A governance vendor bets on an operator, not a researcher
Datamaran, an AI-powered risk and governance software provider headquartered in London and New York with additional offices in Leeuwarden, Netherlands, and Valencia, Spain, announced on September 4 that Bert Sinnema would join as Chief Technology Officer. CEO Marjella Lecourt-Alma explained the choice in terms that prioritize execution over pedigree: "Bert has spent his career building engineering organizations from the ground up and scaling them through demanding environments," adding that his "founder mindset" fit the company's next phase.
That framing is notable in a category where many vendors lead their CTO announcements with academic credentials or AI research backgrounds. Datamaran instead chose someone whose entire career has been spent shipping and scaling security and compliance software inside companies that had to survive regulatory scrutiny while growing fast, which is precisely the operating environment a governance platform vendor needs its own engineering leadership to understand firsthand. Datamaran's own platform helps organizations track and interpret evolving regulatory requirements, which means the company is effectively hiring for its engineering leadership the same operational discipline it sells to customers.
The Eye Security chapter is the most relevant credential
Sinnema spent his most recent stretch as VP of Engineering at Eye Security, which the announcement describes as Europe's fastest-growing cybersecurity firm. During his tenure, he scaled the engineering team threefold and contributed directly to the company closing a 60 million euro Series C round, the kind of growth-stage scaling that stress-tests engineering leadership far more than steady-state maintenance work does. Tripling headcount without breaking delivery velocity or code quality is one of the harder operational feats in software, and investors backing a 60 million euro round typically demand exactly that kind of proof before writing the check.
Before that, he served as Director of Engineering at HackerOne, the ethical hacking platform that itself sits at the center of how enterprises validate security claims made by their software vendors. Having built engineering culture inside a company whose entire business model depends on finding flaws in other people's software gives Sinnema a rare, adversarial vantage point on what actually makes governance software trustworthy rather than merely compliant on paper. That vantage point is unusually well suited to a governance vendor, since it means the person now responsible for Datamaran's platform has spent years watching how skilled researchers break systems that looked airtight on a compliance checklist.
A founder's instinct for the hardest problems
Sinnema also founded SmartLockr, a secure communications startup he bootstrapped and expanded across three countries before it went through Microsoft's Ventures Accelerator program in Berlin. Founder experience of that kind rarely shows up on a typical enterprise CTO resume, and it explains the specific language he used to describe his own priorities: "I like to operate at the intersection of product engineering leadership and AI, where the hardest problems live, and the highest-leverage decisions get made." Bootstrapping a company across three countries also means he has personally dealt with three different regulatory regimes around secure communications, a hands-on education few hired engineering leaders ever get.
That sentence is a useful filter for any buyer evaluating vendor leadership. Sinnema is describing a preference for hard, ambiguous problems over polished, well-scoped ones, which is exactly the posture a regulatory risk platform needs from its engineering chief given how quickly AI governance requirements are shifting across jurisdictions this year. A CTO comfortable operating without a fully scoped spec is better equipped to keep a compliance product current as legislation changes mid-quarter, rather than shipping controls built for rules that expired months earlier.
Why AI governance software needs execution-first leadership
AI governance and regulatory risk software occupies an unusual position in the enterprise stack. It has to interpret fast-moving, often ambiguous regulatory language and translate it into concrete controls that hold up under an actual audit, not just a sales demo. A CTO whose background is entirely academic AI research may understand the modeling problem well but has rarely been tested on whether a compliance control actually survives contact with a regulator or an enterprise procurement team's own security review.
Sinnema's background inverts that risk. He has already spent his career on the delivery side of exactly this problem, first inside a bootstrapped compliance-adjacent startup, then inside two companies whose entire value proposition depended on security and trust claims standing up to outside scrutiny. That is a closer match to what Datamaran's own customers need from the product than a research-heavy hire would have been. Customers buying governance software are not buying a model, they are buying a promise that the vendor's controls will still be accurate the next time a regulator changes the definition of compliant.
What CIOs evaluating governance vendors should watch for
If your organization is shopping for AI governance, regulatory monitoring, or risk management software, vendor leadership hires like this one are a legitimate part of your due diligence, not a footnote. Ask specifically how the CTO's prior experience maps to the regulatory environments your industry actually operates in, and press for concrete examples of controls they have shipped under real audit pressure rather than in a lab setting. A vendor's engineering leadership bio should tell you almost as much about product reliability as its published feature list does.
The broader trend worth tracking is that governance and compliance software vendors are increasingly recruiting engineering leadership from adjacent security and compliance companies rather than from pure AI research labs. That shift should reassure buyers who have grown skeptical of AI governance tools built by teams with strong research credentials but thin experience actually operating inside a regulated environment themselves. Expect more vendors in this category to follow Datamaran's lead over the next several quarters as procurement teams get sharper about asking these questions before signing a contract.



