time studying the data, starting different businesses, compliance has always come up. And I would say in the first business, it was kind of something that we thought of as something that's on the side, but we needed to do. But in the last decade plus, and especially with Amp, compliance and data security is not really a nice-to-have. It must be a core part of what you do. It's not something you do on the side. It's not something you do after you ship product. It needs to be a core component of how you build and ship product." - Shaun Ricci, Co-Founder and COO, Amp

That meant SOC 2 Type II in year one, with ISO 27001 planned for next year. A pentest is an important control in both.

Four things stood in the way:

  • Pentests run at human speed. Amp had commissioned them before. The experience was always the same.
"In the past, pentests were something that we've done before, and it's always something that is driven by human labor. Sure, they have scripts, and they monitor things, but it's driven by humans." - Shaun Ricci, Co-Founder and COO, Amp
  • Setup has always been the real bottleneck with other tools.  Nem Stefanovic’s (VP, AI Operations, Amp) experience with other vendors was that “the hard part came before the engagement started, in getting a test configured and ready to run.”
  • Scope was the open question for an agentic test. Amp wanted the product tested. The corporate website was explicitly out of scope. But he was worried that the agentic solution would automatically crawl the website.
  • One report was never going to be enough. Nem needed two things from the same security test. Something detailed enough to work from, showing him exactly what had to be fixed and in what order. And something clean enough to hand over, first to the auditors and then to prospects asking whether Amp had been tested. The output had to stretch from a one-page summary to line-by-line detail. 

The Solution

Shaun's initial thoughts on the category were that pentesting is unusually well suited to agents.

"I just thought, hey, like, there must be agents that do this. This is such a prime kind of thing for a fleet of agents to do, is to try and infiltrate our infrastructure and our product. And we started looking around, sure enough, we found you all." - Shaun Ricci, Co-Founder and COO, Amp

Shaun ran demos with the vendors on his shortlist. What tipped the decision was how the Escape team showed up:

"It just felt that your team took a bit more of a partner-based approach. Understanding the business, where we're at in the business, knowing that it's our first year in business. The people we talked to just took a more partner-centric approach that even included how responsive you were to questions and emails." - Shaun Ricci, Co-Founder and COO, Amp

Once the agreement was signed, here is what the engagement looked like: 

1. The scope stayed narrow

Amp pointed the test at a dedicated pentest subdomain covering the product application. The corporate website was excluded up front, and Escape's onboarding team verified the subdomain exclusions before the first run.

The agent stayed inside the boundary it was given.

2. Setup was a login and a button

Nem ran the test himself from the Escape platform:

"What I’ve seen with other companies is that the major bottleneck is how you set up the test. With Escape, all I had to do was log into the portal and click a button." -  Nem Stefanovic, VP, AI Operations, Amp

3.The test finished in hours

In several hours of agent time, compared to the weeks a manual engagement takes end-to-end.

4. Findings went straight into the dev workflow

Nem exported the findings, opened remediation tickets against them with detailed information, and issues were fixed very quickly. 

5. Two reports, two jobs

Amp got two reports out of a single test.

One is for the auditors. It is the document that satisfied the pentest control at SOC 2 type II. 

The other is the detailed one. Nem worked through it to fix what the test found. After the retest, the same report showed which findings had been closed.

Impact

1. A pentest that fits inside a working day

Amp's first pentest took about several hours of agent time. A manual engagement of comparable scope is weeks of calendar, most of it spent not testing.

Amp is shipping product, standing up compliance and onboarding customers at the same time. Compressing the pentest from weeks of scheduling to a single day means the security work gets done without becoming a bottleneck for the team. 

2. Findings that closed instead of sitting

Escape findings arrive with the evidence attached, so Nem could move straight from export to remediation. The issues from the first run were resolved and confirmed on retest.

3. A confusing finding, answered without asking anyone

The first run came back with several findings. 

One of them did not make sense, so Nem went into the reasoning logs, and they explained it. The agent had tested its own role access, using the credentials Amp had given it, downgraded itself to test the boundary, and then reported what it found.

Every action the agent took was recorded in a detailed sequence. So when a result seemed wrong to Nem, it was easy to understand why, whether it was actually the case, and how to avoid it in the future. 

4. SOC 2 evidence, handed over

Amp's SOC 2 Type II audit runs once a year. The report goes to the auditors as evidence for the pentest control. ISO 27001 is next.

5. Once a year is no longer the only option

The clearest sign that something changed is what Amp is now willing to consider.

"It's something that we used to do once a year, and now I think, with your product, it may be more than once a year." - Shaun Ricci

When a pentest takes weeks to arrange and a large budget line to approve, once a year is the only cadence that works. When it takes a login, a click of a button, and several hours, the question becomes how often you want the answer.

If you want to escape the limits of manual annual pentests, schedule a demo to see how we can transform your pentest cadence.