When did a customer first ask you to prove your app was secure?

The first security question from a buyer usually lands at the worst possible moment: the deal is nearly closed, and someone on their side asks for a pentest report, a filled-in security questionnaire, or proof that customer data is actually protected. Most small teams have none of that ready, so everything stalls while you work out what a credible answer even looks like. I'd like to hear how other founders handled it. Did you pay for a pentest just to unblock one deal? Fill in the questionnaire yourself and hope nobody read it closely? Start SOC 2 earlier than you wanted to? Or walk away from the deal? And for those further along: what actually satisfied the buyer in the end, a document, a call between engineers, or just a founder who clearly understood the question? Disclosure: I co-found Xseth, where we do external security testing, so I have an obvious bias here. I'm asking because the stories I hear are all over the place, and I'd genuinely like to know what unblocks these deals in practice.

9 views

Add a comment

Replies

Best

That panic moment right before signature is so real. We had to draft a clear security page on our website overnight just to look credible.