Not the consultant who writes a report and leaves — the team that builds and runs it
HEM Bilişim is an IT company working across compliance, software and data protection. The "hem … hem …" construction in our name (Turkish for "both … and …") describes the work itself: we do all three together.
Why these three together
Most compliance projects get stuck in the same place. The consultant produces the inventory, writes the policy, delivers the report and leaves. What remains is a stack of documents the organisation has to operate on its own. A few months later the inventory is out of date, requests pile up in email, and nobody disposes of anything.
The problem is not that the consulting was done badly — it is that half the job is a software job. Keeping the inventory current, answering a request within the deadline, deleting data whose retention has expired: these are all things a system should do.
The third piece is data protection. You have to show that the measure written in the policy was actually taken; without access rights, log records and restore tests, a compliance certificate hangs in the air.
When these three are split across suppliers, nobody owns the whole. Everyone delivers their own piece and the gaps between them land on the organisation. We brought all three under one team and one contract.
Four principles
We speak from evidence
Instead of frightening you with penalty figures, we say what will be done and what will stand as proof. Every claim about legislation rests on an official source.
We promise what can be measured
Not "we will make you compliant", but which deliverable arrives when. The schedule is written at the start.
We build and hand over
Our aim is to leave capability behind, not dependency. Documentation and training are part of the delivery.
We apply it to ourselves
We run our products and this site under the rules we recommend to clients. We do not sell what we do not practise.
Three disciplines, one team
Rather than splitting the work across three suppliers, we keep it in one team. What follows shows how responsibility is divided inside it.
The compliance side
Inventory, document set, retention and disposal, the request process and audit readiness. The side that reads the legislation and turns it into the organisation's own work.
The software side
The side that writes what compliance cannot do by hand: keeping the inventory current, making periods actually run, producing records on their own, and integrating with existing systems.
The data security side
The side that shows the measures on paper were really taken: access rights, system records, restoring from backup and responding when a breach happens.
We do not publish individual profiles without each colleague's own consent. In a meeting we tell you by name who will be working with you.
Who we work with
Organisations of 50–500 people with KVKK and ISO 27001 obligations and no internal resource to run compliance alone, and mid-sized companies that need enterprise software.
Our sector-specific approach and references are collected on separate pages.
Frameworks and certifications
Frameworks we work with
- KVKK
- GDPR
- ISO/IEC 27001
- ISO/IEC 27701
- ISO/IEC 42001
- ISO 22301
The following are our areas of expertise; they are not certificates held by the company.
Our certifications
Our certification details will be listed here once ready to publish. We do not display a certificate we do not hold.
See where you stand in 20 minutes
The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.
Look at it yourself first
A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.
Start the compliance testLet's look together
We discuss your current state and work out which step comes first and how long it takes.
Request a conversation
