Hermes Wiki

SOC2

Audit framework proving security/availability/confidentiality controls exist and are followed — mostly a B2B/enterprise-sales requirement. Moved here from Regulatory/ since it's an attestation/audit standard, not a law.

Why we need this / what value this brings

The de facto standard enterprise B2B customers ask for as proof of security practices — not having it can silently block deals.

When to use this

Once an enterprise sale or partnership explicitly requires it — not worth pursuing speculatively pre-revenue.

How to use or implement this

Start with a Type I (point-in-time) readiness assessment before committing to a Type II audit, which requires controls to have been running over a period.

Research questions

  • Not relevant pre-revenue, but worth knowing what it requires before it becomes a sales blocker with enterprise provider partners.

Empty folder — drop notes, links, and findings here as you research.

Hermes Wiki