What apology letters? Never got anything, not even a reply to my support tickets.
HN user
mlitwiniuk
Making compliance survivable for small teams at humadroid.io. Used our own platform to get SOC 2 - because dogfooding is the ultimate viability test. Past life: built Prograils.com, sold it to Jobandtalent, did the corporate thing for a bit.
Ok, back to $0.17 :D
I was actually in the toilet when I got an email I owe them $36,869,876,146.51. I literally just shit myself.
Yes, this. I never redesign things for sake of redesigning. But being solo developer bootstrapping my product, I don't have a luxury of testing some concepts deeply internally or publishing well-optimized components. And when I see my customers struggle, that's clearly a signal, that's something in UX is wrong. Just today we had to explain one of our customers how to proceed with our ISMS workbook (Clauses 4-10 from ISO 27001) - initial design proved to be bad approach, I now know how to change this. And Claude Design is great translating my thoughts and suggestions into something, that's consistent and better, than I could design it in predictable time.
This is cool, I'll give it a try with my next pet project. So most likely next week, once I'm done with Fable ;) (seriously, I haven't started as many pet projects in the last 10 years as I did in the last 12 months).
Thanks, I'm seriously blushing ;)
No, the design system isn't public. But only because it's a month old and I never considered opening it. I'll give it some thought.
I don't have a design background, but I ran a software house/dev shop for almost 15 years; maybe that taught me a little. And my very first client, after seeing our very first projects, said one thing: "I don't care how ugly this is, but for god sake, please make it consistent, consistency is only think that matters long-term". Those might not be his exact words, but keeping designs consistent is imo pretty important.
Regarding the personal touch, the app itself is the result of gradual evolution. It started as an HR system, which we worked on in Prograils. It even got its first semi-professional design, which evolved over the last two years (during which I learned that bootstrapping an HRMS is a very bad idea ;)). As for the website, I have to admin it - Claude Design did it. I was testing Fable 5 previously and actually decided to give CD a try. It was the result of one prompt, which gave me five proposals. One made it to the main page, and two others went to my other pet projects (which are meant to drive traffic to AuditBadger).
My product is AuditBadger.com - it's an AI-assisted compliance management platform (ISO27001 & SOC2) that guides you through the whole process (with everything a small business might want from such software). Having a few dozen customers allows me to still care about them personally and do onboarding for each and every one of them. During those onboardings, catch-ups, or weekly calls, I see where they struggle. This is how I determine what to work on next. There's no clear measurement of success beyond user satisfaction, though they every now and then praise me a little for UI/UX improvements. With Claude Design, I've got my design system set up (also by Claude scanning the repo); I upload a screenshot of the area I'm not happy with, prompt with some additional remarks, and after a couple of iterations, I get a proposal, which is always better than what I come up with in the first place.
I have to admit that when it was blocked, I canceled my max plan and asked for a refund. It felt like someone took away my previous toy. So I'm happy it's back again; I upgraded to max again. Coding aside, but Claude Design is phenomenal - for both new designs and redesigning existing UIs. So my customers will face a new wave of refreshed screens all over the place in coming days ;)
Had experience with compliance before, now building on it and learning a ton. Growing number of customers suggest I’m onto something, so doubts are minimal
And yes, solo founder.
Define "to succeed".
Had one business (dev shop) that was successfully aqui-hired - but it took my 10 years to build it.
For last two years working on a startup, pivotel last year to GRC / compliance management. Finally with profit and growing number of paying customers, but still waiting to pay myself a decent salary. Moments of doubt are hiting more often recently, but I still think it's worth it.
I have to disagree - did it solo while dogfooding the tool for this exact purpose.
I've created a product around this exact problem and niche. No, you can not automate 99% of it, but one (tool I've created) can help with guidance and translating strange requirements into something, that matches your context. I plan to launch it on HN as soon as I'll get my soc2 type II report. It's called humadroid.io (https://humadroid.io) - feel free to schedule a demo and mention HN; I'll be happy to give a generous discount code. Been working for over a year on it, agree it's not easy, but it's accessible and perfectly doable by solo founders.
Thank you :)
Mostly nodding along, with a few of these aged in interesting ways from where I'm sitting.
The drones bit hurts the most. There's a war an hour from our border eating FPVs by the millions, and Poland - sitting on batteries, motors, chips, a generation of engineers - has not stood up a real domestic drone industry. Money is there. Will is there. We just... haven't shipped. That should keep ministers awake.
EVs are worse. Izera is a punchline at this point. Noah literally called the play in 2024 - "don't bet on one champion, run a bunch and let them fight" - and the state did the exact opposite. We picked one horse and it never left the stable.
The Korea idea, on the other hand, Noah might have undersold. Framework agreement is for ~1,000 K2 tanks. By 2030 Poland will field more main battle tanks than Germany, France, the UK and Italy combined.
Rest holds up. "Try all the things" is right - we're just very uneven at the trying. Defense procurement: shipping. Civilian industrial policy: not so much. Software still works the way it always has: quietly, in apartments, mostly without the state in the loop. Which honestly might be a feature.
Filed from Poznań, which is where I'm typing from. The dateline alone made me smile.
I've been building software here for almost 20 years. Started a software house, grew it to ~50 people, sold it, now back to bootstrapping from scratch. The fact that this is a normal sentence to type from a Polish city is, honestly, kind of the whole story.
That "institutional framework" line in the article is doing a lot of heavy lifting. Having run companies through Polish bureaucracy — it's fine. It works. A generation ago that bar was on the floor. Boring is a feature.
Politics aside, the 35-year arc has been quietly extraordinary. European to the bone, with old roots and a real appetite for what's next.
Full post by Theo:
Fun fact - if you have a recent commit that mentions OpenClaw in a json blob, Claude Code will either refuse your request or bill you extra money.
This is an empty repo, I'm just calling Claude Code directly. Insanity.
Confirmed in my own tests. Crazy
I’m a web dev, I never made publicly accessible desktop app, so please forgive my ignorance, but:
At that time, a GitHub Actions workflow we use in the macOS app-signing process downloaded and executed a malicious version of Axios (version 1.14.1)
So if I understand this correctly their GH Actions is free to upgrade the package just like that? Is this normal practice or it’s just shifting blame?
Haha, thanks for the heads-up
Perfect, thanks. Codex app sucks, but I've been exploring opencode for that. Will try MiniMax!
This is a perfect example of how quickly you can burn through trust that took a long time to earn. I used to be - in my small circle of friends and peers - a genuine advocate for Anthropic and Claude. It was my sole AI assistant for over a year. But somewhere around February/March, something shifted. Declining quality, policy changes, inconsistent output. Nothing dramatic, just... a slow erosion.
That erosion pushed me to try Codex. I signed up for their most expensive pro plan. Now I'm about to experiment with Kimi. I'm not saying they're better (well, sometimes they are). But here's the thing - what Anthropic did is they made me look. They made a loyal customer start shopping around. And I think that's the worst thing you can do.
Having said that - as an LLM provider for my product, we're staying with Claude. I still trust in their ethics. Please don't prove me wrong.
So the fact, that I recently bought used iPod, replaced the battery and storage and use it now with pair of IEMs make me some sort of a... trendsetter?
Makes sense. We're working toward making the auditor connection easier on our end too. Not there yet, but it's on the roadmap.
No, we don't do audits — and that's intentional. I think there's a conflict of interest when the same company advises you on compliance and then certifies you. Incentives get weird.
The good news: there are plenty of EU-based ISO 27001 audit firms. We can recommend one or two if you need a pointer — we just don't have a formal catalogue or marketplace for that yet (though it's on my list).
So you'd use Humadroid for the preparation - policies, controls, evidence, risks, continuity plans, ISMS workbook - and then bring in an independent auditor for certification.
Speaking of missing categories — there's no "Compliance Tools" or "GRC" category yet. I'm building humadroid.io (SOC 2 / ISO 27001 compliance platform, based in Poland) and as far as I can tell, there aren't many European alternatives in this space. Most of the established players (Vanta, Drata, Secureframe) are US-based. Would be great to see this category added.
Understanding what a control actually means is the first "aha" moment. And it feels like you've cracked the code. Then you realize that's maybe 10% of the work. Each control needs sub-controls (because "Access Control" is actually 15 different things). Those sub-controls need evidence. That evidence needs to be versioned (auditors love asking "show me this policy as it existed 6 months ago"). Your policies need to map to controls. Your controls need to map to risks. Your risks need treatment plans.
Oh, and you'll need vendor assessments - because your auditor will ask about that AWS subprocessor you forgot you were using.
And business continuity plans. And an incident management process.
And then, right at the end, you discover the System Description — this dense narrative document that ties everything together and somehow needs to exist before your Type I audit.
I went through ISO 27001 in 2019 and thought "never again." Then I built a tool to make it survivable and got SOC 2 Type I using it (humadroid.io). Took way longer than I expected, and I already knew the domain.
Not trying to discourage — just a heads up that the iceberg goes deep. Happy to answer questions if you're heading down this path.
Honestly, Delve is great. Them and Compai are leading the front of modern AI-assisted compliance right now. I'm chasing them.
What I'm trying to do differently is depth of context. Humadroid learns about your company first - how you operate, your stack, your processes. From there it generates control descriptions that are actually actionable for your setup, and policies that need minimal review rather than a full rewrite.
Whether that's enough differentiation? Ask me in a year.
Honestly, great questions - this is either good exercise for me or actionable feedback. Both valuable.
Right now I recommend auditors but don't have formal partnerships. Vanta/Drata's auditor relationships are... let's say on the edge of conflicted? I don't want to go that route. And at $250/month I can't play the referral game anyway (Vanta pays hundreds per referral - that math doesn't work for me).
What I can do is democratize access. I've watched too many small teams get excited about SOC 2, then ghost once they see the total cost - $15k+ for the platform, $20k+ for consultants, $15k+ for auditors. I want the barrier low enough that smaller businesses can actually get certified and compete with bigger players.
On the checkbox vs. real security thing - you're right, it's tricky. I don't want to be another "generate docs, tick boxes, forget until next audit" platform. But targeting smaller businesses actually helps here - when you're a 10-person company, management is in the compliance process, not just signing off on someone else's work. It tends to stick better.
That said, sometimes I wonder if I help too much. My System Description assistant is almost unfair - what used to take weeks now takes minutes. Is that checkbox-enabling or democratizing? Genuinely not sure.
And yes - "vs Vanta/Drata" pages are going on the list. You're not the first to ask.
Not yet - but literally finishing this week. Promised a customer I'd ship it before Christmas, so that's been my deadline.
AWS and GitHub integrations first. It auto-fetches and verifies the data (where applicable), creating read-only evidence snapshots. No manual screenshots or "I swear this config was set correctly" moments during audits.
Part of the standard price - no integration tier upsell.
The big difference is context-awareness. Vanta/Drata give you templates and checklists. Humadroid starts by understanding your company - what you actually do, how you operate, your tech stack.
From there, the AI generates policies that are yours, not generic docs with [COMPANY NAME] placeholders. Same with control descriptions - they're specific and actionable for your setup, not "implement access control" with no context. It also identifies risks based on what you actually do and helps build business continuity plans around your real critical processes.
You still review everything (it's compliance, not magic), but you're editing 80% done work instead of staring at a blank template wondering where to start.
The price difference is real too, but honestly that's a side effect of being early and solo - not the core value prop.
Humadroid (https://humadroid.io) - AI-Assisted SOC 2 & ISO 27001 compliance for small teams. $125/month flat (for now, during beta).
Recently crossed the $500/month mark after a painful pivot from HR tech earlier this year. The whole thing started because I did ISO 27001 back in 2019 and was completely lost - overpaid for consultants, got lost with policies and controls, figured it out the hard way.
Passed SOC 2 Type I earlier this year using only Humadroid (yes, dogfooding a compliance tool through an actual audit was... an experience).
Currently finishing automated evidence collection (AWS and GitHub integrations first). Pretty proud of that one - compliance shouldn't mean "panic-screenshot everything before audit."