Kshitiz

229 posts

Kshitiz banner
Kshitiz

Kshitiz

@kshitizh

Building @ypal_security | Founding Engineer / Product & Security @Security_Pal

KTM-MPLS-SF-NYC Inscrit le Mayıs 2013
223 Abonnements514 Abonnés
Tweet épinglé
Kshitiz
Kshitiz@kshitizh·
"Compliance platforms" sold founders a lie. You still write the policies. You still chase the evidence. You still answer the auditor. The software just charges you $30+K/year to watch you do it. 🧵
English
3
1
41
2.3K
Zid
Zid@_zidkim·
@kshitizh Yep, big fan of Resend!
English
1
0
1
26
Kshitiz
Kshitiz@kshitizh·
hey @MartinGTobias, most tools in this space sell you a dashboard and call it compliance. @ypal_security pairs you with an actual vCISO who runs the engagement, writes the policies that fit your stack, and sits in the auditor calls with you. SOC 2 type 1 in ~4 weeks, type 2 windows handled end to end. happy to chat if useful: cal.com/khamal/30min
English
0
0
5
87
Martin Tobias (Pre-Seed VC)
Martin Tobias (Pre-Seed VC)@MartinGTobias·
One of my projects needs to do SOC 2 compliance. They are trying Delve. Any other suggestions?
English
46
0
59
14K
Kshitiz
Kshitiz@kshitizh·
What’s the point of paying for @claudeai 20x Max + $200 auto reload if I still hit usage limits like this? Been happening for weeks, but seeing “100% used” on a supposed 20x plan is insane. The paid experience feels completely broken right now.
Kshitiz tweet media
English
1
0
16
357
Grok
Grok@grok·
For a small early-stage SaaS startup, SOC 2 compliance + certification typically runs $20K–$60K in year 1. Breakdown: - Audit (Type 2 most common): $10K–$30K - Compliance tools (Vanta/Drata etc.): $5K–$15K - Readiness, remediation, team time: the rest Type 1 is faster/cheaper for initial sales proof. Costs scale with headcount, scope (Security-only vs full TSCs), and how much you automate. Shop boutique auditors for better rates.
English
1
0
1
71
Kshitiz
Kshitiz@kshitizh·
Love watching founders vibe code an entire SaaS in a weekend then look genuinely surprised when their first enterprise prospect asks for a SOC 2 report. The AI built the app. It did not build the trust🙃
English
4
1
16
420
Voiden.md
Voiden.md@VoidenMD·
Voiden just crossed 1K GitHub stars...⭐⭐⭐ Top 0.2% of all repositories on GitHub. There are so many great developer tools out there that just never get seen. If you have built something for devs, drop it below, let’s help surface more of them. on to the next milestone 🚀 #devtools #api #opensource #github #testing #aitools
English
3
1
10
212
Kshitiz
Kshitiz@kshitizh·
@paulg been doing soc 2 readiness for b2b startups and the founders who launched ugly are always 6 months ahead of the ones who waited to be ready. market feedback compounds. polish doesn’t.
English
0
0
2
221
Paul Graham
Paul Graham@paulg·
By default my first question to any startup is "What's your growth rate?" That's the patient's pulse. Which is why we push startups to launch. Till then you have no pulse; till then you have no idea if you're doing well or badly.
English
150
119
2.6K
158K
Kshitiz
Kshitiz@kshitizh·
That's why @ypal_security ships a vCISO with the platform. Not a dashboard. A team that owns the outcome. Your engineers ship product. We get you certified. 24+ frameworks. Zero on site overhead. Audit ready in weeks.
English
0
0
10
235
Kshitiz
Kshitiz@kshitizh·
Three things kill SOC 2 timelines for startups: 1. Custom policies treated as "we'll do it later" 2. Evidence gathering owned by no one 3. An auditor showing up to a half built program The dashboard you bought won't fix any of these.
English
2
0
14
310
Jacob Eiting
Jacob Eiting@jeiting·
We are building out the next _big_thing_ at RevenueCat, helping developers make more money using the power of money. I think "Capital" has a chance of being as big as our SaaS/JSON business and it's really cool to dream up and build financial tools for developers with our unique position and perspective. We're hiring for a data scientist, an analyst, and an engineer. Read more about the opportunity from the inimitable @itisthefaye notion.so/revenuecat/RC-…
English
4
9
76
25.8K
Nick Lawton
Nick Lawton@nicholasnlawton·
HIRING engineers in NYC Come build with us Reshaping the creator economy
Nick Lawton tweet media
English
20
3
86
7.8K
Nathan S. Robinson
Nathan S. Robinson@NathanSRobinson·
I'm looking for help. If you - code - use AI 24/7 - can communicate well - are looking for work DM me Open to part time or full time. Ideal for indie hackers who want some income working pt while building their own thing. Bonus points if you're obsessed with real estate
English
9
0
5
594
Kshitiz
Kshitiz@kshitizh·
Three reasons, I think: 1. The "automation" pitch only sells the easy 80%, connect your cloud, auto-collect. Audit-day back-and-forth doesn't fit the demo. 2. Customers feel the pain *during* the audit, not at purchase. By then they've already hired a consultant or are eating the spreadsheet. 3. Auditors do this part in spreadsheets/email. Tool vendors never feel it themselves.
English
0
0
1
47
Kshitiz
Kshitiz@kshitizh·
Most SOC 2 tools have one upload box. Real auditors ask three questions in a row: 1. "List everyone you hired." 2. "Pick 5 random ones." 3. "Now prove each one got a background check, handbook, access." Most software stops at #1. @ypal_security models the whole conversation. ↓
Kshitiz tweet media
English
3
2
22
409
Kshitiz
Kshitiz@kshitizh·
@eve_silb the death of duo arc is wild because most marketing teams would've killed the idea in the deck review. takes real conviction to ship something that weird. nice breakdown.
English
1
0
2
27
Kshitiz
Kshitiz@kshitizh·
great launch, but the “we ARE your stack” pitch only covers identity + device + HR controls, call it 1/3 of SOC 2. CC3 risk assessment, CC7 system ops, CC8 change mgmt, CC9 BCP — all live in your product, not your HRIS. and even the controls Rippling automates still need a human to defend the design to an auditor. this is exactly why we’re building @ypal_security . evidence collection is the easy part.
Matt MacInnis@stanine

Today, we launched @Rippling Automated Compliance, starting with SOC 2. We have a unique advantage here: we aren't telling you how to fix your stack, because we ARE your stack. device management, identity and access management, HR, performance management...

English
0
1
16
912
Kshitiz retweeté
Pukar C. Hamal 🏔🗽 🌁
the wonderful students at the Nepali Student Association at @Stanford are hosting a great event this Wednesday do join if you can!
Pukar C. Hamal 🏔🗽 🌁 tweet media
English
3
5
30
1.4K