The typical situation of a young company: there was no dedicated information security department, ISO experience was barely present in the team, and the available resources went into product development and market entry. At the same time, ISO 27001 became the criterion that decides whether customers, particularly in the public sector, will even consider a bid.
About the company
Humaine Health-Tech GmbH (Humaine for short), based in Monheim am Rhein, develops coachBOB, an AI-based prevention platform for companies and public institutions. Its approach starts where workplace health promotion usually fails in practice: not with good intentions, but with actually reaching the workforce. coachBOB is therefore available both as an app and in the browser, bringing evidence-based content on physical and mental health directly to the workplace, with no fixed appointments, no course rooms and no organizational lead time.
At the heart of the platform is a digital coach that supports employees individually and adapts content to personal goals and life circumstances. This digital offering is complemented by AI-based personal support, so that prevention does not stop at generic recommendations but becomes a continuously supported process. For employers, the platform's second value lies in the analytics: instead of anecdotal feedback, they receive anonymous impact data showing where strain arises in the organization and which measures actually land.
It is precisely this combination of sensitive health data, aggregated analysis and the use of AI that makes trust the real product feature. Humaine designed the platform accordingly from day one and made GDPR-compliant processing and audited information security at ISO 27001 level a fixed part of its own value proposition.
Challenge
When coachBOB entered its market phase, these high internal standards turned into a concrete task. Protecting health and employee data had guided the team's decisions from the start, and the technical and organizational foundations were already built into the product. What was missing was not awareness, but the formal, verifiable structure behind it: clearly documented roles, systematic risk management, demonstrable training, and an orderly documentation landscape, which at that point was still spread across SharePoint and OneDrive.
On top of that came the typical situation of a young company. There was no dedicated information security department, ISO experience was barely present in the team, and the available resources went into product development and market entry. At the same time, ISO 27001 became the criterion that decides whether customers, particularly in the public sector, will even consider a bid. Humaine therefore needed a fully developed, audit-proof ISMS that holds up to internal and external auditors, and that turns its own security promise from an internal commitment into solid, communicable proof.
Solution
Humaine Health-Tech chose SECJUR's platform including Expert Guidance, combining a central platform with close support from a dedicated compliance expert. Using the project management function in the Digital Compliance Office, Jan Klues and his team structured the entire ISO implementation, assigned tasks with clear responsibilities, documented internal audits, and set up dedicated improvement projects for every minor non-conformity from the external audits.
The integrated risk management module became the pivotal point of the ISMS. Risks were assessed on the basis of the recorded assets, linked to owners and backed by clearly defined treatment strategies, supported by BSI templates directly in the system. In parallel, a consistent document set was built in the platform, ranging from the Statement of Applicability and the management review to policies and the evidence for supplier management, training and incident processes. Existing storage locations such as OneDrive were integrated rather than dissolved, so that auditors received structured access to the relevant evidence.
Ahead of the audits, the focus shifted to preparing the people. In regular sessions, SECJUR prepared those responsible specifically for the internal audit as well as for Stage 1 and Stage 2 with Proks-Cert, ran through interview situations and reviewed the documentation, right down to collecting the complete evidence for the non-conformities.
Impact
In 2026, Humaine Health-Tech achieved ISO 27001 certification for coachBOB on the first attempt, in just 4.5 months from kick-off to audit. A fragmented starting point became a robust ISMS with risk management that is actually practiced, regular reviews, documented management decisions and established processes for incidents, suppliers and training.
This structure gave more than just the auditors confidence. In parallel with the launch of the first MVP phase, it became a visible selling point: today coachBOB presents itself to employers, public institutions and insurers as an ISO 27001-certified and GDPR-compliant AI platform. That opens up tender processes, shortens the time it takes to build trust in a first conversation, and considerably simplifies contract negotiations, because security questions are no longer negotiated one by one but answered by a certificate.