3 ms·
SaaS vendors that manage PII data needs to go through the - security questionnaires, privacy assessments, vendor risk reviews, procurement due diligence, eviden
by joddystreet 2mo ago
SaaS vendors that manage PII data needs to go through the - security questionnaires, privacy assessments, vendor risk reviews, procurement due diligence, evidence requests - sent by the customer security team.
At digicred, we were managing these in google drive and jira, but with 500+ enterprise customers, and their annual vendor reviews, this practice became unmanagable.
CAOS is a dedicated workspace that helps us manage these assessments like projects, additionally, CAOS turns the questionnaires into a system of record. Questionnaires become structured, answerable work. Finished answers and your compliance documents become a searchable, citable corpus. The next questionnaire starts from what you already said, with every claim traceable to the document or prior answer it came from.
It is self-hosted. Your policies, your answers, and your customers' questionnaires stay on your infrastructure.
Recently open-sourced - https://github.com/DigiCred-OSS/caos-os https://github.com/DigiCred-OSS/caos-os
- joddystreet 2mo agoFollow up - What have you been curious about lately? - Canvas for Agents - LLMs for learning. | Idea: Don't use LLMs for summarisation. | Proof of concept - https://www.youtube.com/watch?v=1oF9M5hAazw https://www.youtube.com/watch?v=1oF9M5hAazw | Repo - https://github.com/veris-pr/bwaiz https://github.com/veris-pr/bwaiz