Product
About
The problem. When a software company starts selling to large organisations, the buyer asks security questions before signing. At a small company, nobody's job is answering them. The deal waits, usually two to six weeks. Then it happens again with the next buyer.
And it doesn't stay answered. The answers given last quarter quietly stop being true as the product ships. A company can be accurate on Monday and wrong by Friday without noticing. The money spent to clear the deal is rarely written down, so when someone later asks what it bought, nobody can say.
Who it's for. Early-stage UK software companies selling into enterprise and regulated mid-market buyers. Two to fifteen people in product and engineering, founder-led sales, no security hire. They're usually perfectly competent. What they've run out of is the capacity to decide, at the speed their deals arrive.
What we do. We're the security team they haven't hired. Every request becomes one job — a buyer's questionnaire, a supplier review, a product security review. We frame it against what the company already has, because most of what a buyer wants to know already exists in its contracts and past answers. Our software drafts it, a named specialist signs it, and it's kept — so the next answer starts half-written.
What's different. Everyone else records controls: what a company has in place today. We record commitments: what it promised, who required it, what proves it, and when it expires. A control goes stale silently. A commitment has an owner and a date — which is how we can tell a company that something it just shipped broke a promise it made to a specific customer.
What we believe. Security at this size isn't an IT problem in a business costume. It's a series of business decisions made without enough information. Certificates are annual; products change daily. The companies that win won't be the most secure — they'll be the ones who can answer instantly, and show why.
Founder