Hacker News new | ask | show | jobs
Ask HN: How do you audit your app for compliance?
3 points by Luxter 16 hours ago
Compliance software like Vanta, Drata and similar only read 3rd party APIs (AWS, Github, Okta etc.) but cannot automatically audit your app that actually uses them, e.g. who had admin access in your app at given point in time.

I'm an engineer in Poland with no compliance background, so if you did an audit for your app in the past (SOC 2/ISO 27001/HIPAA/PCI etc.):

1. What did you produce (Screenshots? SQL query? CSV?)

2. Who did it in your company? How long did it take? Is it a recurring task?

3. Did you build anything in-house for it? Are you still maintaining it?

If you used a tool for that then I'd appreciate if you tell me which one.