Openlane
Background

We're building a security and
compliance platform that is simple,
transparent, and open to everyone.

Our Story
As engineering and operations leaders, we've repeatedly felt the pain of underinvestment in tools, processes, and automation — especially when it comes to security and compliance. Building security and compliance programs across companies and industries taught us that treating compliance as a seasonal effort leads to rushed tests, last-minute evidence gathering, and crossed fingers during audits. There is a better way.
That's why we built Openlane.
We built Openlane for growing companies that want a compliance program without the spreadsheets and guesswork. We believe security and compliance should be accessible to any team, and that the work behind them should be open to inspection, from the code we publish to the proof you share with customers.

Our ethos

Be Additive.
A rising tide lifts all boats. We create an environment that encourages and inspires growth, both for individuals and for the open source communities as a whole.
Be Hungry.
Builders don't wait. When we see a problem, we don't expect someone else to fix it or tell us what to do. Instead, we take initiative, find creative ways around it, and send a pull request to solve it.
Be Honest.
We share our context with transparency and have conversations in the open. We prefer to be intellectually honest instead of sugarcoating the truth to avoid potential conflict.

Meet the team

The Openlane team at an escape room
Kelsey Waters
Kelsey Waters
Chief Executive Officer & Co-founder

I have spent my entire career in leadership, helping organizations build world-class operations and security teams. From my early days

Sarah Funkhouser
Sarah Funkhouser
Head of Engineering & Co-founder

I've spent most of my career building and improving tools for other engineers. I've always been drawn to the work behind the work: the

Matt Anderson
Matt Anderson
Chief Technology Officer & Co-founder

In every job I've had, I've had to touch compliance in one way or another — my first exposure to SOC 2 was in ~2011 where we wanted our