4 ms·
Also, not surprising that LiteLLM's SOC2 auditor was Delve. The story writes itself.
by eoskx 6mo ago
Also, not surprising that LiteLLM's SOC2 auditor was Delve. The story writes itself.
- saganus 6mo agoWould a proper SOC2 audit have prevented this? I've been through SOC2 certifications in a few jobs and I'm not sure it makes you bullet proof, although maybe there's something I'm missing?
- shados 6mo agoSOC2 is just "the process we say we have, is what we do in practice". The process can be almost anything. Some auditors will push on stuff as "required", but they're often wrong. But all it means in the end is you can read up on how a company works and have some level of trust that they're not lying (too much). It makes absolutely zero guarantees about security practices, unless the documented process make these guarantees.
- saganus 6mo agoYeah, that was my understanding as well, so I fail to see how a proper SOC2 would have prevented this. I mean ideally a proper SOC2 would mean there are processes in place to reduce the likelihood of this happening, and then also processes to recover from if it did ended up happening. But the end result could've been essentially the same.
- kyyol 6mo agoIt wouldn't have. lol.
- stevekemp 6mo agoJust so long as it was a proper SOC2 audit, and not a copy-pasted job: https://news.ycombinator.com/item?id=47481729 https://news.ycombinator.com/item?id=47481729