<60 seconds
Lower TCO
Zero dependency

CONTEXT
The compliance conversation Athenium couldn’t avoid anymore
Athenium provides advanced quality assurance and risk analytics solutions that enable enterprises to make more informed, data-driven decisions. As their client base grew, so did the frequency of a familiar conversation: security questionnaires arriving with every new prospect, audit requests from existing clients, and the increasingly urgent question of when they'd achieve SOC 2 attestation.
Ken Haugen, IT Manager and Manager of IT Operations at Athenium, became the driving force behind their SOC 2 initiative, pushing the team through a complex, multi-stage SOC 2 audit effort.
Before partnering with Scrut, Athenium's compliance approach was entirely manual. Their internal security manager handled client questionnaires one by one, interpreted audit requirements by hand, and tried to maintain consistency across responses without any centralized system. There was no definitive process for understanding what needed to be done next, no clear framework for prioritizing which resources required security controls, and no efficient way to track their progress toward completing the SOC 2 audit.
CHALLENGES
When the cost, effort, and uncertainty of SOC 2 threatened to slow progress
- Prohibitive cost of compliance tooling: Most platforms Athenium evaluated required an upfront investment of around $50,000. For a small software company, that cost risked turning compliance itself into a barrier to the enterprise opportunities that made it necessary.
- Manual workflows with no visibility into progress: Questionnaires, policies, and evidence were handled manually, with no centralized system to reuse responses or track progress. The team lacked clear visibility into what had been completed, what remained, and whether effort was focused on the right controls.
- Slow clarification cycles created constant delays: Early on, questions were handled through back-and-forth on Microsoft Teams. Requirements were shared, clarifications were requested, and work paused while the team waited for responses. That back-and-forth quickly became a bottleneck.
- No framework for prioritizing security controls: The team struggled to determine where to focus security efforts. Without clear guidance on audit expectations, they risked spending time on low-impact areas while missing critical gaps.
SOLUTION
How Scrut Teammates became Athenium's virtual compliance analyst
Athenium's partnership with Scrut addressed both the economic and operational challenges they faced. Compared to alternatives, Scrut provided an all-inclusive solution at a significantly lower total cost of ownership. This made enterprise-grade compliance achievable for a small software company.
But the real transformation came when Scrut introduced Teammates to Athenium's workflow in the early months of their SOC 2 journey.
SCRUT TEAMMATES
An AI assistant trained on their actual compliance data
When Ken first used Scrut Teammates, he approached it with caution. He had worked with AI tools before and did not expect more than a generic interpretation of a SOC 2 requirement.
He copied a requirement for evidence directly from the platform and pasted it into Teammates. The response was not a broad explanation or a theoretical overview of the control. It was a concrete task list outlining exactly what needed to be done to satisfy the requirement.
Ken followed the steps as written. Everything aligned.
The difference was in how Teammates generated its answers. Rather than searching the internet or pulling from generic compliance libraries, it referenced only Athenium’s own data. Existing policies, uploaded evidence, and completed testing were all used as context. Scrut Teammates was not explaining what a SOC 2 control typically requires. It was telling Athenium what they needed to provide based on their actual compliance posture.
Ken notes that he has yet to receive an answer that was not relevant to his question. Compliance questions that previously introduced delays could now be resolved immediately, allowing work to continue without interruption.
“If there’s a question, I don’t bother waiting anymore. I ask Teammates, and I get an answer immediately. “
Ken Haugen, IT Manager, Athenium
Tailored explanations for technical and non-technical stakeholders
Different roles at Athenium required different levels of detail.
Ken and the Director of Engineering needed comprehensive explanations so they could translate requirements into concrete technical actions and guide their teams on what evidence to pull and how to configure controls. Other team members did not need the full technical rationale. They needed clear instructions on what to do next.
Scrut Teammates supported both. When questions arose about evidence formats or documentation requirements, the tool clarified exactly what auditors expected. If an explanation felt too detailed or too abstract, the team could ask follow-up questions and have the response reframed at the right level of depth.
This flexibility meant explanations no longer blocked progress. Each team member could get the amount of detail they needed without escalating questions or waiting for clarification.

Automated questionnaire responses from a centralized compliance vault
Beyond audit preparation, Athenium continued to receive security questionnaires from prospects and clients, a process previously handled manually.
The team adopted Scrut Teammates to auto-fill security questionnaires. Every new questionnaire now starts in Teammates, with responses populated based on contextual information and previously answered data. This ensured consistency across submissions while significantly reducing the time required to complete each questionnaire.
As Athenium’s internal processes evolved, Questionnaire responses reflected the current compliance posture rather than relying on outdated answers, removing the need for repeated manual review.

IMPACT
How Athenium reduced friction and kept its SOC 2 work moving
For Athenium, the biggest shift was not tooling or ownership. It was momentum.
- Greater than 80% reduction in evidence submission delays: Delays caused by interpreting requirements and waiting for clarification dropped by more than 80%. Work that previously stalled while the team waited hours for answers could now move forward immediately.
- Immediate, contextual answers that eliminated dependency on human support: Compliance questions no longer introduce wait time. Scrut Teammates delivered contextual answers in under 45 seconds, removing the need to wait on human support for day-to-day clarification and keeping compliance work moving without interruption.
- Significant time savings on questionnaire responses: Security questionnaires became faster and more consistent to complete. Responses no longer had to be rebuilt each time, and they stayed aligned as internal processes evolved, reducing repeated manual effort.
“Once we started using Scrut Teammates, it cut down more than 80% of the delay in understanding what we were looking for and getting the evidence submitted.”
— Ken Haugen, IT Manager, Athenium
Success stories from the GRC frontlines





















