Tweet fijado
Kshitiz
229 posts

Kshitiz
@kshitizh
Building @ypal_security | Founding Engineer / Product & Security @Security_Pal
KTM-MPLS-SF-NYC Se unió Mayıs 2013
223 Siguiendo513 Seguidores

Sure if you don’t value the 40 hours setting up ses, configuring sns for bounces, building your own template engine, and debugging deliverability at 2am.
Resend ships in 10 mins.
@levelsio@levelsio
Resend is literally just SES with a 500% markup @grok fact check
English

hey @MartinGTobias, most tools in this space sell you a dashboard and call it compliance.
@ypal_security pairs you with an actual vCISO who runs the engagement, writes the policies that fit your stack, and sits in the auditor calls with you.
SOC 2 type 1 in ~4 weeks, type 2 windows handled end to end.
happy to chat if useful: cal.com/khamal/30min
English

For a small early-stage SaaS startup, SOC 2 compliance + certification typically runs $20K–$60K in year 1.
Breakdown:
- Audit (Type 2 most common): $10K–$30K
- Compliance tools (Vanta/Drata etc.): $5K–$15K
- Readiness, remediation, team time: the rest
Type 1 is faster/cheaper for initial sales proof. Costs scale with headcount, scope (Security-only vs full TSCs), and how much you automate. Shop boutique auditors for better rates.
English

Voiden just crossed 1K GitHub stars...⭐⭐⭐
Top 0.2% of all repositories on GitHub.
There are so many great developer tools out there that just never get seen.
If you have built something for devs, drop it below, let’s help surface more of them.
on to the next milestone 🚀
#devtools #api #opensource #github #testing #aitools
English

That's why @ypal_security ships a vCISO with the platform.
Not a dashboard. A team that owns the outcome.
Your engineers ship product. We get you certified.
24+ frameworks. Zero on site overhead. Audit ready in weeks.
English

We are building out the next _big_thing_ at RevenueCat, helping developers make more money using the power of money.
I think "Capital" has a chance of being as big as our SaaS/JSON business and it's really cool to dream up and build financial tools for developers with our unique position and perspective.
We're hiring for a data scientist, an analyst, and an engineer. Read more about the opportunity from the inimitable @itisthefaye
notion.so/revenuecat/RC-…
English

Three reasons, I think:
1. The "automation" pitch only sells the easy 80%, connect your cloud, auto-collect. Audit-day back-and-forth doesn't fit the demo.
2. Customers feel the pain *during* the audit, not at purchase. By then they've already hired a consultant or are eating the spreadsheet.
3. Auditors do this part in spreadsheets/email. Tool vendors never feel it themselves.
English

@kshitizh @ypal_security Why do you think most SOC2 tools forgot about the rest? Did customers not know they needed it?
English

Most SOC 2 tools have one upload box.
Real auditors ask three questions in a row:
1. "List everyone you hired."
2. "Pick 5 random ones."
3. "Now prove each one got a background check, handbook, access."
Most software stops at #1.
@ypal_security models the whole conversation. ↓

English

with all the distribution Vanta has, moving into HRIS might be the next right move 😂
Pukar C. Hamal 🏔🗽 🌁@pchamal
the counteroffensive from Vanta is impressive
English

great launch, but the “we ARE your stack” pitch only covers identity + device + HR controls, call it 1/3 of SOC 2.
CC3 risk assessment, CC7 system ops, CC8 change mgmt, CC9 BCP — all live in your product, not your HRIS.
and even the controls Rippling automates still need a human to defend the design to an auditor.
this is exactly why we’re building @ypal_security .
evidence collection is the easy part.
Matt MacInnis@stanine
Today, we launched @Rippling Automated Compliance, starting with SOC 2. We have a unique advantage here: we aren't telling you how to fix your stack, because we ARE your stack. device management, identity and access management, HR, performance management...
English
Kshitiz retuiteado

the wonderful students at the Nepali Student Association at @Stanford are hosting a great event this Wednesday
do join if you can!

English







