All customer stories
How Diligent Got SOC 2 Without Slowing Down, and Why the Pentest Was the Best Part
Diligent sells compliance automation, then had to prove its own. How a YC fintech passed SOC 2 without slowing down, and why the pen test was the best part.
3x
Lorem Ipsum
5x
Lorem Ipsum
120 hours
Lorem Ipsum

Ahmed Gaber
Co-Founder & CTO, Diligent
AI agents for KYC/AML operations. Leading fintechs and banks use Diligent AI agents to automate their risk and compliance workflows
Frameworks
SOC 2
Already held
ISO 27001
Industry
Financial crime compliance (AML)
Company Size
Growth
Backing
Y Combinator, $3M raised
Favourite part
The penetration test
What Diligent does
Diligent AI builds autonomous agent workflows for financial crime compliance. The product enhances AML ops teams' capabilities by automating reasoning-heavy work: the due diligence and name screening workflows that financial institutions run every day, at volumes no analyst team can keep pace with by hand.
Diligent has raised $3M, is YC-backed, and was founded by Edoardo Maschio (CEO) and Ahmed Gaber (CTO) alongside a superstar team drawn from Meta, Amazon, Billie, Citi and BCG, all of whom are ex-founders or part of founding teams.
There's an irony here Ahmed knows well: Diligent sells compliance automation and still had to go through its own compliance journey like everyone else.
SOC 2 Compliance for Startups: The Problem was Never the Security
Diligent's customers hand over some of the most sensitive data in fintech, such as transaction records and customer identities. Security was built into the product from day one. That was never the problem.
The problem was proving it. This is the shape SOC 2 compliance for startups almost always takes. The engineering is rarely the blocker. The blocker is that a buyer's security team has no way to verify any of it, and no reason to take a young company's word. As Diligent grew, prospects started requiring evidence of security posture before deals could progress. Infosec questionnaires began arriving during trials, and each one became a bottleneck between interest and signature.
Having good security and being able to prove you have good security are two different problems.
SOC 2 for Fintech: Banks Don't Take Your Word for It
SOC 2 compliance in fintech carries a weight it doesn't carry elsewhere. When the buyer is a regulated institution, vendor review isn't a formality handled by a procurement inbox. It's run by people whose own regulators will ask them what diligence they performed, and the answer has to be a document, not a conversation.
Banks don't take your word for it. They need a report.
Why Oneleet
Ahmed did what founders do: asked around fintech founder groups for recommendations.
He chose Oneleet for a specific reason: The team still genuinely engages. "Legacy compliance platforms got too automated," as he put it. "I wanted to work with people who actually try to help."
SOC 2 Readiness When You Already Hold ISO 27001
Diligent had been through certification before. The team already held ISO 27001, so they knew what a compliance process could cost in time and attention. That prior work also changed what SOC 2 readiness actually looked like for them: Much of the control environment an auditor wants to see was already standing, and the exercise became one of evidencing it rather than building it. (Weighing the two frameworks yourself?
SOC 2 with Oneleet was significantly easier. The team barely felt the impact beyond completing security training.
Does SOC 2 Require Penetration Testing?
SOC 2 doesn’t require pentesting in the strict sense. The AICPA's Trust Services Criteria never names a penetration test as a required control. In practice, most auditors expect one as evidence that a company monitors and evaluates its own security, and most enterprise buyers ask to see it regardless of what the auditor accepted. So the honest answer is that SOC 2 rarely requires a pentest on paper but almost always requires one in the room.SOC 2 Penetration Testing That Found Real Problems
Then came the part Ahmed didn't expect to like: the penetration test, performed by Oneleet's in-house security team.
This is where SOC 2 penetration testing usually disappoints. Outsourced to the cheapest available vendor, it produces a clean PDF, a scanner's output lightly reworded, and nothing a team would act on.
Diligent's pentest with Oneleet went the other way. It delivered findings that made the product genuinely more secure: real security work, not a checkbox. It's the part Ahmed says he'd pay for on its own. Diligent now runs it annually.
The Results: Security Questionnaires That No Longer Stall Deals
SOC 2 changed the shape of Diligent's sales conversations. Security questionnaires that used to stall trials now get answered quickly, backed by an audited report rather than assurances.
The bottleneck between interest and signature is simply gone, and the engineering team is no longer pulled out of the roadmap to answer it.
For a company asking banks to trust it with regulated workflows, that proof is table stakes, and now it's handled.
What's Next
Diligent is constantly expanding its capability to automate compliance workflows and procedures, with new flows going live rapidly. As regulatory expectations on customers keep rising, Diligent's own security posture scales with them, maintained continuously through Oneleet rather than rebuilt every audit cycle.

