The customer
Qorelo GmbH is a German AI platform for SAP operations, selling into enterprise and SAP consultancy contexts where security proof matters. Like many startups, the team needed ISO 27001 to support enterprise conversations without turning certification into a months-long distraction.
The team was small, technical, and focused. That made speed possible, but only if the process stayed practical and the output could be used in real customer conversations.
The challenge
ISO 27001 can become heavy very quickly for a startup:
- policies need to match the real company, not a generic template
- cloud, access, vendor, incident, and risk evidence needs to be collected cleanly
- founders and engineers need to answer audit questions while still shipping product
- auditor requests need to be interpreted and mapped to the evidence that already exists
For Qorelo, the goal was not to build a compliance department. The goal was credible certification with minimal wasted motion, then a clear way to show enterprise buyers what had been completed.
The Kantis approach
Kantis supported Qorelo through a managed trust path:
- Scope the audit boundary and control expectations.
- Map existing systems, vendors, and operating practices against ISO 27001.
- Prepare policies and evidence around how Qorelo actually worked.
- Organize evidence so the auditor could review it without repeated back-and-forth.
- Prepare and organise material for the independent SOC 2 Type I Security examination.
- Support GDPR readiness work and keep the team focused on the few items that genuinely needed their input.
- Turn the resulting proof into a customer-facing Trust Portal and supporting materials.
The operating principle was simple: Kantis should absorb the compliance coordination load wherever possible, and Qorelo should only be pulled in where customer-specific decisions or evidence were needed.
Clear roles in the audit process
Kantis did not audit, certify, or issue assurance reports. The independent certification body issued Qorelo's ISO 27001 certification. Dansa D'Arata Soucia LLP (DDS) performed the SOC 2 Type I examination for Security and issued the official report and opinion. Kantis supported readiness, evidence, coordination, the Trust Portal, and customer-facing proof materials.
The result
Qorelo reached ISO 27001 certification in approximately six weeks, with 0 non-conformities.
It then completed a SOC 2 Type I examination for the Security category, with an unmodified opinion in the final report. Type I assesses the system description and control design at a point in time; it does not assess operating effectiveness over a period.
Kantis also completed GDPR readiness work and helped package the outcome into customer-facing proof, including Qorelo's Trust Portal.
"With Kantis, we completed our ISO 27001 certification, SOC 2 Type I Security examination, and GDPR readiness review through one coordinated process. ISO 27001 took six weeks with 0 non-conformities — giving us a stronger trust foundation for enterprise customer conversations, including with Mercedes-Benz."
Marino Kurtovic, Co-Founder & CTO, Qorelo GmbH
What this proves
For Kantis, Qorelo is the first completed year-one trust path:
- ISO 27001 certification with 0 non-conformities
- SOC 2 Type I Security report from an independent auditor
- GDPR readiness work
- auditor coordination, Trust Portal, and customer-facing proof materials
This is not a claim that every startup needs every framework, or that every ISO 27001 project should take six weeks. It is proof that a small, focused team can make a broader trust path manageable when the work is scoped, evidence-led, and actively coordinated.
What founders should take from this
If ISO 27001, SOC 2, or GDPR questions are starting to appear in enterprise procurement, do not wait until the deal is blocked. Start with the buyer requirement, understand the budget and evidence needs, and choose an independent audit route plus readiness support that matches your team capacity.
For some teams, that route is a platform. For others, it is a consultant. For lean European startups that want hands-on help, a clear auditor path, and proof materials buyers can actually use, Kantis is designed to be the managed route.
