Kertos
Kertos is a Munich-based RegTech company that provides an AI-powered compliance automation platform for European SMEs and scaleups, covering GDPR, ISO 27001, NIS2, EU AI Act, and related frameworks via subscription SaaS and bundled expert services.
- Company typePrivate
- Founded2022
- HeadquartersMünchen, Germany
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Kertos does
Kertos GmbH is a Munich-based RegTech company that develops and sells an integrated compliance and privacy automation platform for European small and medium-sized enterprises, scaleups, and regulated companies. The platform unifies data privacy (GDPR), information security (ISO 27001, SOC 2, TISAX, NIS 2, ISO 27701), and AI governance (ISO 42001, EU AI Act, DORA) on a single no-code backbone, with 140+ pre-built integrations and a public REST API for connecting HR, ticketing, identity, cloud and CRM systems. Its proprietary agentic AI compliance guide, KAIA (also branded KAI / Kertos AI and served from kertos.ai), orchestrates risk assessments, policy generation from a 40+ template library, DSAR processing, vendor reviews, and continuous control monitoring across all supported frameworks.
The product portfolio is structured as a core Kertos Platform with modular add-ons: Privacy Management System (PMS), Shadow IT Discovery, DSAR Automation, RoPA/TOM/DSFA documentation, Policy Management, External Data Protection Officer service, Employee Trainings, Certifiable ISMS (covering ISO 27001, SOC 2, TISAX, NIS 2), Risk Management, Asset Management, Vendor Management, Trust Center, AIMS (AI Management System), AI Inventory, and AI Risk Assessment. A peer-to-peer Trust Graph, explicitly funded by the September 2025 Series A, is positioned as a longer-term differentiator enabling compliance evidence sharing between Kertos customers and their buyers. Kertos itself holds ISO 27001 and ISO 42001 certifications, and has received the Wirtschaftswoche "Best of Technology" award in 2023, 2024 and 2025.
Kertos generates revenue primarily through quote-based annual SaaS subscriptions to the platform, supplemented by recurring managed-services revenue from the External Data Protection Officer offering and by professional services revenue from implementation, training and ongoing advisory delivered by accredited German-speaking compliance experts. Go-to-market is sales-led with a "Get a demo" / "Request a quote" intake funnel, supported by a self-serve application login, a 5-minute Compliance Check lead qualification form, an enterprise field-sales motion targeting regulated verticals (SaaS, Healthtech, Fintech, InsurTech, automotive/TISAX), and a "Become a partner" reseller/consulting channel. The company has disclosed three funding rounds totaling approximately €19M: a €1M pre-seed (May 2022) led by 10x Founders, a €4M seed (April 2023) led by VR Ventures / Redstone with Pi Labs and Seed + Speed Ventures, and a €14M Series A (September 2025) led by Portage Ventures.
Kertos firmographics
Firmographics- Name
- Kertos
- Legal name
- Kertos GmbH
- Website
- https://kertos.io
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Kertos is a Munich-based RegTech company that provides an AI-powered compliance automation platform for European SMEs and scaleups, covering GDPR, ISO 27001, NIS2, EU AI Act, and related frameworks via subscription SaaS and bundled expert services.
- Ownership category
- akta.pro rank
Kertos industry classification
Industry- Product category
- Compliance Automation Software
- NAICS
- Computer Systems Design and Related Services (5415), Custom Computer Programming Services (541511), Other Computer Related Services (541519), Software Publishers (513210)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Compliance, GRC Workflow & Audit Automation Platforms (HDAEAHAL)
- akta.pro secondary industries
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA), AI Governance, Risk & Compliance (GRC) Platforms (HDAAAMAA), Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO), KYC/KYB & Customer Onboarding (CIP, beneficial ownership, screening) (FSAGAFAB), Fraud Prevention & Identity Verification (IDV/KYC) (BPAMAEAI), Fraud, Risk, KYC/AML & Compliance Platforms (BPAMAFAI)
Keywords
Where Kertos is headquartered
LocationHeadquarters
- HQ city
- München
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Kertos business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- SaaS Platform Subscription: Recurring subscription revenue from the Kertos compliance automation platform, sold with quote-based / "Request Offer" pricing rather than public list prices. Bundles privacy management (GDPR), information security (ISO 27001, SOC2, TISAX), and AI governance (ISO 42001, EU AI Act) modules.
- External Data Protection Officer (DPO) Service: Recurring managed-services revenue from providing an accredited external Data Protection Officer (DPO) including appointment with the supervisory authority, document review, website privacy review, ongoing support, and bundled platform access (Discovery, Task Management, Vendor Management, Incident Management, training, RoPA, DSA, DPIA, TOMs, manual DSR handling).
- Professional Services & Compliance Expert Support: Expert-led implementation and ongoing advisory bundled with platform subscriptions — German-speaking support with regular check-ins, structured milestones for certification projects, training programs, and audit preparation services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Quote-based, not publicly disclosed; multiple "Request a quote" CTAs and 5min Compliance Check intake form |
Go-to-market motion5 records
Distribution channels4 records
Marketing channels9 records
Kertos product offering
Product offeringCore offering
Kertos sells a unified SaaS compliance automation platform that centralizes Privacy Management (GDPR), Information Security Management (ISO 27001, SOC 2, TISAX, NIS 2, ISO 27701), and AI Governance (ISO 42001, EU AI Act, DORA) into a single no-code workflow backbone. The platform combines proprietary agentic AI (KAIA), 140+ pre-built integrations, automated documentation generation, continuous monitoring, and accredited compliance-expert services to deliver compliance-on-autopilot for European SMEs, scaleups, and regulated companies.
Product overview
Kertos offers a single, unified compliance platform (architecture: platform-plus-modules) rather than separate point products. The Kertos Platform is the core, and the Privacy Management System (PMS), Shadow IT Discovery, DSAR Automation, RoPA/TOM/DPIA module, Policy Management, External Data Protection Officer service, Employee Trainings, Certifiable ISMS, Risk Management, Asset Management, Vendor Management, Trust Center, AIMS (AI Management System), AI Inventory, AI Risk Assessment, and the Trust Graph all sit as integrated modules on top of it. KAIA (also called KAI / Kertos AI) is the agentic AI layer that orchestrates the modules across GDPR, ISO 27001, SOC 2, TISAX, NIS2, ISO 42001, ISO 27701, EU AI Act, and DORA workflows. Together, the platform combines no-code and REST-API integrations, automated documentation, continuous monitoring, and accredited expert support to deliver compliance-on-autopilot for European SMEs and scale-ups.
Differentiator
Problem solved
Functional benefit
Brands
- KAIA (Kertos AI): AI-powered compliance assistant/guide (also referred to as KAI) for intuitive compliance management across GDPR, ISO 27001, SOC 2, NIS2, and EU AI Act frameworks. Operated at the kertos.ai subdomain.
Products and services
- Kertos Platform The all-in-one compliance platform that unifies data privacy (GDPR), information security (ISO 27001, SOC 2, TISAX, NIS 2), and AI governance (ISO 42001, EU AI Act, DORA) into a single no-code workflow automation backbone with 140+ integrations, REST API, and accredited expert support.
- Privacy Management System (PMS) No-code GDPR data protection management system that centralizes Record of Processing Activities, Technical and Organizational Measures, Data Protection Impact Assessments, automated DSAR/deletion handling, and external DPO support.
- Shadow IT Discovery Automated data-source and processing-activity discovery module that provides real-time transparency over the entire IT landscape through website scanning and connected application detection, eliminating manual shadow-IT mapping.
- DSAR Automation End-to-end automation of GDPR data subject access and deletion requests — capture, verification, processing across integrated data sources, and final response — fully automated, scalable, and GDPR-compliant, with a stated ~80% effort reduction and >500k requests resolved.
- RoPA, TOM, DSFA & more GDPR documentation module that creates and manages Record of Processing Activities (RoPA), Technical and Organizational Measures (TOM), Data Protection Impact Assessments (DPIA), and Transfer Impact Assessments (TIA) with seamless IT integration and automated risk assessment.
- Policy Management Policy automation module offering a library of 40+ expert-tested templates, automated review and approval workflows, version control, expiration reminders, and control mapping for ISO 27001, GDPR, SOC 2, and TISAX, stated to save 60–80% of policy creation time.
- External Data Protection Officer Accredited external DPO service that handles DPO appointment with the supervisory authority, GDPR document review, policy control, and continuous support, bundled with access to the Kertos privacy platform features (Discovery, Task Management, Vendor Management, Incident Management, training, RoPA, DSAR, DPIA, TOMs).
- Employee Trainings Automated, expert-built online training modules for GDPR, ISO 27001, SOC 2, and AI compliance, with automatic assignment to new employees, real-time progress monitoring, automatic reminders, and audit-ready documentation.
- Certifiable ISMS Automated Information Security Management System module supporting ISO 27001, TISAX, SOC 2, and NIS 2 certification, with central management of policies, controls, risks, and assets for fast (weeks-to-months) audit readiness.
- Risk Management Automated risk management module that records and assesses risks in real time, structures assessments around confidentiality, integrity, and availability (CIA), links risks to controls, and provides reports and incident management.
- Asset Management Centralized, automated asset management module that detects and classifies IT hardware, software licenses, cloud/SaaS resources, and business assets, with automatic risk and control mapping and dynamic risk adjustment.
- Vendor Management Vendor/supplier compliance management module that captures server locations, certificates, and data processing agreements with one click, automates supplier workflows, and supports duty-of-care and risk management.
- Trust Center Real-time customer-facing trust portal that displays a company's certifications, security policies, compliance standards, and sub-processors to accelerate sales cycles and replace one-time security assessments with continuous transparency.
- AIMS (AI Management System) AI Management System module aligned with ISO 42001 and the EU AI Act, featuring pre-mapped controls, PDCA continuous improvement methodology, automated gap analysis, KPI monitoring, and AI risk identification and assessment.
- AI Inventory Centralized AI inventory module that documents, evaluates, and manages AI use cases with automated risk assessments, complete compliance overview, and seamless data/asset linking for EU AI Act readiness.
- AI Risk Assessment AI risk assessment module with a continuously updated AI-specific risk library aligned with the EU AI Act and ISO/IEC 23894, customizable risk models, contextual analysis, and audit-ready tracking of risk assessments and mitigation efforts.
- KAIA (KAI / Kertos AI) Agentic AI compliance guide that runs complex compliance processes on autopilot across GDPR, ISO 27001, SOC 2, NIS 2, and the EU AI Act, automating tasks such as risk assessments, policy management, supplier evaluations, and answering complex compliance questions 24/7.
Quantifiable outcome
- 100% audit success rate across customers
- +18 more outcomes
Companies that use Kertos
Customer profileNamed customers27 records
Segments9 records
Ideal customer profiles5 records
Kertos technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration52 records
AI capability10 records
Feature9 records
Kertos partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core.
- Google Workspace / Google SSOcoreListed as a discovery / SSO integration enabling Kertos to ingest identity and SaaS data sources. One of 100+ no-code integrations on the Kertos platform.
- Microsoft Azure Cloud ServicescoreListed under discovery integrations, allowing Kertos to discover and ingest data from Azure-hosted services as part of its Shadow IT / Discovery and ISMS automation.
- Google Cloud PlatformcoreListed as a discovery integration, enabling ingestion of GCP-hosted services into Kertos's compliance platform and Shadow IT Discovery.
- AWS (implied via cloud integrations page)coreReferenced in vendor-management and discovery contexts ("seamless integration with cloud platforms like AWS, Google Cloud, and Azure") as a key data source for Kertos's compliance platform.
- PersoniocoreHR system integration listed among the platform's pre-built integrations. Personio is also a customer of Kertos (logo featured on homepage/demo page), making this a customer-and-vendor overlap.
- OktacoreIdentity provider integration listed on the platform page, used to ingest identity data for access management, ISMS controls and Shadow IT Discovery.
- Osborne ClarkecoreInternational law firm Osborne Clarke advised venture capital fund VR Ventures / Redstone on its EUR 4 million seed investment in Kertos (announced April 2023). Osborne Clarke acts as legal counsel on the transaction rather than as a commercial partner of Kertos.
Scale indicators14 records
Recent moves6 records
Expansion highlights6 records
Kertos competitors and assessment
Company assessmentDirect peers
- DataGuard: DataGuard is a Munich-based privacy, information security, and AI compliance platform serving European SMEs and scaleups — direct head-to-head competitor with Kertos in DACH with overlapping ISO 27001/GDPR positioning and similar customer segments.
- Vanta: Vanta is the leading US-based compliance automation platform covering SOC2, ISO 27001, HIPAA, GDPR and more. It is the closest direct competitor to Kertos, with broader scale but a less Europe-native footprint — Kertos competes head-to-head on EU framework depth (NIS2, DORA, EU AI Act, TISAX).
- Drata: Drata is a US-based continuous compliance automation platform (SOC2, ISO 27001, HIPAA, GDPR) with a similar no-code integration model. Comparable to Kertos in GTM motion and customer profile, and increasingly competing on European enterprise deals.
- Secureframe: Secureframe provides automated security and privacy compliance (SOC2, ISO 27001, HIPAA, GDPR, PCI). Direct competitor to Kertos in mid-market compliance automation, with overlapping customer personas (B2B SaaS startups and scale-ups).
- Sprinto: Sprinto is a compliance automation platform (SOC2, ISO 27001, GDPR, HIPAA) with a strong no-code integration approach. It targets SaaS startups and scale-ups similar to Kertos' primary segments and competes directly in European mid-market deals.
- Thoropass (formerly Laika): Thoropass (formerly Laika) is a compliance and audit management platform combining automation with in-house auditor expertise — directly parallel to Kertos' hybrid AI + accredited-expert model. Strong overlap in SOC2/ISO 27001 positioning.
- Scrut Automation: Scrut is an India-based compliance and risk observability platform (SOC2, ISO 27001, GDPR, HIPAA) with a similar mid-market SaaS target. Comparable in product scope and integrations approach, increasingly active in European markets.
- Hyperproof: Hyperproof is a compliance operations platform covering SOC2, ISO 27001, FedRAMP, and other frameworks with continuous monitoring capabilities. Direct competitor in the mid-market compliance automation category where Kertos operates.
Broad incumbents
- OneTrust: OneTrust is a large US-headquartered trust intelligence platform spanning privacy, GRC, ethics, and ESG. It is a broad incumbent offering overlapping capabilities (privacy management, DSAR, vendor risk) and competes with Kertos especially on the GDPR/privacy side in enterprise deals.
- AuditBoard: AuditBoard is a large US-based audit, risk, and compliance management platform (SOX, SOC, ISO) typically used by mid-market and enterprise internal audit teams. Competes with Kertos on the risk management and ISMS module side in larger enterprise deals.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks7 records
Key highlights7 records
Customer concentration
Kertos social profiles
Digital presenceKertos compliance and trust
Trust signalCompliance9 records
Kertos financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kertos leadership team
Management profileNumber of profiles
Kertos subsidiaries and ownership
Company hierarchySubsidiaries1 record
Kertos funding detail
Funding detailFunding overview
Funding rounds3 records
Investors8 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kertos M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kertos
What does Kertos do?
Kertos sells a unified SaaS compliance automation platform that centralizes Privacy Management (GDPR), Information Security Management (ISO 27001, SOC 2, TISAX, NIS 2, ISO 27701), and AI Governance (ISO 42001, EU AI Act, DORA) into a single no-code workflow backbone. The platform combines proprietary agentic AI (KAIA), 140+ pre-built integrations, automated documentation generation, continuous monitoring, and accredited compliance-expert services to deliver compliance-on-autopilot for European SMEs, scaleups, and regulated companies.
Is Kertos a public or private company?
Kertos is a private company. It is classified as venture growth investor backed and is currently operating.
When was Kertos founded?
Kertos was founded in 2022. It employs 11 to 50 people.
Where is Kertos based?
Kertos is headquartered in München, Germany, in the Europe region.
How does Kertos make money?
Three revenue lines are on record. SaaS Platform Subscription is the primary driver. The others are external Data Protection Officer (DPO) Service and professional Services & Compliance Expert Support.
Who are Kertos's main competitors?
Direct peers on record are DataGuard, Vanta, Drata, Secureframe, Sprinto, Thoropass (formerly Laika), Scrut Automation and Hyperproof. Broad incumbents are OneTrust and AuditBoard.
Does Kertos have an API?
Yes. Kertos offers a public REST API that, alongside its no-code integrations, enables seamless connection of internal and external systems including databases, SaaS tools, websites, single sign-on (SSO) solutions, office applications, and third-party services. It allows developers and customers to integrate IT infrastructure and pull data sources into the compliance platform for automated GDPR documentation, ISMS asset/policy creation, data subject request processing, risk and control mapping, and discovery scans. Authentication method, rate limits, versioning, and sandbox availability are not specified. Developer documentation is at docs.kertos.io.
What industry is Kertos in?
Kertos's product category is Compliance Automation Software. Its primary akta.pro industry code is HDAEAHAL, Compliance, GRC Workflow & Audit Automation Platforms, with a secondary code of HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies). Its NAICS code is 5415 and its SIC code is 7372.