How TyrAds got ISO 27001 certified while running SOC 2 Type 2 and GDPR in parallel

Advertising & Marketing
10-50
Employees

"Congratulations, Tyrads team! This is an amazing accomplishment," ComplyJet's CEO wrote back within the hour of getting the news. TyrAds had just received its certification decision for ISO/IEC 27001:2022 — passed, on the first attempt, after months of work.

TyrAds is a mobile app growth marketing platform that helps app developers and marketers scale user acquisition through performance-based advertising, reaching 1.4 billion users across a network that spans multiple regions. The data flowing through that network — campaign performance, user engagement metrics, advertiser relationships — is exactly the kind enterprise partners want independently verified before they'll sign.

Most companies pick one compliance framework and add others later, once there's budget and a clearer sense of what buyers actually ask for. TyrAds didn't have that runway. Their advertisers span US enterprises who expect SOC 2, international partners who recognize ISO 27001 as the global standard, and EU data subjects who bring GDPR into scope. All three were live requirements at once, so TyrAds partnered with ComplyJet to build all three frameworks in parallel instead of picking a starting point and hoping the rest would wait.

Splitting the Work So No One Person Is the Bottleneck

What made TyrAds' rollout different from a typical startup's was the team structure. Rather than one founder juggling everything, the work was split across dedicated roles: Senior Legal Counsel Faisal Bhat coordinating with ComplyJet and owning policy and process; an engineering lead — Gus Arisna — working through cloud integrations, infrastructure security, and vulnerability scanning; an operations lead handling finance and vendor coordination; and the CEO providing sign-off on key decisions. While engineering connected cloud providers, compliance was already drafting policy. Nothing had to wait in line.

The ISO 27001 Track: Kickoff to Certification

The ISO 27001 audit began with an internal ISMS audit completed first to satisfy Clause 9.2 ahead of the external certification audit. The process wasn't friction-free — at one point the auditors flagged that evidence requests submitted through the platform weren't visible on TyrAds' side, and the team worked through it directly with ComplyJet until the audit trail was clear again. That kind of mid-audit troubleshooting is normal; what matters is that it didn't slow the outcome. Within a matter of weeks, TyrAds received its certification decision: TyrAds Pte. Ltd., certified to ISO/IEC 27001:2022.

SOC 2: Now in Its Observation Window

SOC 2 Type 2 runs on a different clock by design — it's an examination of controls operating effectively over a period of months, not a point-in-time decision. TyrAds' Type 2 engagement is currently in that observation window. More recently, the team commissioned an external API penetration test against two public-facing APIs — exactly the kind of independent technical evidence a SOC 2 Type 2 auditor wants to see feeding into the control environment, not something bolted on at the end.

What Faisal Says

Throughout our ISO 27001 journey, the founders were directly involved and always available to help us. They took the time to explain every requirement clearly, guided us through the platform, and provided hands-on assistance whenever we had questions. It felt like having a dedicated point of contact who genuinely cared about our success, making the entire compliance process much smoother and easier to manage.— Faisal Bhat, Senior Legal Counsel at TyrAds

GDPR: Built Into the Same Foundation

Because GDPR compliance was scoped from day one alongside SOC 2 and ISO 27001, TyrAds didn't have to retrofit data processing agreements or reopen policy work once the other two frameworks moved. Data processing agreements were established early, and GDPR-relevant policy sections were generated and reviewed on the same platform, at the same time, as SOC 2 and ISO controls — one policy update, not three separate ones.

Where TyrAds Stands Today

  • ISO 27001:2022 — certified
  • SOC 2 Type 2 — observation period underway, reinforced by a completed third-party API penetration test
  • GDPR — data processing agreements and policy in place, running alongside both audit tracks

Why This Matters

Ad tech is under growing pressure from two directions at once: privacy regulators tightening enforcement, and enterprise advertisers raising the bar on vendor security before they'll route spend through a platform. TyrAds didn't wait to feel that pressure before building an answer to it. By running SOC 2, ISO 27001, and GDPR on the same foundation instead of stringing them together over successive years, the compliance work compounded instead of duplicating.

Looking Ahead

ISO 27001 is certified. SOC 2 Type 2's observation period is running, with independent penetration testing already feeding into the evidence base. When the next enterprise advertiser or app publisher at the scale TyrAds operates asks about security, the answer isn't a roadmap anymore — for ISO 27001, it's already a certificate.