Badges

Forums
When did a customer first ask you to prove your app was secure?
The first security question from a buyer usually lands at the worst possible moment: the deal is nearly closed, and someone on their side asks for a pentest report, a filled-in security questionnaire, or proof that customer data is actually protected. Most small teams have none of that ready, so everything stalls while you work out what a credible answer even looks like. I'd like to hear how other founders handled it. Did you pay for a pentest just to unblock one deal? Fill in the questionnaire yourself and hope nobody read it closely? Start SOC 2 earlier than you wanted to? Or walk away from the deal? And for those further along: what actually satisfied the buyer in the end, a document, a call between engineers, or just a founder who clearly understood the question? Disclosure: I co-found Xseth, where we do external security testing, so I have an obvious bias here. I'm asking because the stories I hear are all over the place, and I'd genuinely like to know what unblocks these deals in practice.
I’m starting to think good onboarding explains less, not more
I ve been paying closer attention to onboarding flows lately. A pattern I keep noticing is that products often try to explain everything before the user has done anything. Feature tours, tooltips, welcome screens, setup questions all before the user has experienced the core value. I used to assume more explanation meant less confusion. Now I m not so sure. The products I remember most clearly tend to get me to one useful action first, then explain things when they become relevant. I d be interested in how other makers think about this: At what point does helpful onboarding become friction?How do founders spot "silent churn" when users leave without any bad feedback?
I went through my credit card statement last weekend and finally canceled a software I ve been paying for over a year. I felt bad doing it because the product was great, but I only used it a few times all year.
It was a good reminder that churn isn't always caused by bugs or bad features sometimes people just outgrow the need for the tool.
If you run a SaaS how do you learn from users who leave politely without filling out cancellation surveys?