About the company
Kickscale develops a revenue intelligence platform for sales teams. Sales conversations are recorded, synced to the CRM, then condensed and analyzed by AI, so reps save time on documentation and get feedback on where a deal stands and what to improve.
The company is based in Vienna and sells mostly to startups, software and SaaS companies, but is also seeing growing interest in these solutions from mid-market industrial companies. With its focus on GDPR, ISO 27001 and consistent hosting within the EU, Kickscale positions itself as a European alternative to US tools like Gong.

The challenge
For a fast-growing company selling into larger accounts, compliance was not optional: "No one buys us just because we are good at compliance. But if we are not good at compliance, we are immediately out of a certain number of opportunities," says Herwig Gangl, Co-Founder of Kickscale. IT security and GDPR carry particular weight with industrial customers; some prospects sent 20 pages of questions before a first conversation had even happened.
Internally, IT security had always mattered, but it was not formalized. Processes existed, but they were informal and lived rather than written down. As the company grew, that informality no longer held up, while the market pressure to prove security kept rising.
The solution
Kickscale evaluated a small number of providers and chose Kertos quickly. Part of the fit was cultural, a startup with a similar pace and way of working, plus geographic and language proximity. What stood out in the process was Kertos' honesty about the real effort: no promise of certification in three weeks, but a realistic read on the process, its duration and the work involved. In handling sensitive business data in particular, the combination of GDPR compliance and technical security measures was decisive.
Key components of the solution:
- Central compliance platform: ISO 27001 and GDPR in one place, used by every employee, instead of scattered documents.
- Formalized access control: a defined on- and offboarding process with clear steps and responsibilities that removes access when someone leaves.
- Integrations into the existing stack: Google authorization for access control, Personio for HR, so technical and organizational measures are monitored without duplicate work.
- Certified experts for ISO 27001 and GDPR: dedicated contacts across both areas as integrated expert support from Kertos.
- Continuous upkeep of controls and evidence: the basis for the annual surveillance audit.
The result
With Kertos, Kickscale achieved ISO 27001 certification and is now preparing for the surveillance audit, the annual check that confirms the certification holds. Because controls and evidence are maintained continuously in the platform, keeping the certification is part of the routine rather than a fresh project each year.
The clearest before-and-after is the consistent involvement of every employee through the Kertos platform. Where process descriptions, IT security policies and documentation of control processes had previously been spread across many different places (Google Docs, Slack, Notion), today all employees have access to the Kertos system. It holds all relevant documents, runs IT security trainings, and documents all relevant events or incidents.
For many customers and prospects, compliance and IT security are a knockout criterion and a precondition for entering deeper conversations with a potential supplier at all. With the Kertos system and the consultants' expertise, we are very well positioned here and can usually convince our customers quickly that we meet their requirements.
With ISO 27001 and GDPR, the foundation is in place; a further certification in the area of ISO 42001 (AI management systems) is currently being evaluated.

"Implementing data protection and compliance in a structured way with Kertos"
From the very start, we felt that we were working with a partner who takes a realistic view of the effort and the process involved. The result, for us, is now a central platform that lets us manage our compliance topics in a structured way, across teams.
