Could you elaborate on the 'headaches of various vendor reviews and declarations'? (I thought paperwork etc was table stakes for a SOC 2 certificate)