
Jelle started coding at age 14 and founded Coding Mammoth in 2007 while still studying at the University of Ghent. He created Semonto as an internal tool to alert him when servers went offline, and it grew over 12 years into his most popular product.
Beyond Semonto he has worked as a security leader at Sketch and is interested in security research, AWS cloud hosting, and 3D printing. Semonto is a European-hosted alternative to US monitoring tools, used by organisations including De Lijn.
Across these posts, Jelle De Laender keeps returning to one idea: security and compliance are only useful when they are built in from the start, not bolted on later. He applies this lens to regulation (NIS2, the AI Act, ISO 27001), to client conversations about closing B2B deals, and even, half-jokingly, to a broken office coffee machine that gets a full "incident management procedure" . Over the period covered, this preoccupation widens from process and audits into how AI is changing the threat model itself, and from professional writing into personal, physical challenges like the Dodentocht, where the same instinct for spotting things to improve shows up again, this time applied to his own side project ChaseMe .
De Laender's clearest recurring argument is that compliance should be embedded rather than appended. Reacting to a podcast conversation about SaaS sales, he writes "compliance cannot be something you 'add later'" and says he believes "in compliance by design. Not as a big bureaucratic layer. Not as a separate team that slows everything" . He extends this to regulation itself, arguing that "organisations with a mature ISO 27001 ISMS get a genuine head start" on the AI Act because "both are built on the same principles: governance, risk management, accountability, and continuous improvement" . In Dutch-language commentary on a client's audit, he frames the goal the same way: not to "zo snel mogelijk een ISMS op te zetten" but to "effectief in controle te zijn," with agility coming from doing it early, before legacy and overhead build up . He also tracks the regulatory landscape closely, noting Belgium's near two-year head start on NIS2 over the Netherlands and warning that "SaaS is not the legal test" for who the law applies to .
He is an unambiguous power user of AI who is nonetheless wary of how others use it. "I'm scared of AI. Not of AI itself. Not of the technology. But of how people are using it," he writes, describing himself as running through a "Claude Max plan and an OpenAI Pro 20x plan every month" while still "challenging the PRs" an AI agent produces because "the logic, the architecture or the actual solution is not always the right fit" . His concern is chiefly about context and blind trust: "Too many people are using AI blindly. Unknowingly. Without enough awareness. Without enough critical thinking" . He connects this to a concrete new attack surface, citing "Agentjacking" research where a fake Sentry bug report can get an AI coding agent to "run commands on the developer's machine," concluding that with AI agents, tools like logs and error reports "are no longer just 'data sources.' They can become instruction sources" .
De Laender is drawn to small, low-visibility mechanisms that quietly hold things together, whether social or technical. On a "Thank developer" button in the Homey App Store for his open-source Bose-speaker app, he writes "it's a nice reminder of how much UX, feedback and a little bit of gamification can influence how a product feels," reporting "133 active installations," "18 countries," and "193 Bose speakers brought back to life" , with an earlier count of "85 Bose SoundTouch speakers" restored . He applies the same appreciation to internet-scale infrastructure, pointing out that "one of the most impactful security controls on the internet is maintained by a non-profit," noting that "around 59% of identifiable TLS certificates are issued by Let's Encrypt" and arguing "security is also about supporting the ecosystem we all depend on" . He shows the same forward-looking, practical instinct in flagging Chrome's coming HTTP warnings, telling organisations the real risk is not the main website but "an old domain, forgotten subdomain or legacy service" .
From public career histories · 13 entries