Hacker News new | ask | show | jobs
by crankylinuxuser 2721 days ago
I'm a sysad for a small company. We have an on-prem solution and a social media app.

We don't sell our data. We don't trade it. And we adhere to a fedramp medium (in spirit), even though the social media site wasn't checked for that.

Users have control over their profile, and we admins cant even read it (unless we read raw DB, and we dont). And deletion requests entail in zeroing out all user's data. The next day, zeroed data is then purged completely.

Seriously, companies can do this right. And I work for one that absolutely does this right.