Product @Flock_Safety (ML + New Verticals). Built + sold @TalkHiring on @acquiredotcom. Formerly @techstars @xdotai @DukeU @GCSports. Lover of dumb comedies.
Ever heard of the career readiness industry?
It’s a rarely reported-on but active auxiliary industry spanning career coaching and development, edtech, and more valued at $45 billion.
@harrisosserman founded Talk Hiring (acquire'd) and shared how he found product-market fit:
A tale of two cities with and without Flock over the weekend in Texas:
"Austin had Flock and then turned it off. And as a consequence, they were not able to find these guys."
"These guys drove into some adjacent town up against Austin. And Flock was live in that town, and so Flock tagged them the minute they drove into that town, and then they caught the guys."
"It's crazy to have the ability to solve crimes and stop crimes and not be able to use it."
@pmarca with @joerogan
The Delve scandal is the perfect excuse for me to write my long-simmering rant about SOC-2 and InfoSec.
1. 90% of SOC-2 is security theater. We couldn't pass audit until we had completed an annual performance review (absurd requirement for a team of 4). It is mind-boggling to me that we collectively decided to adopt an accounting framework (and accounting firms) to validate infosec.
2. SOC-2 startups are (at least in part) culpable for this mess, thanks to Jevon's Paradox. It's now "easier" to get it, so getting the certification is table stakes for an enterprise contract.
"But Hari, startups can now sell to enterprise more easily" — nope.
3. I would argue that the approach for selling to enterprise was *better* prior to 2017:
— Enterprises were more open to doing pilots without SOC-2, because it was harder to do and not table stakes. This is, obviously, a more efficient way to transact and explore ad hoc relationships.
— You'd simply have to do actually useful things like pentesting, security questionnaires, etc. to show you were serious about security... which you have to do today anyway, because SOC-2 is a terrible proxy for real security.
And enterprises have gotten easier to sell into, because they realized they need to be more tech forward. Correlation, not causation.
SOC-2-as-table-stakes killed a more pragmatic, trust-based sales motion. All in all, the introduction of SOC-2 as an industry standard introduced *more* friction into the process, racked up *higher* costs for their customers, for ultimately the *same or worse* security outcomes. We would all be better off if we threw the standard in the trash, because then we might actually come up with something sensible.
4. Perhaps the Delve takedown was penned by a competitor, but — if the facts hold up — that doesn't make it any less valid. This is a wildly competitive space, and I've seen some truly nasty stuff happen, from an observer's seat. But people are using that to discredit the piece, even though the facts so far are pretty damning (regardless of the biases of the speaker).
5. All of the SOC-2 companies are roughly equivalent (no matter what they tell you), and you should optimize for a good service at a reasonable price and grit your teeth and get it done when you think you have enough PMF where enterprises might want it.
6. Don't even get me started on GDPR and CCPA. Cookie banners take quality-adjusted years off peoples' lives, just like cigarettes and the DMV. And just like SOC-2 is security theater, they are privacy theater.
7. Most importantly: getting dinged because you didn't pass security reviews has nothing to do with security. It means your buyer / champion didn't care enough to push it through. If you're sorely lacking, it might be an actual issue. You should (obviously) do the important stuff (vulnerability scans, pentests, 2FA, be careful with phishing), but after that...
Spend your time building something that buyers want to rip out of your hands. Your security problems will start disappearing.
@SeeBQ Be really liberal with your requests of the agent to write extensive unit, integration, and selenium-style UI tests. That has worked well for me.
@bran_don_gell Cora = inbox is what will take this product to the next level. I really wanted that capability when I tried cora. Switching between inbox and Cora Web app was a lot of friction.
Automatic License Plate Readers help keep San Diego one of the safest big cities in America. They’ve:
▪️ Aided 600 investigations
▪️ Recovered $5.8M in stolen property
▪️ Led to 420 arrests
▪️ Cut car thefts by 20%
https://t.co/htportHEKL
@joshk@firstround The initial product could be an AI observer that watches how you do your computer work, and with all of the context that that enables, gives you proactive/reactive help to get your work done.