5 ms·
You actually do need to have Enterprise security and authentication features if you intend to sell to Enterprise customers. (SOC2, OAuth, SAML etc)
by bigtones 4y ago
You actually do need to have Enterprise security and authentication features if you intend to sell to Enterprise customers. (SOC2, OAuth, SAML etc)
- JacobThreeThree 4y agoIt's true. These types of security certifications like SOC2 are quickly becoming a minimum requirement.
- bob1029 4y agoI am on calls all week with our banking clients about getting SAML/SSO squared away once and for all. We are having a lot more nervous takes around legacy LDAP/AD auth mechanisms these days.
- dt3ft 4y agoI developed SAML/SSO integration for an application used by the Swiss UBS which initially relied on individual accounts, not even AD. Tricky stuff.
- formercoder 4y agoI did SAML with Barclays years ago. The hardest part was getting someone there to click enable for our app. They’d never reply to my emails so I called them until they picked up. Then it was done in 30 minutes.
- grinich 4y agoSmall plug for http://WorkOS.com http://WorkOS.com (where I work). It’s an API for easily adding SAML, SCIM, and more. Currently being used in production by Vercel, Planetscale, Webflow, and +200 other apps.
- hiharryhere 4y agoI can vouch for this - I’ve just rolled out workos with three enterprise customers in the last 6 months. Super simple, great docs. Had been putting off SSO for years hoping something would come along and solve it for me. E.g I know nothing about Azure AD but I just emailed the WorkOS setup link to our customer’s IT team, they followed the instructions and it just worked. No back and forth. Can’t recommend enough.
- ozim 4y agoI agree with article because you don't need to have it to "start talking" with Enterprise customers. You probably have to prove that you have these on your roadmap and that you have engineering team that can implement these in not so distant future. That you know these things exist and have will to invest in it in future.
- haswell 4y agoThese capabilities are increasingly required just to get in the door, depending on your target customer. The alternative is that your product becomes a security exception, which infosec teams are more and more unwilling to grant, for pretty good reasons. The good news for product teams is that there are more and more off-the-shelf options that can be quickly integrated vs. having to start from scratch. But the main point of this comment is: I think you’re right that “near term roadmap” was good enough a few years ago, but less so now, and continuing to trend towards “not acceptable” if selling to enterprise customers. (Observations as a recent/former auth PM at a SaaS/PaaS that sold primarily to enterprise customers).
- pid-1 4y agoYou actually need OAuth / SAML if you give 2 shits about your customers.
- GauntletWizard 4y agoYou need OAuth and not to use SAML. Saml is insecure by design: https://joonas.fi/2021/08/saml-is-insecure-by-design/ https://joonas.fi/2021/08/saml-is-insecure-by-design/
- akullpp 4y agoYep, I'm working at a Series B startup and I can tell you, you absolutely need SOC 2 or ISO and/or GDPR compliance based on your market. It's not optional, you will lose business if you don't.