fly.io-specific experience and/or resources relating to SOC 2 compliance process?

I was about to ask this same question and was amused when I saw the first post referring my favorite SOC2 article back to the person that probably wrote it. :slight_smile:

We deal with HIPAA data and are going after SOC2 at the moment (with Vanta). We’re frankly tired of rolling our own infra on AWS using terraform and would love to use something like fly. Although as I type this, I realize we’d have to find ways to report the infra back into Vanta manually.

Also some of our gov clients would further scrutinize this if it ever came up. I’m also not exactly sure if all our vendors need to be SOC2 compliant. That’s a question we’ll ask our auditors.

So any updates on this (or a potential roadmap)?

2 Likes