<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ZebraByte Blog</title><description>Analize și ghiduri ZebraByte despre securitate cibernetică, privacy, conformitate și infrastructură securizată.</description><link>https://www.zebrabyte.ro/</link><item><title>Cine mai are acces după ce cineva părăsește compania?</title><link>https://www.zebrabyte.ro/blog/2026-08-17-offboarding-access-review-automation/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-08-17-offboarding-access-review-automation/</guid><description>Offboarding-ul este unul dintre locurile în care controlul accesului eșuează în tăcere. Vedem de ce conturile rămase active contează pentru SOC 2 și ISO 27001 și cum transformi plecarea unui coleg într-un access review verificabil.</description><pubDate>Mon, 17 Aug 2026 12:00:00 GMT</pubDate></item><item><title>Ce sunt Agent Plugins și de ce contează pentru agenții AI?</title><link>https://www.zebrabyte.ro/blog/2026-08-14-agent-plugins-probo/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-08-14-agent-plugins-probo/</guid><description>Agent Plugins combină un server MCP cu skills care îi explică agentului cum să lucreze corect. Vedem ce standardizează acest model, ce nu rezolvă și cum se leagă de datele reale dintr-o platformă de conformitate.</description><pubDate>Fri, 14 Aug 2026 12:00:00 GMT</pubDate></item><item><title>Ce este un Trust Center?</title><link>https://www.zebrabyte.ro/blog/2026-08-12-what-is-a-trust-center/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-08-12-what-is-a-trust-center/</guid><description>Un Trust Center este portalul extern în care clienții și prospecții pot verifica postura de securitate și conformitate a unei organizații. Vedem ce merită publicat, ce trebuie protejat și când are sens accesul condiționat de NDA.</description><pubDate>Wed, 12 Aug 2026 12:00:00 GMT</pubDate></item><item><title>PostHog feature flags behind a cookie banner (without breaking GDPR)</title><link>https://www.zebrabyte.ro/blog/2026-08-05-posthog-feature-flags-cookie-consent/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-08-05-posthog-feature-flags-cookie-consent/</guid><description>How to evaluate PostHog feature flags only after analytics consent and identify() — and why cookieless_mode: on_reject is the right Track 2 default when you need flags.</description><pubDate>Wed, 05 Aug 2026 12:00:00 GMT</pubDate></item><item><title>How to set up PostHog: GDPR, CCPA, and global privacy laws</title><link>https://www.zebrabyte.ro/blog/2026-05-27-posthog-cookie-banner-gdpr-ccpa-compliance/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-05-27-posthog-cookie-banner-gdpr-ccpa-compliance/</guid><description>Two clean ways to wire PostHog into a website that respects GDPR, CCPA, and the rest of the privacy-law alphabet soup, without losing your analytics.</description><pubDate>Wed, 27 May 2026 12:00:00 GMT</pubDate></item><item><title>Is your company concerned by NIS2?</title><link>https://www.zebrabyte.ro/blog/2026-05-25-is-your-company-concerned-by-nis2/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-05-25-is-your-company-concerned-by-nis2/</guid><description>NIS2 came into force in October 2024. Thousands of europeans companies are now under new cybersecurity obligations, and most of them don&apos;t know it yet.</description><pubDate>Mon, 25 May 2026 12:00:00 GMT</pubDate></item><item><title>What is a risk in compliance?</title><link>https://www.zebrabyte.ro/blog/2026-05-13-what-is-a-risk-in-compliance/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-05-13-what-is-a-risk-in-compliance/</guid><description>Risk management is central to ISO 27001, SOC 2, and GDPR. Most teams treat it like a checkbox. Here&apos;s what it actually means and how to think about it properly.</description><pubDate>Wed, 13 May 2026 12:00:00 GMT</pubDate></item><item><title>Can you put a SOC 2 logo on your website?</title><link>https://www.zebrabyte.ro/blog/2026-05-04-are-you-allowed-to-put-soc-2-logo-on-website/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-05-04-are-you-allowed-to-put-soc-2-logo-on-website/</guid><description>Most companies using the AICPA SOC logo never registered for it. Here&apos;s what the rules actually say and what changed recently.</description><pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate></item><item><title>How We Automated Our Client Contract Process</title><link>https://www.zebrabyte.ro/blog/2026-04-24-how-we-automated-our-client-contract-process/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-04-24-how-we-automated-our-client-contract-process/</guid><description>How we handle ZebraByte&apos;s contract workflow end-to-end, from prospect handshake to e-signature, and why we rebuilt the pipeline twice.</description><pubDate>Fri, 24 Apr 2026 12:00:00 GMT</pubDate></item><item><title>Do you need a SOC 2 report?</title><link>https://www.zebrabyte.ro/blog/2026-04-22-do-you-need-a-soc-2-report/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-04-22-do-you-need-a-soc-2-report/</guid><description>SOC 2 is not an industry default. Here is how to decide if you should start now, protect your investment, and pick the right standard for your buyers.</description><pubDate>Wed, 22 Apr 2026 12:00:00 GMT</pubDate></item><item><title>Stripe Security Checklist: 2FA, SAML/SCIM &amp; Automatic Payouts</title><link>https://www.zebrabyte.ro/blog/2026-03-31-stripe-security-101/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-03-31-stripe-security-101/</guid><description>Stripe is probably the most used payment platform in SaaS. Three settings, thirty minutes of work, and your payment platform stops being a security gap.</description><pubDate>Tue, 31 Mar 2026 12:00:00 GMT</pubDate></item><item><title>5 Google Workspace Settings to Fix for SOC 2 &amp; ISO 27001</title><link>https://www.zebrabyte.ro/blog/2026-03-26-google-workspace-default-settings-are-insecure/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-03-26-google-workspace-default-settings-are-insecure/</guid><description>Google Workspace ships with default settings that leave companies exposed to audit findings. Here are five settings to fix right now.</description><pubDate>Thu, 26 Mar 2026 12:00:00 GMT</pubDate></item><item><title>An Open Letter to AICPA and ISO Accreditation Bodies</title><link>https://www.zebrabyte.ro/blog/2026-03-20-an-open-letter-to-aicpa-and-iso-accreditation-bodies/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2026-03-20-an-open-letter-to-aicpa-and-iso-accreditation-bodies/</guid><description>A compliance platform caught producing near-identical SOC 2 reports with controls never verified — an open letter to the bodies enforcing audit quality.</description><pubDate>Fri, 20 Mar 2026 12:00:00 GMT</pubDate></item><item><title>SOC 2 Compliance Cost in 2026 for Startups.</title><link>https://www.zebrabyte.ro/blog/2025-03-04-what-is-soc2-cost/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-03-04-what-is-soc2-cost/</guid><description>SOC 2 costs $25k–$80k for most startups in 2026. Here&apos;s exactly what you&apos;re paying for — audit, tooling, implementation — and where to cut.</description><pubDate>Mon, 19 Jan 2026 12:00:00 GMT</pubDate></item><item><title>Do you need code review reviews for compliance?</title><link>https://www.zebrabyte.ro/blog/2025-11-09-do-you-need-code-reviews/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-11-09-do-you-need-code-reviews/</guid><description>Are code reviews required for SOC 2 or ISO 27001? Learn what auditors expect and how simple processes can satisfy compliance requirements.</description><pubDate>Sun, 09 Nov 2025 12:00:00 GMT</pubDate></item><item><title>What is SOC 2 and how to be compliant?</title><link>https://www.zebrabyte.ro/blog/2025-10-28-what-is-soc2/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-28-what-is-soc2/</guid><description>What SOC 2 is, how it differs from a certification, and what auditors assess. Learn when it makes sense to pursue it and how to approach it efficiently.</description><pubDate>Tue, 28 Oct 2025 12:00:00 GMT</pubDate></item><item><title>Do you need a penetration test for ISO 27001?</title><link>https://www.zebrabyte.ro/blog/2025-10-23-do-you-need-pen-test-for-iso27001/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-23-do-you-need-pen-test-for-iso27001/</guid><description>Is a penetration test required for ISO 27001? Learn when a pen test is expected, what alternatives exist, and how it fits into your certification journey.</description><pubDate>Thu, 23 Oct 2025 12:00:00 GMT</pubDate></item><item><title>Do you need a penetration test for SOC 2?</title><link>https://www.zebrabyte.ro/blog/2025-10-19-do-you-need-pen-test-for-soc2/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-19-do-you-need-pen-test-for-soc2/</guid><description>Is a penetration test required for SOC 2? Learn what SOC 2 actually expects, why auditors often ask for one, and when it&apos;s okay to wait.</description><pubDate>Sun, 19 Oct 2025 12:00:00 GMT</pubDate></item><item><title>What is hands off compliance?</title><link>https://www.zebrabyte.ro/blog/2025-10-17-what-is-hands-off-compliance/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-17-what-is-hands-off-compliance/</guid><description>A clear overview of what hands off compliance means in practice. From automation tools to white-glove services, understand the different models available.</description><pubDate>Fri, 17 Oct 2025 12:00:00 GMT</pubDate></item><item><title>How long does it take to be ISO 27001 certified?</title><link>https://www.zebrabyte.ro/blog/2025-10-12-how-long-for-iso27001/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-12-how-long-for-iso27001/</guid><description>How long does ISO 27001 certification really take? Learn the timeline from scoping to final audits and what drives the duration of the process.</description><pubDate>Sun, 12 Oct 2025 12:00:00 GMT</pubDate></item><item><title>How long does it take to be SOC 2 compliant?</title><link>https://www.zebrabyte.ro/blog/2025-10-09-how-long-for-soc2/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-09-how-long-for-soc2/</guid><description>How long does SOC 2 compliance really take? Learn the timeline from readiness to audit, and what actually takes time — and what doesn&apos;t.</description><pubDate>Thu, 09 Oct 2025 12:00:00 GMT</pubDate></item><item><title>SOC 2 vs. ISO 27001: Which one is right for your company?</title><link>https://www.zebrabyte.ro/blog/2025-10-08-soc2-or-iso27001/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-10-08-soc2-or-iso27001/</guid><description>Compare SOC 2 and ISO 27001 to choose the right compliance framework for your startup based on geography, customer needs, and growth plans.</description><pubDate>Wed, 08 Oct 2025 12:00:00 GMT</pubDate></item><item><title>What are the steps toward compliance?</title><link>https://www.zebrabyte.ro/blog/2025-09-11-what-are-the-steps-toward-compliance/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-09-11-what-are-the-steps-toward-compliance/</guid><description>Learn the essential steps toward achieving compliance with SOC 2, ISO 27001, or GDPR. Build a compliance roadmap that unlocks enterprise deals.</description><pubDate>Thu, 11 Sep 2025 12:00:00 GMT</pubDate></item><item><title>Why a one-size-fit-all solution like Vanta is not ideal</title><link>https://www.zebrabyte.ro/blog/2025-02-17-why-a-one-size-fit-all-solution-like-vanta-is-not-ideal/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-02-17-why-a-one-size-fit-all-solution-like-vanta-is-not-ideal/</guid><description>One-size-fits-all compliance wastes resources and ignores real risks—startups must prioritize a tailored, risk-first approach.</description><pubDate>Mon, 17 Feb 2025 12:00:00 GMT</pubDate></item><item><title>Platform lineage: the case for open-source compliance</title><link>https://www.zebrabyte.ro/blog/2025-02-04-the-case-for-open-source-compliance/</link><guid isPermaLink="true">https://www.zebrabyte.ro/blog/2025-02-04-the-case-for-open-source-compliance/</guid><description>A preserved editorial from the platform lineage on pricing, flexibility, ownership and lock-in in compliance software, with context for ZebraByte&apos;s current Cloud SaaS model.</description><pubDate>Tue, 04 Feb 2025 12:00:00 GMT</pubDate></item></channel></rss>