Real Estate Technology
How a Series A Real Estate Tech Startup Went From Zero to SOC 2 + ISO 27001 in 12 Months
The Challenge
A Series A real estate technology startup engaged Ozoar at the earliest possible point: before there was anything to secure. There was no cloud environment, no security policies, no governance structure, and no one internally responsible for security — just a product roadmap and a growth plan that would require enterprise customers to trust the company with sensitive data.
Enterprise real estate customers — property managers, brokerages, and institutional landlords — increasingly expect vendors to demonstrate mature security practices before signing. For an early-stage company, the challenge wasn't fixing broken security; it was building a real security program and a certifiable one, from nothing, without slowing down a small engineering team trying to ship product.
The Engagement
Ozoar was brought in to own security end-to-end, spanning six service areas over a 12-month engagement:
vCISO — provided the security leadership the company didn't yet have: strategy, governance, risk management, policy development, and a roadmap that sequenced the work realistically against the company's growth timeline. Cloud Security — designed and implemented the company's AWS environment with security built in from the start: identity and access management, network segmentation, logging and monitoring, and cloud security posture management — rather than retrofitting controls onto an existing environment. DevSecOps — embedded security into the engineering team's existing workflow: secure SDLC practices, CI/CD pipeline security, and secrets management, so the security program didn't become a bottleneck for a team used to moving fast. Security Operations — stood up the monitoring and detection capability needed to actually operate the environment day to day, not just pass an audit. Incident Response — built IR planning and playbooks appropriate for an early-stage company's actual risk profile and team size. Compliance — ran the SOC 2 and ISO 27001 programs in parallel, given the significant control overlap between the two frameworks, rather than treating them as sequential, duplicative efforts.Timeline
- Months 1–3: Security assessment, cloud environment build-out, and control implementation — taking the company from nothing to audit-ready
- Months 4–9: Operating the control environment, evidence collection, and control maturation across both frameworks
- Months 10–12: SOC 2 Type II and ISO 27001 audits, completed in parallel
The Results
- SOC 2 and ISO 27001 both achieved, with both audits passed on the first attempt — no failed controls requiring remediation and re-audit
- 3 months from initial assessment to audit-ready state, despite starting with no existing environment or program
- A cloud environment built secure from day one, rather than a later retrofit — avoiding the rework and disruption that comes with bolting security onto an already-built system
- A security program sized appropriately for an early-stage team — sustainable to operate going forward without requiring a large in-house security hires immediately
Key Takeaway
Starting from zero is, in some ways, the easiest time to build security correctly — there's no legacy environment to retrofit and no technical debt to work around. For this company, building the cloud environment and the compliance program together, rather than sequentially, meant the infrastructure was audit-ready by construction rather than by remediation.
Building something from scratch and need it to be enterprise- and audit-ready from day one? Get a security assessment and talk to an Ozoar security expert about building it right the first time.
Ready to strengthen your security program?
Talk to an Ozoar security expert about where to start.
Get Your Security Assessment