
From first compliance step to audit with 0 findings: how Aivory achieved ISO 27001 and NEN 7510 in three months
Hailang ZhouLinkedIn
When Ties had the idea for Aivory, he started by listening. He spoke with dentists across the country and quickly discovered that patient data, records, schedules and communications were all running separately from one another. No cohesive system, no structure, and almost nothing happening in the field of AI. A lot of administrative work that had already been automated elsewhere was still being done manually in dental practices.
Dental practices running on disconnected tools
One AI platform that brings together scheduling, records, treatment plans, dashboards and patient communication in a single system. The idea is that dentists get their time back for patients, and that practices run more efficiently without staff drowning in disconnected tools behind the scenes. That is why Aivory was born.
For healthcare software, compliance is not a checkbox at the end of the build process. It is the gateway to the market. Patient data, records and schedules will all flow through this system. Without ISO 27001 and NEN 7510 certification in hand, you simply get ruled out in healthcare in the Netherlands.
What stands out about Aivory's story is not just that they achieved both certifications together as a young start-up. They did it in a three-month timeline with around eight hours of work per week from the Aivory team, resulting in an external audit with zero findings. Aivory completed this journey together with the Tidal Control platform, combined with implementation guidance from our consultancy partner Fendix, by security officer Jurre 't Lam.
Compliance built in from the very first line of code
Aivory was founded by Ties Verberne and Sara de Jong. Ties is an experienced founder who previously built two start-ups and worked at a tech-scale up as founding GTM (Go-To-Market). There he was already used to working with sensitive customer data at companies with ISO 27001 certification. When he started Aivory, the standard was therefore no surprise. It was part of the plan from day one, according to Ties.
The pace at which Aivory builds leaves no room for a compliance implementation that typically takes six months to a year. Sara contributed significantly to this process by setting up security by design as much as possible at Aivory from the start. She was primarily responsible for the technical side of security throughout this journey.
Moving fast, but not at the expense of substance
When Ties was exploring the compliance market, he noticed that some platforms in the US promise you can become compliant within four weeks. For founders looking to scale quickly, that certainly sounds attractive. For Ties, it was actually a warning signal.
I saw four weeks, and in my view that is simply too fast. It gets rushed. You don't live through the processes, you don't understand your risks, and the auditor has no room to look at it critically. I even heard that some American parties use auditors from India or somewhere, and that those auditors often don't really look closely and just let you get certified.
Ties VerberneCo-founder | Aivory
Fendix also recognises a pattern here based on their experiences, leading them to be cautious about it. They have a warning for others when they face compliance platforms promising compliance in just 1 month.
Becoming compliant in three months is already a bit too fast according to compliance experts, but certainly achievable with the right guidance, the right software and input from everyone involved. When a platform promises you'll be compliant in four weeks however, something in the chain is off. Either the evidence is pre-filled, or the auditor doesn't ask the right questions, or both. Clients think they have a certificate, but in reality they're holding a piece of paper with no real coverage.
Mathijs OppelaarOperations Director | Fendix
For a healthcare software company, such a setup would be a significant risk, even though it sounded tempting. Aivory therefore deliberately chose a Dutch partner that doesn't skip the work, but does organise the implementation in a legitimate, accelerated and efficient way.
The choice: European, and with partners who think along with you
For a Dutch healthcare software platform, an American player like Vanta or Drata felt like a mismatch. They also do not support the Dutch NEN 7510 standard. In this case the search began with a chance encounter between Ties and Dennis van de Wiel, founder of Tidal Control, at a start-up event. They had a good chat and kept it in the back of his mind. When Ties later announced on LinkedIn that he was looking for help with ISO 27001 and NEN 7510, the Tidal Control sales team responded quickly.
That personal and swift approach was the deciding factor in choosing Tidal Control as the compliance platform and Fendix as the consultancy partner to guide the implementation. That combination turned out to be the catalyst.
The pace genuinely surprised me. I hear from others that it usually takes six months to a year in an implementation like this. The combination of Tidal Control, Fendix guidance and around eight hours of effort per week from our team simply made it a successful journey in three months.
Ties VerberneCo-founder | Aivory
ISO 27001 and NEN 7510 audit together with zero findings
The external audit is typically the moment where the real work becomes visible. Auditors almost always find something. 3 to 5 findings is normal in practice, and those can sometimes require corrective actions before the certificate is issued.
For Aivory, it went differently. Zero findings.
That result didn't come out of nowhere. It's what happens when policies aren't written just to satisfy an auditor or generated by AI, but because the company genuinely wants to live by the processes. Tidal Control provided, among other things, pre-built policy templates and the structure that allowed Ties to immediately add what fit Aivory. Fendix brought the substantive guidance to make sharp decisions about scope, risks and evidence.
Personal guidance from Fendix: the connection with Jurre
A three-month implementation stands or falls on the collaboration between client and consultant. As Jurre explains:
The collaboration between Ties, Sara, me and the Tidal system ran smoothly. It ultimately comes down to how we make and keep agreements. From both sides, in my view, mutual trust and transparency about where we stood with our approach developed quickly. For me, that is the foundation of our success!
Jurre 't LamInformation Security Consultant | Fendix
The connection with Jurre really made the difference. He takes the time to understand how we work and adapts his approach accordingly. This feels personal, not like a standard project they pull out of a drawer for every client. It goes super well hand-in-hand with Tidal.
Ties VerberneCo-founder | Aivory
That flexibility matters a great deal in an environment where no companies are the same. Aivory builds with AI at its core, with integrations to Vecozo and VisiQuick. A one-size-fits-all approach simply doesn't fit that. Jurre thinks along about what is specifically relevant for Aivory and leaves out what isn't.
Personal support from Tidal Control too
At the start of the implementation, the onboarding module and MCP functionality were still in development. MCP stands for Model Context Protocol and gives your AI assistant the ability to connect with Tidal to get work done more efficiently.
Ties shared that he had to search a little longer sometimes and had more questions as a result in the beginning.
I have to say, huge compliments to the support team, and also great to see that you've implemented feedback from a fellow software builder so well. The onboarding module and MCP are great additions that came through during my implementation time and truly pushes the value of Tidal even higher.
Ties VerberneCo-founder | Aivory
For Ties, it is precisely that combination of platform and the people behind it that makes the difference. He genuinely feels heard at Tidal, and that feedback was visibly incorporated into the product.
What the platform delivers day to day
In his daily work, Ties uses Tidal Control primarily as his compliance source of truth. Open tasks for maintaining the ISMS are ready and waiting, linked to controls, frameworks and risks. That reduces searching and keeps the overview intact without needing a dedicated staff member for it.
I really appreciate that you've already put together strong policy documents that I as a client can use and tailor it towards Aivory's context. The way you also link controls between tasks, frameworks and risks is incredibly powerful and efficient.
Ties VerberneCo-founder | Aivory
Continuous compliance, not a one-off project
For Aivory, ISO 27001 and NEN 7510 are not a one-off project. They are an ongoing way of working.
Tidal as our ISMS is simply our source of truth for staying demonstrably in control. My team and I listen to the system, and when we need extra help we pick up a few hours of Fendix support. This is the ideal setup for us, and I would definitely recommend it to fellow start-up founders for optimal efficiency.
Ties VerberneCo-founder | Aivory
Ready to accelerate your own compliance journey?
Aivory's story shows what's possible when software and guidance are aligned, and when speed doesn't come at the expense of substance. Three months instead of a year. 8 hours a week instead of a full-time project. An audit with zero findings instead of a list of corrective actions.
Want to know what a similar implementation would look like for your company? Schedule a call with our team. or try a quickscan first.


