In 2024, someone from the sourcing team of a large car manufacturer reached out to us. They were looking for a way to help their global knowledge workforce be more productive in email, using AI. Mailbutler had caught their attention.
It was the first tender we ever applied for. We learned a lot.
One lesson stood out above the rest: for large companies with a proper IT department, information security isn't a nice-to-have. It's a checkbox. And if you can't tick it, you don't get to the next round — no matter how good your product is.
Back then, we couldn't tick it. Our security posture was already solid for a company our size. But we had no certification to prove it. We ended up in the top three. Someone else got the deal.
We didn't win that deal. But we learned exactly what we were missing.
A Distinctive Factor, Not Just a Formality
Shortly after that tender, I decided we should start targeting mid-sized companies more deliberately. And mid-sized companies — increasingly — have real security requirements of their own.
It became a pattern. Prospects would ask about our certifications, or at least our processes, almost as a matter of course. Security had quietly become a distinctive factor for SaaS companies, not just an enterprise formality.
So we made the call: we were going to get ISO 27001 certified.
At the time, the Mailbutler team was about 20 people. The reaction was generally positive — but honestly, none of us really knew what the certification would mean for us in practice. Not even me.
Enter the ISMS
Most guidance we found recommended working with an agency to help build what's called an ISMS — an Information Security Management System. It was one of the first new terms we learned. It would not be the last.
We formed a small ISMS team: myself, our senior developer Tobias, and our head of customer success, Julia. With the agency's platform as our guide, the three of us got to writing. Articles. Policies. Processes. Agreements. A lot of articles.
But it wasn't just paperwork. We implemented real changes across the company. Centrally managing our laptops through an MDM (Mobile Device Management — another new term). No more shared passwords. Enforced MFA everywhere. A proper list of every service we actually use.
Two changes stood out to me the most.
Device management. Before, everyone got a laptop and managed it themselves. No company oversight at all. Now, every device is centrally managed: DNS filtering, runtime process monitoring, enforced password strength, firewall rules, disk encryption — the works.
Account management. Before, people created their own accounts for whatever service they needed — sometimes with a company address, sometimes with a personal Gmail account. It was a mess. Today, we issue a single company-managed Microsoft account per employee, which cascades into a matching Google account and Apple account under the same address, and handles SSO into everything else we use, from Atlassian on down.
It shows up most clearly when I onboard someone new. I add them to the MDM, create one Microsoft account, and that's essentially it. Everything else follows from there.
Honestly, this is the way it should have been done from the start.
Where We Were Already Good
Not everything needed reinventing. Our software development process — code review, testing, project management — was already strong, especially for a company our size. There was just no written policy behind it. Most of that work was simply formalizing what we already did well, not fixing something broken.
The Payoff Isn't Always Where You Expect It
The certification process clearly improved my own peace of mind about our IT systems. It also gave us more confidence in sales conversations — we could finally speak to our security posture with real backing behind it, not just good intentions.
Does this sit in tension with never wanting to sell the company? I don't think so. We want to grow a healthy, sustainable business, and that requires solid information security — whether that shows up as a stronger sales pitch, or simply knowing exactly what to do the moment something goes wrong.
I'll be honest about one thing, though: shortly before our audit in August 2025, I found myself questioning whether all this effort would really pay off. I seriously considered stopping the whole process.
I didn't.
We passed the audit easily. The auditor told us he had rarely seen a company so well prepared, or so consciously working on its own security.
A year later, I still can't point to a clear, direct sales bump from the certification. I want to be honest about that too. But it still feels like exactly the right decision.
Here's what it actually comes down to: I can take a four-week vacation with every work app uninstalled from my phone. No email access, no Teams, nothing. And I know that whatever happens — a database that needs restoring from an AWS backup, a device that needs to be locked down remotely — my team has a well-defined process to follow, without me.
I can go on a four-week vacation with every work app uninstalled from my phone — and know my team has exactly what they need without me.
It just feels more mature. More safe. And I genuinely sleep better because of it.
This is the first of two posts on our ISO 27001 journey. Next up: what it was actually like working with a certification agency, and what I'd tell other founders considering the same path. Have questions about our process, or going through something similar yourself? Drop a comment below — I read and reply to all of them.