Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joetheone
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
joetheone
5y ago
We practice what we preach when it comes to security. So all customer data is encrypted at rest and in transit, access is limited using RBAC, we have 2FA on everything, etc. We also never send customer security data to 3rd parties, so your
2.
▲
by
joetheone
5y ago
Thanks for the kind words!
3.
▲
by
joetheone
5y ago
If you have that problem in the future, please do reach out to us! That is an interesting hypothesis, and to be perfectly honest, I'm not sure what the answer is. There are plenty of existing business where you can pay for outside secu
4.
▲
by
joetheone
6y ago
That sounds terrible! Im so sorry!
5.
▲
by
joetheone
6y ago
The ultimate success or failure of our business depends on our ability to get our NLP to deliver high quality answers and minimize the time our own internal reviewers need to spend on each questionnaire. We are making progress here every da
6.
▲
by
joetheone
6y ago
Yep. Having them now gets you a seat at the table, but (usually) does not get you out of the questionnaire entirely.
7.
▲
by
joetheone
6y ago
You're totally right, which is why I said to read over the NDA before signing :) I fully admit that we do not have the legal expertise to try and tackle that problem at this point.
8.
▲
by
joetheone
6y ago
No worries. 15 pages sounds like a doozy!
9.
▲
by
joetheone
6y ago
No need to feel bad It's a cost of doing business :)
10.
▲
by
joetheone
6y ago
What you describe is exactly what we do. Every single answer output by Stacksi is required to be explicitly approved by a member of our client's infosec team before it can be exported and used. Questions that we don't know the ans
11.
▲
by
joetheone
6y ago
You're right. My answers go something like this: 1. We handle a company's security documentation the same way companies treat any sensitive info they are storing (credit card data, PII, etc). We store it encrypted at rest and in t
12.
▲
by
joetheone
6y ago
Every single answer that comes out of Stacksi needs to be approved by an employee of the client before it can be exported and downloaded. The vast majority of answers to questions comes directly from a client's own security policies, w
13.
▲
by
joetheone
6y ago
You sound like you should talk to us and get your time back :) A lot of auditors make it seems like once you have your SOC2 or ISO27001 certification that you'll be free from these forever, but our finding is that it might get you out
14.
▲
by
joetheone
6y ago
I'd love to see stats on that. I'd bet that rather than losing the deal entirely, the more common case is that the deal gets delayed (possibly significantly) if something is flagged in a security review. After all, even standards
15.
▲
by
joetheone
6y ago
If you want to go in depth on our operational or security controls in due diligence as a potential customer, we'd be happy to do so over email. You could even send us a questionnaire ;) However, you'll have to forgive us for not p
16.
▲
by
joetheone
6y ago
Stacksi is happy to sign (and has signed!) numerous NDAs with our clients. If you're talking about the NDA process between vendors and assessors, that is a whole different can of worms which we have not really waded into at this point.
17.
▲
by
joetheone
6y ago
If you're not answering many questionnaires, it's totally possible that you don't need help. We have customers who are filling out 5-10 of these per week, and the time really adds up. We also have absolutely no requirement fo
18.
▲
by
joetheone
6y ago
Loopio and RFP.io are direct competitors. They are both good tools, but are designed for RFP response in general and not security specific. RFPs do tend to have security sections, so there is some overlap for sure, but these guys by definit
19.
▲
by
joetheone
6y ago
I've never seen a 200 page one, but 200+ questions is fairy common. At 15 pages yours probably clocks in around there at least :)
20.
▲
by
joetheone
6y ago
Hi there! Questionnaires get sent when companies want to do business together that requires sharing sensitive info with each other. I envy that you have never had to deal with these!
21.
▲
by
joetheone
6y ago
We totally agree! At our last company these were a major PITA and slowed us down a lot because when we first started working with other businesses, we were not prepared to handle them at all. We want to help remove the burden from small sof
22.
▲
by
joetheone
6y ago
We appreciate the comment :)
23.
▲
by
joetheone
6y ago
We'd love to! Reach out to us!
24.
▲
by
joetheone
6y ago
Admittedly, I have not seen any of Skypher besides their website. That said, the biggest differentiator that I see is that we use a human in the loop model, while Skypher is a purely software solution. In other industries, an AI that can an
25.
▲
by
joetheone
6y ago
We definitely think about that, but our previous experience is as startup founders so we're starting out by addressing a problem we know very well.
26.
▲
by
joetheone
6y ago
Thanks for the kind words! If you ever have a questionnaire that needs answering or just generally have questions about security & compliance, drop us a line and we'd be happy to chat :)
27.
▲
by
joetheone
6y ago
These types of questions are exactly why we have a human-in-the-loop model :) Our AI is probably not going to touch this as it's very unlikely a good answer in in your documentation, so a real person will take a stab at it and then fla
28.
▲
by
joetheone
6y ago
It's a webflow template: https://softbit-template.webflow.io/
29.
▲
by
joetheone
6y ago
This is actually what we’re trying to build towards :) Our first products rely on the policies that company’s put together themselves, but we’re building towards tools that they could use to show more convincingly that information written i
30.
▲
by
joetheone
14y ago
Interesting. I feel like the difference is that trips which require air transportation are planned in advance, so people start thinking about them long before they plan a trip down the street via lyft, sidecar, uber, or the like.
More ›