SOC 2 compliance automation platform bundled with in-house penetration testing and vCISO services Β· verified
Oneleet
Oneleet bundles its own in-house penetration testing (delivered by Oneleet's own NATO-based, OSCP/OSCE/OSWE-certified testers per its own documentation, not a referred-out third party) with its compliance automation and a vCISO offering.
The actual SOC 2 attestation is still issued by an independent partner CPA firm chosen and vetted by Oneleet, which is the mechanism that keeps the audit opinion independent even though the platform, the pentest, and the security guidance all come from the same vendor; buyers weighing independence should confirm the specific CPA firm assigned to their engagement. Genuine limitation: pricing is quote-only with no published number and third-party cost estimates vary widely (roughly $8K-$60K/year depending on source), and multiple independent reviews describe the bundled pricing as expensive relative to unbundled alternatives for teams that do not need the pentest or vCISO components.
Desk research against public sources. Every figure below carries its source and the date we retrieved it.
What Oneleet does.
Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.
| Capability | Status | Evidence |
|---|---|---|
| Automated evidence collection | Yes | Vendor's own site states 'Automated Monitoring and Evidence Collection' as a core platform feature; exact polling cadence is not published. Source |
| Auditor workspace | Partial | Vendor states it 'works with independent 3rd party auditors to verify your security & compliance controls,' confirming an audit-coordination workflow, but no source confirms a dedicated scoped auditor view/evidence-request workspace inside the product. Source |
| Trust center | Yes | Vendor's own page: 'Prove your security with a real-time trust page. Show customers a live feed of your security controls.' Source |
| Security questionnaire answering | Yes | Vendor's own homepage: 'AI reads the questionnaire, drafts answers from your existing docs and previous responses. You review, adjust, send.' Source |
| Enterprise admin (SSO, SCIM, RBAC) | Partial | RBAC is documented directly by the vendor. SSO and SCIM support were not confirmed in any source found; recorded as partial rather than yes. Source |
| SCIM 2.0 provisioning | Not established | Oneleet's own docs list more than twenty integrations and a role-based access-control page, and none of them is an SSO or SCIM provider for logging into Oneleet itself. Absence from a list that detailed is suggestive but is not a vendor statement of absence. |
| Continuous control testing | Yes | Vendor claims automated, ongoing monitoring and evidence collection rather than a one-time pull; exact test frequency/cadence is not published. Source |
| Native multi-framework support | Partial | Vendor's own homepage: 'One control maps to all frameworks. Getting SOC 2 means you're 70% done for ISO 27001' - a crosswalk model off a shared control set, not fully independent native frameworks. Source |
3 frameworks, and how well each is established.
A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.
| Framework | Evidence | Note |
|---|---|---|
| SOC 2 | Vendor-claimed | Vendor's own frameworks page lists SOC 2 as the starting point of its compliance program, alongside ISO 27001, HIPAA, PCI DSS, GDPR, CIS IG1, NIST 800-171, and EU DORA. Source |
| ISO 27001 | Vendor-claimed | Vendor claims SOC 2 completion gives roughly 70% readiness toward ISO 27001 under its shared-control model. Source |
| PCI DSS | Vendor-claimed | Recorded during the PCI QSA verification pass; the vendor markets PCI DSS support but is not on the PCI SSC QSA company list. Source |
Oneleet does not publish a price.
Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.
- Disclosure model
- Quote-based (reported $8Kβ$60K/yr)
- Observed range (reported)
- USD 8,000β60,000 / year
- Basis
- Estimate, 2026-07-24
Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.
Who actually issues the report.
Oneleet does not issue SOC 2 reports itself and is not a CPA firm. Its own blog states it vets and coordinates a network of partner CPA firms who perform and sign the actual attestation: 'Oneleet has scoured the globe to find some of the best auditors out there, who are not only accredited CPAs qualified to perform a SOC 2 audit by the AICPA, but actually understand the technical security evidence.' The penetration test, however, is delivered by Oneleet's own in-house team, not a subcontracted third party.
Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.
Who Oneleet is for, and who it is not.
Good fit
A pre-Series-B startup pursuing its first SOC 2 (or ISO 27001) report that values a hands-on, security-first vendor which also runs its penetration test, over the widest possible integration catalog or parallel multi-framework rollout.
Poor fit
A company that wants the broadest connector catalog or needs to run multiple frameworks in parallel from day one. Oneleet's own docs list roughly two dozen native integrations, well below larger rivals' published counts (for comparison, Vanta publishes 400+), and reviewers describe its framework rollout as sequential (SOC 2 first, additional frameworks after) rather than parallel.
Typical buyer: Early-stage, security-conscious startups (notably in the YC network) that want compliance automation, penetration testing, and light vCISO guidance bundled from one vendor rather than assembled from separate providers..
Where every figure on this page came from.
5 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.
- Penetration tests are delivered by Oneleet's own in-house team of OSCP/OSCE/OSWE-certified professionals, not a subcontracted third party. https://docs.oneleet.com/penetration-testing/ptaas
- Oneleet raised a $33M Series A led by Dawn Capital, announced October 2, 2025, with Y Combinator, Frank Slootman, and Arash Ferdowsi participating. https://siliconangle.com/2025/10/02/oneleet-raises-33-million-deliver-compliance-security
- Oneleet states it coordinates with vetted, AICPA-accredited partner CPA firms who perform and sign SOC 2 reports; Oneleet itself does not issue the attestation. https://www.oneleet.com/blog/soc-2-auditor-certifications-does-it-matter-who-does-your-soc-2-report
- 4.9/5 average rating across 138 verified reviews (accessed via search snippet; direct crawl was blocked by G2's bot protection). https://www.g2.com/sellers/oneleet
- Founded 2022 (YC S22) by Bryan Onel, Ora Onel, and Erik Vogelzang; describes itself as combining automation, penetration testing, audit support, and continuous monitoring. https://www.ycombinator.com/companies/oneleet
β All SOC 2 compliance software Β· Oneleet review Β· How we verify
Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.
1 fact on this page we could not establish.
Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Oneleet, send us the sources and we will fill them.
Verification is free and always will be. It does not change where Oneleet appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.