Product
ISO 27001
Industry
Sustainability Technology, Digital Product Passports, Life Cycle Assessment
Engagement Length
10 Months
Location
Manchester, United Kingdom
Outcome
Successful ISO 27001 certification for both entities, with Drata at 100% control compliance
How InsightPlay Achieved ISO 27001 Certification with Axipro
InsightPlay builds AI voice and text agents that handle player interactions for iGaming operators: onboarding, reactivation, retention, customer support. Its systems touch player data in some of the most heavily regulated corners of digital entertainment, so every enterprise deal starts with the same question. Can you prove your security, or can you only describe it?
InsightPlay answered that question with an ISO 27001 certification built on deliberate separation of duties: implementation led by Axipro, continuous monitoring on Drata, and an independent audit by Prescient Security. Javier Troncoso, InsightPlay’s co-founder, publicly rates the result five out of five on G2, under the title “Perfect ISO 27001 Certification.”
01- THE CHALLENGE
Why Assurance Comes First in iGaming
An ISO 27001 certificate works because it’s a shortcut. A prospect sees the certificate, and weeks of security due diligence collapse into a single act of recognition. That’s the entire commercial value of the standard, which ISO describes as the world’s best-known framework for information security management systems.
For InsightPlay, the shortcut carries unusual weight. Its AI agents don’t just chat. They interpret player intent and trigger real account actions, from onboarding to account support. Operators in regulated markets can’t hand that access to a vendor on trust alone, and neither can the regulators watching those operators. For a company like this, a certification that survives hard scrutiny is the entry ticket, not a marketing asset.
02- THE BACKGROUND
What Insightplay Actually Needed
The engagement scope had three parts, and the order mattered.
● The first priority wasn't the certificate.
It was a published trust center carrying the minimum credible information, live as fast as possible. Enterprise deals don’t pause politely while a vendor certifies, so sales conversations needed something verifiable to point to right away while the full program matured behind it.
● The second part was the program itself.
Building InsightPlay’s compliance operation on Drata, mapping the control set to ISO 27001, and running evidence collection on a platform built for continuous verification rather than annual scrambles.
● The third looked ahead.
Framework readiness, laying foundations so future standards can be added without starting from zero. The engagement was structured as a yearly contract rather than a one-off project, because compliance that ends at the certificate isn’t compliance. It’s a photo.
03- THE SOLUTION
Three Independent Pillars
The architecture Axipro proposed was deliberately redundant. Axipro served as the implementation partner, running the control mapping, the evidence program, and the audit preparation. Drata provided the continuous monitoring platform where evidence is collected and verified. Prescient Security, an independent accredited audit firm, designed and executed the audit itself.
Three separate parties, none of whom writes its own report card. That separation is what makes the certification believable to a skeptical security team on the other side of a deal. No single company controls the evidence, the platform, and the opinion.
Inside the Engagement
Axipro built the program on Drata, mapped the full control set, and managed every request for evidence raised during the audit through to resolution. Where submitted evidence fell short of the auditor’s bar, Axipro flagged it and worked with InsightPlay’s team to fix it rather than letting it slide through.
That detail matters. A partner willing to reject its own client’s evidence is optimizing for the audit holding up, not for the invoice clearing. It’s slower in the moment and much faster over the life of the certification, because nothing waved through in week six comes back as a finding in year two.
04- THE RESULTS
Beyond Certification: A Long-Term Security Partnership
InsightPlay achieved its ISO 27001 certification through the independent audit with Prescient Security, with every request for evidence addressed. The trust center went live early in the engagement, giving the sales team a credible security story while the full program matured. Framework readiness work is underway for the standards InsightPlay will need next, and the relationship has been formalized as an ongoing yearly engagement.
The best evidence of how the engagement went came from the customer, in a public G2 review scored five out of five:
“Axipro Technology has helped us achieve ISO 27001 certification and update our entire system. Shumaila, who is the person in charge, assists us with the implementation of new frameworks, which allows us to provide guarantees and security to the client by complying with all related regulations. I find the attention received from Shumaila particularly interesting, her availability, and the attention to detail they put into preparing the documents. We are going to continue relying on Axipro as a provider for a long time. We have no complaints and for us, the service has been perfect.”
Javier Troncoso, Co-Founder, InsightPlay