What do you like best?
Easy to use
Great features: Policy mgt, risk mgt, controls
Easy to integrate requirements to documents and controls
Good vendor management tool. The ability to log security reviews, send questionnaires and set reminders is great.
What do you dislike?
The product definitely needs refinement. There are important pieces missing if you want to make SF the sole tool when managing standards and your privacy program.
The developers/team, need a better understand of the different use cases.
The UI/UX is not great.
Onboarding process was not good. But I believe they are improving it.
The TASK feature needs some improvements.
The teams needs to be able to create better test scenarios before releasing features.
Recommendations to others considering the product:
I would recommend to create a good onboarding plan!
What problems are you solving with the product? What benefits have you realized?
I pretty much manage my entire ISO, SOC and privacy compliance program using SF.
I also use it as a central vendor management platform.
All my internal policies, procedures and documents are logged there.
I also use SF during my internal and external audits. Our auditors are usually really impressed with the amount of information we have logged there and how we manage risks and compliance using SF.