When did a customer first ask you to prove your app was secure?
The first security question from a buyer usually lands at the worst possible moment: the deal is nearly closed, and someone on their side asks for a pentest report, a filled-in security questionnaire, or proof that customer data is actually protected. Most small teams have none of that ready, so everything stalls while you work out what a credible answer even looks like. I'd like to hear how other founders handled it. Did you pay for a pentest just to unblock one deal? Fill in the questionnaire yourself and hope nobody read it closely? Start SOC 2 earlier than you wanted to? Or walk away from the deal? And for those further along: what actually satisfied the buyer in the end, a document, a call between engineers, or just a founder who clearly understood the question? Disclosure: I co-found Xseth, where we do external security testing, so I have an obvious bias here. I'm asking because the stories I hear are all over the place, and I'd genuinely like to know what unblocks these deals in practice.
Replies
That panic moment right before signature is so real. We had to draft a clear security page on our website overnight just to look credible.