About the company
Designair runs GPU workstations in the cloud for architecture, engineering, and plant engineering firms. Revit, ArchiCAD, and other CAD applications run in the data center instead of on an expensive machine in the office, reachable from any device. No project data sits on the users' own devices.
Designair's customers plan automotive plants and pharmaceutical facilities, projects worth hundreds of millions. Anyone who puts models like that into someone else's cloud is entrusting a provider with the design data of an entire plant. That large firms approached Designair on their own initiative did not make this question smaller, it made it more urgent.

The challenge
The trigger arrived as a spreadsheet. A large prospect sent over a questionnaire with 118 security questions through a reseller partner. Several employees worked on it for a week before it was answered. The internal conclusion was unambiguous: not again.
The next case followed shortly after: a group with 9,000 employees, with a professional IT and procurement department and a review process to match. With a counterpart like that, a good answer is not enough; it has to arrive in a form procurement will accept.
Security was not a new topic for Designair: it is part of the product promise. Proving it, though, was only possible case by case, and by hand every time. For Don Rekko, that was the point where a conviction turned into a project: know the risks and mitigate them before a customer asks. The decision to go for ISO 27001 came at the end of 2025.
The solution
Two requirements were fixed from the start. The solution had to be cloud-native, not an on-premise system. And it had to automate, instead of managing Excel lists.
What tipped the decision was that Kertos does not just provide the software, it takes on the work. A team of this size cannot teach itself ISO 27001 on the side; it needs experts who help build the ISMS. On top of that came the fit: Kertos is at home in the cloud, works internationally, and as a German company holds high standards for its own data protection, which is how Designair works too. "You were exactly the right fit for us," says Don Rekko, Co-Founder of Designair.
Key components of the solution:
- Building the ISMS together with certified experts, rather than self-study alongside the day job.
- Automated controls and evidence in one place, instead of security documentation in spreadsheets.
- Trust Center for prospects, who can review the security evidence themselves.
- A dedicated contact in the implementation team across the whole project.
The result
Audit passed on the first attempt
The audit produced no major findings, but one opportunity for improvement. Half a year passed between kick-off and certificate, without pausing product development for it.
Questionnaires no longer take a week.
When a security request comes in today, Designair points to its Trust Center. The effect goes beyond the time saved: anyone who sees a certified ISMS and the matching evidence there reads it as a sign that the provider has this under control. The topic no longer reaches Designair unprepared, it is answered before the question arrives.
One sales objection permanently settled.
Three questions repeat across Designair's sales processes:
- Does the technology work?
- What does it cost to run?
- Is it secure?
The third one is now answered by a link.
Access to the enterprise segment.
For Don Rekko, the certification is the precondition for getting into these conversations in the first place.
What's next
With ISO 27001, the foundation is in place for the next frameworks to build on. SOC 2 is next, because interest from the US is growing, and TISAX® for the automotive industry over the longer term. In parallel, AI agents are being built into the Designair platform, and a certification for those will follow.
Put your compliance on autopilot, both data protection and information security: Book a demo.

"ISO 27001 is the entry ticket"
If you want to crack the upper mid-market and the enterprise market, ISO 27001 is the entry ticket. Kertos worked with us to make sure we would actually succeed on the platform.








