<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: arjavmehta</title><link>https://news.ycombinator.com/user?id=arjavmehta</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 10 Jun 2026 00:00:36 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=arjavmehta" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Show HN: Built a verifiable, open-source SoC 2 readiness scanner]]></title><description><![CDATA[
<p>After speaking with over 50+ CISOs, DevOps, & pre-series A founders for months, I realized a problem in the GRC industry. SOC 2 automation exists, but people are split between trusting these black-box tools with systems that are continuously changing. As a result audits are slow & mistrusted.<p>Right now the most important thing is verifiability & depth, rather than just compliance automation-because it does exist, everywhere.<p>Here's what I did from learning this:<p>-> Created an open-source AWS Evidence Scanner & Control Mapper for lean, pre-series A AWS-Native teams thinking about SOC 2 Type l or are undergoing SOC 2 Type l audit. Collects across 15+ AWS Services to 12 critical controls in the trust-service criteria.<p>Why open-source? Accessibility for people who might have their hands tied choosing between expensive GRC tools. Its also used as a trust-mechanism. Code is right there. A CEO or auditor can read exactly what API calls we make before giving us the role ARN.<p>-> I included a paid report embedded within the tool (open-core model). Users have the option to pay for the report in which every finding traces back to the API call that produced it. SHA-256 hashed (at a fraction of the cost of bigger legacy platforms). With remediation steps & a compliance-copilot to help with other parts of the Type l process beyond evidence collection (like policy writing, risk assessment, etc).<p>Why paid report? The best way to make the auditors job as easy as possible is to give them a verifiable package where the evidence is right there in front of them, timestamped so they can see what happened, when (rooted in AWS APIs). No black-box, no way to fake it. Saving weeks of back & forth between auditors and clients, with the click of a few buttons.<p>An auditor can re-run the same API call, hash the response themselves, and verify it matches what's in the report.<p>Value: 30 seconds to deploy. 5 mins to run the scan & evidence is collected & mapped. Paid report includes verifiable evidence companies can send to their auditor. Paid features include a co-pilot to help with audit-readiness beyond just evidence collection.<p>-> Understand Limitations.<p>I understand the scope of this product is pretty limited in part because its also very new. I'm not going to claim it solves all of compliance, because it  doesn't. It makes a very time-consuming part of the process very accessible to be automated & gives an auditor a report they can rely on.<p>What now?
Anyone who's gone through, thinking about or is in the middle of SOC 2, would love your reaction to the output, even if it's critical. Also looking for early testers/users.<p>repo here: <a href="https://github.com/adog0822/AWS-Evidence-Layer" rel="nofollow">https://github.com/adog0822/AWS-Evidence-Layer</a><p>try it here: <a href="https://loxeai.com" rel="nofollow">https://loxeai.com</a></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48164906">https://news.ycombinator.com/item?id=48164906</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 17 May 2026 00:02:18 +0000</pubDate><link>https://loxeai.com</link><dc:creator>arjavmehta</dc:creator><comments>https://news.ycombinator.com/item?id=48164906</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48164906</guid></item><item><title><![CDATA[New comment by arjavmehta in "Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?"]]></title><description><![CDATA[
<p>Yes, its very possible.<p>What's most important for you would just being able to prove to your customers that you do what you say you do.<p>The core issue isn't SOC 2, it's verifiability. Your customers want to know that what you claim about your security posture is actually true, not just documented.<p>I've actually been deeply exploring the compliance space lately and a few days ago I built an open-core pre-audit readiness layer. Every finding traces back to the raw AWS API call that produced it, SHA-256 hashed. An auditor or skeptical customer can verify it themselves without taking your word for it.<p>Its more SOC 2-esque, & its pre-audit readiness not a certification, but it does the job of proving you are trustworthy.<p>repo if relevant: <a href="https://github.com/adog0822/AWS-Evidence-Layer" rel="nofollow">https://github.com/adog0822/AWS-Evidence-Layer</a><p>(I built this, disclosing upfront)</p>
]]></description><pubDate>Sat, 16 May 2026 08:58:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=48158313</link><dc:creator>arjavmehta</dc:creator><comments>https://news.ycombinator.com/item?id=48158313</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48158313</guid></item><item><title><![CDATA[Open-source AWS evidence collector for SoC 2 audits]]></title><description><![CDATA[
<p>Article URL: <a href="https://loxeai.com">https://loxeai.com</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48070885">https://news.ycombinator.com/item?id=48070885</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 09 May 2026 01:32:50 +0000</pubDate><link>https://loxeai.com</link><dc:creator>arjavmehta</dc:creator><comments>https://news.ycombinator.com/item?id=48070885</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48070885</guid></item></channel></rss>