| ▲ | staticassertion 2 hours ago | |||||||
The first thing you do when you're getting this information is get PDFs from these vendors like their SOC2 attestation etc. You wouldn't just screenshot the page, that would be nuts. Any vendor who you work with should make it trivial to access these docs, even little baby startups usually make it quite accessible - although often under NDA or contract, but once that's over with you just download a zip and everything is there. | ||||||||
| ▲ | thayne 21 minutes ago | parent [-] | |||||||
> You wouldn't just screenshot the page, that would be nuts. That's what I thought the first time I was involved in a SOC2 audit. But a lot of the "evidence" I sent was just screenshots. Granted, the stuff I did wasn't legal documents, it was things like the output of commands, pages from cloud consoles, etc. | ||||||||
| ||||||||