惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
Engineering at Meta
Engineering at Meta
Stack Overflow Blog
Stack Overflow Blog
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
I
InfoQ
B
Blog
WordPress大学
WordPress大学
Jina AI
Jina AI
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
Google Developers Blog
C
Check Point Blog
月光博客
月光博客
L
LangChain Blog
GbyAI
GbyAI

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
How I built ZeroAudit — AI-powered SOC 2 compliance autom...
Dmytro Mazurenko · 2026-06-25 · via DEV Community

Dmytro Mazurenko

SOC 2 Type II audits are painful. Auditors want evidence for 42 controls — who has access, are vulnerabilities patched on time, does every deployment go through review. Normally you pay a consultant $15-50k and spend months collecting screenshots and logs manually.

ZeroAudit connects to your tools and has an AI agent collect that evidence automatically, then classifies it against SOC 2 controls and generates an audit-ready report.

Live demo: https://zero-audit-red.vercel.app
GitHub: https://github.com/mazurenkodmytro0710/ZeroAudit

Why DynamoDB

I chose DynamoDB over Aurora because every query I need is org-scoped. There are no cross-org queries anywhere in the app. Single-table design with two GSIs covers all access patterns without joins. Aurora would've been overkill.

The schema uses PK: ORG#orgId with SK patterns for evidence, agent runs, integrations, and metadata. GSI1 queries evidence by control sorted by time. GSI2 queries controls by coverage status.

What's real vs simulated

Real data from live API calls: CC7.2 uses Dependabot alerts and code scanning from GitHub. CC8.1 uses pull requests and branch protection rules. CC6.1 uses repository collaborators. A1.2 uses IAM events and console logins from AWS CloudTrail. CC7.4 uses incident history from PagerDuty.

Simulated: CC6.2 would need Okta for real user provisioning data. The AI classification runs on whatever evidence it gets — real or mock.

AI agent architecture

The agent runs as a fire-and-forget background process. POST /api/agent/run returns 202 immediately. I tried doing it synchronously but Vercel functions timeout at 10 seconds and 6 controls plus AI calls take around 2 minutes.

Each control fetches real evidence from connected integrations, merges it with mock evidence for context, sends it to Grok (grok-3-mini via OpenAI-compatible API), parses the response for coverageStatus, riskLevel, and reasoning, then saves the artifact to DynamoDB.

The UI polls /api/agent/status every 3 seconds while showing a terminal animation. The animation is pre-scripted per control and doesn't wait for actual API responses — intentional UX decision.

I switched from Gemini to Grok mid-development because Gemini's free tier hit daily quota. Grok's OpenAI-compatible API made the switch a one-line change.

Stack

Frontend: Next.js App Router, TypeScript, Tailwind CSS. Database: AWS DynamoDB in eu-north-1, single-table design. AI: Grok API grok-3-mini. Auth: GitHub OAuth, custom implementation. Integrations: GitHub API, AWS CloudTrail, PagerDuty API. Deploy: Vercel.

DynamoDB note: the table is named soc2-autopilot in eu-north-1. DynamoDB only allows creating one GSI at a time while another is being backfilled — I hit this during setup and had to wait about 5 minutes between GSI creations.

What I'd do with more time

Okta integration for real user provisioning data, scheduled scans via Vercel Cron, fixing deduplication at the write level instead of read time, search that actually filters the evidence map, and CSV export for auditors.

Created for H0: Hack the Zero Stack Hackathon #H0Hackathon
Live demo: https://zero-audit-red.vercel.app
GitHub: https://github.com/mazurenkodmytro0710/ZeroAudit