Product Avatar Image

Osto

Show rating breakdown
14 reviews
  • 1 profiles
  • 4 categories
Average star rating
4.7
Serving customers since
2025
Profile Filters

All Products & Services

Profile Name

Star Rating

11
3
0
0
0

Osto Reviews

Review Filters
Profile Name
Star Rating
11
3
0
0
0
Mritunjay P.
MP
Mritunjay P.
Building Raynetics | IIT Bombay | CMU
09/22/2026
Validated Reviewer
Review source: Organic

Fast Project Starts, Rapid Delivery, and Hands-On Manual Testing

|Osto
Fast project start and delivery, manual and not AI/bot based testing.
MB
Mumin B.
09/16/2026
Validated Reviewer
Review source: Organic

Effortless Vulnerability Management with Osto

|Osto
I really appreciate how Osto presents VAPT findings clearly and helps us prioritize what actually needs our attention. The remediation tracking and retesting process is straightforward, making it easier to coordinate fixes with our development team and effectively close vulnerabilities. It's also convenient that Osto brings everything from finding to remediation tracking and retesting into a single place, helping us stay prepared for customer and compliance security reviews.
SS
Sameer S.
09/15/2026
Validated Reviewer
Review source: Organic

Comprehensive ISO 27001 Management with Osto

|Osto
Osto has made managing our ISO 27001 compliance much more straightforward. The platform gives us a clear, centralized view of our controls, evidence, risks, and overall compliance status, which makes it much easier for different teams to stay aligned without relying on scattered spreadsheets or constant follow-ups. The control tracking and evidence management features are especially useful, while the policy workflows and risk register help us keep responsibilities organized and ensure nothing important gets overlooked. Having everything in one place makes it easy to assign ownership, monitor progress, and quickly identify areas that require attention. Another thing we appreciated was how simple the initial setup was. Osto supports ISO 27001 while also bringing security, risk, and compliance workflows together on a single platform. As our security requirements continue to grow, having that centralized visibility and structure has been a significant advantage. Overall, moving to Osto has made our compliance process more organized, efficient, and easier to manage.

About

Contact

HQ Location:
San Francisco, US

Social

What is Osto?

Osto is the complete cybersecurity platform for startups. One platform that runs your full security stack, automates compliance directly from the security stack itself, delivers VAPT by OSCP-certified engineers, and answers security questionnaire in 5 minutes. Most startups today end up paying for a compliance tool (Vanta, Drata, Sprinto), a separate stack of security tools that does not connect to it (WAF, endpoint protection, ZTNA, cloud posture management), an annual VAPT firm, and weeks of engineering time burned on security questionnaires. Three or four separate budgets. Multiple systems. An auditor who cannot tell the difference between configured and operational. Osto replaces all of that. CLOUD SECURITY - Cloud Posture (CSPM): Scan AWS, Azure, GCP for misconfigs and drift - Web API Protection: Shadow API discovery, schema enforcement, malicious traffic blocking - Web App Protection: OWASP Top 10, DDoS, bot blocking, virtual patching APPLICATION SECURITY - Mobile App Scanner: Assess mobile app builds for weaknesses before release - SAST / SBOM: Static analysis and software bill of materials - Web App Scanner: Continuously scan internet-facing applications for exploitable issues - SCA (Software Composition Analysis): Detect known vulnerabilities in open-source dependencies and third-party libraries used by your application - License Compliance: Surface and track open-source licenses in your codebase to avoid legal and IP exposure NETWORK SECURITY - Domain Filtering: Block malicious domains, enforce browsing policies - ZTNA Secure Access: Zero Trust with 2FA, time-based permissions, instant blocking ENDPOINT SECURITY - App Control: Control application behavior to reduce unauthorized execution risk - Device Control: Control USB peripherals and removable media access on company devices - Disk Encryption: Protect startup devices and sensitive data at rest - Endpoint Antimalware: Real-time malware detection, ransomware prevention - File Access DLP: Protect sensitive files with access controls and data-loss prevention - Screen Lock: Enforce automatic device lock and idle-session protection - Swipe Clean: Remote wipe and cleanup actions for managed startup devices COMPLIANCE - AI Security Q&A: Pre-fill questionnaires in 5 minutes at 99% precision - Compliance Automation: Continuously mapped controls, evidence collection, and audit workflows (SOC 2, ISO 27001, HIPAA, PCI-DSS) - Security Awareness Training: Train employees continuously and keep participation evidence audit-ready AUDITS - Logs Analyzer: Centralized logs and audit-ready posture across every module ASSESSMENT - VAPT: OSCP-certified engineers, 2 weeks+ delivery, covering web applications, APIs, networks, mobile, and source code This is what we call TrulyOne: Osto's vision of one cybersecurity platform for startups, where everything you build, protect, and prove runs as a single system. Compliance evidence flows directly from the security stack, audit readiness becomes continuous rather than quarterly, and one dashboard replaces 5-7 separate vendors plus the annual VAPT firm plus manual GRC work. Built for startup founders going from first enterprise deal to Series B and beyond, where compliance is no longer optional and the cost of fragmented security tools adds up fast. Backed by PointOne Capital, GSF, and India Accelerator.

Details

Year Founded
2025
Website
osto.one