The original post: /r/cybersecurity by /u/RandomUsername749 on 2024-11-10 12:16:01.

I’m bootstrapping a startup and looking to sell my SaaS to enterprise who are looking for security certifications. (We load a JS file on clients website to ask the visitors for consent.)

We have been using the best security practices and have a lot of policies and flows in place already. I’ve achieved SOC2 with my previous startup.

My current startup just isn’t certified and audited to have the official seal. And there might be some small things that might need to be updated or put in place - I need a checklist of things to do before just getting someone to audit.