Are We Complaint?

We help SaaS companies answer that question ☝️

Visit Website
December 11, 2020 'I have 200 security questions to answer'

This was my response to our Head of Sales at AirMason when he asked me where we were with a potential enterprise lead we had been courting since summer 2019.

We had a decent size of engineers working on the product, but no one knew how to answer the questions 'properly' because no one had been through an enterprise security assessment before.

I thought to myself; there must be resources out there to help me out. I know how to traverse through this treacherous digital sea of information.

After 7 hours and 15 minutes of searching.......

Nothing!

100s of pages, and I couldn't find any decent resource, article, comment, Reddit thread, or Stackoverflow post that could help me answer just one question.

Of course, I answered all of the questions by bugging our overworked development team enough over two weeks.

I wondered, maybe this isn't a common occurrence with other early-stage startups.

Oh boy, I was proven wrong within one day.

I talked to 50+ founders:

  • At our coworking space.
  • a bunch of friends and acquaintances who had worked in enterprise SaaS.
  • at online communities and forums asking people about their experience with 'conveying' and 'demonstrating' compliance to large enterprises.

I heard the same story over and over again,

  • Enterprise compliance is a maze that I don't want to enter again.
  • The only reason I won't move upmarket.
  • I paid a consultant $15,000 to draft up some crappy documents and forgot to remove the other company's name from the template.

It was terrible. But I saw an opportunity.

I know there are many companies and consultants out there that are solving compliance and are way more competent than me, here are the two problems that aren't solved yet:

  • There is no single platform where you can find and compare companies and consultants providing compliance-related services.

And,

  • The cost of the initial discovery phase in getting compliance such as HIPAA, SOC2, ISO 27001 is long, and it adds to the overall cost.

This ☝️ is the problem I'm setting out to solve.

The question on every SaaS founder's tongue (At least the ones in the enterprise space), Are we compliant?

Comment

About

'Am We Complaint?' This is the question I was asking our team when I was working at a growing SaaS startup trying to close 5-figure and 6-figure deals. I want to help growing SaaS companies answer that question cheaply.