Flamingo Raises $4.5M Seed Round

Back to Life at Flamingo

SOC 2 Push: WAF Hardening, CMEK Encryption, Compliance Backlog

BEST PRACTICESCOMPLIANCEDEVOPSINFRASTRUCTURE MANAGEMENTSECURITY

August 2026

Month

August 27, 2026

Published

Ivan Khropachov

Ivan Khropachov

DevOps Tech Lead

August was a SOC 2 compliance sprint: shipped a fully tuned Web Application Firewall on dev with zero false positives, closed out SMACK encryption findings by migrating production disks and node pools to CMEK, and stood up a four-track compliance backlog with PR-blocking vulnerability scanning already live. Also wrapped dynamic per-branch/PR environments and a couple of small dev-experience wins.

What I Shipped
6

  • Finished dynamic per-branch/PR environments

    Closed out remaining bugs for both tenant and shared environment setups; fully working at the start of the month.

  • Configured and debugged WAF on dev using OWASP CRS

    ~700 rules across ~15 attack categories (SQLi, probes/scanners, rate-limit abuse, etc.), tuned to zero false positives on dev.

  • Encrypted GCP resources with CMEK to close SOC 2 SMACK findings

    Recreated GKE node pools (including production) and migrated production persistent disks to encrypted disks. Took ~1.5-2 weeks due to required restarts/recreation.

  • Built out the SOC 2 compliance backlog

    Organized into four tracks: Security Command Center (GCP findings), Trivy (image/dependency scanning), planned Wiz integration, and firewall rule exclusions.

  • Enabled Trivy scanning to block PRs on high/critical vulnerabilities

    Image and code scanning now runs on every PR; high/critical issues fail the build.

  • Minor dev-experience improvements

    SSO-enabled access to Kafka UI, matching existing Grafana access.

Why It Mattered
3

  • Directly closes SOC 2 gaps

    WAF and CMEK encryption work map straight to SOC 2 requirements and reduce open GCP security findings, even though it's invisible to end users.

  • Shrinks the attack surface without breaking the product

    OWASP CRS rules on dev now block real attack categories with zero false positives, proving the rules are safe to propagate to stage and prod.

  • Creates a clear, trackable path to full compliance

    The four-track backlog (Security Command Center, Trivy, Wiz, firewall exclusions) gives DevOps and dev teams a shared, prioritized view of what's left.

What I Learned
3

  • Encryption migrations are slow by nature

    Most SMACK/encryption fixes require restarting or recreating the resource (node pools, disks), stretching a conceptually simple task into 1.5-2 weeks.

  • Firewall tuning is iterative and time-intensive

    Getting to zero false positives across ~700 rules and ~15 attack categories took about a week of careful debugging and exclusion tuning.

  • Findings overlap across tools

    Security Command Center and the upcoming Wiz integration will surface a lot of duplicate findings, so resolving Command Center issues now reduces future Wiz noise.

What's Next
3

  • Propagate WAF rules to stage, then production

    Dev is stable with zero false positives; next step is validating on stage before rolling out to prod.

  • Set up Wiz scanning

    Planned integration to expand findings coverage alongside Security Command Center and Trivy.

  • Revisit and tighten current firewall exclusions

    Re-include cookie/header handling and other currently-excluded traffic patterns without breaking the product; tracked as its own task set.

Ivan Khropachov

Ivan Khropachov

DevOps Tech Lead

Hi! I’m Ivan, and I’m the new DevOps Engineer here at Flamingo. I’ll be working across infrastructure, CI/CD, and automation to help keep everything stable, secure, and running like clockwork.

Frequently Asked Questions

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.