Live data from Hacker News

Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

news.ycombinator.com

161–164 of 164 posts

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#162

Has no one yet found a way to vibe-code this into a viable self-service solution? and yes I do understand there is a IRL-auditing authority piece to all of this too. Perhaps there this is a play here in the market to create a new auditing firm that 99% automates all this for startups? sans fraud certs of course.

I've created a product around this exact problem and niche. No, you can not automate 99% of it, but one (tool I've created) can help with guidance and translating strange requirements into something, that matches your context. I plan to launch it on HN as soon as I'll get my soc2 type II report. It's called humadroid.io (https://humadroid.io) - feel free to schedule a demo and mention HN; I'll be happy to give a generous discount code. Been working for over a year on it, agree it's not easy, but it's accessible and perfectly doable by solo founders.

Re: Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?

#163
post #45
post #32

Really appreciate this discussion as I'll be shortly going through this with a 1-2 person company. Does anyone have any experience on how it compares to ISO27001 from the 1-2 person company feasibility standpoint?

I'm in a similar position. The business continuity requirements are difficult to satisfy. And the amount of paperwork you need to do (depending on your policies of course) can be a major slow down for developing new stuff. So it's best to get your dev heavy stuff done before. I'm just filling in the questionnaires instead for now (and losing some customers who would be too big anyway)

I have to disagree - did it solo while dogfooding the tool for this exact purpose.
Post reply on HN