1. Home
  2. Companies
  3. BambooHR
BA

BambooHR

About

BambooHR operates an HR software platform serving 34,000 businesses worldwide, built on cloud infrastructure with AI and machine learning capabilities integrated into its core product. The threat model here centers on privileged access to sensitive employee data - payroll information, benefits records, performance reviews, and personally identifiable information across tens of thousands of organizations. The attack surface spans API integrations with third-party payroll and benefits providers, authentication systems handling SSO implementations, and data storage architectures that must enforce tenant isolation at scale.

Founded in 2008, the company has built a complete HR ecosystem focused on small and medium-sized businesses - a market segment that typically lacks dedicated security teams but faces the same compliance requirements as larger enterprises. This creates specific technical constraints: security tooling must be robust enough to defend against sophisticated threats while remaining transparent to end users who aren't security professionals. The platform handles HR automation and employee management workflows, meaning security teams must balance access controls, audit logging, and data retention policies against usability requirements for HR administrators who need rapid access to employee records.

The technical domains include software product development with emphasis on cloud computing architecture and machine learning implementations. Security considerations extend beyond the core platform to encompass the broader HR ecosystem - integration points with benefits providers, background check services, and applicant tracking systems create an expanded attack surface where credential management, API security, and third-party risk assessment become critical operational concerns. The company's US headquarters suggests primary regulatory focus on frameworks like SOC 2, GDPR for international customers, and state-level data privacy laws that increasingly govern employee information handling.

Similar companies

BI

Bihr

Bihr is the leading European distributor of rider gear and spare parts, accessories and tyres for motorcycles, quads/ATV and scooters. Founded in 1975, the company is present in over 15 countries and has established itself as a premier partner for motorcycle dealers across Europe. Bihr offers the widest and most relevant portfolio of 7 product universes: Street, Scooter, Off-Road, Quads/ATV/SSV/UTV, tyres, workshop equipment and rider gear. The company distributes over 200,000 products from approximately 350 brands through a network of more than 15,000 dealers, providing personalized service in their own language. The foundations of Bihr's success are built on comprehensive services and first-class logistics. With a total storage area of more than 54,000 square meters spread across 7 warehouses throughout Europe, Bihr is able to supply practically all dealers in Europe within 24 hours. The company employs 750 people (reaching 1,200 during peak seasons), including 100 in-house sales representatives and over 60 customer service representatives. In 2022, Bihr was acquired by Arrowhead Engineered Products, strengthening its position as a global leader in powersports distribution.

2 jobs
SM

Smarsh

We're a team that's been obsessed with solving the communications compliance problem since 2001. What started as email archiving has evolved into a platform that captures, retains, and analyzes communications across more than 100 digital channels - we're talking email, mobile, social media, collaboration tools, voice, you name it. Our customers are the ones who can't afford to get compliance wrong: top banks, investment firms, insurers, and government agencies who trust us to help them spot risks before those risks become regulatory fines or headlines. The work we do matters because the stakes are real. Regulatory bodies aren't cutting any slack, and the communications landscape keeps getting more complex with new channels popping up constantly. We've built a cloud-native platform that combines capture, archiving, surveillance, and discovery with AI-powered insights to help organizations not just stay compliant, but actually find value in their communications data. Based in Portland with teams around the world, we're proud to have been recognized by analysts like Gartner and Forrester, and to have landed on the Inc. 5000 list of fastest-growing companies for years running.

2 jobs
TH

Thoropass

Traditional compliance audits drag on for months, cost small fortunes, and force growing companies to choose between security and speed. Thoropass exists to end that tradeoff. Founded in 2019, Thoropass is the only end-to-end cybersecurity auditor that combines continuous, AI-powered evidence collection with a highly experienced team of auditors to deliver comprehensive security audits in weeks, not months. The Audit Lifecycle Platform automates the tedious evidence collection work while human experts provide the guidance that ensures real compliance - not just checking boxes, but building security that enterprises trust. Thoropass supports more than 30 frameworks including SOC 2, ISO 27001, PCI DSS, HITRUST, HIPAA, and GDPR, serving over 1,000 companies across SaaS, fintech, and healthcare. With in-house auditors conducting 500+ audits annually and AI that automatically converts documents into audit-ready evidence, Thoropass has eliminated the handoffs, rework, and last-minute surprises that make traditional audits so painful. The company is headquartered in New York with a global team across 18 countries, backed by J.P. Morgan, PayPal Ventures, Bain Capital Ventures, and other leading investors who recognize that modern companies deserve a modern approach to compliance.

2 jobs
HA

HarfangLab

HarfangLab builds endpoint detection and response tools for organizations that need to know exactly what's running on their machines and where their telemetry lives. The Paris-based company's EDR became the first certified by ANSSI - France's national cybersecurity agency - in 2020, a stamp that matters in regulated environments where vendor trust and data sovereignty aren't negotiable. The platform ingests behavioral data from workstations and servers, runs detection logic using YARA and Sigma rulesets, and layers AI-based analysis on top to surface threats. Deployment options include cloud and on-premises configurations, giving customers control over where endpoint data gets stored and processed. The threat model here centers on advanced persistent threats and sophisticated actor tradecraft - the kind of intrusions that signature-based protection misses. HarfangLab's approach combines real-time behavioral monitoring with open-standard detection formats, allowing security teams to write custom rules and integrate existing intelligence feeds without vendor lock-in. The system is designed for environments that can't tolerate blind spots: CAC 40 companies, government agencies, hospitals, and municipal networks across Europe where compliance regimes demand auditability and data residency guarantees. Founded in 2018, the company raised €30 million and has tripled its workforce in three years as it scales beyond France into broader European markets. The customer base spans critical infrastructure operators and enterprise IT teams running hybrid environments where endpoint visibility is the first line of defense. The technical stack emphasizes transparency - analysts can see detection logic, tune rules, and trace alert chains without hitting proprietary black boxes.

2 jobs
KE

Keolis

Keolis is a global leader in the shared mobility market and a committed partner to public transport authorities worldwide. Together, we co-construct safe, smart and sustainable public transport solutions that help to create more attractive places to live and work. With operations spanning 13 countries and 70,000 employees, Keolis serves 300 public transport authorities and operates 13 different modes of transport, from buses and coaches to rail networks, trams, and metros. For over 100 years, Keolis has been dedicated to designing efficient, sustainable, and tailored transport solutions that address communities' environmental, economic, and safety-related issues. Our mission-driven approach focuses on reducing traffic, pollution, and congestion while improving the quality of daily life for millions of travelers. We imagine and deploy mobility solutions that make cities more livable, connecting communities and creating spaces where everyone belongs through responsible and sustainable operations.

KE

Kestra

Kestra Financial operates a broker-dealer and wealth management platform serving 1,700+ independent financial professionals across the United States, managing $142 billion in assets under advisement and $70 billion in assets under management. Founded in 1997 and headquartered in Austin, Texas, the firm runs multiple regulated entities including Kestra Investment Services (broker-dealer), Kestra Advisory Services (RIA), and subsidiaries handling portfolio management, trust services, and insurance planning. The threat surface spans proprietary wealth management platform technology, broker-dealer operations infrastructure, and systems handling sensitive client financial data across nationwide operations. The tech stack includes Microsoft Office suite, Outlook, Adobe, and Redtail CRM alongside proprietary platform technology that powers end-to-end advisory solutions. Security responsibilities extend to protecting PII and financial records for thousands of advisors and their clients, maintaining regulatory compliance across SEC and FINRA domains, and securing M&A transaction data through subsidiary Bluespring Wealth Partners. The operational model combines centralized platform technology with distributed advisor networks, creating authentication, access control, and data segmentation challenges typical of multi-tenant financial services architectures. Kestra Investment Management and Arden Trust add portfolio management and fiduciary service layers requiring additional controls around transaction integrity and client account protection.