Verne is a low-carbon, high-performance data centre operator headquartered in London, running colocation campuses in Iceland and Finland with further sites under development in France and Norway. Serving enterprise and AI infrastructure customers, Verne faces continuous security due diligence from prospects and partners, alongside regulatory expectations under GDPR and NIS 2 and customer-driven ISO 27001 and SOC 2 requirements. Up Secure was engaged to implement Vanta as the operational backbone of the company’s compliance programme, replacing spreadsheet-based tracking with a single, evidence-driven system of record.
Custom Framework Configuration
Standard framework templates did not reflect how a multi-site data centre operator actually works. Custom frameworks were built inside Vanta to represent Verne’s own control set, mapping shared controls once and reusing them across ISO 27001, SOC 2 and internal governance requirements. Physical security, environmental controls and site-level operational procedures — areas that generic SaaS-oriented templates cover poorly — were modelled explicitly and assigned to site operations teams rather than to IT.
Cross-framework mapping meant that a single control test satisfies several obligations at once, which removed duplicated evidence collection and gave leadership one accurate view of coverage instead of several conflicting ones.
Policy Architecture and Ownership
The policy library was restructured into a coherent hierarchy: a small set of governing policies, supported by standards and procedures that carry the operational detail. Each document received a named owner, a review cycle and an explicit link to the controls it supports, so that policy changes and control evidence stay synchronised.
Policy acceptance was moved into the onboarding flow, giving auditable proof of attestation for every employee and contractor without manual chasing.
Automation and Evidence Collection
Vanta integrations were connected across identity, endpoint, cloud and ticketing systems so that control evidence is gathered continuously rather than assembled before an audit. Automated tests were tuned to Verne’s environment to suppress noise and surface genuine failures, with alert routing to the teams able to act on them.
Where automation was not possible — physical access reviews, site inspections, supplier assessments — structured manual workflows with a defined cadence and evidence format were introduced so that these controls remain audit-grade.
Access Reviews, Personnel and Vendor Workflows
Onboarding and offboarding, background screening, security training and periodic access reviews were configured as recurring workflows with clear ownership. Vendor management was brought into the same system, with risk tiering and review triggers aligned to the criticality of each supplier.
What was the business impact?
Verne moved from periodic, project-based compliance effort to a continuously monitored posture. Evidence for customer due diligence and audit preparation is now retrievable on demand, the security questionnaire burden on engineering and operations teams dropped substantially, and control ownership is unambiguous across sites. The custom framework approach ensures the platform reflects how the business genuinely operates, rather than forcing data centre operations into a software-company template. These outcomes were delivered by Up Secure.