logoalt Hacker News

fg137yesterday at 5:13 PM1 replyview on HN

I used a product with SOC2 certification, which uploads all your chatbot conversations to a server they control (mandatory), potentially including source code and other proprietary data, which can be made visible to public with a single click. Doesn't matter if you are an individual or enterprise user.

They do have enterprise level controls that let admins turn this off. Unfortunately, it is on by default, and some of those basic security controls require a higher tier of service.

It is absolutely wild that these companies treat security like an afterthought. And I also realized SOC2 Compliant meant absolutely nothing.


Replies

SAI_Peregrinusyesterday at 7:20 PM

SOC2 requires a company to write policies in a large number of areas, and to demonstrate that they're complying with the policies they wrote. AFAIK SOC2 does not require anything meaningful about the actual contents of the policies, nor does it require the policies to remain constant.

show 1 reply