December 2022 Summaries
2 posts from Socket
Filter
Month:
Year:
Post Summaries
Back to Blog
Socket has achieved SOC 2 Type 1 compliance, demonstrating a strong commitment to security and confidentiality by meeting rigorous standards set by the AICPA for handling customer data securely, particularly for cloud-based service providers. This milestone underscores Socket's dedication to maintaining the trust of its customers by implementing robust security controls and real-time monitoring across its organization, ensuring the safety of sensitive and confidential business data processed through its platform. Socket's approach to security is integrated into every aspect of its operations, emphasizing privacy and safety without uploading or modifying customer source code, and is designed to help developers manage open source software securely and efficiently. The company has since progressed to SOC 2 Type 2 compliance, further solidifying its position as a reliable partner in safeguarding customer data.
Dec 07, 2022
652 words in the original blog post.
Socket has joined the Open Source Security Foundation (OpenSSF) to contribute to enhancing the security of open source software (OSS), addressing the often-overlooked aspect of security within the rapidly expanding open source ecosystem. As a company that helps developers efficiently manage and audit OSS at scale, Socket aims to collaborate with other OpenSSF members to safeguard the software supply chain against potential threats. Their platform is already employed by numerous companies to detect and prevent supply chain attacks, demonstrating their commitment to making open source safer for everyone. The collaboration comes at a crucial time when cross-industry efforts are essential to proactively tackle cybersecurity challenges, as highlighted by Jamie Thomas, OpenSSF Board Chair. Socket's involvement with OpenSSF marks the beginning of their extended efforts to secure the open source supply chain for all.
Dec 05, 2022
394 words in the original blog post.