Ray Sang

Second Foundation - Free Compliance Automation on SOC1&2 and ISO Certifications

by
Second Foundation is an AI-native compliance platform built as a public interest project, making real SOC 2 and ISO 27001 compliance accessible to everyone. It automates risk assessments, controls, and evidence collection—focusing on substance over checkbox compliance. Free for everyone, it aims to eliminate “fake compliance” and raise the standard of trust.

Add a comment

Replies

Best
Ray Sang
Maker
📌
Hey Product Hunt 👋 I’m the creator of Second Foundation. We built this as a public interest project because compliance today is broken. Too much of it is just paperwork and “audit theater,” while real risks go unaddressed. Second Foundation is an AI-native platform for SOC 2, ISO 27001, and emerging AI regulations that focuses on substance — real controls, real evidence, continuously mapped to how your systems actually work. The goal is simple: make high-quality compliance accessible to everyone, not just companies that can afford expensive tools and consultants. So we made it free for everyone. If you’ve ever gone through an audit, built controls manually, or felt like compliance didn’t reflect reality — I’d really value your thoughts. What’s the most painful part of compliance today?