If not, what alternatives can i use?

    • stink@lemmygrad.ml
      link
      fedilink
      English
      arrow-up
      13
      ·
      3 days ago

      Gonna be honest after working in the industry and seeing how corrupt auditing is (incompetent auditors, even some auditors getting paid off) these things don’t make much of a dent to my decision making.

      I say this as someone who pays for Proton.

      • s3rvant@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 days ago

        Valid to an extent. I’ve personally experienced various audits whether for ISO, PCI or SOC and the quality of the auditor certainly does vary though I’ve not encountered one I would consider incompetent; the audits have always been rigorous. I’ve not personally seen bribery though I have seen where an auditor might relax how aggressively they look for issues over the years of getting to know the people and quality of the company.

    • Stowaway@midwest.social
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      3 days ago

      I think soc 2 type ii is nice, but I also don’t think it really says much about privacy in the context of me trusting what a business will do with my personal data. its been 4 or so years since if done an soc audit, so please correct me if I’m wrong. From what I recall its primarily geared toward security in general and when they say privacy, they mean securing your data from use unauthorized by the business.

      The distinction im making here is that, from what I recall, soc 2 type ii says nothing about what can be done with your data (e.g. selling data to brokers, training ai, targeting ads, unclear/communicated eula changes, etc.). During these, and most other, security audits you can make business arguments as to why you should be exempt from various security mechanism or configs. These systems also don’t protect from techno fascist douchebaggery like feeding the government information on individuals without warrant or just cause, to assist in targeting minorities or activists for example.

      To be clear, I use proton, I think its great, and MOSTLY trust them with my data. I do also like that they got soc 2 type ii, i wasnt aware till now so thanks for the heads up. I’m not accusing or trying to infer any wrong doing either. Mostly trying to point out this doesn’t resolve potential abuses some folks may have concerns about after ceo/board member/whateverthefuckingtitleis drama.

      Thanks for coming to my ted talk…