The digital health‑tech company completed the setup across four intensive sessions over three weeks, configuring ISO 27001, the NIST Cybersecurity Framework and SOC 2 controls within Orca Opti’s governed‑AI platform.
STAT’s business model hinges on trusted, paid engagements between practitioners and organisations, making information‑security safeguards a commercial necessity as the firm moved from product development to active partnership talks with government, med‑tech and pharmaceutical buyers.
Co‑Founder and Chief Executive Officer Chris Risby linked the company’s Google Workspace directory to Orca Opti, selected the three frameworks and used the platform’s onboarding wizard to generate policies, procedures, a baseline risk register and 139 assigned controls tailored to a health‑technology firm that works with clinicians rather than patient records.
During the third session Risby uploaded a “knowledge pack” describing STAT’s structure and roles, then employed the Ask Opti assistant to customise policy language. “All of our policies look good. They’ve taken our context and put in our business structure,” he said, noting that the system automatically applied control ownership across the founding team.
In the final session the team created a custom ISO 27001 auditor workspace to run an internal pre‑audit, surface gaps and produce an improvement plan. The resulting environment now includes published policies, a risk register covering twelve baseline risks – from revenue and regulation to key‑person exposure – and scheduled review cycles.
STAT reports that the new compliance suite has slashed partner questionnaire depth dramatically. “Questionnaires that used to run 50 questions deep are now down to single digits,” Risby said, adding that the evidence base now satisfies government and enterprise health‑tech partners.
Orca Opti founder and Managing Director Kat Giudes said the case illustrates how smaller teams can achieve standards traditionally reserved for larger organisations with bigger compliance budgets. “Watching a founder stand up ISO 27001, NIST CSF and SOC 2 in under a month, then answer partner due diligence in single digits, is exactly what we built Opti Core for,” she said.
Risby also hinted that the consolidated platform could replace a range of standalone software subscriptions as STAT scales, turning compliance from an internal checkbox into a commercial lever for closing deals.