1
0 Comments

Kicking off my journey: building a compliance automation tool

I’ve been following how much time startups spend preparing for audits like SOC2, ISO, and HIPAA, and one thing stands out: compliance feels like a never-ending checklist.

Teams spend weeks (sometimes months) collecting screenshots, exporting logs, updating spreadsheets, and answering the same questions again and again. Most of this happens right before an audit, when stress is highest and focus should really be on building the product.

I’ve seen founders ask the same things over and over:

“Where do I even start with compliance?”

“Why are we manually collecting the same evidence each quarter?”

“How do we keep things up to date without losing focus on growth?”

That’s why I’m starting to build a compliance automation tool. My goal is to:

Automate evidence collection

Keep teams audit-ready all the time

Reduce manual work so compliance doesn’t feel like a blocker

I’ll be sharing my journey in public here — the wins, the roadblocks, and lessons from building.

If you’ve been through SOC2, ISO, or any audit:
What’s been the toughest part for you —
documentation, evidence collection, or staying consistent?

Excited to learn from this community and connect with others on similar paths

Why this works:

Starts with the problem founders know (audit pain).

Shows empathy by listing real founder frustrations.

Clearly states your solution.

Ends with a question to spark replies.

on August 21, 2025