Full-stack compliance and security platform for mid-market SaaS
Oneleet bundles compliance automation, code scanning, penetration testing, and vCISO services into a single platform aimed at mid-market companies building security programs from scratch. The hiring composition—28 security roles, 12 marketing, 4 engineering—signals a services-led GTM where hands-on security expertise and compliance advisory drive customer acquisition, not pure product. Active projects around community building and custom presentations suggest the company is investing heavily in thought leadership and direct customer relationships to differentiate in a fragmented compliance market.
Oneleet provides compliance and security infrastructure for SaaS companies pursuing SOC 2, ISO 27001, GDPR, HIPAA, and related certifications. The platform combines automated evidence collection, code security scanning, attack surface discovery, penetration testing (OSCE/OSWE certified), access reviews, and on-demand vCISO advisory. Founded in 2022, the company operates across the US and Europe, with headcount between 51–200 employees. Customers include mid-market companies that need structured security programs but lack full-time security leadership or mature DevSecOps practices.
Oneleet runs on AWS, Azure, and GCP; uses Kubernetes and Docker for orchestration; Go, JavaScript, Python, and React for application code; and integrates HubSpot for CRM. Analytics and reporting flow through BigQuery, Looker Studio, and Google Analytics 4.
Oneleet provides evidence management and audit support for SOC 2, ISO 27001, HIPAA, GDPR, EU DORA, and CIS IG1. The platform also includes penetration testing and access reviews to strengthen overall security posture.
Other companies in the same industry, closest in size