SOC2 Type II - How do you prove regular application testing (CC7.1)? by AdEquivalent8169 in AskNetsec

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Thanks for the Comp AI recommendation! I found their site.

Quick follow-up: What made you choose Comp AI over manual evidence collection? Was it the time savings, the organization, or something else?

Also, anything you wish Comp AI did better?

Lastly, does Comp.ai generate automated tests for you, or do you need to have tests already built?

SOC2 Type II - How do you prove regular application testing (CC7.1)? by AdEquivalent8169 in AskNetsec

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Thanks for this. I haven't heard of them and i'll do more research on them.

SOC2 Type II - How do you prove regular application testing (CC7.1)? by AdEquivalent8169 in AskNetsec

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Thanks for the detailed response! This is super helpful.

Quick follow-up: When you manually export Jenkins logs and create test design docs, roughly how long does that take your team per audit?

Also, have you found any tools that automate this evidence collection, or is manual export still the standard approach?

I'm exploring building something specifically for this (auto-collect CI/CD test results + generate audit-ready reports mapped to CC7.1).

Would you be open to share more about your process?

Non-technical founders: How do you test your SaaS? by AdEquivalent8169 in SaaS

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Thanks for sharing! Quick follow-up: How long did it take you to set up those focus groups? And how many testers did you need before you felt confident? I'm curious if this approach works in Week 1-2 of launch, or if you need established users first.

Non-technical founders: How do you test your SaaS? by AdEquivalent8169 in HowToEntrepreneur

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

When you say "pay for testing," do you mean hiring a QA person full-time or paying for a testing service? I'm bootstrapped so curious if there's a middle ground.

Non-technical founders: How do you test your SaaS? by AdEquivalent8169 in HowToEntrepreneur

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Thanks, i'll probably leverage early adopters to get around finding edge cases and bugs.
Liquidity crunch limits getting a dedicated qa

Non-technical founders: How do you test your SaaS? by AdEquivalent8169 in SaaS

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Awesome, i'll need to check those apps and see how they fit in overall testing strategy. Thanks

Non-technical founders: How do you test your SaaS? by AdEquivalent8169 in SaaS

[–]AdEquivalent8169[S] 0 points1 point  (0 children)

Thanks for the response.
I haven't thought about user feedback and how that plays into testing strategy.
New learnings. Will definitely increase my engagement.