Skip to main content
How Lucis made security a default,
not a tradeoff
Logo Lucis

How Lucis made security a default, not a tradeoff

ISO 27001
certification achieved

Reference case study. This page preserves a real ISO 27001 journey as an industry example. It shows the type of outcome a cloud compliance platform combined with expert support can enable; Lucis is not presented as a ZebraByte customer.

The Challenge: Lucis was expanding quickly across Europe and needed to formalize security around highly sensitive health information without slowing its engineering roadmap.

The Approach: Existing technical practices were mapped to ISO 27001, gaps were prioritized, documentation and evidence were organized around the team’s real architecture, and the operational burden was kept away from engineers wherever possible.

The Results:

  • ISO 27001 certification achieved while the company continued to scale;
  • a low-friction internal workload for the engineering team;
  • a repeatable compliance structure that could continue after certification.

About Lucis

Lucis is a European health-tech company focused on preventive medicine. Its service analyzes more than 180 biomarkers and combines software, AI and medical oversight to help members understand biological age and build a personalized health roadmap across nutrition, sleep, activity, supplements and mental health.

Following an $8.5M seed round, the company expanded across European markets. That growth increased the importance of information security: health information is among the most sensitive categories of personal data, and trust has to be designed into the operating model rather than added after the fact.

Lucis ISO 27001 reference case study

The challenge: scaling without compromising trust

As Lucis expanded across France, the UK, Ireland and Portugal, its informal security practices needed to become an auditable management system.

Three constraints shaped the program:

  • Sensitive data. The company works with personal health information, so information security is part of the trust relationship with members rather than a procurement checkbox.
  • A lean engineering organization. Product and engineering resources needed to stay focused on customer outcomes and the core platform instead of spending months maintaining compliance paperwork.
  • A management system that matched reality. The ISO 27001 implementation had to describe the actual architecture, workflows and responsibilities of the company, not a generic policy template.

The useful principle from this case is that ISO 27001 can be built around the way a good technical organization already works. The compliance layer should make those practices visible, testable and repeatable.

Turning a security mindset into an ISMS

A practical ISO 27001 program begins by converting operational reality into a structured Information Security Management System.

In this reference case, that meant:

1. Mapping the framework to the real environment

Controls were assessed against the company’s actual systems and working practices. That reduces the temptation to create procedures solely for an auditor and makes the resulting ISMS easier to maintain.

2. Centralizing the operational work

Policies, evidence, risks, control ownership and audit preparation were organized as one program. The technical team could contribute the information only it possessed while repetitive compliance coordination remained centralized.

3. Using asynchronous collaboration

Compliance questions were handled in a way that fit the team’s normal operating rhythm rather than through long cycles of meetings and disconnected document requests.

4. Preparing for continuous operation

Certification was treated as a checkpoint in an ongoing security program. Evidence, risks and improvements still need owners and review cycles after the audit is complete.

This model maps naturally to ZebraByte’s two delivery modes: organizations or professional advisers can operate the ZebraByte Cloud platform themselves, while companies that want less internal overhead can use ZebraByte Managed Compliance to have specialists run more of the program for them.

Certification without slowing growth

The important outcome was not only obtaining the ISO 27001 certificate. It was reaching that milestone without turning the certification project into a parallel bureaucracy for the engineering team.

A low-friction program generally depends on several design choices:

  • collect evidence from existing systems whenever possible;
  • reuse existing workflows instead of inventing compliance-only workflows;
  • assign control ownership clearly;
  • keep policies aligned with actual practice;
  • resolve material gaps first rather than chasing theoretical perfection;
  • make audit preparation a consequence of continuous work rather than a one-off scramble.

For a growing health-tech company, this approach makes security easier to scale across markets and teams because responsibilities and expectations become explicit.

Why this case matters

Lucis illustrates why regulated or data-sensitive startups benefit from formalizing security earlier than they might initially expect. Waiting until every enterprise buyer, partner or regulator asks for evidence independently creates duplicated work.

A well-structured compliance platform gives the organization one place to manage:

  • the risk register;
  • controls and owners;
  • policies and approvals;
  • evidence;
  • third parties;
  • audit findings;
  • recurring reviews and remediation.

The result is not simply “having documents.” It is having an operating system for compliance that can continue to evolve with the company.

What another organization can take from this example

For teams handling sensitive or regulated data, the practical questions are:

  • Does the security program reflect the systems that actually exist today?
  • Can the company prove that important controls operate consistently?
  • Is compliance work concentrated with the right people instead of distributed randomly across engineering?
  • Can the same evidence and controls support additional requirements later?
  • Is certification being treated as an ongoing management process rather than a finish line?

The central lesson is that strong security and growth do not have to be opposing goals when compliance is designed around the operating reality of the business.



ZebraByte

Managed frameworks Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Not seeing the framework you are looking for?
Reach out — we may already support it in the programme.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert