Compliance should run itself, so people can make the decisions
Teddy Technologies GmbH builds an agentic compliance platform in Berlin. At its core are AI agents that map every obligation a company carries, build the program and do the recurring work, from the first certification to a complete GRC program.
We spent years doing compliance by hand
Before Teddy, our founders spent years implementing security and compliance programs hands-on: scoping ISO 27001, preparing SOC 2 audits, answering customer questionnaires and keeping evidence current across several frameworks at once.
Every new regulation added another project, another spreadsheet and another tool, even though most of the underlying controls were the same. NIS2, DORA, the CRA and the EU AI Act make that worse for every company in Europe.
So we built Teddy around a simple idea: describe your company once, map every obligation onto it and let agents run the recurring work. The decisions stay with the people who are accountable for them.
How we build Teddy
Three principles guide every agent we ship.
Every regulation is read against the same company model, so nothing is done twice.
Controls and evidence are reused across frameworks instead of rebuilt for each audit.
Agents run daily and weekly. Every result is labelled, logged and approved by a person.
Two founders, one Berlin team
Teddy is led by two experienced founders and emerged from the Antler ecosystem in Berlin. We are building the team now.
We are hiring in Berlin and work with CISOs, GRC managers and consultancies.
