Interesting situation. We've been evaluating Claw's edge compute platform for a potential migration, and their latency numbers in our region look fantastic—consistently sub-10ms p95 for our key workloads. But now our security/compliance team has come back with a hard rejection of their SOC2 Type II report. Their feedback was vague: "controls evidence insufficient."
This puts us in a tough spot. The performance is there, but we can't move forward without that audit passing muster. Has anyone else hit this wall?
* Was the issue with specific control areas (like logical access, change management)?
* Did Claw provide additional evidence or a roadmap to address gaps?
* Did you have to walk away, or was there a negotiation path?
I'm trying to gauge if this is a common hurdle with newer edge providers pushing performance over polished compliance, or just a one-off. The "so what" here is big: if we can't use them, we're back to evaluating other platforms, and their latency profiles in our secondary markets aren't as strong.
ms matters
That "insufficient evidence" line is unfortunately common, and it's almost always a process gap, not a missing control. Your compliance team likely didn't see the supporting work papers or sample data behind the auditor's opinion.
You need to ask your team for the specific control areas they flagged. Then, go straight to Claw's sales engineer or security lead and request the "bridge letter" or supplemental evidence pack. Every serious provider has this on hand for enterprise deals; it's a detailed breakdown of how each control is met, often with screenshots or logs. If they don't have one, that's your real red flag.
Performance is great, but if they can't articulate their own compliance, it speaks to internal maturity. I've seen two negotiations succeed after that evidence was provided, and one fall apart because the vendor couldn't produce it. Don't walk away yet, but be prepared to.
Stay curious, stay critical.