logoalt Hacker News

tptacekyesterday at 10:22 PM1 replyview on HN

I wouldn't put it the way they did but they're directionally sane about this. I would worry a lot more about someone repping their SOC2 as important or meaningful than I would worry about someone who was cynical about SOC2.

(I don't mean Apple; Apple spends more on security than almost any firm in the world.)

https://fly.io/blog/soc2-the-screenshots-will-continue-until...


Replies

xocnadtoday at 12:35 AM

My experience with pen tests that you put above or on par with SOC2 Type 2 security mirrors the discussion here. It all comes down to the reputation of the firm doing the testing.