# Fathommill

*/Startups/Fathommill*

## Startup Overview

This platform parses and maps compliance evidence directly from unstructured infrastructure logs. Instead of relying on manual attestations or API-heavy integrations, the system ingests raw system outputs, traces security events, and correlates log data directly to regulatory frameworks.

Engineering and security teams lose weeks writing manual grep scripts to extract proof of compliance for auditors. Traditional compliance software forces teams into heavy setup phases, requiring them to tag assets and map architectures before generating actionable reports.

The service bypasses this setup phase entirely by operating fully managed without dashboard configuration. Unlike legacy alternatives such as Vanta or Secureframe, it extracts verifiable evidence straight from raw infrastructure data and prices the system strictly per verified control.

## Startup Founding Hypothesis

**Approach**: that parses and maps evidence from unstructured infrastructure logs
**Competitors**:
- [Vanta](/Competitors/Vanta)
- [Secureframe](/Competitors/Secureframe)
- [manual grep scripts](/Competitors/manual_grep_scripts)
**Differentiator2x2**: fully managed without dashboard configuration and priced per verified control

## Startup Solution Coordinate

**Solution**: [Evidence Mapping Service](/Services/Evidence_Mapping_Service)

## Startup Position2x2

```mermaid
quadrantChart
    title Fathommill vs Competitors
    x-axis Dashboard Driven Setup --> Fully Managed (Zero Config)
    y-axis Flat Subscription Pricing --> Priced Per Verified Control
    quadrant-1 Automated & Aligned Value
    quadrant-2 Bespoke Services
    quadrant-3 Legacy Platforms & DIY
    quadrant-4 Turnkey Dashboards
    Fathommill: [0.85, 0.85]
    Vanta: [0.35, 0.20]
    Secureframe: [0.45, 0.25]
    manual grep scripts: [0.10, 0.10]
```

## Startup Customer Journey

```mermaid
flowchart LR; A[Boutique Consultant] --> C[Single Log Stream]; B[Autonomous Security Agent] --> C; C --> D[Evidence Extraction API]; D --> E[Standard Control Pipeline]; E --> F[Custom Infrastructure Parser]; F --> G[External Auditor];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day AWS log integration pilot: Connect standard log streams to map 20 core SOC 2 technical controls, aiming to prove complete automated evidence extraction without manual engineering input.
- 60-day legacy system parallel run: Process unstructured on-prem logs alongside an active compliance audit to target zero auditor requests for supplemental data on Fathommill-handled controls.
**Target Metrics**:
- Target: 40+ hours of manual engineering screenshot collection eliminated per audit cycle
- Aim: 0 auditor kickbacks on evidence extracted from unstructured infrastructure logs
- Target: 100% technical control coverage derived exclusively from raw log streams
- Aim: 24-hour maximum turnaround time for manual evidence retrieval if an automated log parse is rejected
**Target Case Studies**:
- Series B Fintech Engineering Team: Eliminate manual SOC 2 evidence collection by successfully extracting 100% of required technical assertions directly from unstructured AWS CloudTrail and application log streams.
- Legacy Enterprise SaaS Provider: Prove continuous compliance on undocumented on-prem systems by mapping custom infrastructure logs to internal security frameworks without installing new endpoint agents.
- Healthcare Data Platform: Automate technical control verification without exposing sensitive payloads by deploying the Fathommill log parsing engine entirely within their native VPC.
**Testimonial Targets**:
- VP of Engineering: Relief that developers no longer need to pause product work to manually gather configuration screenshots for compliance audits.
- Head of Compliance: Confidence that external auditors readily accept the raw, AICPA-friendly log exports without demanding supplementary proprietary dashboard views.
- Chief Information Security Officer: Satisfaction that the VPC-deployed lightweight parser automated technical evidence extraction without transmitting sensitive payload data externally.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: Auditors reject automated unstructured log parsing as sufficient evidence for compliance frameworks like SOC 2 and ISO 27001 without manual review. · Mitigation Status: in-progress
- Severity: high · Description: Unstructured infrastructure logs from highly customized or legacy environments break the parser, causing missing control evidence and failed audits. · Mitigation Status: in-progress
- Severity: high · Description: Incumbents like Vanta or Secureframe bundle zero-configuration log ingestion into their existing platforms before Fathommill reaches scale. · Mitigation Status: unmitigated
- Severity: moderate · Description: Mid-market security teams reject the per-verified-control pricing model due to unpredictable budget scaling compared to traditional flat-fee alternatives. · Mitigation Status: unmitigated

## Startup Token Bindings

**Vocab Fingerprint**: 731b5fab4fbaf49a

## Neighborhood

### Candidate solutions

- [Extended Financial Close](/Problems/Extended_Financial_Close) — candidate solution for · Problems

### What it offers

- [Evidence Mapping Service](/Services/Evidence_Mapping_Service) — offers · Services
- [Autonomous Close Service](/Services/Autonomous_Close_Service) — offers · Services

### Competitors

- [Secureframe](/Competitors/Secureframe) — competes with · Competitors
- [Vanta](/Competitors/Vanta) — competes with · Competitors
- [manual grep scripts](/Competitors/manual_grep_scripts) — competes with · Competitors
- [Offshore Accounting BPOs](/Startups/Offshore_Accounting_BPOs) — competes with · Startups
- [Manual Excel Spreadsheets](/Startups/Manual_Excel_Spreadsheets) — competes with · Startups
- [FloQast Accounting Operations](/Startups/FloQast_Accounting_Operations) — competes with · Startups
- [BlackLine Close Management](/Startups/BlackLine_Close_Management) — competes with · Startups

### What it addresses

- [chasing lien waivers from subs who finished the job three weeks ago](/Problems/chasing_lien_waivers_from_subs_who_finished_the_job_three_weeks_ago) — addresses · Problems

### Who it serves

- [first-line supervisors of police and detectives](/CompanyTypes/first-line_supervisors_of_police_and_detectives) — serves · CompanyTypes
- [Corporate Finance Department](/CompanyTypes/Corporate_Finance_Department) — serves · CompanyTypes

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### Composed of

- [Ledger Write API](/Agents/Ledger_Write_API) — composes · Agents
- [Autonomous Close Service](/Agents/Autonomous_Close_Service) — composes · Agents
- [Continuous Reconciliation Agent](/Agents/Continuous_Reconciliation_Agent) — composes · Agents
- [Discrepancy Investigation Agent](/Agents/Discrepancy_Investigation_Agent) — composes · Agents
- [Audit Evidence API](/Agents/Audit_Evidence_API) — composes · Agents

### Entrant in opportunity

- [Autonomous Financial Close for Accountants](/Opportunities/Autonomous_Financial_Close_for_Accountants) — is entrant in · Opportunities

### Similar Startups

- [Sociprim](/Startups/Sociprim) — similar · Startups
- [Auditfoundry](/Startups/Auditfoundry) — similar · Startups
- [Auditpoint](/Startups/Auditpoint) — similar · Startups
- [Rubricvault](/Startups/Rubricvault) — similar · Startups
- [Autecheck](/Startups/Autecheck) — similar · Startups
- [Certore](/Startups/Certore) — similar · Startups
- [Allaster](/Startups/Allaster) — similar · Startups
- [Valel](/Startups/Valel) — similar · Startups
- [Spiritpoint](/Startups/Spiritpoint) — similar · Startups
- [Auditunit](/Startups/Auditunit) — similar · Startups
- [Coveloom](/Startups/Coveloom) — similar · Startups
- [Castossom](/Startups/Castossom) — similar · Startups
- [Adherencepark](/Startups/Adherencepark) — similar · Startups
- [Evidencewand](/Startups/Evidencewand) — similar · Startups
- [Assurancepivot](/Startups/Assurancepivot) — similar · Startups
- [Problient](/Startups/Problient) — similar · Startups
- [Aaronic](/Startups/Aaronic) — similar · Startups
- [Auderify](/Startups/Auderify) — similar · Startups
- [Assuranceblend](/Startups/Assuranceblend) — similar · Startups
- [Compibe](/Startups/Compibe) — similar · Startups
