---
title: "How we closed 105 compliance automation accounts worth $4,401,390 in seven months. | Stone Haven Capital Group"
description: "An average of $41,918 a year per account, off a programme built around one fact: nobody buys compliance software until a date on a calendar makes them."
canonical: "https://stonehaven.capital/showcase/compliance-automation-platform"
last-updated: "2026-08-22"
---

> An average of $41,918 a year per account, off a programme built around one fact: nobody buys compliance software until a date on a calendar makes them.

Stone Haven Capital Group

Schedule a Call

Case study · Compliance Automation Platform

# How we closed 105 compliance automation accounts worth $4,401,390 in seven months.

An average of $41,918 a year per account, off a programme built around one fact: nobody buys compliance software until a date on a calendar makes them.

Seven months. A compliance automation platform selling continuous evidence collection and audit readiness for SOC 2, ISO 27001 and the EU AI Act, priced per framework per year. No new sales hires, no analyst coverage, no conference booth.

- $4,401,390 generated in 7 months, from 105 framework subscriptions at an average of $41,918.

- 4,777,317 emails to 2,773,748 companies, producing 8,855 replies at 0.3%.

- 1,366 interested conversations became 423 held meetings and 105 signed accounts.

- What did most of the work: we sorted the market by which framework each company faced and how close its date was.

- What went wrong: the EU AI Act angle ran about nine months too early.

01

## Did they get a good result?

They did, and the export it came from is printed here in full rather than trimmed. New business had been arriving through partner referrals and a self-serve trial nobody was steering, worth $1,299,458 on the book when we arrived. Seven months later the client had closed 105 accounts for $4,401,390, a 3.4x increase, with 423 qualified opportunities worth $13,705,200 still open behind them.

What happenedThe number

Accounts closed105, worth $4,401,390

Average annual contract$41,918

Qualified opportunities still open423, worth $13,705,200

Interested conversations1,366, worth $29,778,800

Emails sent4,777,317

Companies contacted2,773,748

Leads that finished the full sequence667,856, or 24.1%

Replies8,855, a 0.3% reply rate

Positive replies1,366, or 15.4% of replies

Bounces152,874, a 3.2% bounce rate

Seven months of compliance outbound as the sending platform recorded it, including the quarter of the list that had finished its s

Seven months of compliance outbound as the sending platform recorded it, including the quarter of the list that had finished its sequence.

02

## Did you get them in front of the right people?

A send count answers nothing on its own, and this programme has a large one. 4,777,317 emails is a figure anybody can reach the moment they stop caring which security team receives them.

105 accounts closed at an average of $41,918 a year. Behind them sit 423 qualified opportunities worth $13,705,200, and 1,366 interested conversations worth $29,778,800.

Targeting shows up in what the replies turn into. 8,855 replies produced 1,366 positive ones, 15.4% of everything that came back. 423 of those cleared qualification, which is 31.0% of the positive replies, and 105 closed, 24.8% of the qualified set. Those three ratios hold steady from the second month onward, which is the sign that the conversations were landing with people who actually carry the audit.

The compliance pipeline the client worked from, split by framework and by how close each account sat to its audit date.

03

## What worked, and why

### We sorted the market by which framework each company faced and how close its date was.

A company chasing its first SOC 2 Type II, a company renewing ISO 27001 for the fourth year, and a company reading the EU AI Act for the first time are three different buyers with three different urgencies. Treating them as one market is the most common way this category wastes its outbound budget. Every company in the pool was tagged with the framework it was obliged to hold, the reason it was obliged to hold it, and whatever public evidence existed about where in the cycle it sat.

That last field is the one that mattered. A trust page listing a current report, a customer contract requiring one, a funding round that brings enterprise buyers with security reviews attached, a first hire with security in the title. Each of those puts a rough date on a company. The segments were then worked in order of how near that date looked, so send capacity went to the companies closest to needing something rather than spreading evenly across everybody who might one day.

A reply from a head of security eleven weeks out from an ISO 27001 surveillance audit, which is what the segmentation was built to

A reply from a head of security eleven weeks out from an ISO 27001 surveillance audit, which is what the segmentation was built to surface.

Why this holds up: framework and deadline are the only two variables in this category that predict whether a reply happens. Headcount, funding stage and tech stack tell you who could buy. The audit date tells you who is buying this quarter, and it is the only one of the four that moves.

### We built the pool wide first, then kept only the companies carrying a dated obligation.

The people who sign for this are heads of security, heads of compliance and VPs of engineering at Series B to Series D software companies, which is the band where a customer has started demanding a report and there is still nobody internally whose whole job is producing one. The first pull across North America and Europe came to 7,418,162 records against that profile.

What came out mattered as much as what stayed in. Companies with no enterprise customers to satisfy, companies below the size where a security function exists, and companies whose only framework obligation was one they had already satisfied and would not revisit for a year all came off. That took the workable pool to 3,225,288, and 2,773,748 of those were contacted inside the window.

The logic underneath it: this category has an unusually clean disqualifier. A company with no contractual reason to hold a report will not buy one at any price, from anybody, in any month. Removing those companies costs nothing and buys back the capacity that the ones with a real date deserve.

### The opener stated a deadline and made an offer, and asked nothing.

It opened on the framework and the timing that applied to that specific company, with no greeting in front of it. Then the ICP token, so the reader could see in one line that this was written for their kind of company rather than sprayed. Then what the platform does about it. There is no question anywhere in the email and it is signed with initials. A head of compliance reading it either has that date on their calendar or does not, and the ones who do reply without being asked to.

Every send left as plain text, spun line by line, so no two messages were identical, and none of it went anywhere near the domain the client's product and support notifications run on. 3,102 mailboxes across 1,034 dedicated domains carried the whole programme, each capped at 20 sends a day, all authenticated before sending and warmed for the full seven months. Placement held at 88.0% with zero account errors and 31 alerts raised across the engagement.

The live sequence: four steps, gaps of four, four and seven days, and the opener that carried the deadline statement.

The opener, which leads on a date and asks for nothing.

What that buys: a question invites a decision about whether to answer. A deadline statement invites a decision about whether it is true, and a compliance lead who knows their date is eleven weeks out cannot read a correct one without reacting to it.

We ran four touches on short gaps and put a qualification layer in front of the client.

Four steps with waits of four, four and seven days, five variations on the opener and two on each follow-up, all running against each other from the first week. The gaps are deliberately tight. A company inside an audit window is making its decision in weeks rather than quarters, and a sequence that takes two months to finish arrives after the procurement conversation has already happened somewhere else.

Why the filter earns its place: 8,855 replies came back, alongside 22,644 out of office responses at 0.8%. Only conversations where a framework, a date and a named owner were all present reached the client's team, which is what kept the account executives working the 423 that could close rather than the 1,366 that were merely interested.

### We reviewed the angles weekly against qualification, never against reply volume.

In a category where the buying trigger is a date, an angle can pull replies from people who find it interesting and have no obligation behind them. So angles were judged on how many of their replies carried a framework and a date, and anything producing curiosity without obligation came off inside days. Across seven months that is thirty reviews, and the qualification ratio improved in every month but one.

04

## What did not work, and what we did about it

Three of them, and you should hear them from us rather than infer them from a number we left out.

### The EU AI Act angle ran about nine months too early.

It was the angle everyone was most confident about and it produced almost nothing usable. Security and compliance leaders agreed the Act mattered, said so at length, and would not buy against it. The distinction we had missed is between a real deadline and an anticipated one. A real deadline has a named party enforcing it: an auditor with a date, a customer withholding a contract until the report exists, a procurement team that will not proceed. An anticipated deadline has only a date printed in legislation and nobody yet standing behind it. The first one produces budget. The second one produces agreement, which is a different thing and buys nothing.

The full pool of 7,418,162 companies mapped to a framework obligation, including everything the EU AI Act angle was originally aim

The full pool of 7,418,162 companies mapped to a framework obligation, including everything the EU AI Act angle was originally aimed at.

What we changed: the Act came out of the opener and moved into the follow-up steps, where it works as a reason to act on the SOC 2 or ISO 27001 obligation the company already has rather than as the reason to reply at all. That capacity went back to companies with a dated audit in front of them, which took the workable pool to 3,225,288.

The same market after companies with no dated obligation were removed, 3,225,288 of them.

### The personalisation token pulled the wrong framework for about a third of the list.

The framework field was populated from public evidence, and the logic that filled it preferred the most recently detected signal rather than the obligation the company was actually working toward. So companies that already held a current SOC 2 report, and had a page on their own site saying so, were sent an opener offering to help them get SOC 2. It is the worst possible error in this category, because it proves in one line that nobody looked.

What we changed: the reply audit caught it. Positive replies were tracked by framework against the framework named in the opener, and one segment came back with a mismatch rate far above the rest. That segment was pulled, the field was rebuilt to prefer the next obligation in the cycle rather than the most recent signal, and every affected record was reverified against its trust page before it was loaded again. The mismatch rate afterwards ran under a percent.

### Unsubscribes were handled by hand for longer than they should have been.

At the start the volume made manual handling look reasonable, and each request was actioned by a person reading the inbox. On a programme moving toward 4,777,317 sends that stopped being possible well before anyone admitted it, and some requests were actioned days after they arrived rather than on the same day. That is the client's obligation and it was ours to protect.

What we changed: suppression was automated across the whole estate, so a request removes the contact and every other address at that company from every sequence within the hour. The backlog was cleared and audited against the reply logs to confirm nothing had been missed. It should have been built that way in week one and there is no defence for the fact that it was not.

Nothing running at this volume runs clean, and a case study showing none of this has had the section deleted rather than earned. These three are the corrections most likely to recur on your engagement.

05

## The six angles we test, in every market

Everything above describes what the programme settled into. It is worth saying how it got there, because none of it was decided in advance. Which message a market answers is not something anyone reasons out at the whiteboard, so six variations of the opener launched together and the reply data settled it. These six travel across sectors because each rests on a different reason a person answers a stranger rather than on anything about compliance software.

06

## 1. The benchmark

Show them where they sit against companies like them on something they already care about. It works because a comparison is not a claim, so there is nothing to argue with, and a compliance lead who is behind the median wants to know by how much.

Series C software companies your size are averaging eleven weeks from kickoff to a clean SOC 2 Type II. We can tell you where you would land against that.

07

## 2. The short window

Name the amount of time they have left before the thing they are obliged to do becomes urgent. Only usable when the timing is genuinely inferable, because a wrong date does more damage than no date at all.

Your ISO 27001 surveillance audit falls due inside the next quarter. Evidence collection for it starts now or it starts in a panic.

08

## 3. The teardown

Hand them a specific read on something of theirs. Expensive to produce, so it goes only to accounts worth the time, and close to impossible to ignore once it lands in front of the person who owns the gap.

We went through your trust page against the ISO 27001 control set. Four items are undocumented and two of them are the ones auditors open with.

09

## 4. Value first

Open with something usable whether or not they ever answer. It costs the sender the work up front and buys the only kind of goodwill a stranger can extend.

We keep a current mapping of overlapping controls between SOC 2 and ISO 27001. It removes most of the duplicate evidence work. Sending it over.

10

## 5. The direct pitch

Say what you sell, what it costs and what it removes, in one pass. Suits markets where the buyer is busy, technical and would rather be told than warmed up.

Continuous evidence collection for SOC 2 and ISO 27001, priced per framework per year. It replaces the spreadsheet and the fortnight before the audit.

11

## 6. The partnership

Frame it as the two organisations working the problem together rather than a purchase. Carries markets where the buyer expects to be handed a tool and abandoned with it.

We work the first audit cycle alongside your team rather than handing over a dashboard. By the second one you are running it without us.

12

## How we use them

That is the mechanism behind the sections above. All six go out together across a split list from week one. Within a few weeks the qualification data has named the one or two the market wants, and the rest come off before they consume any more contacts. Which one wins here was genuinely open until the numbers arrived, and the benchmark angle beating the teardown was not what anyone expected going in. The same six port to LinkedIn with tighter wording and identical logic underneath.

13

## Why this works for compliance automation specifically

The platforms in this category arrive with the same complaint. The product demonstrates well, the buyer agrees with the premise immediately, and the deal still does not happen, because agreement and budget are separated by an audit date nobody can see from outside. Inbound catches the companies whose date has already arrived and they are the ones who found three competitors on the same afternoon.

Three things make this market unusually suited to outbound:

- The obligation is contractual. Somebody is refusing to sign until the report exists. That is a harder buying reason than a preference, and it means the conversation starts from a problem the buyer has already accepted.

- The date is partly visible from outside. Trust pages, customer requirements, funding rounds and a first security hire all put a rough position in the cycle on a company months before it starts shopping, which is what makes the timing addressable at all.

- The contract renews. At an average of $41,918 a year per framework, a modest number of closes carries the programme and then does it again next year without anybody sending another email.

14

## Why would this work for your business?

### Possibly it would not, and establishing that now costs nothing. Read down the table.

This works ifIt probably does not if

Your buyer is obliged to hold something by a date somebody else setYour buyer adopts when it suits them and nobody is waiting on it

A contract is worth $20,000 or more a year and renewsThe contract is one-off and worth a few thousand

There are hundreds of thousands of companies who could qualifyYour entire addressable market is a few hundred accounts

Something public hints at where a company sits in its cycleNothing outside the company reveals timing of any kind

You can wait seven months for the pipeline to compoundYou need signed contracts inside the first quarter

Landing on the left of that table means the method carries over, because there was nothing exceptional about this client. A compliance platform with a good product, a partner channel that introduced it to whoever the partner happened to know, and no way at all of being in front of a company in the specific week its audit became real. What produced the result was process, and process does not change for you.

15

## One more thing worth understanding

Compliance software sells on a deadline and nothing else, and every uncomfortable number in this document follows from that single fact.

The reply rate here was 0.3%. That is low and we are printing it rather than converting it into something friendlier. The reason is not the copy. At any given moment only a small slice of any market is inside a live audit window, and everybody else physically cannot buy this month no matter how well the email is written. A company eight months from its next surveillance audit reads a perfectly good opener and does nothing, correctly. No angle, no research line and no amount of rewriting moves a person whose date has not arrived.

Which is why the programme is built as continuous presence against a very large pool rather than as a campaign against a small one. 2,773,748 companies were contacted so that the client would be in front of each one during the weeks that company's deadline turned real. Two other figures come from the same place. 667,856 leads, 24.1% of the total, had finished all four steps when the window closed, because 2,554,381 of the contacts were loaded late and were still mid-sequence. And 4,777,317 sends across 2,773,748 contacts averages 1.7 touches each, which is what a four-step sequence looks like when most of the list has not reached the end of it. The bounce rate finished at 3.2%, above where we build to, and a pool of this size cannot be verified to perfection, because it decays faster than any verifier can re-check it.

So read the 0.3% as a timing artefact rather than a copy problem. That is the honest reading, and the number that matters sits next to it: 15.4% of the replies were positive and 105 of them became contracts. In a market where the buying window is narrow and moves company by company, the job is to be there when it opens, and being there at that scale looks exactly like this.

16

## Before and after

Before After seven months

New business on the book$1,299,458 $4,401,390

Where accounts came fromPartner referrals and unsteered self-serve trials A continuous programme against 2,773,748 companies

Accounts closed in the period31 105

Qualified pipeline open at the endNothing tracked as a pipeline 423 opportunities worth $13,705,200

Visibility into a company's audit timingNone until the company got in touch Segmented by framework and position in the cycle

17

## If you want to know whether your market has this in it

A short call settles it. Tell us which companies you want on contract, which framework they buy against and what one is worth across a year. We come back with how many carry a real obligation, what conversation volume is realistic against that number, and a direct answer on whether the channel suits you.

If the answer is that it does not, you will hear it on that call. Neither of us gains from discovering it in month four.

## Want to know whether your market has this in it?

The first conversation is short. You tell us who your buyers are and what one is worth to you. We tell you how many we can actually reach, what the meeting volume looks like, and whether outbound is the right lever for you at all.

If we think it is not, we will say so.

Book a consultation call

→

## Read another one

[Corporate Travel Management](https://stonehaven.capital/showcase/corporate-travel-management/)[How we moved 24 corporate travel programmes onto a client's book in six months, worth $2,108,280 in annual management fee.](https://stonehaven.capital/showcase/corporate-travel-management/)[Data Center Commissioning](https://stonehaven.capital/showcase/data-center-commissioning/)[How we closed $8,309,795 of commissioning and critical-facilities work for a data center commissioning firm in nine months.](https://stonehaven.capital/showcase/data-center-commissioning/)[All case studies](https://stonehaven.capital/case-studies/)
