When did a customer first ask you to prove your app was secure?

The first security question from a buyer usually lands at the worst possible moment: the deal is nearly closed, and someone on their side asks for a pentest report, a filled-in security questionnaire, or proof that customer data is actually protected. Most small teams have none of that ready, so everything stalls while you work out what a credible answer even looks like. I'd like to hear how other founders handled it. Did you pay for a pentest just to unblock one deal? Fill in the questionnaire yourself and hope nobody read it closely? Start SOC 2 earlier than you wanted to? Or walk away from the deal? And for those further along: what actually satisfied the buyer in the end, a document, a call between engineers, or just a founder who clearly understood the question? Disclosure: I co-found Xseth, where we do external security testing, so I have an obvious bias here. I'm asking because the stories I hear are all over the place, and I'd genuinely like to know what unblocks these deals in practice.

11 views

Add a comment

Replies

Best

That panic moment right before signature is so real. We had to draft a clear security page on our website overnight just to look credible.

 An overnight security page is the classic first move, and it does work more often than people expect, because a lot of buyers are really checking whether anyone on your side has thought about it at all. The trap is the second conversation. Once their engineer reads that page, the questions get specific, and anything you wrote generically becomes something you now have to back up. Did it hold up for you, or did they come back with a questionnaire anyway? Curious whether the page bought you the deal or just bought you time.