| Just to drive the point home as I parsed through the details and looks like yall know the tech side well. Roadmap - you’re asking to plug into every mission critical sec tool. Nowhere on your roadmap is sec program details, who is doing it now, when will you get some from of pentest/audit (so so even then) or hire someone, or what yall know about security yourselves vs Facebook data eng. Tech descriptions - nowhere in it are you describing how youve done your appsec, or more accurately who has done it. Why should I give you api keys to crowdstrike and defender in that light. And you’re offering a cloud version already, depsite hitting on 0 of this. I think a big jump devs have trouble making when looking at security is this specific area. Sure, you’re saving me money and building slick tech. But Splunk isn’t going to get me hacked and roast my Saturday night. You (or more fairly vendors in the same profile as you) will. None of the data eng finesse and $50k in cost savings is worth that risk, or rather I price that risk at $50k haha. If the founders aren’t in the right headspace about their own security, I stay away - and you haven’t mentioned it once. Obviously im a little crusty from SaaS vendors burning firms over and over this way. But that’s the candid feedback. Deeper dive - The extent you discuss prodsec of your own sec tool is a token security.md file with nothing of value in it. If you are “practitioner obsessed” as mentioned in there too, then SaaS vendors owning the company and how/if/when id find out is a big part of what we obsess about. Look up the Jumpcloud hack for an example of this. |