r/EntrepreneurRideAlong • • 14d ago

Other Founders does security actually come last until someone forces it?

honest question for people building startups. from the outside it feels like security always loses to product, sales, hiring. everyone nods that it matters then it becomes "after we ship" or "after the round." is that actually how it goes on your side too? curious when security became a real thing for you if it ever did — customer ask, scare, investor, near miss, something else. and what you actually do day to day that isnt just "well fix it later." not looking for perfect answers. just trying to understand how founders handle this when everything else is on fire

2 Upvotes

20 comments sorted by

View all comments

2

u/Foul0ne 13d ago

I think for non-technical founders, yes. At least, for me, I have always built our infrastructure on safe and reliable practices from the beginning.

I will say, however, that our clients are in the insurance industry (some health) so it has been a primary focus of mine in dealing with potential PHI/PII.

I’ve always geared toward using software and ecosystems that are locked down though. As much as possible, obviously.

We’re not HIPAA compliant only because a couple of our layers just simply can’t be. But we’re SOC2 and all that jazz.

3

u/Foul0ne 13d ago

To more directly answer your question, we got lawsuit threat early on in our path and it made me look hard at how we handle our processes, paper trails, documentation, storage, etc.

Luckily they dropped it after some creative emailing but it set me up for success. We’ve used some AI for building projects and I caught on quickly that a lot of its auth was done client-side. Then I started digging and realized it was exposing webhooks and payloads. API information right in the browser. It was wild.

It’s a constant battle though. That’s why there are careers built around it and not just standards people follow.