Comment by fantasizr

2 months ago

there needs to be a fund with an ethos of "move slowly and do things accurately"

The fund is called customers. The independent regulator is called the AICPA. It really comes down to who is paying attention

SOC2 is as useful as a privacy policy at protecting your data. It’s all humans following human incentives.

  • The value of SOC2 is that it does take some experience to be able to plausibly fake the evidence which weeds out people that truly have no idea what they're doing. It also provides a blueprint of the stuff you should be doing if you actually care.

    But beyond that it's not worth a whole lot.

    • yeah it's funny to see some defense of this practice as "well the whole thing is pointless anyway so nothing is lost by defrauding folks". Pretty hollow argument

      1 reply →

There are a few, roughly.

Like the best options in most categories, they don’t spend a bunch of money or time on brand presence, advertising.

You simply find them.