Skip to content
Back to Blog
·6 min read·guides

Case Study: SaaS Startup Shifted Left, Reduced Production Vulns 80%

A 70-engineer SaaS company had a backlog of 340 known vulnerabilities and a SOC 2 auditor asking how they'd reduce it. Bachao.AI's DevSecOps implementation reduced production vulnerabilities 80% in 6 months — and engineering velocity went up.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Get Your Free VAPT Scan

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

The situation

A B2B SaaS company (we'll call them "DataCo") based in Bengaluru had completed SOC 2 Type I. Type II observation was beginning. The auditor's verbal feedback was clear: "Your vulnerability management process needs documented continuous improvement. 340 known production vulnerabilities is a hard number to defend at year-end."

DataCo's profile:

    1. 70 engineers across 14 product teams
    2. ~80 repositories
    3. Java + Node.js + Python services on AWS
    4. 8-month-old SOC 2 Type I in place
    5. Existing vulnerability backlog: 340 across all severities
DataCo's CTO had three constraints:
    1. 6 months until SOC 2 Type II observation ended
    2. Engineering team already complaining about "security blocker" PRs
    3. No security engineer on payroll
    4. Budget approved for security tooling but unsure which

The scoping (Week 0)

Bachao.AI's DevSecOps lead did a 2-day workshop with DataCo's engineering directors. Findings:

    1. 80 repos, ~340 vulnerabilities mostly clustered in 12 critical services
    2. 50% of "vulnerabilities" were duplicate findings (same package, multiple repos)
    3. 22% were false positives or not exploitable in DataCo's context
    4. 28% were genuine and required attention
    5. Tooling: GitHub for code, GitHub Actions for CI, ECR for containers, AWS EKS for runtime
Recommendation: Standard tier — Semgrep Pro + Snyk + Trivy + Wiz + Datadog Security.

Implementation (Weeks 1-6)

Week 1-2: CI pipeline security

    1. Semgrep installed on every repo
    2. Custom rule set tailored to DataCo's framework patterns (Spring Boot, Express, FastAPI)
    3. Triage sprint over 4 days: 340 backlog reduced to 187 genuine findings
    4. Pre-merge gates calibrated
Week 3-4: Continuous monitoring
    1. Snyk integrated across all 80 repos
    2. Daily Trivy scan on ECR
    3. Wiz CSPM enabled on AWS
    4. Centralised dashboard (single pane of glass for vulnerabilities)
Week 5-6: Runtime telemetry
    1. CloudTrail enriched into Datadog Security
    2. 12 custom detection rules (data exfiltration patterns, anomalous API calls, identity behaviour)
    3. On-call rotation set up for security events
    4. First synthetic exercise (red-team-style detection test)

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

Results at 6 months

Vulnerability backlog:

    1. Start: 340 (after deduplication: 187 genuine)
    2. End: 38 (80% reduction)
    3. New introductions per month: dropped from 18-22/month to 4-6/month
    4. Mean time to remediation: dropped from 84 days to 11 days
Detection coverage:
    1. 12 → 47 detection rules
    2. First simulated attack scenarios detected within target SLOs (most under 5 minutes detection)
Engineering velocity:
    1. "Security blocker" PR rejection rate: 4.2% → 1.1% (fewer surprises in CI)
    2. Average PR review time including security checks: increased by 2 minutes (negligible)
    3. Critical/High vulnerability remediation: moved from incident-response work to in-sprint work
SOC 2 Type II:
    1. Auditor noted "documented continuous improvement"
    2. Vulnerability backlog reduction included as evidence
    3. Zero findings on the vulnerability management control area

What it cost

Line itemYear 1 cost
Bachao.AI 6-week implementation sprint₹6L
Bachao.AI monthly retainer (12 months)₹18L
Tool licences (Semgrep Pro + Snyk + Wiz + Datadog Security)₹30L
Internal engineering time (triage workshops, runbook reviews)~₹8L opportunity cost
Total Year-1 investment₹62L
DataCo's CTO assessed: prior approach (manual quarterly vulnerability sweeps + audit-driven remediation) was costing ~₹15L/year in engineering time + ~₹4L in quarterly consultant costs + significant audit risk. New approach: higher direct cost, materially lower hidden cost + audit-quality outcomes.

What DataCo's CTO said

"Security as a separate team felt like the answer until we couldn't afford to hire one. Bachao gave us the playbook for security as part of engineering. The dashboard, the runbooks, the on-call — our engineers now own it. Bachao tunes and reviews monthly. Our SOC 2 auditor stopped asking questions about vulnerability management because the data spoke for itself."

Pattern this engagement followed

Common shape for Bachao.AI DevSecOps engagements:

  1. SaaS engineering team with active engineering velocity
  2. SOC 2 / DPDP / ISO 27001 compliance event creating pressure
  3. No dedicated security engineer
  4. Tooling budget exists but tool selection unclear
  5. Need for documented continuous improvement
If your engineering team is in a similar place:

Schedule the DevSecOps scoping workshop →


Related: DevSecOps Methodology · DevSecOps for Indian Fintech

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Know your vulnerabilities before attackers do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →