Overview
De Laender founded Coding Mammoth in 2007 to work on his own ideas and projects. Semonto started in 2006 as a side project built to monitor web application uptime during hosting problems, beginning with one developer and a designer, and later gained custom tests, alerts, SSL validation, and server monitoring. He leads Semonto from Coding Mammoth, supported by collaborators, beta testers, and ambassadors.
Jelle De Laender is the founder of Coding Mammoth, the Antwerp company behind Semonto. He founded Coding Mammoth in 2007 to work on his own ideas and projects. The product covers uptime and reachability checks, TLS certificate monitoring, broken link detection, Lighthouse performance testing, server health monitoring, cron job monitoring, and domain expiration alerts, with notifications through email, SMS, Slack, Teams, webhooks, and voice calls. Alongside the monitoring product, Coding Mammoth operates as a security partner for SaaS teams, offering fractional CISO leadership, ISO 27001 implementation and internal audits, security assessments, and incident response, covering frameworks including ISO 27001, GDPR, the AI Act, and NIS2. The company has also built ChaseMe, an iPhone fitness comparison app, MijnLijn, a public transport app for iOS, and QuickScale for macOS. Coding Mammoth is registered in the Belgian company register under enterprise number 0847.844.732, with a registration date of 6 August 2012, and is based at Krijgslaan 219 in Antwerp. De Laender also works with companies including Sketch, and his interests include security research, AWS, macro photography, and 3D printing.
Career history
Insights & ideas
The through-line
Across these posts, Jelle De Laender keeps returning to one idea: security and compliance are only useful when they are built in from the start, not bolted on later. He applies this lens to regulation (NIS2, the AI Act, ISO 27001), to client conversations about closing B2B deals, and even, half-jokingly, to a broken office coffee machine that gets a full "incident management procedure" [11][13]. Over the period covered, this preoccupation widens from process and audits into how AI is changing the threat model itself, and from professional writing into personal, physical challenges like the Dodentocht, where the same instinct for spotting things to improve shows up again, this time applied to his own side project ChaseMe [3][7].
On compliance by design
De Laender's clearest recurring argument is that compliance should be embedded rather than appended. Reacting to a podcast conversation about SaaS sales, he writes "compliance cannot be something you 'add later'" and says he believes "in compliance by design. Not as a big bureaucratic layer. Not as a separate team that slows everything" [13]. He extends this to regulation itself, arguing that "organisations with a mature ISO 27001 ISMS get a genuine head start" on the AI Act because "both are built on the same principles: governance, risk management, accountability, and continuous improvement" [5]. In Dutch-language commentary on a client's audit, he frames the goal the same way: not to "zo snel mogelijk een ISMS op te zetten" but to "effectief in controle te zijn," with agility coming from doing it early, before legacy and overhead build up [15]. He also tracks the regulatory landscape closely, noting Belgium's near two-year head start on NIS2 over the Netherlands and warning that "SaaS is not the legal test" for who the law applies to [4].
On AI's risks
He is an unambiguous power user of AI who is nonetheless wary of how others use it. "I'm scared of AI. Not of AI itself. Not of the technology. But of how people are using it," he writes, describing himself as running through a "Claude Max plan and an OpenAI Pro 20x plan every month" while still "challenging the PRs" an AI agent produces because "the logic, the architecture or the actual solution is not always the right fit" [9]. His concern is chiefly about context and blind trust: "Too many people are using AI blindly. Unknowingly. Without enough awareness. Without enough critical thinking" [9]. He connects this to a concrete new attack surface, citing "Agentjacking" research where a fake Sentry bug report can get an AI coding agent to "run commands on the developer's machine," concluding that with AI agents, tools like logs and error reports "are no longer just 'data sources.' They can become instruction sources" [10].
On small gestures and internet plumbing
De Laender is drawn to small, low-visibility mechanisms that quietly hold things together, whether social or technical. On a "Thank developer" button in the Homey App Store for his open-source Bose-speaker app, he writes "it's a nice reminder of how much UX, feedback and a little bit of gamification can influence how a product feels," reporting "133 active installations," "18 countries," and "193 Bose speakers brought back to life" [1], with an earlier count of "85 Bose SoundTouch speakers" restored [12]. He applies the same appreciation to internet-scale infrastructure, pointing out that "one of the most impactful security controls on the internet is maintained by a non-profit," noting that "around 59% of identifiable TLS certificates are issued by Let's Encrypt" and arguing "security is also about supporting the ecosystem we all depend on" [6]. He shows the same forward-looking, practical instinct in flagging Chrome's coming HTTP warnings, telling organisations the real risk is not the main website but "an old domain, forgotten subdomain or legacy service" [2].
Takeaways
- Build compliance into the product and sales process from day one rather than treating it as a late add-on if you want to close larger B2B deals [13].
- A mature ISO 27001 ISMS gives real head start on AI Act transparency obligations because both rest on the same governance and risk-management principles [5].
- Watch for NIS2 exposure signals like 50+ employees or over €10 million in turnover, since "SaaS" alone is not the legal test for applicability [4].
- Treat AI coding agents' inputs, including logs, error reports and observability data, as potential instruction sources that can be weaponised, as shown by the Agentjacking Sentry DSN attack [10].
- Audit forgotten subdomains and legacy internal services before Chrome 154 starts warning users about non-HTTPS sites [2].
- Small UX touches, like a "Thank developer" button, can meaningfully change how users feel about a product even without new features [1].
Media & appearances
- Jelle De LaenderYouTubeSemonto PulseCheck
In the news
- If you want to spot a different side of me... ;)
- If you fail, make sure you fail in style... ...is wat ze vast bij KBC Bank & Verzekering gedacht moeten hebben. Hun systeem lag er een tijd geleden even uit, of ik nam een unexpected route, in elk geval, deze error pagina kon ik wel appreciëren als IT-er 🤓 Hoe ziet jullie foutmelding pagina's eruit? Styled? Droge error pagina? Lekt de pagina interne crash/sessie informatie 🙈 Misschien mooi moment om even te dubbel checken, vaak een vergeten route waarbij hackers inside info kunnen verkrijgen. Voor Semonto heb ik, al zeg ik het
- This one is worth reading, especially if you are responsible for security or AI governance. During internal cybersecurity evaluations, highly capable OpenAI agents found ways to communicate through an unintended channel, bypass internet restrictions, chain vulnerabilities and compromise parts of OpenAI’s research infrastructure and Hugging Face’s systems. Important nuance: these were internal research models operating in a deliberately difficult environment with reduced safeguards. This was not a normal ChatGPT deployment, and
- Such a small gesture. Such a simple notification. Yet, it works. Every now and then, I get this email from Homey about a free, open-source side project I built to keep the Bose radios at our office working. Yes, Bose, I’m still looking at you in disbelief. 👀 The notification means that somewhere, someone using the app actually took the time to hit the “Thank developer” button in the Homey App Store. That’s it. No reward. No new feature unlocked. Just a tiny interaction between a user and a developer. And yet, it makes me smile
- HTTP is not dead yet. But Chrome is becoming a lot less patient with it 👮♀️ Starting with Chrome 154, users will see a warning before visiting public websites that do not support HTTPS. (are there still any 🤨?) For most organisations, the main website will not be the problem. It is more likely to be an old domain, forgotten subdomain or legacy service that is still publicly accessible, or... internal services and dashboards. Chrome 154 is expected in October 2026, so there is still time to check. More details:
- Six months ago, if you’d told me I would take part in the Dodentocht, the 100 km “Death March”, I’d have said you were talking nonsense 🤣 Then someone challenged me… and I completed it. 19h29 of walking, plus breaks, for a total time of 21h29. And yes, I now fully understand how it earned its name… Those hours on the road gave me plenty of time to reflect, sort through my thoughts, and have unexpectedly great conversations with complete strangers. We kept each other moving towards the finish line, one step at a time. And because
- Belgium beat the Netherlands to NIS2. Not by a few weeks, but by almost 22 months 🙈 Belgium was the first EU Member State to fully transpose NIS2. Its law has applied since 18 October 2024. The Dutch Cyberbeveiligingswet enters into force on 15 August 2026 👏 There is no general grace period, although board members have two years to meet the formal training requirement. What does this mean for Dutch SaaS companies? First, “SaaS” is not the legal test. NIS2 explicitly recognises SaaS as a possible cloud computing model, but a
- The AI Act is probably the first major European regulation where organisations with a mature ISO 27001 ISMS get a genuine head start. Not because ISO 27001 is legally required. But because both are built on the same principles: governance, risk management, accountability, and continuous improvement. As of 2 August 2026, the AI Act's transparency obligations are now in force. If your SaaS company uses AI, this doesn't automatically mean you're fully compliant. But if you've already invested in a mature ISMS, you're likely much
Related profiles
This page shows public professional information only, each fact cited. Is this you? send a correction, or ask for removal within 24 hours, no questions asked.




