| ▲ | louthy 5 hours ago | |||||||
That’s not how it works. Especially with compliance schemes like ISO27001, Hippa, etc. they require an audit chain through the supply line. Obviously it depends on what data you’re managing to whether your customers care about whether you’re audited, or not, but if you’re selling enterprise software then this is all part of your compliance process. You can’t offload that responsibility, you have to make sure your suppliers comply too. | ||||||||
| ▲ | augment_me 4 hours ago | parent [-] | |||||||
Maybe it's different in the US, but in the EU you can get certified to be able to handle certain data securely, for example getting SOC/ISO/ESC certifications. When you then are looking for storage solutions you can in practice absolve yourself from liability/gross negligence if you choose a provider that has these certifications. So when an org needs cheap solutions, they find the cheapest compliant provider and hands are clean. | ||||||||
| ||||||||