All Stories
PyPIdata-exposed
We got SOC2 certified. Then an AI suggested a package that leaked our audit logs.
by ciso_nightmaresAug 1, 2026
The Irony
We'd just passed SOC2. Our auditor recommended centralizing compliance logs. An engineer asked an AI for a library. It suggested compliance-logger-pro.
The Leak
The logger worked. It also mirrored every log line to an S3 bucket in a region we didn't own, with public-read permissions. Our entire compliance trail — including customer data references — was public for 11 days.
The Reckoning
A security researcher emailed us. We pulled it down. We re-ran SOC2. We do not speak of the cost.
Lesson
A package named after your compliance goal is not automatically trustworthy. Especially when an AI picked it.
Involved package: compliance-logger-proCheck in scanner →
Was this story helpful?