a corporate/b2b saas environment without stuff like this is often a non starter.
- SOC2
- ISO/IEC 27001:2022
- ISO/IEC 27017:2015
- ISO/IEC 27018:2019
- VPAT 508
https://about.gitlab.com/security/
no mention of these on the forejo site, so i can’t put “our internal software is all SOC2/ISO NUMBER compliant” as a bullet point on a slide deck.
it is theatre. but it’s industry theatre.