I can’t spare you this: For years the community has emphasized the importance of compliance and certification for customers and that it can even bring new customers. There have been numerous threads on this. For example:
Has Storj ever consulted with a professional SOC2 auditor and have checked if the public Storj DCS network in its current state cannot be considered compliant for sure?
There are even more threads in which you have been asked again and again on the status on this issue and you have been made aware of new opportunities in the data storage business that can come along with proper compliance and certification.
And I think one of your last answers or the last answer on this was:
Q. Where are with compliance / certifications
- We are working on our SOC2 certification and are more mature in terms of the less complex frameworks such as HIPAA and GDPR
Now we have to read:
To help us expedite further growth with these larger customers, we have also made the decision to obtain a SOC2 certification for Storj as a company. Compliance is a critical requirement for many customers and a SOC2 certification would certainly help streamline adoption of our services. We are hoping to obtain a certification that covers as many of the Storj products as possible, including the public network (though we recognize that this does represent a challenging argument based on the controls required for SOC2.)
While it sounds great that such a decision has been made, it appears that not much has been achieved until now in regards to the public network.
I strongly suggest not to focus on SOC2 only but also on the other certifications and compliance requirements that do exist. Wasabi has a nice overview of what they cover and that should give an idea what Storj also should seek for: What third-party compliances have been attained by Wasabi?. This seems to be sort of a minimum requirements for a successful cloud storage business.
Without the proper compliance and certification the big business will move their data to compliant competitors like this one that I have made Storj aware of over and over again.
https://www.impossiblecloud.com/ Can anyone figure out what tech they are using? Is it based on Storj open source code?
As it seems it was just pure luck that this 10PB-customer fits into the Select network, Storj management needs to take this as a wake-up call for the public network and make 2025 the year of compliance and certification. To attract large enterprise customers and government customers, certifications of compliance are ultimately required, probably even code reviews, code audits, audits of coding practices, review and auditing of company and management processes, and more. This can take long, should have been started years ago and it is crucial to start this process now.
Finding an auditor with experience in decentralized infrastructure could be beneficial and time saving. Seal Storage Technology’s successful SOC2 audit by Audit Peak is a good example:
I found this:
Seal Sets New Industry Standard with SOC2 Compliant Decentralized Storage
By setting new standards for SOC2 compliance, Seal now offers the most secure decentralized cloud storage solution on the market.
Seal Storage Technology, a leading provider of blockchain-powered cloud storage, is proud to announce the successful completion of a System and Organization Controls (SOC) 2 audit conducted by the highly respected audit firm, Audit Peak. This milestone underscores Seal’s commitment to maintaining the highest standards of data security and integrity, giving clients the confidence that their valuable data is stored with the utmost vigilance, fostering trust through transparent and reliable business practices.
As the first compliant blockchain-powered cloud storage provider, Seal recognizes the critical importance of maintaining robust data security measures. Globally, enterprises are increasingly recognizing the importance of process controls and compliance, which is why Seal made SOC2 certification a core priority. This commitment sets Seal apart as the only decentralized cloud storage provider currently certified to the stringent SOC2 standards. Seal’s dedication to upholding these rigorous data security and integrity measures underscores its pioneering role in the decentralized cloud storage field, especially in a digital landscape where data protection is paramount.
So maybe talking to Audit Peak is a starting point:
Home
Audit Peak provides audit, cybersecurity and compliance services empowering clients to align their vision, strategic and business objectives.