ComplianceLite

30-second SOC2-lite security scan for indie SaaS

Visit Website
April 28, 2026 Day 1: Shipped ComplianceLite — 30-second SOC2-lite scan for indie SaaS

SOC2 is a 6-month death march. Drata + Vanta are great if you're Series A+ and can pay enterprise pricing. If you're <$1M ARR and a B2B prospect just emailed you a "security questionnaire" — you panic.

I built ComplianceLite to give you 80% of what auditors flag in week one, in 30 seconds, for $39/mo.

What it scans:

- Security headers — HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy

- TLS enforcement, redirect loops, mixed content

- Privacy/Terms/Security/DPA page presence at common paths

- Cookie consent detection

- Form hardening (POST forms without CSP)

For each finding it returns the exact nginx/Caddy/Cloudflare snippet to fix it. Written by Claude, reviewed by me before each scan goes out.

Stack: FastAPI + httpx + Anthropic API for remediation prose + SQLite. Runs on Mac Mini, Cloudflare tunnel, $0 infra.

Pricing:

- $39/mo — 1 site, weekly scan

- $99/mo — 5 sites, daily scans, Slack alerts

- $249/mo — unlimited, hourly scans, auto-remediation PRs

14-day free trial, no card.

Honest tradeoffs:

- This is NOT a SOC2 substitute. It's the cheap pre-flight check before you're ready for one.

- No GitHub repo scanning yet (planned for Pro tier)

- Severity scoring is rule-based, not ML

What I'd love feedback on:

1. Which checks would you ADD that you actually got asked about in a recent security questionnaire?

2. Anyone with current Drata/Vanta — what do they catch that this should too?

3. Is "auto-remediation PR" a real Pro-tier draw or vanity feature?

First 10 IH users get the Growth tier free for 30 days. Site: https://compliancelite.mundawebco.shop

Comment