Simon Willison’s Weblog

Subscribe

7th July 2022

SOC2 is about the security of the company, not the company’s products. A SOC2 audit would tell you something about whether the customer support team could pop a shell on production machines; it wouldn’t tell you anything about whether an attacker could pop a shell with a SQL Injection vulnerability.

Thomas Ptacek

This is a quotation collected by Simon Willison, posted on 7th July 2022.