The Challenge
A growing carbon accounting SaaS needed hands-on technical leadership to take their platform from early-stage to enterprise-grade. The challenges were multi-dimensional:
- Compliance requirements: Enterprise clients required ISO 27001, SOC2 Type 2, and GDPR certification before they would sign contracts
- Technical debt: The existing platform had been built for speed-to-market and needed architectural investment to support enterprise scale
- AI opportunity: There was a clear opportunity to use LLMs and vector search to make the platform significantly more intelligent, but no in-house expertise to deliver it
- Team growth: The engineering team needed to scale, and needed a leader who could hire, mentor, and set up processes — not just write code
Our Approach
Hands-On CTO Role
We embedded as CTO, taking full ownership of the technical platform while fulfilling strategic responsibilities. This wasn’t an advisory role — we were writing code, reviewing PRs, and making architecture decisions daily alongside the team.
Architecture for Compliance
We redesigned the platform architecture to meet enterprise compliance standards:
- Security-first infrastructure on Azure, with proper network segmentation, encryption at rest and in transit, and audit logging
- Data governance framework aligned to GDPR requirements, including data residency, consent management, and right-to-deletion workflows
- Documented processes for change management, incident response, and access control that satisfied auditors for both ISO 27001 and SOC2 Type 2
LLM-Powered Features
We led the implementation of AI capabilities that materially improved the product:
- Vector search with RAG using Azure Cognitive Search and OpenAI, enabling users to ask natural-language questions about their emissions data and receive grounded, accurate answers
- Intelligent data extraction from uploaded documents, reducing manual data entry for carbon accounting workflows
- LLM-assisted reporting that helps users generate narrative explanations of their emissions data for stakeholder reports
Team Building
We nurtured and grew a team of high-performing generalists — engineers who could work across the .NET backend, Flutter frontend, and Python infrastructure. We set up agile processes, code review standards, and a culture of ownership.
The Outcome
The platform achieved ISO 27001, SOC2 Type 2, and GDPR compliance — unlocking enterprise contracts that were previously inaccessible. AI-powered features using LLMs and vector search shipped to production, differentiating the product in a competitive market. The engineering team grew from a small group into a capable, self-directing unit with strong processes.
Technologies Used
- Backend: .NET
- Frontend: Flutter
- AI/ML: OpenAI, Azure Cognitive Search, RAG, vector search
- Infrastructure: Azure, Azure DevOps
- Data: Python (emission calculation infrastructure)
- Compliance: ISO 27001, SOC2 Type 2, GDPR