Product Avatar Image

Osto

Show rating breakdown
14 reviews
  • 1 profiles
  • 4 categories
Average star rating
4.7
Serving customers since
2025
Profile Filters

All Products & Services

Profile Name

Star Rating

11
3
0
0
0

Osto Reviews

Review Filters
Profile Name
Star Rating
11
3
0
0
0
Mohit  .
M
Mohit .
09/02/2026
Validated Reviewer
Review source: Organic

Simplifies SOC 2 Compliance

|Osto
I really appreciate how Osto keeps SOC 2 requirements, security controls, and evidence organized all in one place. It provides clear visibility into what's covered and what still needs attention, which makes it much easier to track gaps, reduce manual follow-ups, and keep our compliance work on schedule. It simplifies SOC 2 compliance by reducing manual tracking, organizing evidence, and giving a clear view of compliance gaps and pending requirements. The setup is very straightforward as well, and once everything is set up, the platform is easy to use and manage.
Sandeep S.
SS
Sandeep S.
Senior Engineering Manager at Qubriux Inc
08/28/2026
Validated Reviewer
Review source: Organic

Structured Approach and Constant Support

|Osto
Their structured approach to whatever they do and constant support The support and structured approach to security compliance at Osto Technologies are on par with those offered by the biggest names in the industry, making it an excellent value-for-money choice.
Saumo P.
SP
Saumo P.
Co-Founder @ Unveild Home Spas
08/27/2026
Validated Reviewer
Review source: Organic

Thorough, Actionable VAPT Made Simple with OSTO

|Osto
We use OSTO primarily for our VAPT requirements, helping us identify and address security vulnerabilities across our applications and infrastructure. Their team makes the entire process straightforward - from scoping and testing to reviewing findings and completing remediation. We got clear visibility into identified vulnerabilities, their severity, and recommended fixes, making it easy for our team to prioritize and track remediation. One of OSTO's biggest strengths is the quality and thoroughness of their VAPT services. Their testing goes beyond simply running automated vulnerability scans, combining automated tooling with manual testing to uncover issues that could otherwise be missed. The reports are detailed and actionable, with clear explanations of each finding, its potential impact, and practical recommendations for remediation. The OSTO team has also been excellent to work with. They're highly responsive over Slack and email, quick to answer questions, and happy to provide additional context whenever our engineering team needs clarification on a finding. Once we've implemented fixes, the retesting and validation process is smooth and helps us confidently close out identified vulnerabilities. The overall engagement has been efficient and minimally disruptive to our day-to-day operations. Their team worked closely with us throughout the process and made what can otherwise be a time-consuming security exercise easy to manage. Finally, the pricing is very competitive, particularly for a small and growing team like ours. Overall, OSTO has made the VAPT process significantly simpler and has been a reliable security partner for our team.

About

Contact

HQ Location:
San Francisco, US

Social

What is Osto?

Osto is the complete cybersecurity platform for startups. One platform that runs your full security stack, automates compliance directly from the security stack itself, delivers VAPT by OSCP-certified engineers, and answers security questionnaire in 5 minutes. Most startups today end up paying for a compliance tool (Vanta, Drata, Sprinto), a separate stack of security tools that does not connect to it (WAF, endpoint protection, ZTNA, cloud posture management), an annual VAPT firm, and weeks of engineering time burned on security questionnaires. Three or four separate budgets. Multiple systems. An auditor who cannot tell the difference between configured and operational. Osto replaces all of that. CLOUD SECURITY - Cloud Posture (CSPM): Scan AWS, Azure, GCP for misconfigs and drift - Web API Protection: Shadow API discovery, schema enforcement, malicious traffic blocking - Web App Protection: OWASP Top 10, DDoS, bot blocking, virtual patching APPLICATION SECURITY - Mobile App Scanner: Assess mobile app builds for weaknesses before release - SAST / SBOM: Static analysis and software bill of materials - Web App Scanner: Continuously scan internet-facing applications for exploitable issues - SCA (Software Composition Analysis): Detect known vulnerabilities in open-source dependencies and third-party libraries used by your application - License Compliance: Surface and track open-source licenses in your codebase to avoid legal and IP exposure NETWORK SECURITY - Domain Filtering: Block malicious domains, enforce browsing policies - ZTNA Secure Access: Zero Trust with 2FA, time-based permissions, instant blocking ENDPOINT SECURITY - App Control: Control application behavior to reduce unauthorized execution risk - Device Control: Control USB peripherals and removable media access on company devices - Disk Encryption: Protect startup devices and sensitive data at rest - Endpoint Antimalware: Real-time malware detection, ransomware prevention - File Access DLP: Protect sensitive files with access controls and data-loss prevention - Screen Lock: Enforce automatic device lock and idle-session protection - Swipe Clean: Remote wipe and cleanup actions for managed startup devices COMPLIANCE - AI Security Q&A: Pre-fill questionnaires in 5 minutes at 99% precision - Compliance Automation: Continuously mapped controls, evidence collection, and audit workflows (SOC 2, ISO 27001, HIPAA, PCI-DSS) - Security Awareness Training: Train employees continuously and keep participation evidence audit-ready AUDITS - Logs Analyzer: Centralized logs and audit-ready posture across every module ASSESSMENT - VAPT: OSCP-certified engineers, 2 weeks+ delivery, covering web applications, APIs, networks, mobile, and source code This is what we call TrulyOne: Osto's vision of one cybersecurity platform for startups, where everything you build, protect, and prove runs as a single system. Compliance evidence flows directly from the security stack, audit readiness becomes continuous rather than quarterly, and one dashboard replaces 5-7 separate vendors plus the annual VAPT firm plus manual GRC work. Built for startup founders going from first enterprise deal to Series B and beyond, where compliance is no longer optional and the cost of fragmented security tools adds up fast. Backed by PointOne Capital, GSF, and India Accelerator.

Details

Year Founded
2025
Website
osto.one