We got a SOC2... and still get questionnaires. It's the worst. Companies are just outsourcing their security reviews to the vendor. Rather than rely on a 3rd party audited document companies want their custom questions answered. BUT - they aren't custom questions - it's the same questions for every vendor and they are very often poorly worded. Then when we turn them in - there's no follow up questions which to me implies that no one is reading them. Security theater...
Same here. I wish it was a little faster in changing configurations (I move some speakers around to different rooms and different pairings from time to time), but the last time I did so - it was faster/better than before.
Induction works fine. Our house is all electric. On the coldest winter days the heat pump needs some help using some resistance heat which isn't as efficient - but it does just fine. No need to have gas.
Just moved into our "forever" home and our setup is very similar to isbjorn16's (7 in the family, HPWH "80G", but I have an 8" PowerPipe from these folks: http://renewability.com/#learn-more. (It's a monster - plumber wanted to give me a clean out at the bottom - but that meant some jackhammering to set it low enough.)
So far so good - we do a bunch of baths/showers at bed time and no one runs out of hot water. Also - I'll add that we accidentally had the plumber remove all the low flow "plugs" from the showers so there's a lot of water flowing.
The pipe is pretty fun - not only is it fun to look at - but when someone is taking a shower it's fun to feel the heat at the top of the pipe and as you move down the pipe it gets colder until it reaches the temp of the cold water coming into the house.
Since it was new construction - we'll never know how much of a different the drainwater heat recovery pipe is making - but it is definitely doing work.
I can imagine these pipes becoming more popular (though rising prices will kill off any efficiencies real fast). Maybe code?
I also see that the security requirements are quite high. While its difficult to argue with source code security - here are some of the security requirements:
The standard annual risk assessment shall include, to the best of Developer's ability, the following:
(i) SOC 1 and/or SOC 2 audit report;
(ii) 3rd party proof of PCI compliance (a certificate showing Developer's handling of credit card payments is compliant);
(iii) Privacy Shield Attestation;
(iv) ISO Certification or Cloud Security Alliance Self-Assessment;
(v) Cloud Security Self Assessment;
(vi) any information on subcontractor or vendor production datacenter(s), IaaS, PaaS, or private hosting providers, as required by GitHub based on data and services rendered; and
(vii) Written responses and evidence of specific security requirements as outlined in this agreement
Desk.com had a variety of this (you got a free 30 days no matter cc or not) then could continue to use the free plan if you entered your CC. They had a bunch of a la carte features that they hoped to make easy to upsell to.
Great work guys. I'm sure you've heard a hundred times that this idea is too small or too something, but it is executed super well. Hopefully we can get our own moved over from Google Sites (yikes).
Question - if this is really to be the ultimate status page - a service wouldn't want to use their own DNS - correct? They'll want to use [domain].statuspage.io - right?
We've been exercising this API for a couple weeks at DigMyData. So far so good. Right now the API event history only goes back 30 days so we're having to "create history" so we can offer some metrics that need events (like cancellations). Keep up the great work Stripe.