5 ms·
Both are true simultaneously: * professional security is needed, and this is what it costs * the cost is more of a barrier to smaller companies (and hence pro
by jdp23 8y ago
Both are true simultaneously:
* professional security is needed, and this is what it costs
* the cost is more of a barrier to smaller companies (and hence provides an advantage to larger companies)
It seems like an inherent tension; I'm not sure how to get around it.
- QuercusMax 8y agoSeems like a business opportunity for somebody to create a compliant API that allows other people to write software that accesses gmail data in a limited fashion.
- J-Kuhn 8y agoI'd say that this is nearly impossible. We talk about two different data sets here: * The actual User data. * Data from third persons, including, but not limited to their e-mail address. While a user can agree that their own data should be processed by a third party, the problem is that he cannot consent for other people. And in my understanding (INAL), every part of the software where those third person information is transferred or processed needs to be part of that full assessment. A limited API that does not give out any third persons data would have to somehow filter out all the information of all third partys.
- Alex3917 8y agoTheir TOS explicitly forbids doing that.
- hurlio333 8y agoThese costs definitely seem high. As a reference point - to get through the Salesforce AppExchange security review process, believe the cost is $2,700. It’s an extremely rigorous security testing as one might imagine with corporate CRM data.
- kiallmacinnes 8y agoIs that ran by SalesForce? If so, could they be subsidising it?
- hurlio333 8y agoYes AppExchange is run by Salesforce and they likely do subsidize the security review. They also take a percentage of revenues from direct AppExchange installs(believe 15-25%) after listing. SF wants third party devs building out functionality and the ecosystem. Google seems to be taking a different approach...