Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the thing we are confusing here is "compliance" vs the "highest possible standards".

In theory these two terms mean the same thing.

In practice compliance can be detrimental to the cause and values that you and I both share seemingly.

> I am a founder, and my ambition includes meeting the highest possible standards for my customers.

Same here. This is why I don't care about "compliance" - because I take the privacy of my customers sacred. For example, that means no KYC on my customers. And compliance requires KYC.

 help



Compliance with what requires KYC? Nothing in ISO-27001 requires you to collect any information about your customers. Unless there are laws that require you to. Knowing your vendors is another story.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: