Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

AuditBadger

SOC 2 and ISO 27001 – AI drafts, you approve

Details

External ID
49181982
Source
HN
Company
—
Product
AuditBadger
Website domain
auditbadger.com
Launched
Aug. 5, 2026
Cohort
—
Upvotes
9
Upvotes percentile
0.5309139784946236
Tags
—
Fetched at
Sept. 10, 2026, 5:32 a.m.
Updated at
Sept. 10, 2026, 5:32 a.m.

Description

Hi,Wanted to share something I've been working on for over a year. AuditBadger is a compliance management platform that uses AI to write policies (there are underlying "templates" with basic requirements), rewrite controls (or trust service criterions) to match the company context, help figure out your own controls, does initial risk assessment, and business continuity planning (which at least gives you an example of how the process should look like).Fun fact - I wanted to share this a year ago, but then I spotted something similar here. The most common comment was about lacking the SOC 2 report, so I decided to pick the fight. I got SOC 2 Type I first, and then recently finished SOC 2 Type II using the tool alone. It took some time - both learning the process, the SOC 2 gotchas, and implementing automatic evidence collection.We're now adding support for the European AI Act and NIS 2; HIPAA is already there (though it requires me to explicitly enable it for customers who want to test it), and CyberEssentials and ENS are coming later this year.The platform is now complete, but my business partner (ISO 27001 Lead Auditor) and I are still dog-fooding it. Everything we build is either based on our own pain points or our customers'—most of them joined our Slack where we try to help them if they get stuck.If you have any questions, I'll be happy to answer them all.

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
—
Function
Compliance & governance
Audience
B2B
AI stance
AI-native
Project type
Commercial product
Normalized one-liner
soc 2 and iso 27001 compliance automation
Manually corrected
False

Could you build this?

Partial A web app providing compliance templates and LLM-assisted drafting is straightforward to vibe code, but achieving genuine SOC 2/ISO 27001 readiness requires domain knowledge of auditor scrutiny and automated evidence collectors.

What it would actually take: The core application uses a standard full-stack framework (Next.js, Node/Python, PostgreSQL) with an LLM orchestration layer for policy generation. The difficult piece is writing robust integrations with cloud providers (AWS, GCP, Azure), MDMs, and GitHub to continuously pull cryptographically verifiable configuration evidence matching hundreds of discrete AICPA TSCs and ISO clauses, requiring compliance and DevOps domain expertise.

Discussion

3 comments analyzed.

Concerns raised: SOC 2 is security theater, doesn't actually solve security issues, Product is just shovels for a fake gold rush

Competitors

Other products that read as similar to this one — 47 launches clear the similarity bar, closest 8 shown.

Attention rank: #22 of 48 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 237 days after the earliest competitor.

Other launches for this product