echowin × Sythe Labs.
The whole security department, owned end to end. HIPAA attestation held, SOC 2 underway, and continuous vulnerability management keeping the platform proven as it ships.
HIPAA attestation held and SOC 2 underway, on a security program built to open new markets, starting with a new fintech vertical.
Who echowin is.
echowin is an all-in-one AI agent builder for phone and chat, based in Austin and founded in 2022. Businesses use the platform to build, train, and deploy AI voice and chat agents that answer calls, web chat, WhatsApp, and Discord - 24/7, in more than thirty languages, wired to thousands of downstream tools.
Their customers run from parking and IT services to law firms and healthcare practices. A meaningful slice of that base handles protected health information, which raises the bar on security and compliance from nice-to-have to non-negotiable.
echowin runs lean and ships fast. What they did not have was a security and compliance function to match - and no appetite to build one from scratch.
The challenge.
For echowin's healthcare customers, HIPAA is not optional. It is the gate to the next tier of the market. And as echowin moves upmarket, enterprise buyers are asking for SOC 2 too. Both come down to the same question every serious buyer asks before signing: can you prove this is secure?
At the same time, the product ships fast. AI agents wired to thousands of tools, handling calls and chats that carry protected health information, on a platform that changes every week. The attack surface grows with it.
Building all of this in-house - the compliance program, the security testing, and the people to run both - costs well past half a million dollars a year. echowin needed the whole function, not another tool and not a hire.
What we did.
We took the whole problem off echowin's plate. One team, one platform, across compliance and security.
On compliance, we stood up what was not there: governance, written policies, the controls the business needed to meet, and a process for collecting the evidence to prove them. That work carried echowin to HIPAA attestation, and the same program is now driving SOC 2.
On security, we tested the platform the way an attacker would, then kept testing. A penetration test across echowin's surface, code analysis on the paths that touch customer data, and continuous vulnerability management underneath it all.
The pieces feed each other. What the pen test finds sharpens the scanning and the risk scoring. What the scanning turns up becomes evidence for the next audit. One integrated platform doing the work that used to take five separate vendors.
What keeps running.
A pen test tells echowin where they stand today. Vulnerability management keeps up with everything that changes after. We scan their surface continuously, so new weaknesses get caught as they show up, not at the next audit.
A scanner on its own just makes noise. The difference is what happens next. Real people look at what comes back, sort the real problems from the false alarms, and rank them by how much they actually matter. echowin gets a short list, not a 200-line report: what is urgent, what can wait, and a clear plan for each.
When something needs fixing, we help close it, then test again to make sure it is actually gone.
And it does double duty. The same work that keeps echowin secure also produces the evidence their compliance program needs - so staying secure and staying provable become one motion instead of two.
HIPAA held.
SOC 2 underway.
echowin holds HIPAA attestation, and the program behind it did not exist before: governance in writing and in practice, documented policies mapped to the controls they support, and evidence collected as it happens instead of scrambled together before an audit.
The same machine is now pointed at SOC 2. Because the controls, evidence, and monitoring already run on one platform, adding a framework is an extension, not a fresh start.
The result echowin feels day to day: the BAA conversation has changed, and so has the time it takes to answer a vendor security questionnaire.
The outcome.
Compliance proven and in motion, and a penetration test whose findings were all closed out. HIPAA attestation held, SOC 2 in progress, and every issue the test surfaced remediated, retested, and accepted.
Every finding was fixed and confirmed closed on retest.
Results.
echowin can answer the security question now, with proof behind it.
- -HIPAA attestation held, with governance, policies, and evidence running on their own cadence.
- -SOC 2 underway on the same platform - an extension of the program, not a second project bolted on.
- -Continuous vulnerability management: new issues caught, triaged, closed, and retested as the product ships.
- -Pen test findings closed out: remediated, retested, and accepted, not left as risk to carry.
- -One team, one platform doing the work of five vendors, for one flat price instead of a half-million-dollar build.
- -Cleared to open a new fintech vertical, on the same security and compliance backbone.
The security review that used to stall a deal is now something echowin can point to.
Your security department, on-demand.
One team, one platform, across compliance and security. A 30-minute call and we'll show you what the same program looks like for your stack.