Live data from Hacker News

Ask HN: How to handle sensitive document uploads as a one-person SaaS?

news.ycombinator.com

11–15 of 15 posts

Re: Ask HN: How to handle sensitive document uploads as a one-person SaaS?

#12
I worked for a company that required security clearances. We used a SaaS to store some documents. The SaaS gave our company a document outlining their security practices and we signed up to a system where their support is unable to access our instance unless we explicitly authorized it. It was enough for our company.

Re: Ask HN: How to handle sensitive document uploads as a one-person SaaS?

#13

This'll be unpopular, but if you want to keep it super lean and avoid being asked for compliance certs like SOC2/ISO, you could consider building it as an installable app on top of a platform your customers already trust ie. a Salesforce App. That way, they already use/trust the environment where the storage/processing of their sensitive data is taking place, akin to an old school 'on prem' solution (but without as m…

IMO just get ISO 27001 to demonstrate that you are managing the sensitive information properly, and you will also improve your client confidence.

I work as ISO 27001 auditor, and help companies get ISO 27001 certified in no time (1-2 months), with a budget from 5k - 8k in total (external support and certification included). The goal it to keep it simple, save costs, and in the end get the company certified.

Re: Ask HN: How to handle sensitive document uploads as a one-person SaaS?

#15

This'll be unpopular, but if you want to keep it super lean and avoid being asked for compliance certs like SOC2/ISO, you could consider building it as an installable app on top of a platform your customers already trust ie. a Salesforce App. That way, they already use/trust the environment where the storage/processing of their sensitive data is taking place, akin to an old school 'on prem' solution (but without as m…

IMO just get ISO 27001 to demonstrate that you are managing the sensitive information properly, and you will also improve your client confidence. I work as ISO 27001 auditor, and help companies get ISO 27001 certified in no time (1-2 months), with a budget from 5k - 8k in total (external support and certification included). The goal it to keep it simple, save costs, and in the end get the company certified.

"Oh, wow, I had no idea it was that affordable, we should talk..." is the response you are hoping for, correct? Self-promotion is not prohibited, but it goes better if you engage with the discussions here beyond just your own marketing.

Anyhoo, I don't think thousands of dollars for certification makes sense for a solo dev who is kicking an idea around.

Post reply on HN