frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Built a verifiable, open-source SoC 2 readiness scanner

https://loxeai.com
1•arjavmehta•1h ago
After speaking with over 50+ CISOs, DevOps, & pre-series A founders for months, I realized a problem in the GRC industry. SOC 2 automation exists, but people are split between trusting these black-box tools with systems that are continuously changing. As a result audits are slow & mistrusted.

Right now the most important thing is verifiability & depth, rather than just compliance automation-because it does exist, everywhere.

Here's what I did from learning this:

-> Created an open-source AWS Evidence Scanner & Control Mapper for lean, pre-series A AWS-Native teams thinking about SOC 2 Type l or are undergoing SOC 2 Type l audit. Collects across 15+ AWS Services to 12 critical controls in the trust-service criteria.

Why open-source? Accessibility for people who might have their hands tied choosing between expensive GRC tools. Its also used as a trust-mechanism. Code is right there. A CEO or auditor can read exactly what API calls we make before giving us the role ARN.

-> I included a paid report embedded within the tool (open-core model). Users have the option to pay for the report in which every finding traces back to the API call that produced it. SHA-256 hashed (at a fraction of the cost of bigger legacy platforms). With remediation steps & a compliance-copilot to help with other parts of the Type l process beyond evidence collection (like policy writing, risk assessment, etc).

Why paid report? The best way to make the auditors job as easy as possible is to give them a verifiable package where the evidence is right there in front of them, timestamped so they can see what happened, when (rooted in AWS APIs). No black-box, no way to fake it. Saving weeks of back & forth between auditors and clients, with the click of a few buttons.

An auditor can re-run the same API call, hash the response themselves, and verify it matches what's in the report.

Value: 30 seconds to deploy. 5 mins to run the scan & evidence is collected & mapped. Paid report includes verifiable evidence companies can send to their auditor. Paid features include a co-pilot to help with audit-readiness beyond just evidence collection.

-> Understand Limitations.

I understand the scope of this product is pretty limited in part because its also very new. I'm not going to claim it solves all of compliance, because it doesn't. It makes a very time-consuming part of the process very accessible to be automated & gives an auditor a report they can rely on.

What now? Anyone who's gone through, thinking about or is in the middle of SOC 2, would love your reaction to the output, even if it's critical. Also looking for early testers/users.

repo here: https://github.com/adog0822/AWS-Evidence-Layer

try it here: https://loxeai.com

Quack: A TUI for managing and cancelling active OpenCode sessions

https://github.com/SmolNero/quack
1•edgar_ortega•33s ago•0 comments

The night I dreamed of Archangel Michael

https://mylightstillshines.wordpress.com/2026/04/27/the-time-i-dreamt-of-archangel-michael/
1•jaygirl•6m ago•0 comments

Humans VS AI.IO – Update, New features and turrets

https://humansvsai.io
1•creatorcuffee•9m ago•0 comments

"Deep Generative Modeling": Introductory Examples

https://github.com/jmtomczak/intro_dgm
1•modinfo•10m ago•0 comments

Scalar and Binary Quantization for Pgvector Vector Search and Storage (2024)

https://jkatz05.com/post/postgres/pgvector-scalar-binary-quantization/
1•eigenBasis•14m ago•0 comments

A compact coding agent written in pure C, syscall tools, memory, pi-style TUI

https://github.com/douglascorrea/syscall-agent
1•douglascorrea•16m ago•0 comments

Turnspit Dog

https://en.wikipedia.org/wiki/Turnspit_dog
3•doener•23m ago•0 comments

Chinese University Student Expelled for Improper Contact with a Foreigner (2025)

https://thediplomat.com/2025/09/why-a-chinese-university-expelled-a-student-for-improper-contact-...
2•toilet•27m ago•0 comments

What A.I. Kant Do

https://www.nytimes.com/2026/05/16/opinion/ai-liberal-arts.html
1•doener•28m ago•0 comments

[deleted]

https://www.economist.com/china/2025/07/17/why-a-fling-with-a-foreigner-insults-chinas-national-d...
3•toilet•30m ago•2 comments

Paid HTTP APIs that AI agents auto-pay per-call (x402 and USDC)

https://bshelby88.github.io/x402-portfolio/
1•bshelby88•32m ago•0 comments

Make ZIP files smaller with ZIP Shrinker

https://evanhahn.com/make-zip-files-smaller-with-zip-shrinker/
1•zdw•39m ago•0 comments

FCP – Free Communication Protocol

https://fcp.md/
2•chalyi•39m ago•1 comments

Add –implementation-language flag to Bun

https://github.com/oven-sh/bun/issues/30897
1•quasigloam•57m ago•0 comments

Show HN: Built a verifiable, open-source SoC 2 readiness scanner

https://loxeai.com
1•arjavmehta•1h ago•0 comments

Show HN: I built a free PDF editor to fix Claude's horribly-generated PDFs

https://composer-sepia.vercel.app
2•chaidhat•1h ago•1 comments

Quick, Draw - can a neural network learn to recognize doodling?

https://quickdraw.withgoogle.com/
1•nilsbunger•1h ago•0 comments

Independent dev's physics code stuns PhysicsSE admin

https://physics.stackexchange.com/questions/872398/self-organizing-acceleration-and-stability-in-...
1•spenx•1h ago•1 comments

Fisker went bankrupt and owners built an open source car company from the ashes

https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-after-bankruptcy/
17•breve•1h ago•0 comments

OpenAI seals deal in Malta to give all Maltese access to ChatGPT Plus

https://finance.yahoo.com/sectors/technology/articles/openai-seals-deal-malta-maltese-103120887.html
1•embedding-shape•1h ago•0 comments

Self-Complementary Graphs

https://mathworld.wolfram.com/Self-ComplementaryGraph.html
1•lorenzohess•1h ago•1 comments

Curl maintainer: AI security reports are no longer slop

https://daniel.haxx.se/blog/2026/04/22/high-quality-chaos/
2•notRobot•1h ago•0 comments

Show HN: Anagardens: A Daily Word Game

https://www.anagardens.com/
1•mperrotta•1h ago•0 comments

The offline desk gadget that got me to sit up straight

https://techcrunch.com/2026/05/16/the-offline-desk-gadget-that-actually-got-me-to-sit-up-straight/
1•jnord•1h ago•1 comments

Insdubai.com: Motor insurance policies, data of insured persons was exposed

https://write-ups.security-chu.com/2026/05/insdubai-data-breach-incident.html
1•news_rt•1h ago•0 comments

Quantum-COSMOLOGICAL ALIGNMENT (d=16)

https://github.com/lizbeth307/quantum-superactivation-refutation
1•NeoOdim•1h ago•0 comments

Near-Earth Asteroid 2026 JH2 close encounter: 18 May 2026

https://www.virtualtelescope.eu/2026/05/12/near-earth-asteroid-2026-jh2-extremely-close-encounter...
1•rolph•1h ago•0 comments

My Thoughts on Bun's Rust Rewrite

https://en.liujiacai.net/2026/05/16/bun-rust-port/
2•jwzxgo•1h ago•0 comments

Singapore Former Prime Minister Lee Hsien Loong's Sudoku Solver Written in C++

https://github.com/Doppp/LHL-Sudoku-Solver
1•doppp•1h ago•0 comments

Let's Talk about Benchmarks

https://spacetimedb.com/blog/benchmarking
1•ChadNauseam•1h ago•0 comments