DIY ISMS: How Taxy.io leveraged SECJUR to Achieve ISO 27001 Certification Without InfoSec Consultants

The Company

Founded in 2018 as a spin-off of RWTH Aachen University, Taxy.io develops intelligent software solutions for the tax advisory industry, leveraging artificial intelligence. The technology is designed to automate processes for tax advisors and legal professionals.

Taxy.io’s platform serves as a central information hub, integrating with both internal finance and tax departments and third-party applications such as CRM or accounting software. Thanks to this integration capability and AI-driven automation, Taxy.io enables tax advisors to focus on value-added activities and personalized consulting.

With a growing team of experts in tax, technology, and AI, Taxy.io has established itself as a pioneer in the digital transformation of the tax advisory sector. The company is dedicated to making the industry more efficient and equitable through digital solutions.

The Challenge

Due to customer requirements and strategic positioning in a fast-paced market, Taxy.io decided to pursue ISO/IEC 27001 certification—the gold standard for information security. The company sought a resource-efficient, automation-driven solution that would allow for a largely independent implementation process.

After an in-depth evaluation of various providers, it became clear that existing software solutions in the DACH region required the involvement of information security experts. Such software-assisted consulting projects would have exceeded Taxy.io’s budget and timeline.

We are incredibly proud to have achieved ISO 27001 certification within just a few months—without prior experience or external information security experts. The SECJUR DCO guided us seamlessly through the entire process, and the available tools enabled us to build and successfully implement a complete ISMS.
Sven Peper
Co-Founder & CEO

The Solution

Taxy.io opted for the only visible software solution in the DACH region that enables companies to achieve ISO 27001 certification independently, without dedicated information security experts: The SECJUR Digital Compliance Office (DCO).

- Navigator Feature: Taxy.io used the Navigator feature to independently build its ISMS (Information Security Management System). The step-by-step guidance provided clear instructions, ensuring a straightforward and understandable implementation process.

- Policy Generator: With tools like the Policy Generator, Taxy.io created a tailored ISMS that met its specific needs. This approach ensured scalability and avoided inefficiencies that arise from using rigid, one-size-fits-all templates.

- Task Manager: The Task Manager guided the company through the implementation process step by step, ensuring that the ISMS was not just a theoretical framework but delivered real cybersecurity value.

The Results

With the help of SECJUR DCO, Taxy.io successfully built its customized ISMS in under six months and obtained ISO 27001 certification with confidence. By eliminating the need for external information security experts and choosing an auditor from the SECJUR Auditor Network, Taxy.io was able to minimize costs.

During the ISMS implementation, Taxy.io also decided to manage its data protection compliance with SECJUR. This allowed for an efficient integration of ISO 27001 and GDPR on a single platform.