Show HN: AuditBadger – SOC 2 and ISO 27001 – AI drafts, you approve
auditbadger.comHi,
Wanted to share something I've been working on for over a year. AuditBadger is a compliance management platform that uses AI to write policies (there are underlying "templates" with basic requirements), rewrite controls (or trust service criterions) to match the company context, help figure out your own controls, does initial risk assessment, and business continuity planning (which at least gives you an example of how the process should look like).
Fun fact - I wanted to share this a year ago, but then I spotted something similar here. The most common comment was about lacking the SOC 2 report, so I decided to pick the fight. I got SOC 2 Type I first, and then recently finished SOC 2 Type II using the tool alone. It took some time - both learning the process, the SOC 2 gotchas, and implementing automatic evidence collection.
We're now adding support for the European AI Act and NIS 2; HIPAA is already there (though it requires me to explicitly enable it for customers who want to test it), and CyberEssentials and ENS are coming later this year.
The platform is now complete, but my business partner (ISO 27001 Lead Auditor) and I are still dog-fooding it. Everything we build is either based on our own pain points or our customers'—most of them joined our Slack where we try to help them if they get stuck.
If you have any questions, I'll be happy to answer them all.
SOC 2 is security theater. You're selling shovels for a fake gold rush.
I kinda agree, I won't pretend it's otherwise. But I do believe, that particularly now, it's important to keep the bare minimum. And some aspects of managing compliance are kinda useful (like checking that you have a lot of backups, but no decryption key).
Not sure I agree. It might sound like theater if you expect it to solve your security issues. But it is extremely good at finding undocumented or broken processes - these processes tend to hide the biggest offenders.