Orbion builds AI systems that help scientists predict how protein candidates will perform before committing them to the bench — work that depends on customers trusting Orbion with hard-won research: protein sequences, experimental data, and years of IP. Proving that trust was well placed meant building a real information security management system behind it, not just writing a policy.
Orbion has now achieved ISO/IEC 27001 certification, passing its independent Stage 2 audit — conducted by Tempo Audits — with zero nonconformities. The team led its own implementation and audit preparation, using the Kantis platform and support along the way.
Talk to a founder about your ISO route · Explore ISO 27001 for startups
Discuss your scope, team responsibilities, and readiness for an independent audit.
Results at a glance
- ISO/IEC 27001 certified
- Zero nonconformities in the independent Stage 2 audit, conducted by Tempo Audits
- Implementation, policy work, and evidence preparation led in-house by Orbion
- Kantis platform and support used throughout the process
- Security posture visible to customers through Orbion's live Trust Center
The customer: security as part of the product, not a side project
Orbion's product depends on customer trust as much as on the science. When customers share protein sequences and research data, they're trusting Orbion with work that took years to generate. ISO/IEC 27001 gives that trust an independently assessed foundation — an information security management system (ISMS) covering how the company manages risk, access, and day-to-day security.
For Orbion, the milestone reflects two things at once: the outcome of an independent audit, and the work the team put in to get there.
The challenge: turning intent into evidence
Certification isn't a policy you write once — it's controls you actually run, and evidence you can show an independent auditor. For Orbion, that meant adapting internal policies to match how the company actually operates, putting those controls into practice, and gathering the evidence to demonstrate it.
That work depended on the team's own understanding of its systems — nobody outside Orbion could have done it for them. Kantis's role was to provide the platform and support that made the process efficient, not to do the work itself.
How Orbion and Kantis worked together
| Responsibility | Who |
|---|---|
| Adapting policies, implementing controls, and preparing evidence | Orbion |
| Compliance platform and support throughout the process | Kantis |
| Independent Stage 2 certification audit | Tempo Audits |
Kantis supported the process. It did not conduct the audit or issue the certificate — that independence is what gives the certification its value.
The result: zero nonconformities
Orbion passed its Stage 2 audit with zero nonconformities — a strong result for a first-time certification, and a reflection of how rigorously the team ran the implementation.
Aniruddh Goteti, Co-Founder & MD at Orbion, describes it in his own words:
"Protecting our customers' data is a responsibility we take seriously. Working with Kantis, we achieved ISO/IEC 27001 certification with zero nonconformities in our independent Stage 2 audit, conducted by Tempo Audits. We are proud to have reached this milestone together and grateful for Kantis's support throughout the process."
— Aniruddh Goteti, Co-Founder & MD, Orbion
What founders can take from Orbion's experience
The clearest lesson from Orbion's process is about ownership: the customer team owns implementation, a platform and support partner helps them move faster, and the certification audit stays independent of both. That separation is what makes the result credible.
If you're starting your own ISO 27001 process, the useful first step is the one Orbion took: agree early who owns each part of the work, and what support they'll need to do it well. Orbion's result shows what that structure can achieve — every team's timeline and effort will look different.
Plan your own ISO 27001 route
Kantis can help you think through scope, responsibilities, and what independent-audit readiness actually looks like. Talk to a founder about your ISO route, or read the startup ISO 27001 cost guide for budget considerations.
For other customer stories, see Centinel Analytica's ISO 27001 case study and Qorelo's ISO 27001, SOC 2 Type I, and GDPR readiness story.
