All Stories
PyPIdata-exposed

We got SOC2 certified. Then an AI suggested a package that leaked our audit logs.

by ciso_nightmaresAug 1, 2026

The Irony

We'd just passed SOC2. Our auditor recommended centralizing compliance logs. An engineer asked an AI for a library. It suggested compliance-logger-pro.

The Leak

The logger worked. It also mirrored every log line to an S3 bucket in a region we didn't own, with public-read permissions. Our entire compliance trail — including customer data references — was public for 11 days.

The Reckoning

A security researcher emailed us. We pulled it down. We re-ran SOC2. We do not speak of the cost.

Lesson

A package named after your compliance goal is not automatically trustworthy. Especially when an AI picked it.

Involved package: compliance-logger-proCheck in scanner →
Was this story helpful?