This year's SOC-2 audit is even worse than last year.

I got a not so technical auditor and it's hard to explain why git repository with no code but critical in other way does not have dependency CVE scan enabled.

Any recommendations for next year's SOC-2 auditor ?

#soc_2compliance #soc2

Lumoar - SOC 2 Compliance for Tech Startups

Lumoar is a compliance-as-a-service platform designed for tech startups to achieve SOC 2 readiness efficiently and affordably. Streamline your audit process.

Lumoar