SOC II
topic on 6 shows · 9 statements across 8 episodes
In Depth
Startups For the Rest of Us
Cheeky Pint
Latent Space
A Product Market Fit Show
20VC
9 statements about SOC II, every show
Kolter: SOC 2 is not a great security compliance model
“So, so I think SOC II is not a great model. We'll just say, but it is a model.”
Collison: Real-world industry experience is required to discover massive B2B markets
“You talk to university students and often their ideas for companies are pretty half-baked. Yeah, it's find my friends. It's like a college textbook exchange app, you know, but you know, there's like the five apps or whatever. Whereas so frequently what happens…”
Cacioppo: The startup SOC 2 market in 2018 was zero dollars
“The market for startups getting SOC II in 2018 was zero dollars. Truly zero.”
Only 10-15% of TinySeed portfolio companies have SOC 2 or ISO
“Across my entire portfolio, TinySeed Plus private investments, I'm about to be at like, two 34, two 35. Companies. And probably, if I were to guess, it's maybe 10%, 15% of those have a, like a SOC II or an ISO.”
Stauch: Serval prioritized enterprise compliance on day one, unlike Verkada
“Verkata waited several years to support things like SCIM and SSO and SOC II and various compliance frameworks. We did all of those things from day one because we knew that that was going to be a blocker to sell into the large accounts that unlocked the bigger …”
Kenney: SOC 2 Controls Provide Vital Business Continuity for Micro-Startups
“So, like, it's funny, but some say, oh, you're too small to do it right now. But because we're small, I look at these things, and I'm like, these are actually kind of, like, viability of the business. If we can resolve these, It actually kind of helps me sleep…”
Nejatian: Enterprise software is terrible because companies build directly for compliance
“What most people end up doing Is doing this the wrong way, right? They go to SOC II saying, what can I build? And then they build the thing SOC II says you shall build. Which is why all enterprise software ends up being shit.”
Walling: Bootstrappers can achieve HIPAA compliance on a tight budget
“HIPAA compliance is not out of the realm of bootstrappers. Now, if you want SOC II compliance, that becomes pretty pricey, pretty quick. HIPAA compliance is different. And of course, this is not legal nor HIPAA advice that I'm giving you, but I have known many…”
McLeod: Background checks are now mandatory for SOC-2, ISO, and PCI compliance
“Things have changed now where background screening is, you know, you need it for SOC-II, you need it for ISO, you need it for PCI, you need it for pretty much every business these days needs Some type of background check, and that process is, is really painful…”