frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: Ex-Deloitte auditor open-sourced the whole SOC 2 method for your AI

https://github.com/Chiaro-HQ/methodology
28•yylyyl•1h ago

Comments

yylyyl•58m ago
I'm the author. CPA, spent 5 years doing SOC 2 fieldwork at Deloitte, recently started my own audit firm.

This repo is the methodology we actually audit against, not a summary of it: 86 controls, 355 test attributes with pass criteria, evidence standards, and the Type II testing method including how we call deviations, with worked examples. It's generated from the same JSON that drives our audit tooling, so it can't drift from what we actually do.

What "for your AI" means concretely: the framework is JSON rather than prose, so the controls, the attributes, their pass criteria and the evidence map are all machine-readable, and there's a file listing every tool our server exposes. It's CC BY 4.0 — point your own model at it and run your own readiness against the same bar the examination applies. The part that makes that work is 498 calibration examples: each one records a judgment call, the verdict an AI reached, the verdict that was correct, and why. Without those a model grades itself generously.

Why publish it: the audit criteria (AICPA's Trust Services Criteria) are public, but every firm's actual testing layer is a black box. A buyer holding two SOC 2 reports can't tell whether one auditor inspected evidence and the other just collected screenshots — the reports look identical. This year's Delve episode (hundreds of near-identical reports, procedures allegedly drafted before client evidence arrived — allegations Delve disputes) made that opacity harder to defend. Standards bodies publish their standards; we think the testing layer should be public too.

The thing that surprised us building it: sampling mostly shouldn't exist at small-company scale. Sampling exists in audit because looking at everything used to be expensive. At the company sizes we serve, populations are tiny — for most of our 79 sample-typed attributes, a proper sample would have been most of the population anyway — and AI collapsed the cost of looking at the rest. So the method defaults to testing complete populations, and sampling survives only as a disclosed fallback with hash-seeded selection that nobody (client, us, or either side's software) can steer.

Limitations, stated plainly: this is a methodology, not a track record. The firm is new — one Type I issued, no Type II yet. We published the method before the first Type II run on purpose, so it can't be quietly fitted to results afterward. Peer review: enrolled, first review due 2027.

Happy to answer anything about how SOC 2 audits actually work from the inside.

devy•46m ago
Is this how every auditor does though or just you/Deloitte? SOC 2 is a set of guidelines, not mandates, there is one size fits all and every org may design their own security controls based on their unique systems. Is that the same philosophy on the auditing side as well?
yylyyl•39m ago
The method is mine. How I test, what evidence I accept, how I call a deviation. Every firm has their own methodology but none of them publish it.
bookmon•44m ago
Don't most people get the SOC 2 audit to also have credibility from a reputable firm? How valid would an AI SOC 2 audit be for marketing purposes
yylyyl•38m ago
Your AI can read the open source methodology to get audit ready for you without relying on a compliance platform. The actual audit is done by a licensed firm.
bijowo1676•42m ago
Thank you for sharing this, I have a question: can you tell us some lore behind SOC 2 certification, why is this certification is most frequently pursued by startups/tech companies?

Do all SOC 2 audit certifications worth the same, or some worth more, (big four vs smaller firm?)

Are there other/better alternative certifications that provide higher level of assurance to clients?

yylyyl
jpitz•32m ago
This is an incredible resource for someone trying to prep for an audit. Thank you!
yylyyl•29m ago
Appreciate it! Happy to answer any questions.
•
30m ago
SOC 2 is almost a must-have for startups if they want to pursue enterprise deals. Not all soc 2 audits worth the same. People usually trust 2 types of audits: 1. a reputable name or 2. a transparent report that can show all the details like what evidence the auditor checks, how the auditor checks it, and what the auditor finds.

And soc 2 currently is the mostly widely accepted one. There are other more specialized ones for sure but not as universally accepted as soc2.

Show HN: Simple algorithm and color space to generate diverse skin tones

https://toneyalexander.github.io/inclusive-color-space/
185•automatoney•2h ago•46 comments

Show HN: Fine-tune an 8B model on a 4 GB laptop GPU

https://github.com/MakazhanAlpamys/Soup
92•MakazhanAlpamys•6h ago•14 comments

Show HN: Run an 80B Qwen in 4.3 GB of RAM on a Mac, and a 35B on an iPhone

https://github.com/leonickson1/Swiftlet
278•leonickson•1d ago•128 comments

Show HN: SIEMatic, a fair-sourced observability and security platform

https://github.com/mcindi/siematic
2•ilovetux•42m ago•0 comments

Show HN: FastStrapy – A create-next-app-inspired CLI for FastAPI

https://github.com/AnoopGeorge418/faststrapy
2•anoopgeorge418•1h ago•0 comments

Show HN: Jido Assembly; Slack Clone in Pure Elixir with Integrated Agents

https://jido.run/blog/jido-assembly-slack-clone
5•mikehostetler•1h ago•0 comments

Show HN: Adapt, Automatically Turns Files into REST APIs, Web UI, and MCP

https://github.com/mcindi/adapt
3•ilovetux•1h ago•0 comments

Show HN: Korvo – Local-first AI workspace that traces answers to the source

https://www.korvo.xyz/
2•akshay_bhardwaj•1h ago•0 comments

Show HN: OpenEdit – Your coding agent can now edit videos

https://github.com/veedstudio/open-edit
3•sabbakeynejad•2h ago•1 comments

Show HN: Simple self-hosted LLM assistant with user-steered compounding context

https://github.com/kol3x/pawmc
2•kol3x•2h ago•0 comments

Show HN: Listen to audiobooks like you read, at your own pace

https://listendock.com/sentence-mode
2•janpmz•4h ago•0 comments

Show HN: cctap – see and reach the Claude Code session that needs you

https://github.com/chipmates/cctap
3•micstradev•6h ago•0 comments

Show HN: Listnr – macOS meeting transcription that never mixes mic and speakers

https://github.com/rokib16x/listnr
7•rokib16x•6h ago•0 comments

Show HN: The invisible WiFi man. How one man built global "Brand" WiFi in 2009

https://calumbugattimacdonald.com
2•BugattiMacD•4h ago•0 comments

Show HN: Paranoia – Get a cold, adversarial review of your code

https://github.com/subvertnormality/paranoia-local
4•Grahf•7h ago•2 comments

Show HN: ssh ssh.place

https://ssh.place
181•jeninh•1d ago•112 comments

Show HN: Nightcrawler – A local AI pentesting agent running on a smartphone

https://github.com/garagehq/nightcrawler/
113•NickySlicks•1d ago•32 comments

Show HN: Bourdon – one shared memory file for Claude Code, Codex, Cursor

https://bourdon.ai
3•RADLAB•5h ago•0 comments

Show HN: Salary Ticker – a macOS menu bar app that ticks up your pay

https://steveharrison.dev/salaryticker/
5•steveharrison•5h ago•0 comments

Show HN: A new type of search engine

https://galefox.com/
3•wesammikhail•6h ago•4 comments

Show HN: A Handwritten Blogging Platform

https://handwritten.blog/
184•emilesilvis•4d ago•87 comments

Show HN: Product analytics (and evals) for agent sessions on your MCP

https://armature.tech/
41•screm•1d ago•2 comments

Show HN: A speed reading test you can fail

https://www.readkinetic.com/speed-test
2•SamuraiLion•6h ago•0 comments

Show HN: Turn one plain-English question into a decision-ready market

https://researchmaster.ai/en
2•not_wowinter13•6h ago•0 comments

Show HN: Çetele – Open-source notepad calculator

https://cetele.online/
5•nurulmac11•6h ago•0 comments

Show HN: I built a tool to find your first users before they find you

https://agenmatic.ai/
3•Nancylily•6h ago•3 comments

Show HN: Knuth–Plass algorithm for short-form video

https://viki.wiki/assets/waffle/wafflemaker-slop2.html
2•richardprince4•6h ago•1 comments

Show HN: PolyTrip – crowd-funded group trip planning with AI

https://polytrip.co/
3•Maorperry1•7h ago•2 comments

Show HN: We Fixed UniFi's Slow PPPoE Performance with PPPoE Half-Bridge

https://arcbox.dev/blog/unifi-pppoe-half-bridge-acceleration
71•uneven9434•1d ago•35 comments

Show HN: NixOS-DGX-Spark – Nix and NixOS on the DGX Spark

https://github.com/graham33/nixos-dgx-spark
128•graham33•2d ago•40 comments