Practice

The security question in the fundraise, and how it actually goes

The wrong answer is not “we have gaps”. The wrong answer is not knowing.

Dr Kelvin K Awagu28 April 20266 min read

At some point between the first meeting and the wire, somebody asks about security. Sometimes it is diligence, sometimes it is an operating partner, sometimes it is the first enterprise buyer arriving with a questionnaire while the round is still open.

Founders tend to dread this, and they usually dread the wrong part. The fear is that the honest answer is embarrassing. Almost always, the honest answer is fine and the vague answer is what does damage.

What the question is really testing

Nobody investing at seed expects a certified security programme. They know what a company of four people looks like. They are not checking whether you are secure, because at your stage that word does not mean much and they know it.

They are checking one thing: whether you can distinguish between what you have done, what you have decided not to do yet, and what you have not thought about. The first two are normal. The third is what worries them, because it generalises. A founder who has not thought about authorisation has probably not thought about several other things, and the investor has no way to find out which.

Gaps are expected. Not knowing where your gaps are is the finding.

How the two conversations diverge

The vague version goes: we take security seriously, we use best practices, everything is encrypted. Every one of those phrases is unfalsifiable, and the person across from you has heard them from companies that later had incidents. The follow up questions get more specific and the answers get softer, and what began as one question becomes a thread they now want to pull.

The specific version goes: here is what we have checked, here is what is open, here are the two things we know are wrong and when we are fixing them. That conversation ends. Not because the posture is better, often it is identical, but because you demonstrated the thing they were testing for in the first thirty seconds and there is nothing left to probe.

What to have ready

  • A dated record of what you have reviewed, rather than a claim that you review things.
  • Your open items, with severity, and a date against the ones that matter. An empty list reads as a list nobody maintains.
  • Where customer data lives, which third parties touch it, and what each of them does with it.
  • What happens when something goes wrong. Not a polished plan. Who gets called, in what order, and how you would tell affected users.
  • The two or three things you have consciously deferred, and why. This is the item that most changes how the conversation lands.

That last one feels counterintuitive, like volunteering weaknesses. It does the opposite. A founder who says "we have not done formal access reviews, we are four people sharing an office, we will start when we hire past ten" has demonstrated judgement about their own risk. That is a far stronger signal than a clean sheet, and it is much harder to fake.

The part that is actually hard

None of this requires expertise you do not have. It requires having written things down at the time, which almost nobody does, because at the moment you check something it feels obvious and not worth recording.

Six weeks later, in a meeting, the entire value was in the record. That gap between how worthless it feels to write it down and how valuable it is to have written it down is the whole problem, and it is the one thing a tool can genuinely solve for you.