A man reviews a cloud security dashboard at his desk, with a city map and rising growth chart in the background.
A Sunderland compliance-automation startup has raised £1 million, and its pitch involves your Microsoft 365 tenant. That makes the round worth a look from IT admins, not just from people who follow regional venture capital. OneClickComply sells software to help businesses get through Cyber Essentials, ISO 27001 and SOC 2. It says it can reach into Microsoft 365, Google Workspace and AWS and change security settings with one click.

The funding: who, how much, and what for​

OneClickComply took investment from the North East Accelerate Fund, managed by Mercia Ventures. It also took money from the Venture Sunderland Fund and the Northstar EIS Growth Fund, both managed by Northstar Ventures. The round takes total funding to more than £2.4 million. The company says it will spend the money on technology, sales and customer service, and four new jobs.

The timing is a little muddier than the headlines suggest. IT Brief UK ran its report on 6 October 2026. Northstar's own announcement is dated 24 September 2026, and one deal tracker lists the funding date as 23 September 2026. So this is a round that has been public for a couple of weeks and is now being picked up more widely.

It's also worth keeping the rounds apart. Northstar reported an earlier round in August 2025: £580,000, including £275,000 of follow-on money from the Venture Sunderland Fund. At that point the company, then still branded FAT32 in places, said it had secured over £1.2 million in total. The £2.4 million figure covers everything raised to date, including this £1 million.

Growth claims, and who is making them​

All of the following comes from the company or its founder. None of it has been independently audited:

  • Revenue: Monthly recurring revenue has doubled in the past six months, and the company aims for similar growth in the next six. No revenue figure was disclosed, so "doubled" could mean a small number became a slightly larger one.
  • Scale: The company was set up in 2024 and now employs 12 staff and serves dozens of customers. The IT Brief report says those customers range from sole traders to a large fast-food brand.
  • Automation: The "up to 90%" figure for certification work appears throughout the coverage. It covers standards such as Cyber Essentials, ISO 27001 and SOC 2, plus monitoring, vulnerability management, policy generation and evidence gathering for auditors. No source defines how that percentage is calculated.

The investors' quotes are positive, as you'd expect from people who just wrote cheques. Mercia's Owen Conquest praised the platform's ability to detect and remediate compliance issues without specialist intervention. That is a view from the investor side, not a test result.

The Microsoft 365 angle: what connecting actually involves​

This is where the story matters to admins. The platform can automatically configure security settings across programs such as Microsoft 365, Google Workspace and AWS with a single click, replacing what is otherwise a laborious manual process. That is a vendor claim. The vendor's own documentation, however, shows the setup is not casual.

Permissions​

OneClickComply's Microsoft 365 integration guide asks you to confirm you have Global Administrator permissions before you start. The vendor's platform-requirements page repeats the point, saying Microsoft 365 needs Global Administrator access. For Google Workspace it needs Super Admin, and for AWS, Azure or GCP it needs administrative access to the relevant accounts or subscriptions.

Documented connection steps​

The vendor's guide lays out this workflow:

  1. Open Integrations from the main navigation bar and find the Microsoft 365 integration.
  2. Select Connect Microsoft 365, then enter a recognisable connection name.
  3. Enter your Azure tenant ID. The guide points to a link for finding it in Microsoft Entra.
  4. Select Sign in with Microsoft and grant the displayed consents, using a Global Administrator account.
  5. Return to the platform, select I've granted consent - finish setup, and follow the remaining prompts.
  6. After a short wait for initial authentication, the platform starts scanning the environment for gaps and misconfigurations.

Licensing​

The vendor's published guidance sets Microsoft 365 Business Premium as the minimum. It recommends E5 and also lists E3, A3 and A5 as supported. It warns that basic or entry-level licences can restrict access to the controls the platform needs. This is the vendor's compatibility guidance, not a Microsoft recommendation. It does show that smaller tenants on lower plans may hit limits, whatever the marketing says.

What admins should weigh​

The sources do not establish which Microsoft Graph permissions are requested, which settings can be changed, or whether any independent party has tested the remediation. The points below are general considerations, not findings about this company:

  • Read the consent screen. Global Administrator is the most privileged role in a tenant, and the consents granted to a third-party app deserve the same review as any other.
  • Separate finding from fixing. Automated remediation changes live configuration. Conditional Access, mail flow and legacy-protocol changes can all break something for real users. Staging and change control still apply.
  • Know your own baseline. A tool that fixes drift is only useful if you understand what the "correct" state is for your organisation.
  • Don't confuse a platform with a certificate. Nothing in the coverage says that connecting the product guarantees certification or security. Auditors still make their own judgements.
  • Check the broader product. The vendor's platform guide describes modules for policy drafting, risk registers, asset inventory, incidents, vendor management and a trust centre. That is a wider compliance suite than a one-click settings tool.

Why it matters​

The founder's argument is that customers increasingly demand proof of security before signing contracts. For UK small and mid-sized firms, Cyber Essentials in particular often turns up as a procurement requirement. Tools that claim to compress months of consultant work into software are therefore a growing category. This round is a small seed-stage deal, and the investors are regional funds. It signals appetite for compliance automation, not a market verdict on this product.

For Microsoft 365 administrators, the practical takeaway is simple. Treat any "one-click" compliance tool as a privileged integration. It needs the same scrutiny of permissions, licensing fit and change control as any other app with administrative reach into your tenant.

 

References

  1. OneClickComply secures GBP £1 million to fuel growth - IT Brief UK IT Brief UK 2026-10-06T10:45:00+00:00
  2. Microsoft 365 Integration Guide - OneClickComply support.oneclickcomply.com
  3. Platform Requirements - Permissions & Licenses - OneClickComply support.oneclickcomply.com