CASE STUDY | Industry
Trust & Privacy Platform

OneTrust Uses Oligo to Build Customer Confidence & Save Developers Time

2016
FOUNDED
2300
EMPLOYEES
>500
DEVELOPERS
Atlanta, GA
HQ LOCATION
“Oligo is a weekend saver. When there’s a zero day, it feels like it’s always on a Friday. With Oligo, we can see right away what is actually affected and make a decision about what to do.”
Joe Sanders
Joe Sanders
Sr. Director of Product Security

OneTrust builds the platform that enables organizations to use data and AI responsibly. The company offers solutions for data privacy, consent and preferences, data and AI governance, risk, and compliance.

The Challenge

Finding Signal in Noisy CNAPP and SCA Results

For OneTrust, defense-in-depth required a tool that could cut through the noise and help keep its teams focused on the security alerts that matter the most, without any compromise to OneTrust’s risk.

“Many vulnerability tools, especially CNAPPs, are very noisy. It takes a lot of analysis time to identify the real security risk,” said Joe Sanders, Sr. Director of Product Security, OneTrust

To help prioritize findings, OneTrust reached out to Oligo.

The Oligo Solution

The Oligo Application Defense Platform cuts through the noise of CNAPP and SCA tools by observing all application components directly in runtime—enabling unprecedented visibility into which components are loaded and executed.

Unlike tools that prioritize results based on algorithms that make estimations of risk, the Oligo platform observes risk exposure directly, with proof of vulnerable functions or libraries being executed. This enables companies like OneTrust to drive further value by demonstrating vulnerability context for customers and offering assurance that issues are already fixed

Results & Benefits

After deploying the Oligo Application Defense Platform, OneTrust saw immediate value from the runtime visibility, allowing security and development to see which dependencies are and are not loaded or executed in production. “This allowed us to take a more risk-based approach and focus on fixing what is actually important,” Sanders said.

In addition to helping developers manage the security issues backlog, OneTrust also found that thanks to its zero-day response capabilities, the Oligo Application Defense Platform enabled them to rapidly take action. 

“With Oligo, we know almost immediately if there is something we need to address, and if so, we can take rapid and precise action,” Sanders said. Granting particular peace of mind: Oligo’s capabilities to identify whether a dependency zero-day is present and executed in any application.

An unexpected benefit of the Oligo Application Defense Platform: real time SBOM capabilities. “With Oligo’s assistance, we now deliver a more robust SBOM with each release,” said Sanders. “This enhances our transparency to customers and our ability to meet contractual obligations more effectively."

Why Oligo?

In addition to the immediate benefits the Oligo Application Defense Platform has provided to OneTrust, Sanders is also excited about the future of the product.

With Oligo implemented at OneTrust, Sanders says he’s now recommending it to other executives in the industry. “I advertise the Oligo platform often, especially with colleagues I’ve worked with in the past who are now getting into application security—I highly recommend they entertain Oligo, because it’ll make your life a lot easier.”

Built to Defend Modern & Legacy apps

Oligo deploys in minutes for modern cloud apps built on K8s or older apps hosted on-prem.