Uncover earned ISO 27001 certification in 14 days with Sprinto

Founded in 2022, Uncover is a legal-tech SaaS company based in the Netherlands that builds an AI-enabled platform for structuring, managing, and analyzing case documents for lawyers. With founders who bring legal backgrounds and a strong engineering culture, the team builds and deploys infrastructure at a rapid pace.

14 days to complete the ISO 27001 audit
4 sessions to implement the ISO 27001 program
15 % additional effort for GDPR over ISO 27001
Sprinto white-logo
Before Sprinto
After Sprinto
EU customers required proof of data security compliance, but Uncover lacked a recognized certification
ISO 27001 certification earned in 14 days, providing EU customers with recognized proof of security
Reactive security work lacked structured workflows aligned to compliance standards
Structured workflows and continuous monitoring shifted security left across compliance standards
Previous compliance partner was unresponsive and inefficient through the process
Sprinto proved responsive and efficient from day one with clear timelines and expert-guided sessions
“In continental EU, customers need proof that you are a service provider that complies with all data security requirements”


– Ingrid Van-de Pol Mensing
Cofounder and Co-CEO, Uncover

“Being compliant is an important part of the way we operate. Continuous monitoring is a big part of why we like Sprinto – it makes sure we are and remain compliant”

– Ingrid Van-de Pol Mensing
Cofounder and Co-CEO, Uncover

Introduction

Uncover had always operated with strong data security standards. As the company expanded its footprint in continental Europe, however, good practice alone was not enough. Customers wanted documented proof. “In continental EU, customers need proof that you are a service provider that complies with all data security requirements,” notes Ingrid Van-de Pol Mensing, Cofounder and Co-CEO at Uncover.

An ISO 27001 certification, complemented by GDPR compliance, would give the team a recognized way to demonstrate trustworthy security practices to EU customers. Uncover turned to Sprinto to reach that goal.

The Problem

The team needed more than a certificate. They needed structured workflows aligned to compliance standards and a way to shift from reactive security work to proactive controls. Their engineering culture meant infrastructure was deployed frequently, and any compliance process had to keep up.

A previous compliance partner had proven unresponsive and inefficient through the process. “Price aside, responsiveness and efficiency in the process were important criteria,” remarks Ingrid. “We aren’t experts so we preferred working with experts and standardized workflows,” she adds. The team needed a partner that could provide clear guidance, structured workflows, and the ability to fold compliance into their fast-moving development cycle.

The Solution

Imre Gelens, CTO at Uncover, led the ISO 27001 implementation with Sprinto. “Everything was clear from the get-go,” he notes. “The initial meeting made clear the time requirements, what the process was going to be like, what we are doing, and the nature and number of meetings and topics we’ll go through in each. Most of these were on my plate,” he adds.

During implementation, Imre worked with a Sprinto CSM to connect the platform directly to Uncover’s systems, pulling risk and control data from their infrastructure. Because the team deploys infrastructure frequently, they configured Sprinto to pick up new entities automatically. Imre tagged each resource in AWS so the platform could process information without manual intervention. “I preferred a repeatable process that could keep pace with how we deploy infra,” Imre notes.

“With Sprinto the process is now fully automated.”

The team then used Sprinto’s integrated risk management suite to scope out security risks, assess business impact, and map risk mitigation controls. “This process happens fast because the platform equips you with standardized resources,” notes Imre. Through this exercise, Uncover identified gaps in its security practice, filled them, and set up continuous monitoring to keep them closed.

For ISO 27001-aligned policies, the team used Sprinto’s policy templates as a starting point and tailored each one to reflect Uncover’s own operations and controls. “It’s a real time saver!” Imre says.

In just four sessions, the ISO 27001 program was fully implemented and ready for audit. Adding GDPR required only six additional checks on top of ISO 27001, including appointing an EU representative, establishing a DSAR process, documenting a Record of Processing Activities, reviewing contractual obligations, conducting a privacy policy review with legal counsel, and deploying a GDPR-compliant cookie banner. “The additional effort was no more than 15%,” remembers Imre.

With Sprinto’s automated workflows and integrations connected to their infrastructure, the team kept checks running continuously across both frameworks.

Impact

Uncover completed its audit and received ISO 27001 certification in 14 days.

At an architectural level, the team had to modify very little of its existing infrastructure. The effort spent logging and tagging entities created a self-sustaining process for all deployment-related events, monitored end-to-end through Sprinto. “This mechanism makes sure all the infra is getting picked up by Sprinto whenever we deploy something,” remarks Imre. “Right up front, Sprinto asks you to classify whether something is a production or nonproductive event. By tagging your resources as you deploy them, you can easily automate necessary checks,” he adds.

In practice, Uncover has built compliance directly into its development function. “Now when we deploy something new, we immediately get a notification asking if we have classified this piece of infrastructure. It’s easy to stay on top of things with minimum effort,” Imre remarks.

Sprinto also reinforces the operational discipline the team values. “Things like database recovery plan, disaster recovery plan – these are things one has to anyway think about. It is important to build for it, train for it, and check every so often. Sprinto encourages this behavior, forcing us to be more specific,” Imre notes.

Since earning the certification, the team has woven its compliance posture into sales conversations. “We make it a point to mention we are compliant,” notes Ingrid. “Being compliant is an important part of the way we operate. Continuous monitoring is a big part of why we like Sprinto – it makes sure we are and remain compliant,” she adds.

Got questions? Talk to our experts!

Frameworks-logos-bg
Frameworks-logos-mob-bg
Uncover logo
Industry Type

Technology

Employees

Regions

EU

Modules used
ISO 27001 GDPR
Frameworks used
ISO 27001
GDPR