SimpleRose automates security with Mondoo across entire tech stack
How a high-performance optimization company achieved real-time, centralized visibility into the compliance and configuration of their diverse tech stack.
Published December 2025 · Updated August 2026
- Organization
- SimpleRose
- Industry
- Technology — optimization software
- Headquarters
- St. Louis, MO (USA)
- Environment
- Cloud-first — AWS multi-account organization
- Compliance
- SOC 2, GDPR, CCPA, PCI DSS
- Mondoo's role
- Automated security and compliance across the entire tech stack
Who is SimpleRose?
SimpleRose helps teams tackle the world's most complex planning and scheduling problems — faster and in fuller detail. Whether organizations are looking to accelerate their existing optimization models, build a tailored decision support system, or explore SimpleRose's next-generation solver, SimpleRose helps their customers spend less time simplifying and more time solving.
SimpleRose is a cloud-first organization with infrastructure primarily on AWS, structured through multiple sub-accounts managed under an AWS Organization and aligned with best practices for workload separation and security. SimpleRose employs cloud-native development practices and designs its applications for scalability, resilience, and observability, leveraging containerization and infrastructure-as-code within AWS.
SimpleRose's security function is embedded within the broader IT and operations teams. While not a standalone department, they operate a cross-functional team approach involving security champions from Engineering, Compliance, and IT, coordinated through the Rosarians — SimpleRose's team for Security, Ops, IT, and Compliance.
What security challenges did SimpleRose face?
One of SimpleRose's biggest challenges was achieving real-time, centralized visibility into the compliance and configuration of their diverse and rapidly growing tech stack — including cloud infrastructure, endpoints, SaaS platforms, and developer tooling.
SimpleRose lacked a unified platform that could provide deep insights into the broader compliance posture of their systems: patch status and software versions, file permissions and system configurations, cloud services configuration and container security, and web asset security posture (such as misconfigured domains or cloud services).
“Although we had strong perimeter and endpoint protections in place through tools like CrowdStrike and Cloudflare, and we had Vanta to validate basic workstation compliance (e.g., password lock, encryption, antivirus, screen lock [PEAS]), all these solutions worked in silos.”
Todd Bradfute, Senior Director of Security & Technology, SimpleRose
Why did SimpleRose choose Mondoo?
When Todd heard about Mondoo's Policy as Code solution at DevOpsDays, his interest was immediately sparked. That, coupled with Mondoo's ease of use, got SimpleRose quickly hooked. Although they already had other tools that provided high-level insight, Mondoo goes much deeper into config-level verification, providing both breadth and depth.
“As we scaled up cloud-native services and moved faster in CI/CD pipelines, these blind spots became more pressing. We needed a way to not just check boxes for compliance, but to validate the actual state of systems in a developer-friendly, extensible way — and Mondoo gave us that.”
Todd Bradfute, Senior Director of Security & Technology, SimpleRose
How does Mondoo automate security across the tech stack?
With Mondoo, SimpleRose can now view their compliance status across different types of tools and assets in one place: consolidated compliance insights from diverse environments — laptops, AWS, DockerHub, internal web services — with deep config-level verification.
Policies are customizable and scalable: SimpleRose can write and customize policies as code, making it easy to tailor checks to their specific internal standards. Smooth integration with their CI/CD and infrastructure pipelines enables security-as-code without blocking developer velocity, and streamlined remediation processes bridge the gap between detection and action with clear, actionable paths to resolution.
“We were already using tools like Vanta to validate foundational workstation compliance, but we needed to go beyond high-level controls and into the specifics — like verifying if file permissions were correctly applied, patch versions were up-to-date, and Docker configurations followed best practices.”
Todd Bradfute, Senior Director of Security & Technology, SimpleRose
How long did it take SimpleRose to deploy Mondoo?
Getting started did not require a rollout project: SimpleRose had workstation scanning running within an hour, and connecting the remaining environments was just as effortless.
“Mondoo was very easy to deploy. I had workstation scanning running literally within an hour of seeing Mondoo's presentation at DevOpsDays. Connecting to our other environments was also pretty effortless.”
Todd Bradfute, Senior Director of Security & Technology, SimpleRose
What results did SimpleRose achieve?
With Mondoo, SimpleRose achieved a reduction in manual work — what used to be multi-step, manual, and siloed workflows are now clear, actionable paths to resolution with automated patching of affected systems — and a significant decrease in vulnerabilities: instead of a sea of red alerts with no clear path forward, after fully implementing Mondoo with automated policies there are now only a handful of issues at a time.
Attention is focused where it matters: SimpleRose can now concentrate on what actually needs remediation and apply the granularity to create custom policies that fit their business needs. Remediation is repeatable and automated across the entire tech stack: Mondoo reports on the worst offenders; SimpleRose targets the best ones to fix and deploys fixes using RMM (for workstations), IaC (for workloads), and Terraform (for cloud tooling) with Mondoo's remediation code snippets; then Mondoo rescans and shows if the score improved.
The key business drivers for SimpleRose adopting Mondoo centered around the need to unify and deepen compliance and configuration visibility across a rapidly growing tech stack, but Mondoo has delivered far more than that. With an automated, repeatable remediation process, SimpleRose has been able to reduce manual work, accelerate remediation, and ensure the most critical exposures are resolved quickly.
Mondoo Policy as Code and integration into the SDLC has also helped SimpleRose introduce security into their development process, catching security issues early without compromising on speed.
“Mondoo became our bridge between technical configuration and policy requirements, which is critical for scaling secure operations without introducing friction.”
Todd Bradfute, Senior Director of Security & Technology, SimpleRose
“No matter where you are in your security journey, Mondoo meets you there. For those with existing tooling, Mondoo has had an answer for every tool we've needed to support. For organizations that know they have to support lots of different frameworks, Mondoo has been a great partner to grow with.”
- of open issues at a time, down from a sea of red alerts
- Handfulof open issues at a time, down from a sea of red alerts
- to get workstation scanning running after first seeing Mondoo
- 1 hourto get workstation scanning running after first seeing Mondoo
- in the automated, repeatable remediation loop — report, target, fix, rescan
- 4 stepsin the automated, repeatable remediation loop — report, target, fix, rescan
Frequently asked questions
Mondoo consolidates compliance insights from SimpleRose's diverse environments — laptops, AWS cloud infrastructure, DockerHub, and internal web services — with deep config-level verification. In Todd Bradfute's words: "Mondoo enhances our ability to monitor, validate, and enforce security policies across all our IT surfaces from a single platform."
Tools like CrowdStrike, Cloudflare, and Vanta provided strong perimeter and endpoint protections and validated basic workstation compliance, but they worked in silos. Mondoo goes much deeper into config-level verification — checking whether file permissions are correctly applied, patch versions are up-to-date, and Docker configurations follow best practices — providing both breadth and depth.
Through an automated, repeatable four-step loop: Mondoo reports on the worst offenders; SimpleRose targets the best ones to fix; fixes are deployed using RMM for workstations, IaC for workloads, and Terraform for cloud tooling, with Mondoo's remediation code snippets; then Mondoo rescans and shows if the score improved. "Mondoo gives us a razor sharp answer for how to address identified problems."
No. Mondoo integrates with SimpleRose's CI/CD and infrastructure pipelines to enable security-as-code without blocking developer velocity, and Mondoo Policy as Code integrated into the SDLC catches security issues early without compromising on speed.
The entire tech stack.One automated security workflow.
SimpleRose is proof that policy as code scales security across an entire tech stack — workstation scanning deployed within an hour, an automated four-step remediation loop, and a handful of open issues instead of a sea of red alerts.

