Kosli
Kosli provides SDLC governance infrastructure for regulated enterprises, recording cryptographic, append-only audit trails of software changes across CI/CD pipelines, runtime environments, and infrastructure, with automated compliance evaluation, primarily serving large financial institutions and other regulated industries.
- Company typePrivate
- Founded2019
- HeadquartersOslo, Norway
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Kosli does
Kosli is an Oslo-headquartered SaaS company (founded 2019 as ComplianceDB, renamed Merkely, and rebranded to Kosli in November 2022) that sells an SDLC governance platform to regulated enterprises. The platform records cryptographic, append-only audit trails of every software change across CI/CD pipelines, runtime environments, and infrastructure, and evaluates those trails against customer-defined policies in real time. Core product modules include Evidence Vault (immutable evidence storage), Flows (process recording), Actions (policy-violation alerts), Continuous Compliance and Continuous Monitoring, and the open-source Kosli CLI plus an official Terraform Provider; newer additions include Kosli Enterprise (launched March 2025), Kosli Dedicated (single-tenant SaaS in any AWS region, September 2025), Kosli Answers (AI-driven natural language audit queries, October 2025), and Kosli Spaces (December 2025). Kosli is SOC 2 Type 2 certified and integrates with the major DevOps, ITSM, security, and feature-flag tooling.
Kosli firmographics
Firmographics- Name
- Kosli
- Legal name
- Kosli
- Website
- https://kosli.com
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Kosli provides SDLC governance infrastructure for regulated enterprises, recording cryptographic, append-only audit trails of software changes across CI/CD pipelines, runtime environments, and infrastructure, with automated compliance evaluation, primarily serving large financial institutions and other regulated industries.
- Ownership category
- akta.pro rank
Kosli industry classification
Industry- Product category
- DevOps Continuous Compliance Automation
- NAICS
- Computer Systems Design and Related Services (54151), Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- Compliance, GRC Workflow & Audit Automation Platforms (HDAEAHAL)
- akta.pro secondary industries
- IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Data Access Governance & Entitlement Management (DSPM / CIEM-for-Data) (HDADAFAG)
Keywords
Where Kosli is headquartered
LocationHeadquarters
- HQ city
- Oslo
- HQ country
- Norway
- HQ region
- Europe
Offices1 record
Markets served
Kosli business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Marketing or Sales, Operations
Revenue model
- SaaS Subscription: Subscription-based SaaS model with tiered pricing. Enterprise tier includes enhanced support for mapping GRC requirements to DevOps/CI/CD. Multi-tenant SaaS hosted on AWS with single-tenant option for demanding enterprise needs.
- Free Tier: Free tier launched November 2022 enabling teams to record, connect and search DevOps changes without credit card. Serves as customer acquisition and community-building channel.
- Professional Services: Professional services team helps enterprise customers map high-level GRC controls to atomic level of software delivery. Includes Automated Compliance Workshop and Getting Started training.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free tier for individual teams and community adoption |
| Subscription | Annual | Enterprise tier for large financial institutions |
Go-to-market motion3 records
Distribution channels4 records
Marketing channels8 records
Kosli product offering
Product offeringCore offering
Kosli provides an SDLC governance SaaS platform that records cryptographic, immutable, append-only audit trails of every software change across CI/CD pipelines, runtime environments, and infrastructure. It automates compliance evaluation and change management for regulated industries (primarily banks and financial services), replacing manual CAB approvals with evidence-based automated gates. The platform supports both multi-tenant SaaS and single-tenant (Kosli Dedicated) deployments and includes an AI-driven natural language interface (Kosli Answers) for querying governance data.
Product overview
Kosli is an SDLC Governance platform designed for AI-assisted software delivery in regulated industries. The core platform provides continuous, tamper-proof audit trails and automates compliance mapping across the software delivery lifecycle. The product portfolio consists of the core Kosli Platform with modules including Kosli Answers (AI-driven natural language interface for querying compliance data), Evidence Vault (secure immutable storage), Flows (process recording), Actions (real-time alerts), Environments and Continuous Monitoring (runtime change tracking), and Continuous Compliance (real-time compliance evaluation). Enterprise offerings include Kosli Enterprise for large financial institutions with enhanced GRC mapping support, and Kosli Dedicated for single-tenant SaaS deployments. The Kosli CLI provides command-line access while the Terraform Provider enables Infrastructure as Code management of Kosli resources. Kosli Spaces enables hierarchical data organization for large enterprise governance data.
Differentiator
Problem solved
Functional benefit
Products and services
- Kosli Platform
- Kosli Enterprise
- Kosli Dedicated
- Kosli Answers
- Kosli Spaces
- Kosli CLI
- Terraform Provider for Kosli
- Evidence Vault
- Automated Compliance Workshop
- Getting Started with Kosli Training
Quantifiable outcome
- Approval lead time reduced to milliseconds for automated approvals vs. days/weeks for manual approvals
- +2 more outcomes
Companies that use Kosli
Customer profileNamed customers7 records
Segments3 records
Ideal customer profiles4 records
Kosli technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration15 records
AI capability6 records
Feature11 records
Kosli partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core, flagship and minor.
- AdaptavistcoreStrategic partnership to help regulated enterprises automate governance for AI-driven software delivery. Adaptavist brings deep enterprise DevOps transformation expertise: assessment and strategy, DevSecOps integration, developer experience, and implementation across Atlassian, GitLab, and AWS.
- Team TopologiesflagshipStrategic partnership to accelerate compliant software delivery in regulated industries. Combines Kosli's automated governance platform with Team Topologies' organizational design approach to eliminate manual governance friction. Includes joint thought leadership, co-developed resources for enterprise technology leaders, and coordinated guidance for implementing organizational and technical patterns.
- FINOS (Fintech Open Source Foundation)flagshipKosli joined FINOS to collaborate on DevOps controls and change compliance in financial services. Co-chairs the SDLC Common Controls Working Group where major banks, auditors, and software vendors collaborate on open industry-wide standard for automated software controls. Kosli is working to establish common design patterns for automated controls, standardized change management automation approaches, and shared specifications for audit trails.
- Swiss Digital NetworkminorStrategic partnership to enhance Continuous Compliance and Verification for Swiss organizations. Combines Kosli's automated governance with SDN's digital transformation expertise to enable regulated sectors like finance and healthcare to deliver software with security, compliance, and speed.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Kosli competitors and assessment
Company assessmentBroad incumbents
- GitLab: GitLab is a broad DevSecOps platform with built-in compliance, audit, and change-management features across the SDLC. It competes with Kosli by bundling governance primitives into its much larger CI/CD and source-control platform, targeting the same regulated enterprise buyers.
- Atlassian: Atlassian's Jira, Jira Service Management, and Compass products dominate software delivery tracking and ITSM at large enterprises and provide change approval, audit, and compliance workflows that overlap with Kosli's automated SDLC governance value proposition.
- ServiceNow: ServiceNow is the dominant ITSM and GRC platform for large enterprises, including change management, audit, and compliance workflows. Kosli integrates with ServiceNow for change evidence but ServiceNow's broader governance suite competes head-on for the same regulated-customer budget.
- GitHub: GitHub Advanced Security, GitHub Actions, and supply chain security features provide native compliance, secret scanning, and audit primitives within the dominant developer platform. Kosli offers a verified GitHub Action and competes with GitHub's own expanding compliance surface.
Direct peers
- Snyk: Snyk provides developer-first security scanning integrated directly into CI/CD pipelines — Kosli has a native `kosli attest snyk` integration for vulnerability compliance, and the two compete for DevSecOps tooling budget within regulated software delivery teams.
- Sonar (SonarCloud / SonarQube): Sonar provides static code analysis and automated compliance for code quality across pipelines, overlapping with Kosli's evidence attestation capabilities. The two are complementary in deployments but compete for the same compliance-in-CI budget line at regulated enterprises.
- JFrog: JFrog Artifactory provides artifact provenance and chain-of-custody features that overlap with Kosli's Evidence Vault and Trails. Both target regulated enterprises needing tamper-proof artifact and deployment records, often as part of the same SDLC governance purchase decision.
Emerging players
- Vanta: Vanta is a leading automated compliance evidence collection platform for SOC 2, ISO 27001, HIPAA, and similar frameworks. While broader than SDLC governance, Vanta competes for the same compliance automation budget line at regulated customers and overlaps in evidence collection.
- Drata: Drata is a continuous compliance and audit automation platform — interestingly, also the vendor through which Kosli publishes its own SOC 2 Type 2 trust report. The two compete for evidence-based compliance automation spend at mid-market and enterprise regulated companies.
- Ox Security: Ox Security provides software supply chain security and SDLC posture management, addressing similar needs to Kosli's continuous compliance and runtime monitoring for development pipelines — an emerging direct competitor in the SDLC governance space.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks7 records
Key highlights7 records
Customer concentration
Kosli social profiles
Digital presenceKosli compliance and trust
Trust signalCompliance4 records
Kosli financial estimates
Financial estimateRevenue estimate
Valuation estimate
Kosli leadership team
Management profileNumber of profiles
Profiles3 records
Kosli funding detail
Funding detailFunding overview
Funding rounds3 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Kosli M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Kosli
What does Kosli do?
Kosli provides an SDLC governance SaaS platform that records cryptographic, immutable, append-only audit trails of every software change across CI/CD pipelines, runtime environments, and infrastructure. It automates compliance evaluation and change management for regulated industries (primarily banks and financial services), replacing manual CAB approvals with evidence-based automated gates. The platform supports both multi-tenant SaaS and single-tenant (Kosli Dedicated) deployments and includes an AI-driven natural language interface (Kosli Answers) for querying governance data.
Is Kosli a public or private company?
Kosli is a private company. It is classified as venture growth investor backed and is currently operating.
When was Kosli founded?
Kosli was founded in 2019. It employs 11 to 50 people.
Where is Kosli based?
Kosli is headquartered in Oslo, Norway, in the Europe region.
How does Kosli make money?
Three revenue lines are on record. SaaS Subscription is the primary driver. The others are free Tier and professional Services.
Who are Kosli's main competitors?
Broad incumbents on record are GitLab, Atlassian, ServiceNow and GitHub. Direct peers are Snyk, Sonar (SonarCloud / SonarQube) and JFrog. Emerging players are Vanta, Drata and Ox Security.
Does Kosli have an API?
Yes. Kosli provides a REST API for interacting with the platform. Access is controlled via API keys (personal or service account), web UI login through SSO or GitHub Social Login. The CLI tool (kosli-cli) is open source and available on GitHub, enabling access to Kosli via command line. Terraform Provider (kosli-dev/kosli) is available for managing Kosli resources as Infrastructure as Code. Kosli also offers a verified GitHub Action (setup-kosli-cli) for GitHub workflows. Developer documentation is at docs.kosli.com.
What industry is Kosli in?
Kosli's product category is DevOps Continuous Compliance Automation. Its primary akta.pro industry code is HDAEAHAL, Compliance, GRC Workflow & Audit Automation Platforms, with a secondary code of HDAEALAK, IT Governance, Risk & Compliance (IT GRC) Platforms. Its NAICS code is 54151 and its SIC code is 7372.