Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I've heard they claimed to have SOC 2 security compliance, but refused to prove it (show the SOC2 report to customers) -- that's really fishy.


They had that cert for the last ~3 years and were audited yearly and had a standard package to share with clients so doubt there's much to this rumor


Nope, just confirmed, they refused to share SOC2 Report with their paying customers.


Can someone explain why potential customers would put up with this?

I'd think that the last thing a company wants to do is hire an bookkeeping company that seems shady.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: