Skip to content

Comment on Apple Private Cloud Compute SoC 3 audit reportsparent

Comments

I'm not going to, like, whip out my resume here, but I am going to confidently assert that if you structure your Type 1 carefully, you can trivialize your Type 2, and as someone currently operating a globally deployed public cloud I can tell you right now that SOC2 doesn't really touch on anything interesting in our engineering.

I wrote an article about this, and I think it's the Correct advice for virtually every startup thinking about SOC2:

https://fly.io/blog/soc2-the-screenshots-will-continue-until...

A few years before that, I wrote an article about what we learned from the consulting practice we ran building SOC2-supporting security programs for startups:

https://www.latacora.com/blog/2020/03/12/soc2-starting-seven...

I've had the experience, many times, of offering this advice in some forum and having someone try to rebut it, claiming that SOC2 is difficult, or that real customers will pick a SOC2 attestation apart with a fine-toothed comb looking for shortcuts you took, or that they built their whole security practice around SOC2. I can go all 12 rounds with someone on any of those points, but I think you can get most of my take from those two posts.

It doesn't look like fly.io publicly disclose who there auditor is so it is hard to judge that specific part of your experience. I'm not disagreeing with your perspective on startups. I'm saying that type 2 gets much harder when you are large. non-homogenous and lack sufficient automation and monitoring.

Our auditor is Aprio.

For anyone reading along, both of tptacek's comments are saying the same thing I'm saying. Or I'm saying the same thing he's saying.

Either way, go read his links.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.