4 ms·
Since this is enterprise tool, what's your security posture like? Are you compliant/certified with framework's like ISO27001?
by aktive0 7y ago
Since this is enterprise tool, what's your security posture like? Are you compliant/certified with framework's like ISO27001?
- grinich 7y agoWe're currently in the middle of our SOC-2 Type 2 observation period and should have that certification in Q2. The company is barely 1 year old and the process of certification can be a bit slow. Other attestations including ISO/IEC 27001, 27017, and 27018 will come later. We also have a lot of internal practices and policy for how we secure WorkOS while still allowing our engineering team to ship code incredibly fast. It involves separation of duties, hardware security keys (YubiKey), and lots of automation with alerting. Hopefully we can write something public about it later this year. Many of the ideas came from Stripe's security team. (Thanks Angie! <3)
- j4ah4n 7y agoWill you be supporting HIPAA/PIPEDA as well? I'm just teeing up all of this work for a healthcare SaaS offering, non-trivial. We're presently deployed as a "per-customer" model as some require enterprise options, others not so much. Would be great to have a tool that fills those gaps simply when/as required. Looks great, I'll definitely be going through it in more detail after work.
- grinich 7y agoYep - everything in WorkOS already pipes into our Audit Log so it's quite close. Would love to learn more about your app. Send me a note and we can chat? mg@workos.com
- Reebz 7y agoThis is extremely impressive. The value prop, the product, all of it. It resonates. I was at a startup 5 or so years ago, and now am at a very large company. The world of pain you enter as a small shop when the Large Co. takes you through their third-party compliance and enterprise IT requirements are mind boggling. WorkOS seems to be that critical and much overdue on-ramp between startups and the FT500.