Product
SOC 2 Type II, SOC 3, vCISO
Industry
Financial services
Engagement Length
Ongoing since 2025
Location
New York, USA
Outcome
Zero security breaches and a SOC 2 program maintained year-round ahead of the December 2026 audit
Key Performance Metrics
In place, now maintained month by month
Penetration testing of Hitch’s client lender instances
Security breaches since Axipro came on board in 2025
Next audit, prepared for all year rather than crammed for
At a Glance
- Challenge: Hitch had a SOC 2 Type II and SOC 3 report, but teams worked in silos, some processes weren’t yet running in practice, and several controls had no clear owner, while its lender partners expected continuous proof of security.
- Solution: Axipro became Hitch’s security and compliance function, with a dedicated vCISO, a monthly compliance plan, regular stakeholder syncs, recurring vulnerability and penetration testing, and 24/7 monitoring.
- Results: Zero security breaches since the engagement began, gaps that get fixed as they happen instead of at audit time, and Hitch heading into its December 2026 examination with controls, evidence, and testing maintained throughout the year.
The Company
Hitch turns traditional lenders into home equity fintechs. Its white-label platform covers the whole lending flow, from the borrower’s application to a loan officer portal to connections with capital markets partners, so lenders can offer home equity products under their own brand.
Founded in 2023 and based in New York, Hitch runs with a team of fewer than 50 people. The data moving through its platform is what makes security a commercial issue, not just a technical one: borrower applications, credit and property information, and loan decisions, all processed on behalf of lenders.
Those lenders hold Hitch to their own standards. Hitch’s mortgage-lender partners require monthly penetration testing of the Hitch instances that serve them, and a current SOC 2 report is part of passing their vendor reviews. Hitch also holds a SOC 3 report, the public summary of its SOC 2 Type II that it can share openly with prospects.
01- THE CHALLENGE
Keeping a Type II Report Working Between Audits
Hitch’s SOC 2 Type II and SOC 3 examination was performed by Sensiba, with the report completed in March 2026. Keeping the controls behind it running every week of the year is harder, especially for a company of Hitch’s size without a full-time security leader.
When Axipro started working with Hitch in 2025, teams were working largely in silos, and certain control activities had no clearly assigned owner.
Some processes existed on paper but weren’t yet operationalized. None of that shows up on the day a report is issued. It shows up months later, when evidence is missing for a period or an auditor asks who owned a control.
A Type II report tests whether controls work consistently over time, so drift puts the next report at risk. For Hitch, it also put lender relationships at risk.
02- THE ENGAGEMENT
A vCISO, a Monthly Plan, and Testing on the Lenders’ Cadence
● Why Hitch brought in Axipro
Hitch wanted dedicated professional support to run its compliance program, rather than leaving it as a side job spread across the team. It was already in discussions with Axipro, so it brought Axipro in to support both its SOC 2 compliance and its wider information security program, led by a dedicated virtual CISO instead of a full-time hire.
● A security leader without a full-time hire
Axipro’s vCISO started with structure: clear ownership for each control activity, better coordination between teams that had been working separately, and documented controls that are actually implemented and evidenced.
The vCISO meets Hitch’s PM and Tech Lead every two weeks to review findings, open vulnerabilities, log reviews, and SOC 2 posture. Each month Hitch receives a security posture report and any policy updates needed to stay audit-ready. Each quarter brings a full risk register review, a tabletop incident response exercise, and a compliance roadmap update.
● A monthly plan and a weekly rhythm
Axipro built a structured monthly activity plan based on Hitch’s own documented processes and compliance requirements, and tracks every activity through the month so the team can see what’s due and whether it’s done.
Weekly syncs with the relevant stakeholders review progress, clear blockers, clarify who is responsible for what, and agree on the week’s activities. The monthly plan sets the requirements. The weekly sync keeps the program moving.
● Testing on the cadence lenders expect
Because Hitch’s lender partners require it, penetration testing isn’t an annual box to tick. Axipro runs monthly vulnerability scans across production and staging, monthly penetration tests targeting the Hitch instances used by its lender clients, and a quarterly full-scope test covering infrastructure, APIs, and application layers.
Every round comes with prioritized remediation guidance, retesting, and documented findings. That gives Hitch a current, evidenced answer when a lender asks how its platform is tested.
● Round-the-clock monitoring
Between tests, a 24/7 SOC monitors Hitch’s systems, and SIEM analysis correlates activity across sources to flag threats. High-severity alerts are reviewed within two hours, medium alerts within eight, and critical alerts go straight to Hitch’s PM and Tech Lead.
● Catching issues when they happen, not at audit time
Because Axipro reviews the control environment month to month, issues come to light while they are still simple to fix. Monitoring showed that some routine operational steps weren’t always completed on time, and that a few documented procedures weren’t yet fully reflected in day-to-day practice.
Rather than leaving those findings for the next annual audit, Axipro raised them with the relevant process owners as they came up and worked with them to tighten the processes and close the gaps.
03- THE RESULTS
Zero Breaches and Proof on Demand
Hitch now runs security and compliance as a continuous operation rather than an annual event. For a platform that lenders trust with borrower data, that means it can show partners where its security stands at any point in the year, not just when a new report is issued.
- Zero security breaches since Axipro came on board in 2025
- Clear owners for control activities, and teams coordinating through a shared weekly rhythm
- Monthly and quarterly penetration testing, backed by 24/7 monitoring
- Security leadership from a dedicated vCISO, without a full-time hire
What’s Next
Hitch’s next audit is scheduled for December 2026. Axipro and Hitch are using the months leading up to it to keep monitoring the control environment, close any remaining gaps, and make sure evidence and control activities are maintained ahead of the examination.
After that, the annual compliance roadmap session will set priorities for the year ahead.