Rhosys/soc2.fyi

Some additional info to add to the website

Closed this issue · 2 comments

Company Pros Cons
Trustcloud - Integrations are not as robust as other toolsNot able to share evidence across controlsClunky UI and navigation
Vanta Lots of integrationsCustomer portal Expensive relative to othersNo way to view employee or vendor to vendor permissions
Secureframe Necessary integrations, OAuthEmployee and vendor access visibilityCustomer portalAbility to share evidence across controlsGood UIReasonable pricingSlack nudges for evidence collectionAuto-answer vendor questionnaires Missing some integrationsNotification of failure feature not yet released (EOY23)
Trustero Engineering-forward tool (APIs, CLI, use version control)Aim to eliminate “thrash”Tools to streamline audit Doesn’t have a lot of the integrations we’d like and pushed back on why we’d even want some of themService account integrations
Drata Large support teamFocus on rapid innovation and feature development UI clunkier than othersNo autobuild Section 3Evidence upload suboptimal
Sprinto Good set of integrationsCustomer portalGood pricingUI seems mature No way to view employee or vendor permissionsNo employee offboarding functionalityComplex Workflow management rather than Control management

Also include this information if valuable:

SOC2 Vendor Selection - Public Matrix.ods

Add compliance scorecard by compliancerisk.io

Pros - full governance lifecycle, signature authorizations, lots of integrations, process management

Cons - MSP/channel only

Add compliance scorecard by compliancerisk.io

Pros - full governance lifecycle, signature authorizations, lots of integrations, process management

Cons - MSP/channel only

@glodeneye This ticket only applies to the providers that are already listed on the site. If you are interested in getting compliancerisk.io added, it would be great if you could provide the full breakdown of the provider in a new ticket.

Thanks!