Prior Foundry, an a16z speedrun alum, gives governments a system for understanding how policies are implemented, how they perform and what outcomes they reach. Its buyers ask hard security questions before they share any data. With Kantis, it went from its first ISO 27001 audit to a certificate in 22 days.
Book a free gap assessment · Explore ISO 27001 for startups
Results at a glance
- 22 days from the first audit (Stage 1) to the ISO 27001 certificate
- About seven weeks of focused work in total
- Trust Center live for government buyers the day the certificate landed
- SOC 2 Type II next, also with Kantis
The customer
Prior Foundry builds AI tools for policy teams. They help teams research evidence, simulate the impact of a policy on realistic populations, gather stakeholder input and draft decision-ready documents.
Its promise to governments is full auditability: every evidence source is traceable, and customer data is never used to train models. The team is small and technical, mixing computational behavioural science with real-world policy experience.
The trigger: you can't sell auditability without being auditable
When your customers are governments, security is part of the sale. Public-sector teams ask detailed security questions before they share data with a supplier, and for a company that sells auditability, "trust us" is not an answer.
Prior Foundry wanted ISO 27001 in place before European public-sector buyers asked for it. The team set a firm target: the main audit (Stage 2) in mid-September.
The challenge: a real ISMS in a few focused weeks
ISO 27001 asks for more than policies. A company needs a risk assessment, a Statement of Applicability, controls that actually run, an internal audit and a management review, and an independent auditor checks all of it.
Prior Foundry needed all of that done properly in a few focused weeks, without pulling the CTO away from the product.
How Kantis helped
- Built around how they actually work. Policies, risks and evidence were fitted to Prior Foundry's real setup, with the team's cloud, code and identity tools connected to the Kantis platform.
- A dress rehearsal first. Kantis ran the internal audit before the first audit and gave the team a clear fix for every finding.
- In the room for both audits. Kantis joined the Stage 1 and Stage 2 sessions and turned every auditor comment into a concrete fix, so every Stage 1 finding was closed before Stage 2, eight days later.
- Proof buyers can use. Prior Foundry's Trust Center showed the new certificate straight away, so buyers can see the programme and request documents.
The result: 22 days from first audit to certificate
Stage 1 took place on 7 September 2026. Stage 2 ran from 15 to 17 September, right in the window the team had planned, and the auditor recommended certification at the end of it.
Tempo Audits, one of Kantis's UKAS-accredited audit partners, issued the certificate on 29 September: 22 days after the first audit, and about seven weeks after the focused work began. GDPR readiness work was done in the same programme.
Keshav Sivakumar, Co-founder and CTO of Prior Foundry:
"Our customers are governments and public-sector policy teams, and they ask hard security questions before they share data. Kantis ran our internal audit, joined our audit sessions and turned every auditor comment into a concrete fix. We went from Stage 1 to an ISO 27001 certificate in 22 days, and we're now doing SOC 2 Type II with them."
Keshav Sivakumar, Co-founder & CTO, Prior Foundry
What founders can take from this
- If you sell to governments or other regulated buyers, start early. Their security questions arrive before the contract does.
- Treat the internal audit as a dress rehearsal. Findings fixed before the real audit don't come back.
- Speed comes from closing findings fast. The 22 days were possible because every Stage 1 comment had an owner and a fix before Stage 2.
Plan your own ISO 27001 route
Selling to the public sector or other regulated buyers? A free gap assessment shows how far you are from ISO 27001 and how fast you could realistically get there. Book a free gap assessment, or read the ISO 27001 cost guide first.
For more customer stories, see Qorelo's ISO 27001, SOC 2 Type I and GDPR readiness story and Centinel Analytica's ISO 27001 case study.
