frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Ask HN: What do you look for in compliance reporting tools?

2•lukejkwarren•3h ago
I’m building a web security monitoring platform and recently added branded compliance reporting for things like SOC 2 and ISO 27001.

The reports include:

- Your logo/colors or full whitelabel

- Mapped vulnerabilities (OWASP/CWE/WASC)

- Executive summaries for non-technical stakeholders

If you're responsible for security or reporting (internally or for clients), I'd love to know:

- What do you need to see in a compliance report?

- Who are you generating these for — clients, auditors, execs?

- What do you currently use (manual process, automated, third-party tools)?

- What’s still frustrating or slow about your current setup?

Curious how others are approaching this and what you'd actually want to see improved.

Comments

lukejkwarren•3h ago
Added context: I've been working on a security scanning tool called PenZen (https://penzen.app) ad interested in how others have solved it.
qzhaxn3fxocmjpu•2h ago
I worked in this space as a "virtual" CISO for a friend's company for several years (2020–2023) before giving up in frustration, so take the following with that caution.

Automated report generators made for very pretty graphics for the C level executives but failed us on actionable items for the managers and staff who had to actually fix exposures.

There was no sanity checking on some of the layout tools used, e.g. a crazy long endpoint URL would either spill off the side of the page (and be truncated) or be truncated with an ellipsis. In neither case could we tell what the original URL was without tracking down the scan log and searching it line by line.

If you're going to allow me to add my branding to the report I've paid to generate, don't charge me an arm, a leg, and an unmentionable part of anatomy to do so. And prefer SVG graphics so you can scale up/down/sideways as necessary. Or document the dimensions of the PNG/JPG you need. Or both.

One tool we used had two report options: executive level, which was a 10–15 page high level summary that was barely useful to brief senior management, or core dump, which was a potentially hundreds of pages long detailed report on each and every end point hit by the scan. There needed to be something in between (e.g. filter by severity or compliance area or…something). Generate multiple content types (pdf, pptx, html, xml, md, JSON, etc).

As you ask…there’s multiple audiences. Reports need to be generated for each. And the act of generating the report itself can be a compliance event, so the options selected or ignored for generating the report themselves may need to be recorded somewhere for a future auditor or litigator.

We typically used the service's automated process to do a scan and generate the initial report, and then manually edit the report to make it more appropriate for the given audience we were presenting to.

One service we used repeatedly until they priced themselves out of viability for us had multiple API endpoints for different types of scans where each API had wildly different parameters for the request (e.g. ?domain=example.com in one request would be ?ddns=example.com in another) and the results would have variably different JSON responses that had to be manually inspected almost every time.

There was no concept of a “organizational” account on a number of the services we tried. If I requested a scan under my account, my partner could not access the results unless he logged in as me. It would not have mattered if we were vCISO consultants or a corporation attempting to use the service.

Scan results were not directly actionable. If you're going to tell me something may be exposed to a particular CVE, link the CVE, and if possible what tripped the CVE.

As I said, I don't do this any more, and have zero interest in returning to it.

It was frustrating to be pinched between customers who wanted to spend as little money as possible checking off the “we are so secure” boxes and the service providers viewing the market as a flood of cash to grab as quickly as possible. It made zero sense for us to build our own tools out, yet once we got out of the trial phase of many of the tools the increased cost was beyond what we could bill our own customers.

Ask HN: Yard Noise Cancellation Speakers/Systems?

1•EwanG•26s ago•0 comments

I told AI to make me a protein. Here's what it came up with

https://www.nature.com/articles/d41586-025-01586-y
1•rntn•46s ago•0 comments

Microsoft-backed Builder.ai enters insolvency proceedings

https://techcrunch.com/2025/05/20/once-worth-over-1b-microsoft-backed-builder-ai-is-running-out-of-money/
2•upupupandaway•2m ago•0 comments

Show HN: Claude Code Editor (VS Code Extension)

https://github.com/ananddtyagi/Claude-Code-Editor
1•ananddtyagi•2m ago•0 comments

Build Real-Time Product Recommendation Engine with LLM and Graph Database

https://cocoindex.io/blogs/product-recommendation/
1•badmonster•3m ago•0 comments

Show HN: Ghostwriter – Structured thinking tool for teams using mind maps and AI

https://app.gwriter.io/
1•mitch_said•5m ago•0 comments

Grumpy Old Man: Error Handling and Hubris

https://karl-pickett.medium.com/grumpy-old-man-error-handling-and-hubris-41620a11c57a
1•karl_p•6m ago•0 comments

Show HN: I made the vibe coders' cybersecurity app

https://securevibing.com
1•lorikmor•6m ago•0 comments

'Delaying extinction': The last-ditch race to save the Orinoco crocodile

https://www.aljazeera.com/gallery/2025/5/20/delaying-extinction-the-last-ditch-race-to-save-the-orinoco-crocodile
1•Qem•6m ago•0 comments

Show HN: I built a tool to track top indie profiles on X using engagement data

https://socialleaderboard.com
1•VaultCodeBoy•6m ago•0 comments

Show HN: I made a tool that helps your content get cited by LLM's like ChatGPT

https://llmcontentready.com/
1•rashwell•6m ago•0 comments

Ice cream and foods with emulsifiers may upset your gut health

https://www.cnn.com/2025/05/19/health/emulsifiers-gut-kff-health-news-wellness
1•yalok•7m ago•0 comments

Google's AI tools are the culmination of its hubris

https://arstechnica.com/google/2025/05/zero-click-searches-googles-ai-tools-are-the-culmination-of-its-hubris/
2•samizdis•8m ago•0 comments

II-Agent – open source autonomous AI agent

https://ii.inc/web/blog/post/ii-agent
1•emadm•8m ago•0 comments

Wallet Fingerprints: Detection and Analysis

https://ishaana.com/blog/wallet_fingerprinting/
1•wslh•9m ago•0 comments

Pkg.go.dev Is Down

https://github.com/golang/go/issues/73799
1•nateb2022•10m ago•1 comments

The Wonder of Modern Drywall

https://www.worksinprogress.news/p/the-wonder-of-modern-drywall
1•jger15•12m ago•0 comments

SF startup Anthropic, valued at $61B, sees legal drama caused by own errant tech

https://www.sfgate.com/tech/article/sf-ai-startup-anthropic-trouble-lawyer-20331584.php
3•nradov•13m ago•2 comments

MCP Streamable HTTP – Python and TypeScript Examples

https://github.com/invariantlabs-ai/mcp-streamable-http
2•lbeurerkellner•14m ago•0 comments

Autopsy of an LHC Beam Dump

https://home.cern/news/news/accelerators/autopsy-lhc-beam-dump
1•voxadam•15m ago•0 comments

Launch HN: Opusense (YC X25) – AI assistant for construction inspectors on site

4•rcody•16m ago•0 comments

Show HN: I made a no-code and AI platform to create serious games

https://www.ludiz.com
1•jidefr•17m ago•0 comments

Show HN: A free MVP that outperformed Lovable, Bolt, and V0

https://chromaflow.ai/
2•Fran-Morrone•17m ago•0 comments

The Agentic Web and Original Sin

https://stratechery.com/2025/the-agentic-web-and-original-sin/
2•ppsreejith•20m ago•0 comments

Demonstrating end-to-end scientific discovery with Robin: a multi-agent system

https://www.futurehouse.org/research-announcements/demonstrating-end-to-end-scientific-discovery-with-robin-a-multi-agent-system
1•eamag•20m ago•0 comments

How I Mastered Data Structures and Algorithms

https://blog.algomaster.io/p/how-i-mastered-data-structures-and-algorithms
2•ashishps•20m ago•0 comments

How does The Guardian track us?

https://old.reddit.com/r/privacy/comments/10dct3h/how_does_the_guardian_and_other_websites_track_us/
1•bundie•20m ago•0 comments

Better Zustand Store

https://github.com/PhilipWee/better-zustand-store
1•PhilipWee•21m ago•0 comments

Predicting solar photovoltaic generation impacted by wildfire smoke

https://iopscience.iop.org/article/10.1088/1748-9326/adcf3b
1•PaulHoule•21m ago•0 comments

The AI Engineering Stack

https://newsletter.pragmaticengineer.com/p/the-ai-engineering-stack
1•yarapavan•21m ago•0 comments