Success Stories

Verne Success Story — Vanta Implementation

How Up Secure implemented Vanta at Verne — custom frameworks, a restructured policy library, and automated evidence collection across multi-site data centre operations.

Verne is a low-carbon, high-performance data centre operator headquartered in London, running colocation campuses in Iceland and Finland with further sites under development in France and Norway. Serving enterprise and AI infrastructure customers, Verne faces continuous security due diligence from prospects and partners, alongside regulatory expectations under GDPR and NIS 2 and customer-driven ISO 27001 and SOC 2 requirements. Up Secure was engaged to implement Vanta as the operational backbone of the company’s compliance programme, replacing spreadsheet-based tracking with a single, evidence-driven system of record.

Custom Framework Configuration

Standard framework templates did not reflect how a multi-site data centre operator actually works. Custom frameworks were built inside Vanta to represent Verne’s own control set, mapping shared controls once and reusing them across ISO 27001, SOC 2 and internal governance requirements. Physical security, environmental controls and site-level operational procedures — areas that generic SaaS-oriented templates cover poorly — were modelled explicitly and assigned to site operations teams rather than to IT.

Cross-framework mapping meant that a single control test satisfies several obligations at once, which removed duplicated evidence collection and gave leadership one accurate view of coverage instead of several conflicting ones.

Policy Architecture and Ownership

The policy library was restructured into a coherent hierarchy: a small set of governing policies, supported by standards and procedures that carry the operational detail. Each document received a named owner, a review cycle and an explicit link to the controls it supports, so that policy changes and control evidence stay synchronised.

Policy acceptance was moved into the onboarding flow, giving auditable proof of attestation for every employee and contractor without manual chasing.

Automation and Evidence Collection

Vanta integrations were connected across identity, endpoint, cloud and ticketing systems so that control evidence is gathered continuously rather than assembled before an audit. Automated tests were tuned to Verne’s environment to suppress noise and surface genuine failures, with alert routing to the teams able to act on them.

Where automation was not possible — physical access reviews, site inspections, supplier assessments — structured manual workflows with a defined cadence and evidence format were introduced so that these controls remain audit-grade.

Access Reviews, Personnel and Vendor Workflows

Onboarding and offboarding, background screening, security training and periodic access reviews were configured as recurring workflows with clear ownership. Vendor management was brought into the same system, with risk tiering and review triggers aligned to the criticality of each supplier.

What was the business impact?

Verne moved from periodic, project-based compliance effort to a continuously monitored posture. Evidence for customer due diligence and audit preparation is now retrievable on demand, the security questionnaire burden on engineering and operations teams dropped substantially, and control ownership is unambiguous across sites. The custom framework approach ensures the platform reflects how the business genuinely operates, rather than forcing data centre operations into a software-company template. These outcomes were delivered by Up Secure.

Who did benefit from the service?

  • Product teams preparing for security, privacy, or maturity audits
  • Teams building products in regulated industries or processing sensitive data
  • IT Managers and CISOs improving security posture and operational compliance
  • Executives and Business Owners interested in strategic security and compliance maturity

What our customers say?

David Llewellyn
Head of Compliance and Security @Verne

[DRAFT — proposed wording, pending David’s review and approval. Not to be published as attributed until confirmed.]

Up Secure took our compliance programme from something we assembled ahead of each audit to something that runs continuously. Piotr understood quickly that a data centre operator doesn’t fit a standard SaaS control template, and built frameworks around how our sites actually work rather than forcing us into someone else’s model. The result is that control ownership is clear across our footprint and evidence is there when we need it.