4 ms·
You've nailed exactly the problem — the "mentally joining logs across systems with no shared context" is the core pain. Each tool gives you a slice but nobody g
by Gowrishankarhq 7mo ago
You've nailed exactly the problem — the "mentally joining logs across systems with no shared context" is the core pain. Each tool gives you a slice but nobody gives you the full picture in one place.
On SOC2 — you're right, I'm not generating audit evidence artifacts (yet). Right now it's a gap assessment — it scans infra signals like encryption at rest, public access configs, logging enabled/disabled, IAM policies, and maps them to SOC2 criteria. It's honest about what it can't assess — access reviews, change management, vendor questionnaires — and explicitly flags those as out of scope. The goal is to give a team a starting point, not replace an auditor.
On credentials — currently key-based, encrypted at rest with Fernet. OIDC/role-based is on the roadmap. The honest tradeoff is that OIDC requires more setup on the user side which adds friction for early adoption — but for teams with real compliance requirements it's clearly the right answer. Planning to add AWS AssumeRole + GCP Workload Identity as the next auth layer.
Would love your feedback on what a useful evidence artifact output would look like — you clearly know what auditors actually want to see.