FleetDM

United States · fleetdm.com · 13 vendors

Resilience scores

Technology vendors

Services catalogue

1 service in catalogue across 1 category; runs on 13 sub-vendors.

Insights

Last updated 2026-08-16 · revision 2

13 direct vendors, 190 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 9/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

FleetDM exhibits very high migration readiness, largely due to its highly modern, cloud-native oriented tech stack. The extensive use of AWS, Docker, and Terraform signifies a strong foundation in cloud infrastructure, containerization, and Infrastructure as Code (IaC), which are critical enablers for seamless migration. The adoption of GitOps, managing configurations as YAML files in Git, and CI/CD-driven deployments, significantly reduces the complexity and risk of migration by enabling automated, repeatable, and auditable changes. Their reliance on open-source components (Fleet itself is open-source, osquery) and widely adopted technologies (MySQL, Redis, REST API) generally reduces vendor lock-in and increases portability across different environments or cloud providers. While FleetDM's own regulatory environment is not specified, the fact that their 'Fleet Premium' product offers compliance reporting for major standards (CIS, SOC 2, ISO, NIST, PCI, HIPAA) suggests that their internal systems and processes are likely structured in a way that would facilitate meeting compliance requirements during a migration. The primary weaknesses are the absence of data on financial stability, which makes it difficult to assess the capacity to fund a significant migration, and the unspecified data residency requirements, which could introduce unknown constraints. Additionally, the 'Vendor Lock-in Risk' is unknown, though the tech stack suggests lower inherent lock-in.

Compliance

7 in-scope frameworks identified; showing 3.

NIST Cybersecurity Framework — Assessment Required

NIST CSF is a voluntary framework but is widely adopted by US enterprises and government contractors. Fleet's product is explicitly designed to help customers achieve NIST CSF compliance (device visibility, vulnerability management, patch management align directly with NIST CSF Identify, Protect, and Detect functions). Fleet's own internal security posture, evidenced by SOC 2 Type 2 and forthcoming ISO 27001, suggests alignment with NIST CSF principles. Risk is Low as NIST CSF is voluntary for private companies, though it may be contractually required by some of Fleet's government or enterprise customers.

Evidence: https://fleetdm.com/trust, https://fleetdm.com/security-and-control, https://www.nist.gov/cyberframework

FedRAMP — Assessment Required

Fleet explicitly mentions government customers in its handbook ('enterprises, governments, startups, families, and hobbyist racks all over the world') and its platform manages endpoints for government organizations. If Fleet's cloud-hosted service is used by US federal government agencies, FedRAMP authorization is required. Risk is Medium because: (1) FedRAMP is mandatory for cloud services used by US federal agencies; (2) Fleet's MDM platform collects sensitive endpoint data that would be classified as federal information if used by agencies; (3) lack of FedRAMP authorization would prevent Fleet from serving US federal customers with its cloud offering; (4) however, Fleet's self-hosted deployment option allows government customers to deploy on their own FedRAMP-authorized infrastructure (e.g., AWS GovCloud), potentially bypassing the need for Fleet itself to be FedRAMP authorized.

Evidence: https://fleetdm.com/handbook/company, https://fleetdm.com/deployment, https://marketplace.fedramp.gov/

SOC 2 (source) — Compliant

Fleet has achieved SOC 2 Type 2 certification, as explicitly confirmed on the company's official website footer and Trust Center page. SOC 2 Type 2 is the most rigorous form of SOC 2 attestation, demonstrating that Fleet's security controls have been independently audited and found to be operating effectively over a sustained period (typically 6-12 months). This significantly reduces risk because: (1) an independent auditor has verified Fleet's security controls against AICPA Trust Services Criteria; (2) Type 2 (vs. Type 1) confirms operational effectiveness, not just design; (3) Fleet uses Vanta for continuous compliance monitoring, indicating ongoing control maintenance; (4) SOC 2 Type 2 is the industry standard for SaaS providers and is required by most enterprise and government customers. Risk is Low as the certification is confirmed and actively maintained.

Evidence: https://fleetdm.com/, https://fleetdm.com/trust, https://trust.fleetdm.com

Financials

Three-year financials

Financial Resilience Score: 7/10

Fleet Device Management is a well-capitalized private SaaS company with approximately $52M in total venture funding through a 2025 Series B round, providing multi-year runway. The company self-reports 6x revenue growth over 2023-2025 (implying ~145% CAGR), a marquee Fortune 1000 customer base including Stripe, and adoption across 1,300+ organizations in 90+ countries managing 2M+ devices. Its open-source foundation on osquery (co-created by the founder) provides a defensible moat and bottom-up adoption model that reduces customer acquisition costs. However, financial transparency is limited—no absolute revenue, EBIT, or equity figures are disclosed, and the company is almost certainly operating at a loss consistent with venture-backed growth-stage SaaS. It faces intense competition from well-funded incumbents (Jamf, Microsoft Intune, VMware/Omnissa, Kandji, Ivanti) and depends on continued private capital markets support. Concentration risk on large flagship customers and key-person risk in a small ~70-person founder-led team also weigh on the assessment. Overall, resilience is solid for its stage but not investment-grade in a traditional sense.

Key strengths: ~$52M total venture funding through Series B (2025), Self-reported 6x revenue growth over 2023-2025, Fortune 1000 customer base including Stripe (10,000 Macs), 1,300+ organizations across 90+ countries, 2M+ devices managed, Open-source moat built on osquery, SOC 2 Type 2 certified; ISO 27001 in progress, All-remote lean cost structure, High-profile advisors/investors (GitLab, Figma, VMware, Vercel)

Risk factors: No public financial statements or disclosed revenue/EBIT/equity, Likely unprofitable as growth-stage venture-backed SaaS, Intense competition from Jamf, Microsoft Intune, VMware/Omnissa, Kandji, Ivanti, Customer concentration risk on large Fortune 1000 accounts, Key-person risk with small ~70-person founder-led team, Dependency on continued private capital market support, Open-source alternative creates monetization tension

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report