# soc 2

Published articles for soc 2.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## How Ninth Wave built AI-powered open finance onboarding on Amazon Bedrock

DevFeed: [How Ninth Wave built AI-powered open finance onboarding on Amazon Bedrock](<https://devfeed.tech/articles/how-ninth-wave-built-ai-powered-open-finance-onboarding-on-amazon-bedrock-21548.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/machine-learning/how-ninth-wave-built-ai-powered-open-finance-onboarding-on-amazon-bedrock/>)

Author: Shawn Kelly

Published: 2026-09-14T15:58:57Z

Content type: article

Language: en

Sources: [Artificial Intelligence](<https://devfeed.tech/sources/artificial-intelligence.md>)

Topics: [Amazon Bedrock AgentCore](<https://devfeed.tech/topics/amazon-bedrock-agentcore.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [API](<https://devfeed.tech/topics/api.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Security](<https://devfeed.tech/topics/security.md>), [Finance](<https://devfeed.tech/topics/finance.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [advanced-300](<https://devfeed.tech/tags/advanced-300.md>), [ai](<https://devfeed.tech/tags/ai.md>), [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [amazon-bedrock-agentcore](<https://devfeed.tech/tags/amazon-bedrock-agentcore.md>), [apis](<https://devfeed.tech/tags/apis.md>), [customer-solutions](<https://devfeed.tech/tags/customer-solutions.md>), [fintech](<https://devfeed.tech/tags/fintech.md>), [onboarding](<https://devfeed.tech/tags/onboarding.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

The article describes how Ninth Wave built Compass, a multi-agent AI onboarding assistant powered by Amazon Bedrock AgentCore. Compass helps financial institutions validate bank APIs, map fields to Financial Data Exchange standards, and score production readiness while supporting secure, compliant open finance connectivity.

### Source excerpt

Learn how Ninth Wave built Compass, a multi-agent AI onboarding assistant on Amazon Bedrock AgentCore that validates bank APIs against Financial Data Exchange (FDX) standards, scores compliance, and compresses open finance onboarding from weeks to minutes while meeting SOC 2 and PCI DSS requirements.

## 🎙 How I AI: GPT-6 Astra is a banger + Stripe's AI playbook + Grok Bot vs. OpenClaw: why I replaced my entire agent stack

DevFeed: [🎙 How I AI: GPT-6 Astra is a banger + Stripe's AI playbook + Grok Bot vs. OpenClaw: why I replaced my entire agent stack](<https://devfeed.tech/articles/how-i-ai-gpt-6-astra-is-a-banger-stripe-s-ai-playbook-grok-bot-vs-openclaw-why-i-replaced-my-entire-agent-stack-40018.md>)

Original publisher: [Read original article](<https://www.lennysnewsletter.com/p/how-i-ai-gpt-6-astra-is-a-banger>)

Author: Claire Vo

Published: 2026-09-07T15:02:41Z

Content type: opinion

Language: en

Sources: [Lenny's Newsletter](<https://devfeed.tech/sources/lenny-s-newsletter.md>)

Topics: [Bot](<https://devfeed.tech/topics/bot.md>), [OpenClaw](<https://devfeed.tech/topics/openclaw.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Linear](<https://devfeed.tech/topics/linear.md>), [Slack](<https://devfeed.tech/topics/slack.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>)

Tags: [agent](<https://devfeed.tech/tags/agent.md>), [ai](<https://devfeed.tech/tags/ai.md>), [linear](<https://devfeed.tech/tags/linear.md>), [openclaw](<https://devfeed.tech/tags/openclaw.md>), [slack](<https://devfeed.tech/tags/slack.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

A podcast episode compares Grok Bot with OpenClaw through Claire's migration of her agent setup. It discusses using specialized bots for inboxes, family coordination, pull-request review, compliance monitoring, customer support, subscription audits, and shopping, along with permissions, multi-account access, and maintaining agent context and routines.

### Source excerpt

Your weekly listens from How I AI, part of the Lenny's Podcast Network

## Compliance documents are now available in Team settings

DevFeed: [Compliance documents are now available in Team settings](<https://devfeed.tech/articles/compliance-documents-are-now-available-in-team-settings-872.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/compliance-documents-are-now-available-in-team-settings>)

Author: Will Sather

Published: 2026-08-19T00:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [SOC](<https://devfeed.tech/topics/soc.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [trust-center](<https://devfeed.tech/tags/trust-center.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Vercel added a Compliance section to Team settings, allowing users to preview and download compliance documents such as SOC 2 Type 2 attestations and security policies. Downloads and previews are watermarked, and the feature is available on Pro and Enterprise plans.

### Source excerpt

A new Compliance section in Team settings lets you preview and download Vercel's compliance documents directly in the dashboard. These include attestations like SOC 2 Type 2, security policies, and other security documents that are available through the Trust Center. You can select a single document, an entire attestation, or multiple documents, and download them together as a single zip archive. Every download and preview is watermarked with your user and team information. Some entries link out to external resources instead, such as an auditor's public certificate directory. The Trust Center remains available for additional security information. Vercel's compliance documents are available on Pro and Enterprise plans. Learn more in the compliance documentation. Read more

## Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL

DevFeed: [Scaling Kubernetes governance: A platform engineer's guide to Kyverno and CEL](<https://devfeed.tech/articles/scaling-kubernetes-governance-a-platform-engineer-s-guide-to-kyverno-and-cel-12220.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/scaling-kubernetes-governance-a-platform-engineers-guide-to-kyverno-and-cel>)

Author: Koray Oksay

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>), [developer velocity](<https://devfeed.tech/topics/developer-velocity.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [opa](<https://devfeed.tech/topics/opa.md>), [rego](<https://devfeed.tech/topics/rego.md>)

Tags: [common-expression-language](<https://devfeed.tech/tags/common-expression-language.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cosign](<https://devfeed.tech/tags/cosign.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [developer-velocity](<https://devfeed.tech/tags/developer-velocity.md>), [governance](<https://devfeed.tech/tags/governance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [integration](<https://devfeed.tech/tags/integration.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kyverno](<https://devfeed.tech/tags/kyverno.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [platform](<https://devfeed.tech/tags/platform.md>), [policy](<https://devfeed.tech/tags/policy.md>), [security](<https://devfeed.tech/tags/security.md>), [security-policies](<https://devfeed.tech/tags/security-policies.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

A guide to using Kyverno and its Common Expression Language support for Kubernetes governance. It explains how platform engineering teams can enforce policies, automate resource changes, generate resources, verify image signatures, and maintain security and compliance while preserving developer velocity.

### Source excerpt

Kyverno with CEL support provides Policy-as-Code for Kubernetes governance. Enforce security, automate guardrails, and boost developer velocity for platform engineering teams.

## Trust you can verify: Figma is now ISO 42001 certified

DevFeed: [Trust you can verify: Figma is now ISO 42001 certified](<https://devfeed.tech/articles/trust-you-can-verify-figma-is-now-iso-42001-certified-9687.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/figma-is-now-iso-42001-certified/>)

Author: Tushar Badlani

Published: 2026-07-01T12:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [ai-governance](<https://devfeed.tech/topics/ai-governance.md>), [Figma](<https://devfeed.tech/topics/figma.md>), [responsible-ai](<https://devfeed.tech/topics/responsible-ai.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [figma](<https://devfeed.tech/tags/figma.md>), [iso](<https://devfeed.tech/tags/iso.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [responsible-ai](<https://devfeed.tech/tags/responsible-ai.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Figma announces ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System. An accredited independent auditor assessed Figma's AI governance policies, risk management processes, data practices, development practices, and technical safeguards across its platform.

### Source excerpt

Saying you use AI responsibly is easy, but proving it to an accredited auditor is harder. We decided that was a standard worth meeting.

## SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8

DevFeed: [SOC 2 Controls for Non-Human Identities: CC6, CC7, and CC8](<https://devfeed.tech/articles/soc-2-controls-for-non-human-identities-cc6-cc7-and-cc8-29856.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-non-human-identities/>)

Author: info@goteleport.com (Kayne McGladrey)

Published: 2026-06-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

This article explains how Teleport maps workload attestation, short-lived certificates, access rules, and audit logs for non-human identities to SOC 2 controls CC6, CC7, and CC8. It describes evidence auditors can use, including access rules, denied credential issuance logs, and Sigstore policy configurations where enabled.

### Source excerpt

Discover how to meet SOC 2 CC6, CC7, and CC8 controls for non-human identities.

## Audit trails are a feature, not a compliance tax

DevFeed: [Audit trails are a feature, not a compliance tax](<https://devfeed.tech/articles/audit-trails-are-a-feature-not-a-compliance-tax-9179.md>)

Original publisher: [Read original article](<https://webflowmarketingmain.com/blog/audit-trails-not-a-compliance-tax>)

Author: Mohit Bansal

Published: 2026-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Webflow Blog](<https://devfeed.tech/sources/webflow-blog.md>)

Topics: [Logging](<https://devfeed.tech/topics/logging.md>), [log management](<https://devfeed.tech/topics/log-management.md>), [SIEM, Security](<https://devfeed.tech/topics/siem-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

The article argues that audit logging has evolved from an overlooked compliance requirement into a product capability. Queryable, timestamped logs can support sales, vendor evaluations, accountability for AI agents, and more complete breach reconstruction.

### Source excerpt

Logging used to satisfy auditors. Now it closes deals, holds AI agents accountable, and decides whether you can reconstruct a breach.

## EU AI Act Compliance: Requirements, Risks, and What to Document

DevFeed: [EU AI Act Compliance: Requirements, Risks, and What to Document](<https://devfeed.tech/articles/eu-ai-act-compliance-requirements-risks-and-what-to-document-29638.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/eu-ai-act-requirements/>)

Author: info@goteleport.com (Kayne McGladrey, CISSP)

Published: 2026-04-15T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Documentation](<https://devfeed.tech/topics/documentation.md>), [audit](<https://devfeed.tech/topics/audit.md>), [data-governance](<https://devfeed.tech/topics/data-governance.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [data-governance](<https://devfeed.tech/tags/data-governance.md>), [dataset](<https://devfeed.tech/tags/dataset.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [development](<https://devfeed.tech/tags/development.md>), [documentation](<https://devfeed.tech/tags/documentation.md>), [eu](<https://devfeed.tech/tags/eu.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [lifecycle](<https://devfeed.tech/tags/lifecycle.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [nist](<https://devfeed.tech/tags/nist.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [versioning](<https://devfeed.tech/tags/versioning.md>)

### AI overview

A practical guide to EU AI Act compliance covering requirements, risks, technical documentation, logging, data governance, lifecycle evidence, traceability, monitoring, and human oversight. It outlines key compliance milestones from August 2025 through August 2027.

### Source excerpt

Cut through EU AI Act complexity with practical guidance on requirements, risks, and documentation.

## CockroachDB Plans Native X.509 SAN Support for SPIFFE and SPIRE Integration

DevFeed: [CockroachDB Plans Native X.509 SAN Support for SPIFFE and SPIRE Integration](<https://devfeed.tech/articles/modernizing-database-authentication-cockroachdb-embraces-zero-trust-with-spiffe-and-spire-support-23827.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/zero-trust-database-authentication-spiffe-spire>)

Author: Sanchit Khanna,Biplav Saraf

Published: 2026-03-13T00:00:00Z

Content type: article

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [SPIFFE](<https://devfeed.tech/topics/spiffe.md>), [SPIRE](<https://devfeed.tech/topics/spire.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Security](<https://devfeed.tech/topics/security.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>)

Tags: [architectures](<https://devfeed.tech/tags/architectures.md>), [auditability](<https://devfeed.tech/tags/auditability.md>), [aws-iam](<https://devfeed.tech/tags/aws-iam.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [database](<https://devfeed.tech/tags/database.md>), [distributed](<https://devfeed.tech/tags/distributed.md>), [processor](<https://devfeed.tech/tags/processor.md>), [regex](<https://devfeed.tech/tags/regex.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [spiffe](<https://devfeed.tech/tags/spiffe.md>), [spire](<https://devfeed.tech/tags/spire.md>), [standards](<https://devfeed.tech/tags/standards.md>), [teams](<https://devfeed.tech/tags/teams.md>), [verification](<https://devfeed.tech/tags/verification.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

The article previews planned CockroachDB authentication support for Subject Alternative Name fields in X.509 certificates. It explains how SAN support is intended to enable integration with SPIFFE and SPIRE and support regex-based identity mapping for cloud-native workloads.

### Source excerpt

In the evolution of cloud-native security, identity has become the new perimeter.

## How AI Agents Impact SOC 2 Trust Services Criteria

DevFeed: [How AI Agents Impact SOC 2 Trust Services Criteria](<https://devfeed.tech/articles/how-ai-agents-impact-soc-2-trust-services-criteria-29560.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/ai-agents-soc-2/>)

Author: info@goteleport.com (Kayne McGladrey)

Published: 2026-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [models](<https://devfeed.tech/tags/models.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>)

### AI overview

This article explains how agentic AI affects SOC 2 Trust Services Criteria. It maps SOC 2 requirements to autonomous systems and discusses controls for models, APIs, training data, automated decisions, AI outputs, and production execution records. It also outlines compliance challenges caused by autonomous actions and the need for effective, auditable oversight.

### Source excerpt

Learn how AI agents impact SOC 2 compliance and discover best practices for compliant agentic systems, models, and data.

## Chainguard + Second Front: A faster, more secure path into government markets

DevFeed: [Chainguard + Second Front: A faster, more secure path into government markets](<https://devfeed.tech/articles/chainguard-second-front-a-faster-more-secure-path-into-government-markets-12980.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-second-front-a-faster-more-secure-path-into-government-markets>)

Published: 2026-02-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-for-compliance](<https://devfeed.tech/tags/chainguard-for-compliance.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [container-image-compliance](<https://devfeed.tech/tags/container-image-compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve-remediation](<https://devfeed.tech/tags/cve-remediation.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [federal-compliance](<https://devfeed.tech/tags/federal-compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [iso](<https://devfeed.tech/tags/iso.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [second-front-systems](<https://devfeed.tech/tags/second-front-systems.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard and Second Front are partnering to help software companies pursue federal market requirements, including FedRAMP authorization and DoD impact-level accreditations. The article describes combining Chainguard's hardened container images with Second Front's Game Warden DevSecOps platform to support secure application delivery and vulnerability reduction.

### Source excerpt

Discover how Chainguard and Second Front are partnering to help build a secure path into government markets for your organization.

## Latacora Achieves AWS Advanced Tier Services Partner Status

DevFeed: [Latacora Achieves AWS Advanced Tier Services Partner Status](<https://devfeed.tech/articles/latacora-achieves-aws-advanced-tier-services-partner-status-29190.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2026/01/27/aws-advanced-tier-status/>)

Published: 2026-01-27T21:00:00Z

Content type: release

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [iam](<https://devfeed.tech/tags/iam.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>)

### AI overview

Latacora announces that it has achieved Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network. The company says the designation reflects validated technical expertise, AWS-certified professionals, and a proven record of customer success in cloud security and compliance.

### Source excerpt

We are thrilled to announce a major milestone for Latacora: we have achieved the Amazon Web Services (AWS) Advanced Tier Services Partner status within the AWS Partner Network (APN). This designation reflects Latacora's technical expertise and diligence in delivering exceptional cloud security and compliance solutions to our clients, and confirms that we have successfully completed a rigorous validation process demonstrating a proven track record of customer success delivered by a team of AWS-certified professionals with specialized technical capabilities.

## Applying SOC 2 with Chainguard: A practical guide for DevOps and engineering leaders

DevFeed: [Applying SOC 2 with Chainguard: A practical guide for DevOps and engineering leaders](<https://devfeed.tech/articles/applying-soc-2-with-chainguard-a-practical-guide-for-devops-and-engineering-leaders-12888.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/applying-soc-2-with-chainguard-a-practical-guide-for-devops-and-engineering-leaders>)

Published: 2026-01-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [SOC](<https://devfeed.tech/topics/soc.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [chainguard-sboms](<https://devfeed.tech/tags/chainguard-sboms.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [how-does-chainguard-help-with-soc-2](<https://devfeed.tech/tags/how-does-chainguard-help-with-soc-2.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-by-default](<https://devfeed.tech/tags/secure-by-default.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-chainguard](<https://devfeed.tech/tags/soc-2-chainguard.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

This practical guide explains how DevOps and engineering teams can apply SOC 2 principles to continuously changing cloud-native infrastructure and software supply chains. It covers Type 1 and Type 2 reporting, continuous control evidence, automated integrity checks, audit visibility, secure-by-default containers, and automated SBOMs, with Chainguard presented as a way to reduce audit friction without slowing delivery.

### Source excerpt

Learn how Chainguard helps DevOps teams meet SOC 2 requirements with secure-by-default containers, automated SBOMs, and continuous, audit-ready evidence.

## Ensuring Compliance and Governance in Kubernetes for Banking Workloads

DevFeed: [Ensuring Compliance and Governance in Kubernetes for Banking Workloads](<https://devfeed.tech/articles/ensuring-compliance-and-governance-in-kubernetes-for-banking-workloads-17642.md>)

Original publisher: [Read original article](<https://www.urolime.com/blogs/ensuring-compliance-and-governance-in-kubernetes-for-banking-workloads/>)

Author: Urolime Technologies

Published: 2025-11-04T12:50:33Z

Content type: article

Language: en

Sources: [Kubernetes Archives - Urolime Blogs](<https://devfeed.tech/sources/kubernetes-archives-urolime-blogs.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [governance](<https://devfeed.tech/tags/governance.md>), [kubernete](<https://devfeed.tech/tags/kubernete.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

This article examines how Kubernetes can support compliance and governance for banking workloads. It describes benefits such as scalability, high availability, and fault tolerance, while identifying governance and security challenges involving complex configurations, dynamic workloads, regulatory requirements, and audit visibility. It highlights Kubernetes consulting services and zero-trust network policies as relevant practices.

### Source excerpt

In the fast-paced banking era, data security and compliance is not a choice, but a necessity. Here Kubernetes has emerged as an adaptable platform to govern the containerized workloads. Its scalable, fault-tolerant application orchestration feature has proven it to be the ideal choice for the industry. In this blog we will analyze on how Kubernetes [...]

## Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster

DevFeed: [Simplify Continuous Compliance: How to Stay Audit-Ready and Ship Software Faster](<https://devfeed.tech/articles/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster-13233.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/simplify-continuous-compliance-how-to-stay-audit-ready-and-ship-software-faster>)

Published: 2025-10-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Software](<https://devfeed.tech/topics/software.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-security](<https://devfeed.tech/tags/chainguard-security.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cves](<https://devfeed.tech/tags/cves.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [stateramp](<https://devfeed.tech/tags/stateramp.md>)

### AI overview

This article explains how organizations can treat software compliance as a continuous practice rather than a periodic audit exercise. It describes how open-source components, CVE remediation, provenance, SBOM coverage, and audit evidence affect platform engineering, application security, development velocity, and regulated-market access, while presenting Chainguard as a solution provider.

### Source excerpt

Turn compliance into a growth driver with Chainguard. Eliminate CVEs, stay audit-ready, and meet FedRAMP, SOC 2, and ISO 27001 with secure images.

## Laravel Nightwatch Achieves SOC 2 Type 1 Certification

DevFeed: [Laravel Nightwatch Achieves SOC 2 Type 1 Certification](<https://devfeed.tech/articles/laravel-nightwatch-achieves-soc-2-type-1-certification-3788.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-nightwatch-achieves-soc-2-type-1-certification>)

Author: André Valentin

Published: 2025-10-09T16:55:44Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [log management](<https://devfeed.tech/topics/log-management.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [logging](<https://devfeed.tech/tags/logging.md>), [logs](<https://devfeed.tech/tags/logs.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Laravel Nightwatch has completed a SOC 2 Type 1 audit, confirming that its controls were suitably designed and in place at a specific point in time. The certification strengthens assurances around the security, confidentiality, availability, and handling of customers' monitoring and logging data. Laravel plans to pursue SOC 2 Type 2 certification for Nightwatch and extend similar compliance work to Laravel Forge.

### Source excerpt

Laravel Nightwatch achieves SOC 2 Type 1 certification, enhancing security and compliance for monitoring Laravel applications in enterprise environments.

## 10 reasons your CISO will love Temporal Cloud

DevFeed: [10 reasons your CISO will love Temporal Cloud](<https://devfeed.tech/articles/10-reasons-your-ciso-will-love-temporal-cloud-35692.md>)

Original publisher: [Read original article](<https://temporal.io/blog/10-reasons-your-ciso-will-love-temporal-cloud>)

Author: Tim Imkin

Published: 2025-09-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Temporal Blog](<https://devfeed.tech/sources/temporal-blog.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [saml](<https://devfeed.tech/topics/saml.md>), [ci](<https://devfeed.tech/topics/ci.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [api](<https://devfeed.tech/tags/api.md>), [api-keys](<https://devfeed.tech/tags/api-keys.md>), [aws](<https://devfeed.tech/tags/aws.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data](<https://devfeed.tech/tags/data.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [gdpr](<https://devfeed.tech/tags/gdpr.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [network](<https://devfeed.tech/tags/network.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [temporal-concepts](<https://devfeed.tech/tags/temporal-concepts.md>)

### AI overview

This article presents ten security and compliance characteristics of Temporal Cloud for CISO review. It describes client-side encryption with customer-controlled keys, outbound-only connectivity, mutual TLS, SAML SSO, RBAC, private connectivity options, secure debugging, and stated SOC 2, HIPAA, and GDPR support.

### Source excerpt

Discover 10 reasons CISOs choose Temporal Cloud: no plaintext data, no inbound connectivity, mTLS with your CA, private links, SOC 2/HIPAA, secure debugging.

## Laravel Cloud Achieves SOC 2 Type 2 Certification, Nightwatch and Forge Next

DevFeed: [Laravel Cloud Achieves SOC 2 Type 2 Certification, Nightwatch and Forge Next](<https://devfeed.tech/articles/laravel-cloud-achieves-soc-2-type-2-certification-nightwatch-and-forge-next-3756.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-achieves-soc-2-type-2-certification-nightwatch-and-forge-next>)

Author: André Valentin

Published: 2025-09-05T09:54:10Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [SOC](<https://devfeed.tech/topics/soc.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [attestation](<https://devfeed.tech/tags/attestation.md>), [audits](<https://devfeed.tech/tags/audits.md>), [availability](<https://devfeed.tech/tags/availability.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [reports](<https://devfeed.tech/tags/reports.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [standards](<https://devfeed.tech/tags/standards.md>), [trust](<https://devfeed.tech/tags/trust.md>), [verification](<https://devfeed.tech/tags/verification.md>)

### AI overview

Laravel Cloud achieved SOC 2 Type 2 certification for Security, Confidentiality, and Availability after completing its audit on July 31, 2025. The article explains the significance of SOC 2, contrasts Type 1 and Type 2 reports, and outlines planned SOC 2 audits for Nightwatch and Forge.

### Source excerpt

Laravel Cloud achieves SOC 2 Type 2 certification for Security, Confidentiality, and Availability. Read how Laravel's compliance roadmap includes Nightwatch and Forge SOC 2 audits.

## Laravel Cloud achieves SOC 2 Type 1 Compliance

DevFeed: [Laravel Cloud achieves SOC 2 Type 1 Compliance](<https://devfeed.tech/articles/laravel-cloud-achieves-soc-2-type-1-compliance-3755.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-achieves-soc-2-type-1-compliance>)

Author: André Valentin

Published: 2025-03-26T03:04:00Z

Content type: news

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [SOC](<https://devfeed.tech/topics/soc.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [data](<https://devfeed.tech/topics/data.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [availability](<https://devfeed.tech/tags/availability.md>), [certifications](<https://devfeed.tech/tags/certifications.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [soc](<https://devfeed.tech/tags/soc.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Laravel Cloud has completed a SOC 2 Type 1 audit, confirming that its security controls are suitably designed and implemented at a specific point in time. The article explains the certification's implications for access protection, availability, confidentiality, privacy, and operational transparency, and notes plans for SOC 2 Type 2 certification and certifications for Laravel Forge and Laravel Nightwatch.

### Source excerpt

SOC 2 Type 1 compliance achieved with SOC 2 Type 2 coming soon for Laravel Cloud as well as Laravel Forge and Laravel Nightwatch.

## Overcoming AppSec Challenges in FinServ: How CIBC Balances Speed, Security, and Compliance

DevFeed: [Overcoming AppSec Challenges in FinServ: How CIBC Balances Speed, Security, and Compliance](<https://devfeed.tech/articles/overcoming-appsec-challenges-in-finserv-how-cibc-balances-speed-security-and-compliance-8042.md>)

Original publisher: [Read original article](<https://snyk.io/blog/overcoming-appsec-challenges-in-finserv-how-cibc-balances-speed-security-and/>)

Author: Snyk Team

Published: 2025-03-20T04:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [DevSecOps](<https://devfeed.tech/topics/devsecops.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [threat detection](<https://devfeed.tech/topics/threat-detection.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [automation](<https://devfeed.tech/tags/automation.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [community](<https://devfeed.tech/tags/community.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [customer](<https://devfeed.tech/tags/customer.md>), [customer-featured](<https://devfeed.tech/tags/customer-featured.md>), [data-privacy](<https://devfeed.tech/tags/data-privacy.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [executive](<https://devfeed.tech/tags/executive.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [finserv](<https://devfeed.tech/tags/finserv.md>), [interest](<https://devfeed.tech/tags/interest.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [threat-detection](<https://devfeed.tech/tags/threat-detection.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article distills a fireside-chat discussion about application security challenges in financial services, featuring Snyk's Field CTO and CIBC's Senior Director of Security Service Management. It covers the tension between rapid innovation and strict compliance, risks from cybercrime, data privacy, cloud infrastructure, third-party services, legacy systems, and modern applications, and the role of automation, continuous security testing, monitoring, DevSecOps, AI-driven tools, and human oversight in vulnerability management.

### Source excerpt

Join Snyk's Field CTO, Steven Schmidt, and Mihai Saveschi, Senior Director of Security Service Management at CIBC, for an exclusive fireside chat on the evolving landscape of application security in financial services.

## Neon is HIPAA Compliant

DevFeed: [Neon is HIPAA Compliant](<https://devfeed.tech/articles/neon-is-hipaa-compliant-5328.md>)

Original publisher: [Read original article](<https://neon.com/blog/hipaa>)

Author: Busra Demir

Published: 2025-03-13T16:17:42Z

Content type: article

Language: en

Sources: [Blog -- Neon Docs](<https://devfeed.tech/sources/blog-neon-docs.md>)

Topics: [Database](<https://devfeed.tech/topics/database.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Shared Responsibility Model](<https://devfeed.tech/topics/shared-responsibility-model.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [company](<https://devfeed.tech/tags/company.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [logging](<https://devfeed.tech/tags/logging.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [product](<https://devfeed.tech/tags/product.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [shared-responsibility](<https://devfeed.tech/tags/shared-responsibility.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

Neon announces completion of its HIPAA compliance audit, enabling customers to store Protected Health Information (PHI) on its database platform. The article describes safeguards including encryption, role-based access control, audit logging, continuous monitoring, incident response, breach notification, employee training, third-party requirements, and shared customer responsibilities.

### Source excerpt

Neon has completed its HIPAA compliance audit, adding to our security achievements: SOC 2 Type 2, ISO 27001, ISO 27701, GDPR, and CCPA. If your company needs a HIPAA-compliant database, Neon can now securely store Protected Health Information (PHI). What is HIPAA Compliance? The...

## Turso completed SOC2 Type II compliance with zero issues

DevFeed: [Turso completed SOC2 Type II compliance with zero issues](<https://devfeed.tech/articles/turso-completed-soc2-type-ii-compliance-with-zero-issues-6056.md>)

Original publisher: [Read original article](<https://turso.tech/blog/turso-achieves-soc2-compliance>)

Author: Glauber Costa

Published: 2024-07-09T00:00:00Z

Content type: news

Language: en

Sources: [Turso Blog](<https://devfeed.tech/sources/turso-blog.md>)

Topics: [Turso](<https://devfeed.tech/topics/turso.md>), [Security](<https://devfeed.tech/topics/security.md>), [SOC](<https://devfeed.tech/topics/soc.md>), [Data Management](<https://devfeed.tech/topics/data-management.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [github](<https://devfeed.tech/tags/github.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [soc2](<https://devfeed.tech/tags/soc2.md>), [turso](<https://devfeed.tech/tags/turso.md>), [vanta](<https://devfeed.tech/tags/vanta.md>)

### AI overview

Turso announces that it completed a SOC 2 Type II compliance audit with zero issues. The article explains that the audit assessed its information-security policies, controls, and procedures, and describes how Vanta helped the small team automate compliance tasks and maintain velocity.

### Source excerpt

Turso's SOC2 audit is now complete. And we passed with flying colors!

## Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones

DevFeed: [Teleport Achieves ISO 27001, HIPAA, and SOC 2 Compliance Milestones](<https://devfeed.tech/articles/teleport-achieves-iso-27001-hipaa-and-soc-2-compliance-milestones-29855.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/soc2-iso-27001-hipaa/>)

Author: reed@goteleport.com (Reed Loden)

Published: 2023-08-11T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [soc 2 compliance](<https://devfeed.tech/topics/soc-2-compliance.md>), [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Security](<https://devfeed.tech/topics/security.md>), [trust](<https://devfeed.tech/topics/trust.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Availability](<https://devfeed.tech/topics/availability.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [iso-27001](<https://devfeed.tech/tags/iso-27001.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [soc-2-compliance](<https://devfeed.tech/tags/soc-2-compliance.md>), [trust](<https://devfeed.tech/tags/trust.md>)

### AI overview

Teleport announces ISO 27001 certification, HIPAA compliance, and an expanded SOC 2 Type II report covering the Confidentiality and Availability trust service criteria.

### Source excerpt

An overview of Teleport Achieved ISO 27001, HIPAA, and SOC 2 Compliance Milestones

## Tinybird is SOC 2 Type II compliant

DevFeed: [Tinybird is SOC 2 Type II compliant](<https://devfeed.tech/articles/tinybird-is-soc-2-type-ii-compliant-18705.md>)

Original publisher: [Read original article](<https://www.tinybird.co/blog/tinybird-is-soc-2-type-ii>)

Author: Tinybird

Published: 2022-12-19T00:00:00Z

Content type: release

Language: en

Sources: [Tinybird](<https://devfeed.tech/sources/tinybird.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [security](<https://devfeed.tech/tags/security.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>), [tinybird-news](<https://devfeed.tech/tags/tinybird-news.md>)

### AI overview

Tinybird announces that it is SOC 2 Type II certified, highlighting enterprise security and compliance.

### Source excerpt

Tinybird is SOC 2 Type II certified. Enterprise security without enterprise friction. Your compliance team will thank you.

[Next page](<https://devfeed.tech/tags/soc-2.md?cursor=WyIyMDIyLTEyLTE5VDAwOjAwOjAwKzAwOjAwIiwgIjJkOGY5NzI0LTZhODYtNGVhOC05ODZlLWY4NzA0NWRhNjA5ZSJd>)