logo
hamburger-menu-icon
Back to Projects

Daybreak

Running security and IT ops for enterprise AI

Daybreak AI, a growth stage AI company selling to enterprise customers, had no dedicated IT and security leader, and compliance work was overloading engineering. Ollon embedded a fractional IT and security lead running SOC 2 and GDPR compliance across teams in North America and India. Daybreak now passes enterprise security reviews cleanly, with SOC 2 audits closing with zero exceptions.

Daybreak AI is a growth-stage AI company serving enterprise customers in manufacturing, CPG, retail, and logistics. As the company grew, closing deals with large enterprise customers required passing rigorous security audits, maintaining compliance certifications, and producing detailed documentation on demand. Without a dedicated IT and security leader, these requirements were creating friction in sales and placing unmanageable overhead on the engineering team.

Ollon provided a fractional IT and security lead embedded directly within Daybreak's organization, owning the function end-to-end across IT operations, compliance, vendor and customer security reviews, and cloud cost management. The role covered maintaining SOC 2 Type II and GDPR certifications, running regular security testing, standardizing IT support across teams in North America and India, and handling security due diligence for enterprise customer onboarding.

Daybreak's IT and security function now operates at the level enterprise customers expect, with certifications maintained, audits passed cleanly, and documentation ready when customers ask for it. The engineering team is no longer pulled into compliance work, and the company has successfully onboarded multiple customers through their security review processes. Ollon's embedded resource continues to lead the function as Daybreak scales.

Terraform, Docker, AWS, Databricks, Datadog, Sprinto, Azure DevOps, GitHub, SonarCloud, Jira, Confluence

Our Expertise in Action

Security and compliance consulting

Daybreak's enterprise customers in manufacturing and consumer packaged goods will not sign onto its SaaS platform without proof of certified security controls. Ollon manages Daybreak's full compliance program through Sprinto, covering continuous control monitoring, policy management, and audit evidence collection, and maintains a security policy library spanning access control, vendor risk management, and data sanitization. Ollon keeps SOC 2 Type II audits clean, most recently closing with zero exceptions, and keeps GDPR certification current, including records of processing activities, subject access requests, and data processing agreements enterprise customers require before signing on.

Fractional CISO and IT leadership

Before this engagement, Daybreak had no dedicated IT or security leader, and enterprise security requirements were creating friction in sales while piling overhead onto the engineering team. Ollon stepped in as that leader, setting the operating model and reporting directly to Daybreak's executive team on security posture and IT direction. That leadership has standardized onboarding, offboarding, and access provisioning across Daybreak's teams in North America and India, giving a distributed workforce one consistent IT support model.

Cybersecurity assessment and incident response

An annual audit alone couldn't tell Daybreak whether its platform would hold up against a real attack. Ollon runs the company's ongoing security testing program, including quarterly internal penetration tests and an annual external test, with the most recent cycles turning up zero critical or high vulnerabilities. Network security is hardened using AWS WAF, VPC security groups, site to site VPN, and zero trust network access, alongside continuous monitoring through AWS GuardDuty and CloudTrail, and Ollon has built out the incident response and business continuity policies that give Daybreak a documented, tested process ready if an incident occurs.

Azure DevOps

Daybreak ships code across multiple teams and needs to catch vulnerabilities before they reach production, not after a customer's security review flags them. Ollon runs Azure DevOps as part of that delivery pipeline, layering in SonarCloud and Checkov to catch vulnerabilities and misconfigurations early, alongside branch protection policies and mandatory code review before any change ships. That pipeline now catches security and code quality issues automatically on every pull request, before a human reviewer ever has to go looking for them.

GitHub

Daybreak's code lives across two systems, Azure DevOps and GitHub, and each needed the same security discipline applied to it. Ollon manages security across Daybreak's GitHub repositories, including dependency vulnerability monitoring and the same code scanning and branch protection standards applied to Azure DevOps. That parity means a vulnerability gets caught the same way regardless of which system it surfaces in, with both platforms feeding into the same review and remediation process Daybreak's engineering team already follows.

DevOps and infrastructure management

Daybreak runs AWS infrastructure across regions including us-east-1 and us-west-1, and needs to keep environments consistent and auditable as the company scales. Ollon manages that infrastructure using Terraform and Docker, and on the FinOps side identifies savings through AWS Savings Plans and resource optimization, reducing cloud spend. That work moved cost visibility from a reactive line item into something leadership monitors and adjusts on an ongoing basis, catching overages before they show up on a monthly bill.