Formbricks has been open source since day one, with 10,000+ GitHub stars. So what does a penetration test add when anyone can already read the source code? Two things: Source code shows how the software was built, but doesn't prove how it behaves once it's actually deployed: how it's configured, authentication flows, what the API accepts that the docs don't mention, and how it handles edge cases. And since an open source product ships to self-hosters, a finding in Formbricks is a finding in every deployment of Formbricks. Oneleet tested the deployment on top of the repo: 20 hours across their production web app and API. Two findings, both remediated and retested before the report was finalized. Formbricks completed SOC 2 Type II in February and received their ISO 27001 certificate this month. Congrats to the team!
Oneleet
Computer and Network Security
Wilmington, DE 6,630 followers
Oneleet is the full-stack compliance platform that makes effective cybersecurity easy and painless.
About us
Oneleet is the cybersecurity platform for building real security controls, achieving compliance (SOC 2, ISO 27001, GDPR, HIPAA), and maintaining a strong security posture as you grow. Everything You Need in One Platform- Manage your entire security program from a single view. At Oneleet, we believe compliance should follow security—not the other way around. We start by building a pragmatic, effective security program tailored to your company. We provide the tools and expertise you need: • Compliance Platform. Streamline evidence collection and management for SOC 2, HIPAA, ISO 27001, GDPR, and more. Reduce audit preparation time. • Code Security Scanner. Embed security early. Identify and resolve vulnerabilities in your codebase. • Attack Surface Discovery. See your business like an attacker. Identify and monitor external-facing assets and risks. • Penetration Testing. Expert-led testing by OSCE/OSWE certified pros to find critical vulnerabilities missed by automated scans. • Access Reviews. Ensure least privilege. Stay on top user permissions across critical systems to reduce risk. • vCISO + Security Programs. Get on-demand, enterprise-grade security expertise and tailored programs without the full-time CISO cost or ramp-up time. • Trust Center. Showcase your security posture and compliance achievements to build customer confidence and speed up sales cycles. • Third-Party Audits. We streamline the auditing process for SOC 2, ISO 27001, HIPAA, and more with trusted third-party auditors. • Oneleet Agent. Enforce security policies and monitor your company’s devices. • Employee Portal. One place for security resources, training, and support to boost employee awareness. Pass vendor reviews faster, and unlock deals. Stop security from being a blocker.
- Website
-
https://www.oneleet.com/?utm_source=linkedin&utm_medium=organic&utm_campaign=traffic
External link for Oneleet
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Wilmington, DE
- Type
- Privately Held
- Founded
- 2022
- Specialties
- Information security, Cybersecurity, Penetration Testing, SOC 2, ISO 27001, Compliance, HIPAA, GDPR, EU DORA, CIS IG1, PCI DSS, NIST 800-171, CCPA, HITRUST, and 21 CFR Part 11
Locations
-
Primary
Get directions
Wilmington, DE, US
-
Get directions
Amsterdam, NL
-
Get directions
1111b S Governors Ave
STE 6771
Dover, Delaware 19904, US
Employees at Oneleet
Updates
-
Can anyone spot us?😉 Grateful to be featured on Brex's fastest-growing vendor list.
Our summer 2026 fastest-growing vendors list is out, with more than half of the vendors selling infrastructure for AI products, not the products themselves. Turns out the real AI hype isn't the app, it's what's under it.
-
-
Hydra Host is one of those companies where the more you learn about what they’re building, the more interesting it gets. They’re building critical infrastructure for the AI economy, connecting data centers and GPU capacity with companies that need it, and making bare metal compute easier to deploy, manage, and access at scale. It’s an ambitious business solving a massive problem, and exactly the kind of company we love working with. Huge congratulations to the entire Hydra Host team on completing SOC 2 Type II. It’s a pleasure helping ensure security is built into the foundation.
Achievement Unlocked 🔓 Hydra Host has officially completed its SOC 2 Type II attestation. While SOC 2 Type I independently verified that our hardened security controls protect client data, Type II verifies that protection is continuous over time, the audit that matters most to enterprise security teams. It's a reflection of the discipline our team brings to protecting your data every single day, not just at a single point in time. Huge thanks again to Oneleet for partnering with us through the entire process. Security isn't an add-on. It's built into the core of Hydra Host. #HydraHost #Oneleet #SOC2 #BareMetal #Cybersecurity
-
-
Stop wasting hours and effort on the same 200 questions. Every B2B team knows the moment a 200-question security review lands in the inbox and the deal goes quiet for two weeks. We hear it constantly. The questions barely change from one buyer to the next, but without one place to pull from, you start every questionnaire from scratch and pull your best engineers off actual work to answer them. Oneleet is the all-in-one security and compliance platform that lets you answer every questionnaire from one living, always-up-to-date source. Take Ryan Underwood at Replica Cyber. Replica sells into banks and government, so every deal comes with a long security review before anyone signs. Now Ryan simply opens the SOC 2 evidence he already prepared in Oneleet and pastes it straight in. One source. Zero repeated work.
-
-
Pumped to be working with Ram Venkataraman and the Sei AI team. They are proving AI can work inside the most regulated corners of finance, without cutting corners to get there.
A wise man once said: "Trust is hard to gain and easy to lose." 🚀 We just moved our SOC 2 program to Oneleet. It's a deliberate choice in how we approach security for the AI agents we build. We work with banks, NASDAQ-listed mortgage lenders, and servicers. Our agents handle customer conversations, run pre-underwriting checks on loan documents, and automate workflows that are traditionally time-consuming and expensive. We are increasingly bulking up the contract ACV both within and across customers. So, the bar our customers hold us to is very high, and only getting higher as AI becomes part of the operating stack inside financial institutions. A few reasons I made the move: 1. Real pentesting of the AI surface: engineers who actually pressure-test the application 2. Security as engineering - findings that come with a fix-it path 3. Team that responds on Slack like our own engineers I didn't want a vendor treating compliance as a checkbox. I wanted one that viewed compliance as a byproduct of good security. As AI becomes part of the system of record in financial services, security is one of the important moats. #AI #Fintech #Banking #MortgageTech #AIAgents #Cybersecurity
-
What does security look like when AI is grading a million+ exam papers and deciding whether students pass? Vision Marker is leading the way with a full pen test alongside their ISO 27001. Congrats Dr. James Lambert and team, amazing working with you!
When you’re marking 1,000,000+ exam items with AI, security takes on a different weight. National Ministries of Education, International awarding bodies, and FTSE 100 companies trust us with outcomes that students can rely on. The sector talks a lot about model accuracy and bias, both of which matter, but AI marking introduces a threat model that traditional assessment software did not have to consider. We recently completed a full penetration test with Oneleet alongside our ISO 27001 implementation, with focused testing of the Co-Pilot for Marking® pipeline. We’re committed to meeting the standards our customers and their students deserve. #eAssessment #EdTech #AImarking #ISO27001 #VisionMarker
-
-
First customer being the DoD is no joke... Replica Cyber builds secure, isolated environments that keep high-stakes work off the corporate network. Proud to be their compliance partner.
The tighter you lock down the corporate laptop, the more your employees rely on their personal ones. Now imagine that's your malware analyst, fraud investigator or brand team monitoring threats – some of the most important work in your company happening on devices you can't see. That's the shadow IT problem we set out to solve when we built Replica Cyber out of extensive US Intelligence Community real-world experience – and security-first from day one. What that meant for the product: ➡️ Patented zero-trust isolated environments. Full-stack isolation across OS, network, and data. Single-tenant infrastructure. Your data is your data ➡️ SOC 2 Type II with Oneleet gave us the single pane of glass to prove at the organizational level what we'd already built into the product Our first customer was the Department of Defense. Then our first big bank spent 10x internally trying to build something like Replica themselves before buying Replica at 10% of that cost. Now when a Process Unity, CyberGRX, Corl Tech, or any TPRM questionnaire hits my inbox, it's nearly copy-paste. If your teams are still working around your own security controls, we should talk. #SecureEnvironments #HighStakesWork #BCorp #ProtectLifeOnline
-
Love this. Change Agents Technologies Inc. helps fintech companies get and keep regulatory licenses - putting all the state-by-state paperwork in one place, instead of scattered across spreadsheets. Now they've got SOC 2 and a live trust center to match. Proud to be their compliance partner 🛡️
Change Agents Technologies Inc. recently achieved SOC 2 certification, and now we've launched our trust center! The trust center is where we publish our security, privacy and compliance information for our customers and the fintech industry. It reflects our steadfast commitment to prioritizing data protection, and it also reflects a great deal of hard work on our part. Many thanks to our engineering team, and to our SOC 2 compliance partner, Oneleet! Oneleet's platform helped keep our SOC 2 process smooth, and they've been valuable advisors and advocates for us throughout. Check it out: trust.changeagents.co
-
Talk to Spot helps line managers at large enterprises write up sensitive cases and routes each one to the right team automatically. Congrats to Jessica Collier, PhD, Dylan Marriott, and the entire Spot team on their second SOC 2 Type 2 with us. Grateful for the partnership. 👏
I find these kinds of posts so cringey, but I'm doing one anyway because others here can probably learn from our mistake. We lost a customer two years ago, as they were preparing for IPO. They'd been with Talk to Spot for years, but their timeline accelerated faster than anyone expected, and we didn't have SOC 2 yet. For context: Spot has evolved way beyond workplace case management. We now build AI that helps managers draft sensitive documentation about frontline workers and get it resolved fast by corporate. Everything EthicsPoint does, plus a lot more (and—dare I say it?—better). Dealing with all of that sensitive information, we always took security seriously, but that lost customer was the push to get it formalized. Anyway, we vetted several vendors; two years later, we've just wrapped our second SOC 2 Type 2 with Oneleet. So if you have logos you want to hold on to, do this sooner rather than later. As Dylan Marriott will tell you, the process gets less painful each time.
-
Teams choose Oneleet for many reasons. For dotenvx, the security layer behind billions of developer secrets, founder Scott Motte just broke down a few of his. This is the kind of partnership where customers actually understand the work, not just the tool. Excited to keep building with Scott and the team. 👏
-