For founders

Your first ISO 27001 or SOC 2. Without a compliance team.

Teddy’s agents plan your ISO 27001 certification or SOC 2 audit, draft the documents and find what needs fixing. A compliance engineer takes you through the audit. You make the calls and get back to building.

Antler portfolio company? Claim your discount →
First certificateISO 27001 or SOC 2
Your toolsEvidence from cloud, logins and code
Real peopleA compliance engineer through the audit
The founder’s problem

The deal is ready.
The security review is not.

Your first enterprise customer wants an ISO 27001 certificate or a SOC 2 report before they sign. Nobody on the team has done this before, and every hour spent on compliance is an hour not spent on the product.

01Customers ask for a certificate

Teddy plans your way to ISO 27001 or SOC 2 so the deal can close.

02Where to start

The Certification Agent sets the scope and the order of the work.

03Policies that fit

The Policy Agent writes them based on the tools you actually use.

04A chatbot writes documents. It doesn’t get you through the audit.

ChatGPT or Claude can draft a policy set in an afternoon. But it doesn’t know your systems, contradicts itself and links to no evidence. Teddy guides you step by step instead.

How it works

From “where do we start?” to your first audit

Teddy turns the standard into a plan for your company. Agents do the preparation at every step, and you approve what matters.

01 Certification Agent

Pick your framework, define your scope

Choose ISO 27001 or SOC 2 Type II. Teddy proposes a scope around your product and the teams that run it, so the audit covers what customers ask about and nothing more.

Choose your frameworkStep 1 of 6
SOC 2 Type IIFor US customers
ISO 27001For European customers
Proposed scope: Acme platform, AWS, engineering and supportReview
02 Gap Audit Agent

See what is missing, and what needs fixing

A first gap audit checks every requirement against what you already have, including your live systems. You get a short list of gaps and findings instead of a 100-page standard.

Gap audit · ISO 27001:202212% ready
Clause 4 · Context of the organizationMissing
A.5.15 Access controlMet
A.8.24 · acme-backups not encryptedFinding
03 Certification Agent

Risks and Statement of Applicability, prefilled

Risks from the gap audit and your systems land in the register automatically. Teddy drafts the Statement of Applicability with a justification for every control. You decide on treatment.

Risk registerAdded by Teddy
Backups stored unencryptedHigh
Single cloud regionMedium
Teddy: A.7.4 is applicable because your office holds laptops with customer data. Do you control access at the entrance?
04 Policy Agent

Policies that tell your team what to change

Policies set the rules your company has to meet. Teddy adapts proven templates to your stack and checks your systems against them, so you know exactly what to change.

Cryptography policyDraft v1
Encryption at rest for all customer dataNot met
TLS 1.2 or higher in transitMet
Teddy: acme-backups is not encrypted. I created a task for Lukas to enable default encryption.
05 Evidence Agent

Evidence from the tools you already use

Connect your cloud, identity provider and code repositories read-only. Evidence is collected on a schedule and mapped to every control it supports.

EvidenceUpdated today
AWS · Encryption at restCollected
Google Workspace · MFA for all usersCollected
GitHub · Branch protection2 repos missing
06 Compliance engineer

Through the audit, with a person at your side

Teddy connects you with an accredited certification body for ISO 27001 or a CPA firm for SOC 2 and prepares the audit package. Your compliance engineer joins the audit and handles the communication with you.

AuditStage 1 scheduled
Readiness checkPassed
Audit package for the certification bodyReady
Compliance engineer joins Stage 1 and 2Confirmed
Why not just ask a chatbot?General AI assistants like ChatGPT or Claude write documents fast. They don’t know what an auditor accepts, what in your setup has to be fixed, or how your scope, risks, policies and evidence fit together. Getting through an audit takes someone who knows, and that is why a compliance engineer is part of every audit.
Never stuck

Ask Teddy. Agents do it. People back you up.

Whenever you are unsure, ask in plain language. Teddy answers in the context of your company and does the work. When you want a person, our team is one message away.

1

Ask TeddyWhat do I need next? What will the auditor ask? Teddy knows your scope, your systems and your progress.

2

Agents do the workDrafts, checks and evidence arrive ready for your approval, each with its source.

3

Our team backs you upA compliance engineer introduces the certification body or audit firm, handles the communication and joins your audit.

TeddyAcme Inc. · ISO 27001
The auditor asks how we handle backups. What do we show them?
Show the backup policy, the AWS Backup report and your last restore test. I linked them as evidence for A.8.13.
  • Backup policy v2Approved
  • AWS Backup report · SeptemberCollected
  • Restore test · Q3Missing
The Q3 restore test is missing. Shall I plan it for next week?
Plan restore testAsk our team
CEYour compliance engineer is available for anything you want to discuss with a person.
“As a founder, I needed a certificate before our first enterprise deal could close. As a CISO, I spent years taking other companies through the same audit. Teddy is what I wished I’d had on both sides of the table.”
Sven MoritzCo-founder, Teddy · former CISO
Startup offer

Special pricing for startups. More for Antler founders.

Early-stage companies get startup pricing for their first framework. Antler portfolio companies get an additional discount on top.

Your first framework, from scoping to the audit
Compliance engineer through the audit
Introduction to a certification body or audit firm
Ready for your next framework on the same control set
FAQ

Questions founders ask

How long does a first ISO 27001 or SOC 2 take?

It depends on your starting point and scope. After the first gap audit, Teddy shows every remaining step in order. ISO 27001 then has two audit stages with the certification body. SOC 2 Type II needs an observation period, usually between three and twelve months.

How much of my time will it take?

Agents do the preparation. Your time goes into decisions and approving drafts, and Teddy shows what is waiting for you each week.

ISO 27001 or SOC 2: which one first?

Start with the one your customers ask for. European buyers usually ask for ISO 27001, US buyers for SOC 2. Both run on the same control set in Teddy, so the second one is much faster.

Do we still need a consultant?

No. Teddy’s agents prepare everything, and a compliance engineer from our team introduces the certification body or audit firm and takes you through the audit.

Get your first certificate or SOC 2 report. Keep building.

Start with a short call. We look at your customers, your stack and the framework you need.

What changes with Teddy

How long your first audit takes, and how Teddy cuts it to weeks

Typical6 to 12 months

From kickoff to a first ISO 27001 certificate. Most of the time goes into working out what the standard means for your company.

With TeddyWithin weeks

Audit-ready. Scope, risks, policies and evidence built from your real systems, and a compliance engineer through the audit.

Why Teddy

Teddy was built by former CISOs and GRC managers who took companies through ISO 27001 and SOC 2 audits, and by founders who needed a certificate before their first enterprise deal could close. That is why every plan in Teddy ends at the audit, not at a pile of documents.

Meet the founders →