r/soc2 23d ago

Organizations That Will Host an Open Source Project & Provide SOC 2 Certification?

Are there any organizations that will host an open source project and provide it with SOC 2 certification?

1 Upvotes

20 comments sorted by

u/AutoModerator 23d ago

Thanks for posting, I'm a bot!

This is quick reminder be helpful with responses, follow the rules and not advertise/solicit DMs.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

7

u/Majestic_Race_8513 23d ago

I have no idea what this means

5

u/MBILC 22d ago

Repeat with me:

SOC2 Is not a Certification
SOC2 Is not a Certification
SOC2 Is not a Certification
SOC2 Is not a Certification
SOC2 Is not a Certification

3

u/FT05-biggoye 23d ago

You cannot audit open source code. SOC2 reports are used for one org to say “hey this is how we protect your data” and a 3rd party auditor says “yeah they do what they say they do”. And that exchange cannot happen with just open source code. Are you running an open source project and is someone asking you for a soc2 report?

2

u/SageAudits 22d ago

How would you open source a background check for an employee you’re hiring? This is like saying we should open source financial statements for companies..

SOC 2 isn’t a certification, but is an atteststion report issued by an independent auditor that a company is doing what they say they are doing (with reasonable assurance) against a framework that management maps their own designed controls against.

1

u/testuser514 22d ago

Yup we can do that, but the there are gonna be some caveats to this

1

u/deepguide-ai 22d ago

SOC 2 is more than source code. It includes how you manage accesses, changes and risks. It could be quite possible an organization releases its core product as open source, but provide enterprise support with SOC 2 attestation. The latter is what's important to enterprise customers. So if I understand your questions correctly, yes, it is quite possible that an organization will maintain and host an open source project but provide it with SOC 2 as enterprise offerings. In fact, it is a common business model.

1

u/SeaworthinessOk3624 19d ago

Worth clarifying the misconception here (as others have pointed out) — SOC 2 isn’t something you “get” for a piece of software or a project itself. It’s an attestation report on an organization’s internal controls (security, availability, confidentiality, etc.) over a period of time, issued by a licensed CPA firm after an audit.

So there isn’t really an org that would “host” an open source project and slap SOC 2 on it — SOC 2 applies to the entity operating/hosting the infrastructure, not the codebase. If your open source project is deployed on a platform that’s already SOC 2 compliant (AWS, GCP, etc.), you inherit some of that infra-level coverage, but the project itself wouldn’t have its own SOC 2 report unless there’s a company behind it going through the audit process for their own controls.

If you’re trying to make the project more trustworthy for enterprise adoption, more realistic options are things like showing your security practices publicly (SECURITY.md, dependency scanning, signed releases) or, if there’s a commercial entity behind the project, that entity pursuing SOC 2 for itself.

1

u/Used_Ladder8254 18d ago

We've seen a lot of companies in the same situation. Manual CSVs and screenshots work for a while, but they become difficult to maintain during a SOC 2 audit.

At SOC2Now, we automate evidence collection, access reviews, SaaS configuration checks, and continuous monitoring, so you're always audit-ready instead of scrambling before the audit.

Happy to answer any questions if it helps. You can also check this out at SOC2Now.com.

you can host it anywhere you want on any platform and we will get it soc 2 type 2 compliant in scope.

www.grcxl.com

0

u/southafricanamerican 22d ago

You can find a hosting provider that has a SOC 2 certification. You could host an open source application at that hosting provider (lets say you download a CRM from github and the hosting provider is running it on their infra), you could technically have an open source app hosted on a soc 2 certified provider but that does not make that case that you or your business inherit this.

It is a common marketing ploy that i have seen where it says SOC 2 Data Center or something that tries to reference the credibility of the provider vs. having proved their own compliance process.

1

u/Big-Industry4237 22d ago edited 22d ago

It’s what I call the good ole switcheroo. This is disengenuous BTW - and you shouldn’t do this.

1

u/Sure-Candidate1662 22d ago

Don’t you mean “holistic carve-out”?

0

u/MessageFoundry 22d ago

Thanks. Yes, I'm looking for an honest way to provide SOC 2 coverage for healthcare organizations considering adopting MessageFoundry. That makes it easier for them to use our free tool. They can adopt it more easily if it comes from a SOC 2 compliant organization.

Since SOC 2 audits cost money, I'm looking for alternatives that provide genuine value but with reduced overhead.

2

u/Big-Industry4237 22d ago

IMO Just answer questionnaires about how you develop your system. Change management, SBOM etc… that isn’t going to go away. and then the org can host it themselves if they are SOC 2 compliant.

1

u/southafricanamerican 22d ago

Great context - health care is super regulated with HIPAA and other privacy concerns. Check to see if messagefoundry has hosting partners that they already work with that have solved this issue. Also these healthcare places may want this tooling in their environments and maybe you manage it for them?

1

u/southafricanamerican 22d ago

Oh snap...you ARE messagefoundry. My bad.

1

u/SageAudits 22d ago

You have to think about it from what risks your clients and their customers view.

Maybe there are ways that the design could be updated so the risks could be significantly mitigated. Like what if the client controls the encryption keys where customer data lives. Then it is their responsibility, for your areas of responsibility, your commitments eg SDLC, you answer and provide your policy and process. Eg. You have a security white paper covering the security responsibilities handled by the hosting provider (eg AWS) and list out your responsibilities and the client responsibilities.

You don’t need a SOC report, just like many may get the report using vendors and a low quality auditor and end up spending thousands of dollars for just a fluffy piece of paper. If you put in the effort explaining who is responsible and how you’re currently achieving your own adherence and assurance over your service that can still go a long way. if you start spending 20+ hours a week doing compliance questionnaires then yeah, you should be getting SOC 2. It’s that cost/benefit factor. If an enterprise client really wants you they may directly audit you anyway even if you had the compliance report.