惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
博客园 - 司徒正美
Last Week in AI
Last Week in AI
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
博客园 - 聂微东
M
MIT News - Artificial intelligence
博客园_首页
Jina AI
Jina AI
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
Vercel News
Vercel News
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG
N
Netflix TechBlog - Medium
B
Blog
Google DeepMind News
Google DeepMind News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
How I built ZeroAudit — AI-powered SOC 2 compliance autom...
Dmytro Mazurenko · 2026-06-25 · via DEV Community

Dmytro Mazurenko

SOC 2 Type II audits are painful. Auditors want evidence for 42 controls — who has access, are vulnerabilities patched on time, does every deployment go through review. Normally you pay a consultant $15-50k and spend months collecting screenshots and logs manually.

ZeroAudit connects to your tools and has an AI agent collect that evidence automatically, then classifies it against SOC 2 controls and generates an audit-ready report.

Live demo: https://zero-audit-red.vercel.app
GitHub: https://github.com/mazurenkodmytro0710/ZeroAudit

Why DynamoDB

I chose DynamoDB over Aurora because every query I need is org-scoped. There are no cross-org queries anywhere in the app. Single-table design with two GSIs covers all access patterns without joins. Aurora would've been overkill.

The schema uses PK: ORG#orgId with SK patterns for evidence, agent runs, integrations, and metadata. GSI1 queries evidence by control sorted by time. GSI2 queries controls by coverage status.

What's real vs simulated

Real data from live API calls: CC7.2 uses Dependabot alerts and code scanning from GitHub. CC8.1 uses pull requests and branch protection rules. CC6.1 uses repository collaborators. A1.2 uses IAM events and console logins from AWS CloudTrail. CC7.4 uses incident history from PagerDuty.

Simulated: CC6.2 would need Okta for real user provisioning data. The AI classification runs on whatever evidence it gets — real or mock.

AI agent architecture

The agent runs as a fire-and-forget background process. POST /api/agent/run returns 202 immediately. I tried doing it synchronously but Vercel functions timeout at 10 seconds and 6 controls plus AI calls take around 2 minutes.

Each control fetches real evidence from connected integrations, merges it with mock evidence for context, sends it to Grok (grok-3-mini via OpenAI-compatible API), parses the response for coverageStatus, riskLevel, and reasoning, then saves the artifact to DynamoDB.

The UI polls /api/agent/status every 3 seconds while showing a terminal animation. The animation is pre-scripted per control and doesn't wait for actual API responses — intentional UX decision.

I switched from Gemini to Grok mid-development because Gemini's free tier hit daily quota. Grok's OpenAI-compatible API made the switch a one-line change.

Stack

Frontend: Next.js App Router, TypeScript, Tailwind CSS. Database: AWS DynamoDB in eu-north-1, single-table design. AI: Grok API grok-3-mini. Auth: GitHub OAuth, custom implementation. Integrations: GitHub API, AWS CloudTrail, PagerDuty API. Deploy: Vercel.

DynamoDB note: the table is named soc2-autopilot in eu-north-1. DynamoDB only allows creating one GSI at a time while another is being backfilled — I hit this during setup and had to wait about 5 minutes between GSI creations.

What I'd do with more time

Okta integration for real user provisioning data, scheduled scans via Vercel Cron, fixing deduplication at the write level instead of read time, search that actually filters the evidence map, and CSV export for auditors.

Created for H0: Hack the Zero Stack Hackathon #H0Hackathon
Live demo: https://zero-audit-red.vercel.app
GitHub: https://github.com/mazurenkodmytro0710/ZeroAudit