Summary
Security-first compliance platform for SOC 2, ISO 27001, and related frameworks, combining automation with human security expertise.
Description
Oneleet appears to operate as a hybrid security compliance company: a productized platform for compliance management plus service-led security expertise. The company’s website explicitly claims support for SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, CIS IG1, EU DORA, NIST 800-171, and custom frameworks, with features including cross-framework mapping, real-time gap monitoring, unified control dashboards, access reviews, risk management, vendor management, trust center, and employee portal. The Y Combinator page adds that the platform includes code security scanning, attack-surface management, penetration testing, vCISO services, MDM, and continuous monitoring. Public pricing is quote-based only. Public evidence indicates a Series A venture-backed private company founded in 2022 and based in Amsterdam, with LinkedIn also showing Wilmington, Delaware. Overall, it is best classified as a direct competitor to compliance automation vendors and a related, lower-probability adjacent monitor for AI governance or quality management buyers rather than a direct competitor in conversational AI or contact-center AI.
Positioning
Oneleet appears positioned as a productized compliance platform with meaningful service-led security and advisory components. The strongest validated overlap is in enterprise security compliance, trust management, and regulated workflows rather than in conversational AI, contact-center AI, or AI quality management. It is best treated as a direct competitor to compliance automation vendors and an adjacent competitor to broader AI governance buyers only where compliance, auditability, and security posture are central.
Key facts
- HQ location
- Amsterdam, Netherlands; LinkedIn also lists Wilmington, Delaware, United States.
- Founded
- 2022
- Employee range
- 51-200 (Y Combinator lists team size 65; LinkedIn snippet indicates 11-200 employees.)
- Funding stage
- Series A
- Company type
- Private
- Pricing model
- Custom Quote (Book-a-demo, custom quote pricing; no public price list found.)
- Last updated
- —
Financials
- Revenue estimate
- Unknown
- Valuation estimate
- Unknown
- Investments
- Public evidence indicates a $33M Series A announced in 2025, with third-party coverage and Y Combinator references pointing to Dawn Capital and other investors. Exact valuation and full cap table are not publicly verified in the sources reviewed.
Relationships
- Target customers
- Fast-growing SaaS companies, startups, SMBs, and enterprise buyers seeking compliance automation and security support.
- Key competitors
- Vanta, Drata, Secureframe, Sprinto, Hyperproof, AuditBoard, and compliance/security consulting firms.
- Known customers
- Public site references thousands of companies and named testimonial examples such as GovernGPT, LayerUp, AviaryAI, Sero, AccessOwl, and Elyos; no independently verified customer list was found.
Classification (raw research text)
- Core focus
- Security-first compliance platform for audit readiness, control management, security workflows, and trust center operations.
- Core industry
- Cybersecurity compliance and security governance.
- Core category
- Compliance platform / GRC software.
Shown verbatim from the research spreadsheet — deriving structured industry tags from this text is a future phase.
Segments, Industries & Certifications
- Segments
- Industries
- Certifications