← Back to the call brief
External26 Apr 2026· Redwood Clinical29% captured

Aegis / Redwood Clinical - ISO 27001 Preparation

39 turns · 9 min captured of 29 min stated?Only the captured portion exists in the database. The remaining 20 min of this call was never transcribed, so nothing said in it appears anywhere in this application.

Show facts?Markers in the left gutter show which facts the model built from each turn. Click a marker to open that fact's evidence — this is the citation trail running backwards.

Showing 39 of 39 turns · 27 turns were used as evidence for at least one fact.

  1. Daniel OkaforAegisCloud0:03turn 0ASR 89%

    Hey Thomas, can you hear us okay?

  2. Thomas HargroveCustomer0:07turn 1ASR 92%

    Yeah, loud and clear — good to hear from you guys, it's been a couple weeks.

  3. Daniel OkaforAegisCloud0:13turn 2ASR 95%

    Good, good — yeah sorry it took us a bit to get this on the calendar, things have been moving fast on our end with the Comply v2 launch and everything.

  4. Daniel OkaforAegisCloud0:26turn 3ASR 96%

    Actually that's kind of why we're here today, right, so — Thomas, I also want to introduce Kevin, he's our solutions architect and he's going to be the technical lead on your ISO 27001 prep work.

  5. Kevin O'BrienAegisCloud0:40turn 4ASR 95%

    Hey Thomas, great to meet you — I've been looking forward to this one, Daniel's told me a lot about what Redwood is trying to accomplish this year.

  6. Thomas HargroveCustomer0:51turn 5ASR 94%

    Likewise, yeah, and honestly the timing could not be better because our CISO has been breathing down my neck about ISO 27001 since like January, so — any help getting a clearer picture of where we stand is going to be huge.

    +1Says timing could not be better and any help would be huge. · support experience

  7. Daniel OkaforAegisCloud1:06turn 6ASR 89%

    Yeah, absolutely, and I think that's exactly where Comply v2 is going to change the game for you — um, before we dive in though, Thomas, can you just give Kevin a quick sense of where you are in the ISO journey? Like, have you done a formal gap assessment yet or are you still kind of in the early stages?

  8. Thomas HargroveCustomer1:28turn 7ASR 96%

    Yeah so we're — we're pretty early if I'm being honest. We had an external consultant come in back in February, they did a high-level gap assessment, and the short version is we have a lot of work to do on the information security management side, particularly around evidence collection and demonstrating continuous monitoring, which as a healthcare organization is like, that's a big deal for us.

  9. Kevin O'BrienAegisCloud1:53turn 8ASR 94%

    Right, and that's such a common pain point, especially in healthcare — the auditors want to see a continuous thread of evidence, not just a snapshot, and that's historically been really painful to pull together manually.

  10. Thomas HargroveCustomer2:07turn 9ASR 93%

    Oh god, yeah, the last time we went through a HIPAA audit my team spent like three weeks just pulling logs and documentation together — it was a nightmare.

    -1Describes prior HIPAA audit as a nightmare. · compliance reporting

  11. Kevin O'BrienAegisCloud2:18turn 10ASR 92%

    Three weeks, yeah — that's — I mean that's not unusual but it's also exactly the kind of thing we built Comply v2 to eliminate, so let's talk about what that actually looks like in practice.

  12. Thomas HargroveCustomer2:31turn 11ASR 89%

    Please, yeah, walk me through it.

  13. Kevin O'BrienAegisCloud2:34turn 12ASR 90%

    So — okay so the big thing with v2, and this just went GA on April 7th so it's very fresh, is the on-demand reporting engine. You can now generate a full ISO 27001 readiness report at any point, and it maps your current control posture directly to the Annex A controls — so you're not having to manually cross-reference anything, the platform does that work for you.

  14. Thomas HargroveCustomer2:59turn 13ASR 94%

    Wait, so it's actually mapping to the specific Annex A controls? Like, is that — is it just a template thing or is it actually pulling live data from our environment?

  15. Kevin O'BrienAegisCloud3:11turn 14ASR 96%

    Live data — so it's pulling from your Detect telemetry, your Identity configurations, your Protect backup logs, and then surfacing all of that against the control framework. So when an auditor asks you to demonstrate, say, A.12.4 on event logging and monitoring, you can literally generate that section of the report on the spot.

  16. Thomas HargroveCustomer3:31turn 15ASR 93%

    Okay that is — yeah that is genuinely impressive, I wasn't expecting that level of granularity.

    +1Calls live Annex A mapping genuinely impressive and more granular than expected. · compliance reporting

  17. Kevin O'BrienAegisCloud3:38turn 16ASR 95%

    And it's not just ISO either — you mentioned HIPAA a second ago — the same report engine covers HIPAA, SOC 2, and PCI DSS as well, so if you ever need to spin up a HIPAA evidence package, it's the same workflow, same interface.

  18. Thomas HargroveCustomer3:54turn 17ASR 92%

    Yeah that multi-framework piece is something we specifically asked for in our renewal discussions, so it's great to see that actually shipped — Daniel you might remember that conversation.

    +1Notes multi-framework support was requested in renewal and is glad it shipped. · product capability

  19. Daniel OkaforAegisCloud4:05turn 18ASR 92%

    I do, yeah, I have the notes from that call — it was definitely on the roadmap and I'm glad we could deliver on it before your audit cycle.

  20. Kevin O'BrienAegisCloud4:17turn 19ASR 93%

    So Thomas, one thing I want to make sure we cover — in terms of your timeline, do you have a target date for the ISO 27001 certification audit? Because that's going to shape how we structure the onboarding to Comply v2.

  21. Thomas HargroveCustomer4:33turn 20ASR 92%

    Our CISO is targeting Q1 2027 for the formal audit, so we have — you know, roughly eight or nine months, which sounds like a lot but when you factor in the remediation work it's going to go fast.

  22. Kevin O'BrienAegisCloud4:47turn 21ASR 89%

    Eight months is actually a really solid runway for this — um, what I'd typically recommend for organizations at your stage is we start with a baseline report run in the first two weeks, just to get a concrete picture of where you are against the framework, and then we build a remediation roadmap from those gaps.

  23. Thomas HargroveCustomer5:07turn 22ASR 89%

    Yeah and that baseline report — is that something Kevin can help us interpret, or is it pretty self-explanatory on the platform?

  24. Daniel OkaforAegisCloud5:16turn 23ASR 91%

    Both, honestly — the report is designed to be readable by a non-specialist, we have like a traffic light system for control status, but Kevin and I will absolutely walk through it with you line by line on a follow-up call.

  25. Kevin O'BrienAegisCloud5:31turn 24ASR 96%

    Yeah I was going to say — I'd actually love to do a working session with you and maybe whoever on your team is going to be the compliance lead, we can go through the report together and I can explain what each gap actually means in practical terms, not just the framework language.

  26. Thomas HargroveCustomer5:51turn 25ASR 89%

    That would be — yeah that would be incredibly helpful, I have a security analyst, her name is Priya, she's been leading the internal ISO prep work and she would get a lot out of that kind of session.

    +1Calls the proposed working session incredibly helpful. · support experience

  27. Kevin O'BrienAegisCloud6:06turn 26ASR 89%

    Perfect, let's make sure Priya is on the next call — I'll send a calendar invite for a technical working session, maybe two weeks out, that gives you time to get Comply v2 activated and run that first report.

  28. Thomas HargroveCustomer6:21turn 27ASR 96%

    That works — and just so I understand the activation piece, is that something I need to loop in my IT team for, or is it more of a — like a configuration thing on the Aegis side?

  29. Kevin O'BrienAegisCloud6:36turn 28ASR 89%

    It's pretty lightweight on your end — since you're already running Detect and Identity, the data connectors are mostly already in place, we just need to enable the Comply v2 module on your tenant and do a quick configuration review to make sure all your data sources are mapped correctly, should take maybe an hour of your team's time.

  30. Thomas HargroveCustomer6:58turn 29ASR 92%

    Oh wow, okay, yeah that's much less overhead than I was anticipating — I was kind of bracing myself for like a big implementation project.

    +1Expresses relief that activation overhead is much lower than expected. · onboarding and implementation

  31. Kevin O'BrienAegisCloud7:07turn 30ASR 88%

    Yeah that's the benefit of being on the full platform — you're not starting from scratch, we're just unlocking capabilities that the underlying data already supports.

  32. Thomas HargroveCustomer7:17turn 31ASR 91%

    You know, I'll be honest — when we were evaluating platforms last year, one of the things that tipped us toward Aegis was exactly that, the idea that everything would be integrated rather than bolted together, and it's good to see that actually playing out in practice.

    +1Praises the integrated platform as playing out in practice. · product capability

  33. Daniel OkaforAegisCloud7:34turn 32ASR 93%

    That means a lot to hear, Thomas — and we want to make sure it keeps playing out that way through the audit, so Kevin's going to be your dedicated point of contact for all things Comply through this ISO process.

  34. Kevin O'BrienAegisCloud7:49turn 33ASR 94%

    Yeah, consider me on speed dial — seriously, if you or Priya hit questions on the platform or you're not sure how to interpret something in the report, just reach out, that's what I'm here for.

  35. Thomas HargroveCustomer8:04turn 34ASR 89%

    Really appreciate that — okay so just to make sure I've got the next steps straight: Kevin sends a calendar invite for the technical working session in two weeks, Daniel gets Comply v2 activated on our tenant, and in the meantime we — or I guess Kevin's team handles the module enablement, and then we run the first baseline report before that working session.

  36. Kevin O'BrienAegisCloud8:27turn 35ASR 94%

    That's exactly it — I'll also send you a short prep document that explains what to expect from the baseline report so you and Priya aren't going in cold.

  37. Thomas HargroveCustomer8:39turn 36ASR 97%

    Perfect — honestly this call was really reassuring, I feel like we actually have a path forward now, which is not how I felt last week.

    +1Says the call was reassuring and there is a path forward now. · support experience

  38. Daniel OkaforAegisCloud8:49turn 37ASR 94%

    That's exactly what we want to hear — alright Thomas, we'll let you get back to it, talk soon.

  39. Thomas HargroveCustomer8:57turn 38ASR 97%

    Sounds great, thanks guys — really looking forward to it.