Teddy’s agents plan your ISO 27001 certification or SOC 2 audit, draft the documents and find what needs fixing. A compliance engineer takes you through the audit. You make the calls and get back to building.
Antler portfolio company? Claim your discount →
Your first enterprise customer wants an ISO 27001 certificate or a SOC 2 report before they sign. Nobody on the team has done this before, and every hour spent on compliance is an hour not spent on the product.
Teddy plans your way to ISO 27001 or SOC 2 so the deal can close.
The Certification Agent sets the scope and the order of the work.
The Policy Agent writes them based on the tools you actually use.
ChatGPT or Claude can draft a policy set in an afternoon. But it doesn’t know your systems, contradicts itself and links to no evidence. Teddy guides you step by step instead.
Teddy turns the standard into a plan for your company. Agents do the preparation at every step, and you approve what matters.
Choose ISO 27001 or SOC 2 Type II. Teddy proposes a scope around your product and the teams that run it, so the audit covers what customers ask about and nothing more.
A first gap audit checks every requirement against what you already have, including your live systems. You get a short list of gaps and findings instead of a 100-page standard.
Risks from the gap audit and your systems land in the register automatically. Teddy drafts the Statement of Applicability with a justification for every control. You decide on treatment.
Policies set the rules your company has to meet. Teddy adapts proven templates to your stack and checks your systems against them, so you know exactly what to change.
Connect your cloud, identity provider and code repositories read-only. Evidence is collected on a schedule and mapped to every control it supports.
Teddy connects you with an accredited certification body for ISO 27001 or a CPA firm for SOC 2 and prepares the audit package. Your compliance engineer joins the audit and handles the communication with you.
Whenever you are unsure, ask in plain language. Teddy answers in the context of your company and does the work. When you want a person, our team is one message away.
Ask TeddyWhat do I need next? What will the auditor ask? Teddy knows your scope, your systems and your progress.
Agents do the workDrafts, checks and evidence arrive ready for your approval, each with its source.
Our team backs you upA compliance engineer introduces the certification body or audit firm, handles the communication and joins your audit.
“As a founder, I needed a certificate before our first enterprise deal could close. As a CISO, I spent years taking other companies through the same audit. Teddy is what I wished I’d had on both sides of the table.”Sven MoritzCo-founder, Teddy · former CISO
Early-stage companies get startup pricing for their first framework. Antler portfolio companies get an additional discount on top.
It depends on your starting point and scope. After the first gap audit, Teddy shows every remaining step in order. ISO 27001 then has two audit stages with the certification body. SOC 2 Type II needs an observation period, usually between three and twelve months.
Agents do the preparation. Your time goes into decisions and approving drafts, and Teddy shows what is waiting for you each week.
Start with the one your customers ask for. European buyers usually ask for ISO 27001, US buyers for SOC 2. Both run on the same control set in Teddy, so the second one is much faster.
No. Teddy’s agents prepare everything, and a compliance engineer from our team introduces the certification body or audit firm and takes you through the audit.
Start with a short call. We look at your customers, your stack and the framework you need.
From kickoff to a first ISO 27001 certificate. Most of the time goes into working out what the standard means for your company.
Audit-ready. Scope, risks, policies and evidence built from your real systems, and a compliance engineer through the audit.
Teddy was built by former CISOs and GRC managers who took companies through ISO 27001 and SOC 2 audits, and by founders who needed a certificate before their first enterprise deal could close. That is why every plan in Teddy ends at the audit, not at a pile of documents.
Meet the founders →