Full-stack compliance and security control platform for growing companies
Oneleet bundles compliance automation, code scanning, penetration testing, and vCISO advisory into a single platform—positioning itself against point-tool sprawl in a fragmented security market. The hiring distribution reflects a security-led org (28 in security roles) with proportional marketing and engineering support, suggesting aggressive market education and product expansion rather than sales-driven growth. Active hiring spans 24 countries across Europe, North America, and Canada, signaling distributed operations maturity unusual for a 2022 founded company.
Oneleet is a compliance and security control platform serving mid-market engineering teams building toward SOC 2, ISO 27001, GDPR, and HIPAA certification. The product spans compliance evidence collection and audit management, code security scanning, external asset discovery, penetration testing, access reviews, and on-demand vCISO services. The company operates from Wilmington, DE with a distributed workforce across North America and Europe. Founded in 2022, Oneleet positions compliance as a by-product of sound security practice, not an afterthought.
Compliance automation for SOC 2, ISO 27001, GDPR, HIPAA; code scanning; external asset discovery; penetration testing by OSCE/OSWE certified staff; access reviews; vCISO advisory; and a Trust Center for customer-facing security credentials.
AWS, GCP, Azure for cloud; Go, Python, TypeScript, JavaScript, React for development; PostgreSQL for storage; Kubernetes and Docker for orchestration; compliance frameworks including SOC2, ISO 27001, CMMC, NIST; HubSpot for operations.
Oneleet is actively hiring across 24 countries: US, Canada, UK, and 21 European nations including Portugal, Germany, Poland, Sweden, Netherlands, and others. Security roles represent the majority of current openings (28 active), with marketing (12), engineering (6), and smaller product/sales/support teams.
Other companies in the same industry, closest in size
Oneleet's technology stack, projects, and hiring signals are inferred from public hiring and company data — career pages, public listings, and company web presence — then clustered and de-duplicated. Figures are estimates that refresh over time. Read our full methodology →
This is not an official vendor or customer list. It is a technology-adoption signal inferred from public data, intended for B2B research.