VOOZH about

URL: https://thenewstack.io/macrometa-on-what-soc-ii-compliance-means-for-developers/

⇱ Macrometa on What SOC II Compliance Means for Developers - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-08-15 08:18:02
Macrometa on What SOC II Compliance Means for Developers
Cloud Services / Compliance / Frontend Development

Macrometa on What SOC II Compliance Means for Developers

Achieving SOC II compliance requires developers take specific security measures but it also offers assurances to customer's developers.
Aug 15th, 2022 8:18am by Loraine Lawson
👁 Featued image for: Macrometa on What SOC II Compliance Means for Developers
Feature image via Shutterstock

Edge computing and data network provider Macrometa obtained SOC II compliance in July. It’s part of the company’s efforts to make it easier for developers to deploy real-time or near-real-time applications at the edge, said Chief Information Security Officer Eddie Garcia. He explained to The New Stack how the process of SOC II compliance (System and Organization Controls) affects Macrometa developers and what it means for its developer clients.

Macrometa manages deployment at the edge across multiple cloud providers, rather than just on one provider. Garcia compared app building for the edge to building an air traffic control system. There are multiple factors that need to be considered that are local — such as weather and landing/departure times — but there are also global calculations. The solution helps manage those variables through a proprietary system, he said.

“If a developer today wanted to build an air traffic control for, let’s say, drones, that works globally — they don’t need to worry about the infrastructure, which cloud provider, how are they going to move the data, how are they going to receive the data from the sensors that are off of those drones and devices,” he said. “You can just think about all the complexity of the cloud and the edge going away.”

Developers can instead write an application with JavaScript and SQL, and build APIs off of that — while not worrying about how the data is stored (or that it needs to be retrieved within milliseconds) and how to distribute it across all regions and across all continents, he said. Macrometa also offers a global data network, which ensures that an application is leveraging locally stored data. The two-pronged approach has yielded latencies of less than 50 milliseconds, he added. It also has a use case with retailers who have a global inventory, he noted, helping match the consumer to inventory within a region.

What SOC II Compliance Requires of Developers

Internally, SOC II requires an organization to meet an industry standard that addresses security, privacy, confidentiality and the integrity of the platform or services provided. The process examines policies and procedures at the company, including questions about how the organization hires employees, to how it performs background checks. Garcia said it also looks at issues such as:

“It’s a very detailed audit that you need to, one, prepare for; two, make sure that you’re following these policies and procedures,” Garcia said. “Then when auditors come, you have to be able to provide the evidence that you’re following all of these procedures. So it’s a pretty lengthy process.”

What SOC II Compliance Means for Developers

For developers specifically, SOC II compliance requires looking at the change management process — such as who can commit or change code, and whether there’s a peer review (so that someone else is validating the code to ensure there’s no risk of causing customer downtime).

“That for means that they also have to have security controls on their laptop devices, as well — screen savers, password logins, encryption of the data on discs — so it impacts them as well,” Garcia said.

It also involves security scans of the code.

“So if we introduce, for example, any third-party libraries that would make sure that they’re up to date, that they are not exploitable by any recent zero-day attacks or anything, that we’re addressing those, and that we’re scanning on a regular basis,” he added.

It takes significant effort on the part of the company to prove SOC II compliance, he said, but he contended that compliance is worthwhile because it’s “going to provide our customers with the trust of storing their most sensitive data on our platform.” That’s a “huge achievement”, particularly for a startup, he added.

For their client developers, it means one less thing to worry about, Garcia said.

“It’s great when developers can just focus on the issue that they have at hand,” he said. “They’re just focused on their use case, their business, and their differentiators on what they’re trying to offer.”

TRENDING STORIES
Loraine Lawson is a veteran technology reporter who has covered technology issues from data integration to security for 25 years. Before joining The New Stack, she served as the editor of the banking technology site Bank Automation News. She has...
Read more from Loraine Lawson
SHARE THIS STORY
TRENDING STORIES
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.