Live data from Hacker News

We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

trustcompliance.xyz

41–50 of 83 posts

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#41
post #22
post #10

Is SOC 2 legit? I have this on my roadmap but now I’m wondering if it’s just security theatre?

It's security theater. Friendly plug for Oneleet, who actually talked us out of getting it. We were considering getting certified, but it only really makes sense if your customers require you to have it.

Tangential to this but do ISO certifications make sense or are they security theater as well?

And another question but as a consumer, is there any certification which can meaningfully try to show if people/business take their security carefully or are all things security theater in that aspect and at some point, we just have to trust the enterprise and look for other signals of security (like for example blog posts which might show a deep-dive into security for example comes to my mind)

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#42

Earlier quoted context omitted.

boilerplate is one word. sorry for the nit, feel free to backpfeifengesicht

I don't think that is an important point.

it does highlight the efficiency value of boilerplate. you only have to proof it once, really well of course. all downstream instances get the benefit of that one very good review.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#44
post #15

Earlier quoted context omitted.

That's a difficult question to answer. It shouldn't be, but it is. The reality is, SOC2 is a sales-enablement tool. You should: * Run a SOC2/compliance program that is entirely disjoint from your security practice. * Defer SOC2 until the work required to sell into customers demanding it (phone calls, questionnaires) exceeds the cost of obtaining SOC2. * Prepare for SOC2 by making simple best-practices engineering dec…

Since you know a lot about SOC: is SOC2 Type I (point in time) enough to close enterprise sales? Is it worth getting for a new startup (seems super simple)?

Yes, it is, and no, you should not get it, not until you know you need it. If you have to ask, defer.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#46
post #14
post #7

The damage this will do to the reputation of the SOC2 Security Attestation is incalculable.

As someone unfamiliar with the topic, should I read this comment as very dry humour?

Based on my personal experience with security theater and its many talented actors, yes.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#47

Looking at our SOC 2 report (we don't use Delve, our auditor isn't on their list) I don't think this is quite the smoking gun it might look like if you're not reading SOC 2 reports for a living. There's a fair amount of boiler plate language in these reports, and a bunch of re-stating the SOC 2 controls. I'd expect two reports (same auditors, same platforms) to be nearly identical. If they're both using AWS, Github,…

But maybe you shouldn’t raise so much money and make a big fuss about it when all you’re selling is a template?

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#48
post #10

Is SOC 2 legit? I have this on my roadmap but now I’m wondering if it’s just security theatre?

It basically shows clients that you are not doing wildly incompetent things with their data, or if you are, they can more easily sue you, since you probably lied to your auditor about it.

But it’s ultimately not up to you if you do it or not. If all of your potential clients demand it, it’s generally easier to get it than it is to get on the phone with all of your potential clients’ IT departments and explain why you don’t have it.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#49

Earlier quoted context omitted.

This mirrors my thoughts. A page of boiler play text with some check boxes, with some checked vs unchecked is going to be 99.8% similar between companies as well. A lot of audits are very much forms with boiler plate and fill in the blank. There is no point rewriting everything from scratch.

boilerplate is one word. sorry for the nit, feel free to backpfeifengesicht

One word is two words.

Re: We indexed the Delve audit leak: 533 reports, 455 companies, 99.8% identical

#50
" let r = ["Acme Corp", "CloudVault", "DataSync Pro", "NexGen AI", "SecureStack", "TrustLayer", "Vanta", "ComplianceIQ", "InfraSec", "ByteShield", "PipelineOps", "CyberNova", "TokenGuard", "ZeroTrust Labs", "Aether Security", "PrismData", "CloudArmor", "RiskLens", "AuditTrail", "ShieldIO"] , n = ["just checked", "searched for", "ran a scan on", "verified"] , a = ["San Francisco, CA", "New York, NY", "Austin, TX", "London, UK", "Berlin, DE", "Toronto, CA", "Seattle, WA", "Chicago, IL", "Denver, CO", "Boston, MA", "Singapore", "Sydney, AU"]; "

fake popups, xyz domain, recent zeitgeist, 100% straight vibecoded. good hustle I have to say. a domain that'll now get ranked on google for SOC 2 compliance which likely has a high CPC and good DR to piggyback off.

Post reply on HN