Real companies asking for SOC 2, ISO 27001 and AI governance help on Reddit right now, updated weekly.
When a deal stalls on "do you have SOC 2?", the first place many founders vent is Reddit. Communities like r/cybersecurity, r/msp, r/startups and r/compliance are full of posts asking how to get ISO 27001, how to manage shadow AI, whether the EU AI Act applies to them, or which tool catches leaked credentials.
Leadverse tracks those conversations continuously and filters them for buying intent against security and compliance offerings. The posts below are from companies with a concrete, current security or compliance need. The feed rotates weekly as new demand appears.
Trusted by growing businesses worldwide
Leads over the last 7 days
Daily buyer-intent posts, past 7 days
Total
493
Lead Intents
High-quality leads grouped by buying intent
Tool Request
293
Troubleshooting
152
Exploring Solutions
25
Comparison
10
Hiring / Outsourcing
6
Pain / Frustration
6
Alternative Search
1
Live now
Live security & compliance leads from Reddit
Anonymized previews - the full posts, links and outreach drafts are inside Leadverse.
This page is a public preview of Reddit posts where people are asking for security and compliance solutions. Leadverse finds these conversations so you can spot potential customers before they go cold.
What are the best ways to protect yourself from social engineering?
What practical steps would you recommend to protect against social engineering, especially phishing, impersonation and targeted scams? Beyond strong passwords and 2FA, what habits or tools actually make a difference? Any useful guides would be appreciated.
Are Evony accounts/items advertised on Facebook usually scams?
I’ve been seeing people on Facebook advertising different Evony: The King’s Return services, such as Keep upgrades, RSS/resources, gems, account upgrades, and other game-related services. I’m wondering how legitimate these offers actually are. For anyone who has personally dealt with these sellers: Have you successfully bought Keep upgrades, RSS, gems, or other services from them? Are these sellers generally legit, or are most of them scams? What are the common scams or red flags to watch out for? Do they actually provide the service after receiving payment? Is there any safe way to verify a seller before paying? Are there any trusted sellers or safer methods that experienced players recommend? I’m not asking for specific sellers necessarily — I’m mainly trying to understand whether these Facebook offers are generally trustworthy and what risks I should be aware of. Would appreciate hearing from anyone who has actually used these services.
You would think that a product that charges you almost 50 USD per year would have a good dev team behind it, right?. They decided to put many into marketing in the F1. Well... no... Autoupdate feature on Windows is bad, the app tells you there's an update pending, that will take place once you restart it... you hit "restart now", it closes 1password and then it does nothing... You open 1password again, and it says "there's an update pending, it will be installed next time you restart the app", which is not true, and also fails to install if you select "restart now". Considering Bitwarden is 20 USD per year, I'm really going to consider switching it when my annual subscription ends. Where's 1password's added value for over 2x the price?. Thanks.
My.mailstop.ai is being marketed to me by a postal shop in silicon Valley. The guy had me buy my business domain using the crm with cloudflare. He "accidentally" paid with his card instead of mine. I do not want my domain paid by a stranger. Now I'm paranoid. How do I verify trust and security.
trying to clean up my digital footprint without running ten different apps
i found my main email on a bunch of data broker sites recently and started looking at my overall setup. i run bitdefender ultimate security to cover basic endpoint protection, dark web alerts, and encrypted vpn traffic when on public networks, but an all in one suite definitely has its limits. a basic vpn and antivirus combo does not stop browser fingerprinting, background telemetry, or data brokers from trading your public info. true anonymity does not exist with one software install, so i am trying to build a practical privacy stack that pairs an all-in-one security app with dedicated browser hardening and manual opt-out removals.
So I've come across this American company The Saber Outpost, and they have crazy good prices right now. However, their symbol and 'About Us' descriptions call themselves The Padawn Outpost, seemingly as if it is the UK based company. They seem to have very similar options for both blade models and soundboards (Both, RGBX, Xenopixel V3, and Proffie V2.2) At the top of The Saber Outpost page it does say, 'Save big and enjoy free shipping', but I'm unsure if that means its legit, or is that a way they are trying to get about seemingly like a scam. Does anyone know if The Saber Outpost is just an offshoot American version of Padawn Outpost that does have cheaper prices, or is it a full scam/knockoff website that either will provide terrible quality product or no product at all? I'm new to buying sabers online and this would be my first one, so any information people can provide is greatly appreciated! Links below if anyone wants to have a look:
Advice for someone who uses Google products with Apple devices
All my devices are Apple (MacBook, iPhone, iPad) but I use Chrome, Gmail, Drive, and other Google products more than anything. I never use Safari, for example. Right now, I’m prioritizing Google Password Manager over Apple Password, and I think I’ve got all my settings correct (although I could be wrong), but I still get conflicts. For example, when I need to sign into one of my Google accounts on my MacBook, I get a pop-up asking about managing how passkeys work and directing me to system settings - the passkey I have set up in Google Password Manager doesn’t come up. Is it common that Apple and Google systems have hiccups like this? Would a third-party password manager eliminate these problems? Or would Apple Passwords be better to prioritize than Google Password Manager?
bitdefender premium security vs norton 360 for identity theft protection
i'm comparing bitdefender premium security vs norton 360 mainly for the identity protection features. i'm trying to understand how useful the dark web monitoring actually is, what kind of alerts people get, and whether the recovery support is something you'd realistically use if your information showed up somewhere. also curious how people judge the bundle value. if you're paying for coverage across several devices or people in the household, do the identity theft features make a noticeable difference, or are you mostly paying for the regular security stuff? i'm more interested in the practical differences with dark web identity monitoring than antivirus test results.
How's your claude setup when it comes to secrets handling
I was wondering how other folks out here handle secrets and other sensitive stuff when it comes to agents. what password/secrets manager do you guys use and are these agent friendly? I have seen people using some secrets.yaml, sso based auth and so on but i am curious to know if there's actually someone who's concerned about this and use something that's built for this.
open the door to the agents without handing the keys?
I was wondering how other folks out here handle secrets and other sensitive stuffs when it comes to agents. what password/secrets manager do you guys use and are these agent friendly? I have seen people using some secrets.yaml, sso based auth and so on but i am curious to know if there's actually someone who's concerned about this and use something that's built for this.
For founders with a live AI-built SaaS: when did reviewing it yourself stop feeling like enough?
For people who built a big chunk of their SaaS with Cursor, Claude, Lovable, Bolt, etc. and now have real users: Did you ever hit a point where having the same tools review their own work stopped feeling like enough? I’m curious what triggered it. Was it getting your first paying customers? Handling sensitive data? An enterprise prospect asking security questions? A production incident? Payments? Or did you never reach that point? And what did you do once you got there? Another model, automated scanners, a developer friend, contractor, security person, full code review? Mostly interested in what people actually did, especially if you spent money on it, rather than what the ideal process is supposed to be.
Found this seller for some shoes I want and not sure whether they are legitimate or not. Would anyone be able to help out on how to assess this? Thanks in advance
I need to spend a certain amount of AI tokens a month for my job so what ways do you use Claude to automate your job as IAM admins? We use OKTA as our IDP and I’m looking for ideas to brainstorm my own from
How do discount gift card sites work and are they safe?
I keep hearing about buying gift cards at 5 to 15% off but I don't understand how these sites get the cards cheaper in the first place. If a $100 gift card costs $100 at the store, why would someone sell it for $92? Also how do you tell if a site is legit vs a scam?
How many of you have memorized yours? It's good if you did. Then what about if you have a stroke or memoryl oss or get hit by a cement truck. How to store it elsewhere besides your own noggin?
is there perhaps a website out there that functions like google docs in terms of just a doc with tabs, but each tab has its own passwords? and the tabs are accessible to everyone with a link and anyone with the right password can look through any tab?
Just off the back of an MS support ticket, We got some info but left with more questions than answers, as MS are reluctant to explain out of the bounds of the break fix. So we are currently using the default MS passkey with both types and no attestation. I am trying to make specific keys for certain types of users. I believe this is the correct way? I am looking at making the following Auth Strengths EA Admin Auth (with Attestation)? Using YubiKey Flows Microsoft Authenticator (iOS) Microsoft Authenticator (Android) OR Temporary Access Pass (One-time use) GA Admin Windows Hello (Hardware Authenticator) Windows Hello (Software Authenticator) Windows Hello (VBS Hardware Authenticator) Microsoft Authenticator (iOS) Microsoft Authenticator (Android) OR Temporary Access Pass (One-time use) OR Password + Microsoft Authenticator (Push Notification) And similar setup to GA Admin for General Staff and Guests Our users have both, iPhone keychain passkey and MS Windows Passkey or MS Authenticator passkey So presumably they can have 2 different policy setups at the same time and still be fine (Attestation + Synced) When MS were explaining very quickly, If I understand it correctly I would need Passkeys (FIDO2) targets, pointed at the groups for those users? And then I would need CA policies that use the specific Auth Strengths tailored to each user type (so multiple policies presumably) We are a small company <15 users is this overkill? Or am I on the right path? This is a fair bit of work, which we will do if its the right way but as we are small do we need something simpler. Any more detail you need just ask.
Hello, Apple has been automatically creating passkeys in my passwords instead of 1password. I just finally turned off autofill for passwords. How do I transfer my passkeys from passwords to 1password? If that’s not a thing, what do I need to do?
As the title says, I would like to know options for a password manager that has multiple accounts. My family has been using Nortons for ages and we are finally getting tired of not only how buggy it is, but how greedy they've become. So we are looking for options for a password manager for multiple people. We are considering Bitdefender which has a password manager, however I need my own pass manager and so does my parents. My mother works away from home and uses her own laptop, so we need one that can isn't locked to one person accessing it at one time. I had found one called 1passkey or 1password? Something like that but I cannot remember which one it was. Is there any other options out there that will allow at least 3 people to have their own "vault" of passwords?
For those who have hands-on experience with both NordPass and Proton Pass: How do they compare across iOS and Android, specifically regarding Auto-fill reliability on both platforms? Also, what is your experience with them on Windows ?
Since i started reselling iphones m I've made some sales but I'm honestly getting tired of having to explain why I'm legit everytime a customer wants to buy, I mean I understand there are scammers right but I've tried getting verified on insta and I'm always posting videos of my customer reviews, I haven't a physical store yet and I've noticed scammers steal my videos to use on their own pages, is there another way or a platform that will boost customer trust instantly?
My kid applied to this site to be a tutor and now they have reached out to her, she has asked me to confirm whether its legit, I figured i'd ask if anyone here has used this service? ScamAdvisor gives it a so-so rating.. Thx!
is there perhaps a website out there that functions like google docs in terms of just a doc with tabs, but each tab has its own passwords? and the tabs are accessible to everyone with a link and anyone with the right password can look through any tab?
I have 3 requirements from a private key 1. bound to device, unextractable 2. protected by some sort of rotateable auth + touch 3. can be registered without the private key (hardware key) being present have 1 1. to not have the credential stolen have 2 1. so i dont have the credential used unknowingly have 3 1. so i can put it in more then one location as backup without needing to reach for it when registring to new services I have tried to use PIV, but i find that it is very hard to implement in almost any case that isnt just encrypting and decrypting files on my computer. fido2 is very seamless but i cant register with a public key like piv is there something i am missing? using a yubikey 5.7.4 example for piv issues - tried to set up opening the computer hardware with pkcs11 and was very hard to set up so that more then one key works, setteled on fido2 but as i said, i dont have a real backup since all the keys are accessible so that i can do such registration.
How can you secure your phone in the best way possible to maximise privacy and protection from downloads or information being broken into/extracted? IOS specifically. I.E if a chat is deleted etc. Is it actually deleted or not? Passwords? Images? App data if it is deleted from the phone? Does a factory reset or new phone remove all the old data?
Leadverse subscribers see every lead the moment it's found - full post, direct link, and an AI-drafted personalized DM ready to review and send.
Get fresh security & compliance leads daily
How it works
How to find security and compliance customers on Reddit
1
Describe what you sell
Tell Leadverse about your product or service. The AI builds a buyer profile and knows exactly which posts count as leads for you.
2
AI scans Reddit daily
Thousands of subreddits are monitored around the clock. Matching posts are filtered for clear buying intent so only the best-fit opportunities reach you.
3
Start real conversations
Each lead comes with an AI-drafted, personalized DM or comment reply. You review it, make it yours, and send it to win the customer.
FAQ
Frequently asked questions
What kind of security leads show up here?
Everything from SOC 2 / ISO 27001 readiness and AI governance to phishing training, cloud security reviews and breach-exposure checks - always from an author describing their own active need.
How fresh is this list?
The page rebuilds weekly from recent matching posts. Leadverse subscribers see new security and compliance leads daily, within hours of posting.
Can I get the link to the original post?
Not from this public preview - usernames and links are hidden here. Subscribers get the full post, its link, and an AI-drafted personalized reply or DM to open the conversation.
How does Leadverse avoid noise?
Vendor promos, security news and academic discussion are filtered out. This page focuses on posts where the author has a problem a security or compliance provider can directly solve.
Want security & compliance leads like these every day?
Leadverse monitors Reddit for people actively looking for security and compliance solutions, filters posts for buying intent, and drafts personalized outreach so you can start the conversation while the lead is still hot.
Find your leads now
Warm Conversations, Delivered Daily
Thousands of buying intent posts are created every day. Don't miss tomorrow's customers.