There seem to be a lot of illegitimate SOC 2 certifications happening at the moment. If someone can't tell yo…
There seem to be a lot of illegitimate SOC 2 certifications happening at the moment. If someone can't tell you who performed the audit, it's not legitimate. In case you missed it, a Y Combinator startup called Delve was completely faking reports (https://deepdelver.substack.com/p/delve-fake-compliance-as-a-service) using Indian certification mills and faking information for the whole process. They were the worst offender, but imo it really boils down to this: is someone disclosing the licensed CPA firm that conducted the audit? If they are not they are lying, it's that simple. They will say who made the report is under NDA, but there is an important difference between the full report, and knowing who conducted the audit. It doesn't make sense to pay a licensed reputable firm and then refuse to disclose who that was. This would also be completely unacceptable in DeFi for very common sense reasons. Of the services you use that claim to be SOC 2 certified (especially as a founder), you should actually check how many disclose who performed the audit. It's kind of shocking how uncommon it is for companies to disclose that obviously necessary information. I'm not an expert on the topic, but I don't think you need to be to see what's happening across the vast majority of small/medium sized orgs claiming SOC 2 compliance