Kantis case studies
Customer story

Selling AI to governments: how Prior Foundry got ISO 27001 in 22 days from first audit to certificate

Prior Foundry sells governments AI they can audit and trust. Its buyers ask hard security questions before they share data, so its own security had to be provable too, and fast.

Selling to governments or other regulated buyers? Find out how fast your own route could be.

Prior Foundry, an a16z speedrun alum, gives governments a system for understanding how policies are implemented, how they perform and what outcomes they reach. Its buyers ask hard security questions before they share any data. With Kantis, it went from its first ISO 27001 audit to a certificate in 22 days.

Book a free gap assessment · Explore ISO 27001 for startups

Results at a glance

  • 22 days from the first audit (Stage 1) to the ISO 27001 certificate
  • About seven weeks of focused work in total
  • Trust Center live for government buyers the day the certificate landed
  • SOC 2 Type II next, also with Kantis

The customer

Prior Foundry builds AI tools for policy teams. They help teams research evidence, simulate the impact of a policy on realistic populations, gather stakeholder input and draft decision-ready documents.

Its promise to governments is full auditability: every evidence source is traceable, and customer data is never used to train models. The team is small and technical, mixing computational behavioural science with real-world policy experience.

The trigger: you can't sell auditability without being auditable

When your customers are governments, security is part of the sale. Public-sector teams ask detailed security questions before they share data with a supplier, and for a company that sells auditability, "trust us" is not an answer.

Prior Foundry wanted ISO 27001 in place before European public-sector buyers asked for it. The team set a firm target: the main audit (Stage 2) in mid-September.

The challenge: a real ISMS in a few focused weeks

ISO 27001 asks for more than policies. A company needs a risk assessment, a Statement of Applicability, controls that actually run, an internal audit and a management review, and an independent auditor checks all of it.

Prior Foundry needed all of that done properly in a few focused weeks, without pulling the CTO away from the product.

How Kantis helped

  • Built around how they actually work. Policies, risks and evidence were fitted to Prior Foundry's real setup, with the team's cloud, code and identity tools connected to the Kantis platform.
  • A dress rehearsal first. Kantis ran the internal audit before the first audit and gave the team a clear fix for every finding.
  • In the room for both audits. Kantis joined the Stage 1 and Stage 2 sessions and turned every auditor comment into a concrete fix, so every Stage 1 finding was closed before Stage 2, eight days later.
  • Proof buyers can use. Prior Foundry's Trust Center showed the new certificate straight away, so buyers can see the programme and request documents.

The result: 22 days from first audit to certificate

Stage 1 took place on 7 September 2026. Stage 2 ran from 15 to 17 September, right in the window the team had planned, and the auditor recommended certification at the end of it.

Tempo Audits, one of Kantis's UKAS-accredited audit partners, issued the certificate on 29 September: 22 days after the first audit, and about seven weeks after the focused work began. GDPR readiness work was done in the same programme.

Keshav Sivakumar, Co-founder and CTO of Prior Foundry:

"Our customers are governments and public-sector policy teams, and they ask hard security questions before they share data. Kantis ran our internal audit, joined our audit sessions and turned every auditor comment into a concrete fix. We went from Stage 1 to an ISO 27001 certificate in 22 days, and we're now doing SOC 2 Type II with them."

Keshav Sivakumar, Co-founder & CTO, Prior Foundry

What founders can take from this

  • If you sell to governments or other regulated buyers, start early. Their security questions arrive before the contract does.
  • Treat the internal audit as a dress rehearsal. Findings fixed before the real audit don't come back.
  • Speed comes from closing findings fast. The 22 days were possible because every Stage 1 comment had an owner and a fix before Stage 2.

Plan your own ISO 27001 route

Selling to the public sector or other regulated buyers? A free gap assessment shows how far you are from ISO 27001 and how fast you could realistically get there. Book a free gap assessment, or read the ISO 27001 cost guide first.

For more customer stories, see Qorelo's ISO 27001, SOC 2 Type I and GDPR readiness story and Centinel Analytica's ISO 27001 case study.

Book a free gap assessment

Book a free gap assessment

Selling to governments or other regulated buyers? Find out how fast your own route could be.

Frequently asked questions

How long did Prior Foundry's ISO 27001 take? +

About seven weeks of focused work. Most of the preparation happened in the four weeks before the first audit (Stage 1), and the certificate followed 22 days after it.

What did Prior Foundry's team do, and what did Kantis do? +

Prior Foundry's team made the decisions, approved the policies and ran the controls. Kantis prepared the ISMS around how they work, ran the internal audit, joined both audits and turned every auditor comment into a concrete fix.

What's next for Prior Foundry? +

SOC 2 Type II, also with Kantis. The observation period is under way, and the report will come from an independent CPA firm.

Could my startup move this fast? +

Often, if the team can give a few focused weeks and the audit dates are booked early. Your timeline depends on your scope and how ready you are at the first audit. A free gap assessment tells you your realistic timeline before you commit.

Sources and references

We use cookieless measurement by default. Accept to also allow analytics and advertising cookies. Privacy Policy