Very Good Security (VGS) lets companies use and exchange any kind of sensitive data without ever needing to see or hold the data itself. Built on the premise that “you can’t hack what isn’t there”, VGS is on a mission to protect the world’s information by transforming security and privacy from a business obstacle into an opportunity. VGS provides a developer-friendly platform to act as a custodian for sensitive data, improving security while also accelerating business growth without the cost or liability of securing the data themselves.
Secureframe is recommended for startups, small to medium-sized businesses, and enterprises seeking an efficient way to manage compliance obligations, particularly those in the technology, finance, and healthcare sectors that need to comply with strict security regulations.
Secureframe might be a bit more popular than Very Good Security. We know about 3 links to it since March 2021 and only 3 links to Very Good Security. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.
Actually, PCI Compliance is largely a solved problem. Use something like https://verygoodsecurity.com and wrap the proxy around Lago and your self hosting will qualify you for the easiest PCI compliance tier. (Disclosure: I founded Very Good Security & was the CEO for 8 years). - Source: Hacker News / about 1 year ago
You also asked about the security of this data, which is a great question. At Gem, we've gone the painstaking lengths to protect this information. We partnered with a firm VeryGoodSecurity (https://verygoodsecurity.com) to securely vault all personally identifiable information. You can read their security statement here: https://www.verygoodsecurity.com/docs/security/security-statement. Source: over 3 years ago
The way we approached this is to use a vendor. Basically, the part of our app that collects card data is literally a small iframe. That iframe proxies calls to the vendor (we used verygoodsecurity.com, their VGS collect product) so that we never are actually aware of the card data. They return to us a token we store in our database, so we can work with the card and have no actual knowledge of the card. Source: about 4 years ago
Secureframe | Remote (Canada) | https://secureframe.com | 150-200k CAD Secureframe helps company get compliant and build trust with their customers. We do this by integrating in a companies core SaaS tools, ingesting data, and then displaying all misconfigurations that need to be remediated for a given security framework. Stack is Rails/React/Typescript/Postgres/Elasticsearch We've got three open engineering roles... - Source: Hacker News / 6 months ago
My org is in a position where we'll need to get SOC II or ISO 27001 certified in the next year. I've been doing some research on the easiest way to go about this, and discovered secureframe (https://secureframe.com/). It looks like it is a platform that helps you automate/track some of the compliance tasks, but doesn't actually do the audit (they have partners that work through the platform). I'm wondering if... Source: over 2 years ago
Hi, founder of Secureframe (https://secureframe.com) here. Secureframe helps streamline compliance across SOC 2, ISO 27001, HIPAA, PCI DSS, and more. There are so many accurate responses in this thread. Like many have mentioned, SOC 2 is indeed not a prescriptive framework. Much of the confusion behind SOC 2 stems from that fact. It allows you to customize your InfoSec program to your company's needs. As we know,... - Source: Hacker News / over 3 years ago
Drata - Put SOC 2 Compliance on Autopilot
Vanta - Automate compliance, simplify security.
Jotform - Free Online Form Builder & Form Creator
Unicis - Unicis Open-source Trust Management platform offers automated solutions that streamlines the process of identifying vulnerabilities, conducting audits, and achieving regulatory compliance.Low-cost GRC platform for effortless Security and Compliance
Accountable - Accountable is a platform designed to help organizations manage HIPAA compliance.
Deel - Payroll and compliance for international teams