Logo Menu

SOC 2 compliance automation platform bundled with in-house penetration testing and vCISO services Β· verified

Oneleet

Oneleet bundles its own in-house penetration testing (delivered by Oneleet's own NATO-based, OSCP/OSCE/OSWE-certified testers per its own documentation, not a referred-out third party) with its compliance automation and a vCISO offering.

The actual SOC 2 attestation is still issued by an independent partner CPA firm chosen and vetted by Oneleet, which is the mechanism that keeps the audit opinion independent even though the platform, the pentest, and the security guidance all come from the same vendor; buyers weighing independence should confirm the specific CPA firm assigned to their engagement. Genuine limitation: pricing is quote-only with no published number and third-party cost estimates vary widely (roughly $8K-$60K/year depending on source), and multiple independent reviews describe the bundled pricing as expensive relative to unbundled alternatives for teams that do not need the pentest or vCISO components.

Desk research against public sources. Every figure below carries its source and the date we retrieved it.

Capabilities

What Oneleet does.

Seven capabilities, graded the same way for every platform in the directory. "Not established" means we looked and could not confirm it, not that the feature is missing.

CapabilityStatusEvidence
Automated evidence collection Yes Vendor's own site states 'Automated Monitoring and Evidence Collection' as a core platform feature; exact polling cadence is not published. Source
Auditor workspace Partial Vendor states it 'works with independent 3rd party auditors to verify your security & compliance controls,' confirming an audit-coordination workflow, but no source confirms a dedicated scoped auditor view/evidence-request workspace inside the product. Source
Trust center Yes Vendor's own page: 'Prove your security with a real-time trust page. Show customers a live feed of your security controls.' Source
Security questionnaire answering Yes Vendor's own homepage: 'AI reads the questionnaire, drafts answers from your existing docs and previous responses. You review, adjust, send.' Source
Enterprise admin (SSO, SCIM, RBAC) Partial RBAC is documented directly by the vendor. SSO and SCIM support were not confirmed in any source found; recorded as partial rather than yes. Source
SCIM 2.0 provisioning Not established Oneleet's own docs list more than twenty integrations and a role-based access-control page, and none of them is an SSO or SCIM provider for logging into Oneleet itself. Absence from a list that detailed is suggestive but is not a vendor statement of absence.
Continuous control testing Yes Vendor claims automated, ongoing monitoring and evidence collection rather than a one-time pull; exact test frequency/cadence is not published. Source
Native multi-framework support Partial Vendor's own homepage: 'One control maps to all frameworks. Getting SOC 2 means you're 70% done for ISO 27001' - a crosswalk model off a shared control set, not fully independent native frameworks. Source
Frameworks

3 frameworks, and how well each is established.

A framework on a marketing page is a vendor claim, not a confirmed capability. We grade the difference rather than repeating the list.

FrameworkEvidenceNote
SOC 2 Vendor-claimed Vendor's own frameworks page lists SOC 2 as the starting point of its compliance program, alongside ISO 27001, HIPAA, PCI DSS, GDPR, CIS IG1, NIST 800-171, and EU DORA. Source
ISO 27001 Vendor-claimed Vendor claims SOC 2 completion gives roughly 70% readiness toward ISO 27001 under its shared-control model. Source
PCI DSS Vendor-claimed Recorded during the PCI QSA verification pass; the vendor markets PCI DSS support but is not on the PCI SSC QSA company list. Source
Pricing

Oneleet does not publish a price.

Getting a number requires a sales conversation. Anything below comes from reported quotes or marketplace listings, and is labeled as such.

Disclosure model
Quote-based (reported $8K–$60K/yr)
Observed range (reported)
USD 8,000–60,000 / year
Basis
Estimate, 2026-07-24

Auditor fees are separate from all of these. See the SOC 2 audit cost guide for what the audit itself runs.

Auditor handoff

Who actually issues the report.

Oneleet does not issue SOC 2 reports itself and is not a CPA firm. Its own blog states it vets and coordinates a network of partner CPA firms who perform and sign the actual attestation: 'Oneleet has scoured the globe to find some of the best auditors out there, who are not only accredited CPAs qualified to perform a SOC 2 audit by the AICPA, but actually understand the technical security evidence.' The penetration test, however, is delivered by Oneleet's own in-house team, not a subcontracted third party.

Software prepares you for the audit; a licensed CPA firm performs it and issues the report. If you have not picked a firm yet, we list independent SOC 2 auditors separately, and we are not one of them.

Fit

Who Oneleet is for, and who it is not.

Good fit

A pre-Series-B startup pursuing its first SOC 2 (or ISO 27001) report that values a hands-on, security-first vendor which also runs its penetration test, over the widest possible integration catalog or parallel multi-framework rollout.

Poor fit

A company that wants the broadest connector catalog or needs to run multiple frameworks in parallel from day one. Oneleet's own docs list roughly two dozen native integrations, well below larger rivals' published counts (for comparison, Vanta publishes 400+), and reviewers describe its framework rollout as sequential (SOC 2 first, additional frameworks after) rather than parallel.

Typical buyer: Early-stage, security-conscious startups (notably in the YC network) that want compliance automation, penetration testing, and light vCISO guidance bundled from one vendor rather than assembled from separate providers..

Source ledger

Where every figure on this page came from.

5 sources, each with what it establishes and when we read it. If a claim here is out of date, this is the list that tells you which one to re-check.

← All SOC 2 compliance software Β· Oneleet review Β· How we verify

Some links to compliance platforms on this page are affiliate links: if you sign up through one, the vendor may pay us a commission at no cost to you. It never changes our ranking, our review, or which platform we recommend.

For Oneleet

1 fact on this page we could not establish.

Everything above renders with its evidence state, so a gap is visible rather than quietly filled in. If you work at Oneleet, send us the sources and we will fill them.

Verification is free and always will be. It does not change where Oneleet appears in any list on this site, what our reviews conclude, or which platform we recommend to a buyer. We only accept a correction that comes with a source we can check ourselves, and the source is published in the ledger above alongside the date.

Correct this record