Hacker News new | past | comments | ask | show | jobs | submit login

SOC Type 2 compliance only suggests they have a sit in audit once a year. Basically the produced a lot of paperwork and it doesn't mean that they evidenced stuff honestly to the auditors.



Auditors audit for one year. They make sure all the processes and controls are hit and used as expected. I am wondering why the audit firm is not made accountable when these hacks happen.


Having gone through SOC2 at two different companies, anyone who takes these certificates seriously is a fool.


Indeed they are just ticking a box for your customers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: