SPEAKER_00
Christina Cassioppo founded Vanta in 2018 to solve a problem most founders didn't even know they had: compliance. Under her leadership, the company has defined the trust management category, growing to over 15,000 customers.
SPEAKER_01
Cheers. Good to see you.
SPEAKER_00
Tell the Vanta story.
SPEAKER_01
We help companies start or build out their security programs and then get credit for all that work through an audit, through a security questionnaire, a trust center. It's get all the work to improve your security and then go get credit for that with your customers.
SPEAKER_00
All the Vanta billboards I see use the word compliance rather than security.
SPEAKER_01
Yes.
SPEAKER_00
What's going on there?
SPEAKER_01
It is one of those where you're thinking vitamin versus painkiller, right? Compliance is SOC 2, which is a word that no one knows what it means until they deeply know it, and then they want it.
SPEAKER_00
When they know they have to do it this quarter. Exactly.
SPEAKER_01
Yeah. One of the original founding hypotheses of the company is if you want to start a security company for startups, you should actually start a compliance company. Because your customers never ask you for security, but they do ask you for compliance.
SPEAKER_00
So compliance is the buying moment for startups. [SPEAKER_00] I see. [SPEAKER_01] Exactly.
SPEAKER_01
And then when you're going through that, you have to implement a bunch of best practices, maybe buy some tooling. Yes. But you don't do it before that moment, even if you want to. [SPEAKER_00] Yeah, yeah.
SPEAKER_00
[SPEAKER_01] Because you're doing the thing the customer wants.
SPEAKER_01
[SPEAKER_00] And I guess at a later stage, the buyer would be different, where security would be the CISO versus compliance would be the CFO, GC, something like that.
SPEAKER_00
[SPEAKER_01] I actually think Stripe is a little different in what I see, which is biased.
SPEAKER_01
Compliance is usually part of this unified GRC—governance risk and compliance function—and that lives in the CISO org. [SPEAKER_00] Okay.
SPEAKER_00
[SPEAKER_01] It'll centralize internal audit, it'll centralize enterprise risk.
SPEAKER_01
[SPEAKER_00] Okay, so you're mostly—
SPEAKER_00
[SPEAKER_01] You put those teams together.
SPEAKER_01
[SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] Third party risk.
SPEAKER_01
Those teams are all together in the CISO org. [SPEAKER_00] So you're mostly selling to CISOs.
SPEAKER_00
Yes. Okay. How did you wake up in the morning and decide you were passionate about starting a compliance company? [SPEAKER_01] When I was three years old, it was my first word.
SPEAKER_01
Yeah, exactly. We joked in the early days, we'd never be able to pull that story off. I don't know, I heard training businesses are good. [SPEAKER_00] I've heard more absurd founding myths.
SPEAKER_00
Yeah. So I think you could just go for it. [SPEAKER_01] Yeah, go.
SPEAKER_01
[SPEAKER_00] Yeah.
SPEAKER_00
[SPEAKER_01] No, the real story is twofold.
SPEAKER_01
One, prior to Vanta, I worked at Dropbox. I worked on what at the time was a new product, Dropbox Paper. We were trying to take it to market and didn't take it to market as well as we could have for several reasons. One of which was, turned out at the time, all the Dropbox contracts had written into them that we're secure, we're compliant, we're pen tested, we're XYZ. Our new thing had none of those. So in order to talk to someone with a Dropbox account, which was 100 million people or whatever it was, we had to go through this process.
SPEAKER_01
And then a year and a half later, just talking to startups and founders about security, trying to figure out why is there a company to be built here?
SPEAKER_01
How do you get more startups to care about security? And I came across companies that either did nothing for security but felt really badly about it, and then companies that had a lot of stuff in place because they'd gotten a questionnaire from an enterprise customer. [SPEAKER_00] Yeah. And that was the thing. [SPEAKER_00] Yes. I remember that being crazy, onerous, and terrible, but also if you do it, that's like pass go, collect $200—a huge benefit on the other side.
SPEAKER_00
Yeah, yeah.
SPEAKER_01
And it was the combo of those two things.
SPEAKER_00
Yeah.
SPEAKER_01
[SPEAKER_00] What you're describing is so commonly the experience of founders who start companies.
SPEAKER_00
I mean, it was our experience with Stripe as well, where we had run into the problem before.
SPEAKER_01
[SPEAKER_00] But it's funny, I often run into people in university who are excited about starting a startup.
SPEAKER_00
And there are lots of success stories of people who dropped out of college to start something. Yeah. And it's generally a bad time because university students' ideas for companies are often half-baked. Find my friends. Yeah. It's a college textbook exchange app. Yeah, college apps. Yeah, yeah, yeah. It's one of five apps. Yeah. [SPEAKER_01] Whereas what frequently happens is people go out and build successful products in the world, do Dropbox Paper or get some experience. And it turns out there are huge markets available with problem spaces that most normal people have not heard of, with things like SOC 2.
SPEAKER_00
But you have to spend a while seeing how the value flows in the real world work to discover those big opportunities. [SPEAKER_01] Okay, so how do you feel when you go to YC now and you have these founders who've dropped out and they're like, my passion is sales enablement. [SPEAKER_01] But they actually do know surprisingly much about it. [SPEAKER_01] Yeah. I mean, if you truly manage to learn enough about sales enablement to field a strong product there, then good on you. I just think you're more likely to discover those areas after five or 10 years.
SPEAKER_01
[SPEAKER_00] What stage is the business at now? We have 15,000 customers. Our growth rate has actually quickened the last couple of years and quarters and months. It's been 60% annual plus for the last couple of years since that milestone.
SPEAKER_00
[SPEAKER_01] So a ballpark number there. Yeah, yeah, yeah. [SPEAKER_01] Yeah, it's a proper business.
SPEAKER_01
[SPEAKER_00] Yeah. [SPEAKER_00] Mostly. [SPEAKER_00] If you truly manage to learn enough about sales enablement to be able to field a strong product there, then good on you. I just think you're more likely to discover those areas after five or 10 years. What stage is the business at now? We have 15,000 customers. Our growth rate's actually quickened the last couple of years and quarters and months. And so it's been 60% annual plus for the last couple of years since that milestone. So a ballpark number there.
SPEAKER_00
Yeah, yeah, yeah.
SPEAKER_01
Yeah, it's a proper business.
SPEAKER_00
Yeah. Mostly. And you go to market, it's all sold. [SPEAKER_01] All sales. Yeah.
SPEAKER_01
Yeah, yeah, just one of the blessings and curses of them.
SPEAKER_00
With what company sizes?
SPEAKER_01
All, so we do the call them the two founders on the couch, but it's the two founders on the couch are building their thing and someone asks them for SOC 2 and they're working on it on Friday night. Because when else are you going to do the thing? All the way up to at least one member of the Fortune 50.
SPEAKER_00
[SPEAKER_01] Hmm.
SPEAKER_01
[SPEAKER_00] I would have thought that compliance is very different for founders who have never even heard of it versus companies who have a lot of existing teams here with opinions and stuff built out. So how does that work? Yeah, that's true. So down market, I kind of, we're not quite TurboTax, but I think that is the experience a founder wants. [SPEAKER_00] I see.
SPEAKER_00
[SPEAKER_01] It's like, this is high stakes and I don't want to get it wrong and I don't really know, but just guide me through. Yes. And then, so that's more of the product experience and then the output is a set of controls with security rules you follow that are monitored on an ongoing basis. And because of that, whenever you're constantly audit ready, you always have everything in place. Great. And so that's the experience a founder wants, but the output is still a security program that's monitored all the time. Up market, I, especially when I'm talking to an engineer, it's more Datadog for your compliance controls, right? You're like, I have my program, I have my thing, but it lives in a spreadsheet, it lives in Jira, custom Jira, it lives in something like that. And I want real time dashboards and visibility.
SPEAKER_00
I see.
SPEAKER_01
And deviations and auto remediation and I want that world. [SPEAKER_00] Okay. So there's almost two layers to Vanta. There is what your controls should be and then how the controls are monitored and implemented. [SPEAKER_00] And early stage companies want both.
SPEAKER_00
[SPEAKER_01] Yeah.
SPEAKER_01
[SPEAKER_00] Later stage companies may want more of the latter. Exactly. [SPEAKER_00] Yeah, yeah. Exactly. And then the tie to audit is great. Well, in some ways it's if controls are monitored, you just pass the logs to an auditor. It's more complicated than that, but that's the base model. [SPEAKER_00] Yes. Well, okay, you're getting to a question I had, which was compliance at some level is not a thing you can just buy. It's a thing you have to do. And so if you actually talk about all these rules, I don't know about SOC 2 in particular, but for example, a lot of compliance regimes have this notion of doer and approver being separate for something. And so it's the-
SPEAKER_01
[SPEAKER_00] Prover view is the famous one. [SPEAKER_00] Yeah. [SPEAKER_00] The nuclear submarine where you have to have the two keys turned simultaneously to launch the PR, I guess, in this analogy. And again, Vanta can't do that for you.
SPEAKER_00
Right.
SPEAKER_01
[SPEAKER_00] And so what you do is, one, for say a startup, you actually just let them know the complete list of things they actually need to do. And I presume there's some, maybe you can talk about, there's some logic of only telling them the stuff that actually applies to them.
SPEAKER_00
[SPEAKER_01] Yep, exactly. And then there's actually, how do you enforce, say, separate doers and approvers in something like code review? [SPEAKER_01] Yeah, so for something like, so this is where the first thing we built and we call it test, so it's advanced, but modeled after unit tests. You're turning each of these controls into a unit test. Yes. And so pull from version, GitHub, GitLab, whatever, look at every pull request and check these fields or this thing or run some logic over it. [SPEAKER_00] Yep. [SPEAKER_01] And that is our test for the control.
SPEAKER_01
Ah.
SPEAKER_00
[SPEAKER_01] And so that was the first thing we built were these tests.
SPEAKER_01
But tests are just ways to prove control.
SPEAKER_00
Ah, so you're just a test suite. You're the battery of unit tests for the compliance rules.
SPEAKER_01
Exactly. Ah, why don't you just say that? [SPEAKER_01] Sorry. Why don't you just billboard say that? There was a niche audience in San Francisco that would be, oh, now I understand. [SPEAKER_00] Yeah, but I think for the 101 billboards, what's the controversy with your 101 billboard?
SPEAKER_00
[SPEAKER_01] Oh my goodness. How much do we want to do this? We had a great 101. Great billboard. You just drive by it every day. Yeah, yeah. [SPEAKER_01] Compliance that doesn't suck too much. [SPEAKER_01] Yeah. [SPEAKER_01] Arguably, hundreds of millions of dollars in market cap attributed to that billboard. It's funny, that was just in the annuals and Vanta startups. The person who came up with that billboard, very pleased with herself, as she should have been. Yeah, yeah, yeah. [SPEAKER_01] 100% right. Yeah, yeah, yeah. [SPEAKER_01] Her manager at the time was very skeptical of that billboard. That's a C-level type line. Are we negging our users?
SPEAKER_00
[SPEAKER_01] Yeah, yeah. Is this okay? Are we too far over the line? Yeah.
SPEAKER_01
Anyway, you can guess which one of those people is still at Vanta today. Not just because of that.
SPEAKER_00
Yeah, yeah, yeah. But it was a good.
SPEAKER_01
[SPEAKER_00] Yeah, it's a cultural test. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] Her manager at the time was very skeptical of that billboard.
SPEAKER_01
[SPEAKER_00] That's a can level type line. [SPEAKER_00] Are we negging our users? Yeah, yeah. [SPEAKER_01] Is this okay? Are we too far over the line?
SPEAKER_00
Yeah. [SPEAKER_01] Anyway, you can guess which one of those people is still at Vantan today. [SPEAKER_01] Not just because of that.
SPEAKER_01
[SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] But it was a good. [SPEAKER_00] Yeah, it's a cultural test. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] Anyway, so we had this billboard.
SPEAKER_01
It was great. For many years. For many years.
SPEAKER_00
[SPEAKER_01] Yeah. [SPEAKER_01] I used to joke that we've had it locked up for years. [SPEAKER_01] Turns out we didn't, and I'm an idiot.
[SPEAKER_00] Oh, you forgot to renew it. Not even. I wish. [SPEAKER_00] You should have had a little Vantan check for that. [SPEAKER_00] I know, it was like your domain, and you're just like good thing you're not supposed to. [SPEAKER_01] Yeah, exactly. [SPEAKER_01] It was slightly better, but still bad.
SPEAKER_01
The agency we worked with, one, I should have caught this, our contract was just written in Crayon.
SPEAKER_00
Oh.
SPEAKER_01
And we got locked people asked about our billboard.
SPEAKER_00
[SPEAKER_01] We'd introduced them to lots of startups. [SPEAKER_01] Some of those startups were also buying with that agency.
SPEAKER_01
[SPEAKER_00] Wow. And so that agency— [SPEAKER_00] A startup you introduced to them went and took your billboard.
SPEAKER_00
[SPEAKER_01] They didn't even do it on purpose.
SPEAKER_01
[SPEAKER_00] Yeah, yeah, yeah. The agency went to them and was like, oh, we have this great inventory. Would you like it?
SPEAKER_00
[SPEAKER_01] And then we found out. [SPEAKER_01] Yeah. Okay. Hmm. That's rough.
SPEAKER_01
[SPEAKER_00] But people will learn about— This is the drama in the compliance world. [SPEAKER_00] People will learn about Vantan in other ways. They do learn. We do mark it. [SPEAKER_00] Yeah. [SPEAKER_00] Yeah.
SPEAKER_00
Okay.
SPEAKER_01
[SPEAKER_00] And then going back to the other part of the question. [SPEAKER_00] So how does the layer work for the rulebook might be a thousand pages long, compiling that rulebook into the steps that are actually actionable for me because I am not a farm. And so all the farm parts of the rulebook don't apply to me.
SPEAKER_00
[SPEAKER_01] Yeah. [SPEAKER_01] Okay.
SPEAKER_01
So the initial version of it actually was, this is like back when we were founders on a couch, was getting as many SOC tools as we could. So it's like Salesforce, Slack, AWS, right? [SPEAKER_00] Yeah. Whatever. And actually opening them all and just comparing them.
SPEAKER_00
Yes.
SPEAKER_01
And trying to extract what was common and doing it that way. So that was the first cut. What we do now is hopefully more advanced, but there's a bit of, now that we have probably 30,000 audits completed.
SPEAKER_00
Yes.
SPEAKER_01
We can just go back and be like, okay, for a company that looks like you and for this auditor often, what sorts of controls are there?
SPEAKER_00
Yep.
SPEAKER_01
So we have that input in.
SPEAKER_00
[SPEAKER_01] Then we can also layer in both for a company in particular and in general, you get questionnaires. What are the things and the questions you're being asked?
SPEAKER_01
[SPEAKER_00] Yes. We just launched a new commitments product that ingests contracts and scans the contracts for things that are contracted. That's cool. So you can then pull them out and say, hey, this should be a control. [SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] And, you know, God forbid something happens, but you're like, what are my obligations to my customers? Yes. [SPEAKER_01] And you can just have, you know, you basically have all that structured data. [SPEAKER_01] But one of the most important things, they just want to see progression over time and increase maturity over time.
SPEAKER_01
And you've probably had this at Stripe where you want to do some cool new tool that had no security posture.
SPEAKER_00
Yes.
SPEAKER_01
And a contingent, say, heck that baby. But one part of it was, oh, can you just walk this up over time and show me you're making progress.
SPEAKER_00
Yes. Yes. Is SOC 2 the main Bible, the book from which you read? [SPEAKER_01] Basically, I mean, we don't, it's funny, we don't break it out by framework anymore because it's all just inputs into the system. Sure, but ultimately you need to comply with some specific things. [SPEAKER_01] Yeah, yeah, yeah. [SPEAKER_01] But yes, most customers will come to us for that first. Yeah.
SPEAKER_01
Number two is ISO 2701, which is if you partner, you're a SOC 2. [SPEAKER_00] Who demands ISO 2701? [SPEAKER_00] European? [SPEAKER_00] European enterprises. [SPEAKER_00] Okay.
SPEAKER_00
[SPEAKER_01] Yeah, yeah, yeah.
SPEAKER_01
And so if you're a European company selling to Europeans, you will start with that. If you're European selling to Americans, you'll start with SOC 2.
SPEAKER_00
Okay.
SPEAKER_01
[SPEAKER_00] How aligned are they? I think our mapping is 60-ish, 65%. [SPEAKER_00] Okay. And the additional ISO stuff is often documentation.
SPEAKER_00
Okay.
SPEAKER_01
Which is a great place for software to help you out. [SPEAKER_00] Sounds like Europe, yeah.
SPEAKER_00
[SPEAKER_01] Yeah, yeah, yeah, exactly.
SPEAKER_01
There's less, you know, please implement these six more rules. [SPEAKER_00] Okay, so is SOC 2 and its international equivalence basically capturing most of what you're doing? It is probably plurality, not majority.
SPEAKER_00
Okay.
SPEAKER_01
And so we see a lot of growth. And there's this whole host thousand flowers bloom of AI standards right now. [SPEAKER_00] Yeah. It's the whole thing there.
SPEAKER_00
[SPEAKER_01] There's the healthcare specific things.
SPEAKER_01
[SPEAKER_00] Sure. There's the PTI piece, which I know you're very familiar with.
SPEAKER_00
[SPEAKER_01] There's that.
SPEAKER_01
Yeah, yeah, yeah, exactly. There's less. Please implement these six more rules.
Okay, so is it SOC 2 and its international equivalence basically that captures most of what you're doing? [SPEAKER_01] It is probably plurality, not majority. Okay. And so we see a lot of growth. And there's this whole host thousand flowers bloom of AI standards right now. Yeah. It's the whole thing there. There's the healthcare specific things.
SPEAKER_00
[SPEAKER_01] Sure. [SPEAKER_01] There's the PTI piece, which I know you're very familiar with. [SPEAKER_01] There's that.
SPEAKER_01
[SPEAKER_00] On healthcare, is this which? There's HIPAA, which is US law.
SPEAKER_00
[SPEAKER_01] You can just declare yourself compliant with HIPAA.
SPEAKER_01
[SPEAKER_00] Mm-hmm. [SPEAKER_00] Yeah, self-certification.
SPEAKER_00
Yeah, exactly.
SPEAKER_01
The downside of doing that is if you do that and are breached, the fines are enormous.
SPEAKER_00
[SPEAKER_01] And so that's the check that there's some semi-market check there. Can you describe the policy goals that something like SOC 2 seems to accomplish? And you might say, oh, it's simple. It's just security. But as we know, there's many different facets to that.
SPEAKER_01
[SPEAKER_00] And so it could be preventing information leaks or it could be preventing fraud against the customer. [SPEAKER_00] Or it could be all these different things. [SPEAKER_00] And so if you're at a stack rank, what is SOC 2 actually trying to accomplish at a policy level?
SPEAKER_00
[SPEAKER_01] I would say it is trying to ensure customer data is protected. [SPEAKER_01] I think that is what it is trying to do.
SPEAKER_01
[SPEAKER_00] And to round out the point of your Java, JavaScript comparison is that Java was a very popular language before the emergence of web browsers with JavaScript. [SPEAKER_00] And so when they invented JavaScript, they wanted to ride off the Java halo as an easy-to-do programming language. [SPEAKER_00] Despite the fact Java and JavaScript share no commonality at all. [SPEAKER_00] But it was just good branding. [SPEAKER_00] And what you're saying is that is similar with SOC 2 here.
SPEAKER_00
Okay.
SPEAKER_01
[SPEAKER_00] So you're saying the primary goal is to ensure that the data that you are giving this company, your software provider, whatever, is adequately protected. [SPEAKER_00] Many companies have had humongous data breaches. Equifax was a great example.
SPEAKER_00
Yeah, Equifax, AT&T, I believe.
SPEAKER_01
[SPEAKER_00] Yeah. All of them. [SPEAKER_00] Exactly. [SPEAKER_00] Assuming every big company has SOC 2. Yeah, yeah. [SPEAKER_00] But the difference between some data was leaked in some context versus in the Equifax case, sorry, we lost all of your data. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] We didn't fix the database. [SPEAKER_00] Which data did you lose?
SPEAKER_00
All of it.
SPEAKER_01
[SPEAKER_00] Yeah. [SPEAKER_00] It's very hard to find that moment in the Equifax stock price chart.
SPEAKER_00
[SPEAKER_01] Yes. What's going on there? As in, we think society cares.
SPEAKER_01
[SPEAKER_00] Society should care. [SPEAKER_00] Yes.
SPEAKER_00
It's valuable to not lose this data. And yet, it does not seem to impair what investors deem to be the terminal value of the company. [SPEAKER_01] Yes. [SPEAKER_01] What are investors betting on? [SPEAKER_01] They're betting on will anyone churn off of Equifax because this happens? [SPEAKER_01] And I think the cynical but correct take is no. [SPEAKER_01] Sometimes because you're Equifax or Delta, you're not going to stop.
SPEAKER_01
I'm not going to stop flying Delta, especially 10 to 15 years into this where you're another one. [SPEAKER_00] I'll add an eighth credit monitoring service, right?
SPEAKER_00
[SPEAKER_01] Yeah, exactly. [SPEAKER_01] And I think there is a cynicism there that is probably correct. Yes. The other thing that feels like it's changing in this ecosystem is that the costs of having data breaches are going up because Europe in particular is getting very strict about notifications and sometimes fines around these breaches. How is that changing your world? [SPEAKER_01] We see more. [SPEAKER_01] So we also cover some of the data privacy standards. [SPEAKER_01] So your GDPR, your CCPA, there's Brazil, there's a whole alphabet soup of acronyms here. [SPEAKER_01] It goes, honestly, we see demand for that that goes in waves.
SPEAKER_00
[SPEAKER_01] And it kind of tracks what you expect.
SPEAKER_01
It's higher in Europe.
SPEAKER_00
Yeah. [SPEAKER_01] Vanta as a product in general does better in Europe and better than you would guess for an American, for a California company that doesn't have European roots.
SPEAKER_01
Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] And I do think there's some cultural affinity and just seriousness there. Yes, yes.
SPEAKER_01
Versus the easy critique of Americans and compliance is I'm just checking.
SPEAKER_00
Yeah, yeah. [SPEAKER_01] You tell me where the bar is and I'll meet your bar. But the box checking. Exactly. [SPEAKER_01] Where it is culturally something that is more important. [SPEAKER_01] You can tell me where the bar is and I'll meet it. [SPEAKER_01] But I also have my own internal bar, which is more the European way. [SPEAKER_01] But we see demand for say CCPA, which is the California version of GDPR, quote unquote, go in waves. [SPEAKER_01] And right now it is definite.
SPEAKER_01
I mean, all the American regulation is at a total nadir, but it's down right now.
SPEAKER_00
Yeah. Well, it's down at a federal level. Is it also down at a state level, the energy around the CCPA type things? Yes, it is. [SPEAKER_01] Even with it's not clear what California is going to do and it could go multiple ways. [SPEAKER_01] But I think the national politics casts a larger shadow, even over a state like California.
SPEAKER_01
[SPEAKER_00] Oh, that's interesting. [SPEAKER_00] Yeah. [SPEAKER_00] Okay. And then on the national side, the current administration is very into streamlining regulation through automation and AI. [SPEAKER_00] Yeah. That is the catchphrase that they deeply believe in and are driving.
SPEAKER_00
I would have thought that this is just too boring to be caught up in any reform initiative or will this be streamlined?
SPEAKER_01
I think there's very hardworking folks in DC, in particular across the board, but in GSA, in the Office of Management and Budget trying to do this. And the primary lever they're using is FedRAMP.
SPEAKER_00
Yes. Oh, that's interesting. Yeah.
SPEAKER_01
[SPEAKER_00] Okay. And then on the national side, current administration is very into streamlining regulation through automation and AI. [SPEAKER_00] Yeah. That is the catchphrase that they deeply believe in and are driving. [SPEAKER_00] I would have thought that this kind of stuff is just too boring to be caught up in any reform initiative or will this be streamlined? I think there's very hardworking folks in DC, in special across the board, but in GSA, in the Azure Arc Office trying to do this.
SPEAKER_00
[SPEAKER_01] And the primary lever they're using is FedRAMP.
SPEAKER_01
[SPEAKER_00] Yes. [SPEAKER_00] Yeah, I know this. Yeah.
SPEAKER_00
[SPEAKER_01] And which broadly I would think of, I'd talk to for the federal government, but a very onerous set of both controls and requirements and documentation in order to begin trying to think about selling to federal and often states and sometimes even local governments.
SPEAKER_01
[SPEAKER_00] How do you think state and local governments also use FedRAMP as their fuel set?
SPEAKER_00
[SPEAKER_01] The state ramps?
SPEAKER_01
[SPEAKER_00] Yeah, yeah.
SPEAKER_00
[SPEAKER_01] So there's literally Texas ramps. But they conform to FedRAMP. Yeah, yeah.
SPEAKER_01
And there is a part of GSA and one team in particular led by a guy called Pete Wasserman, who is trying to modernize FedRAMP, but I would say make a 2020 version of FedRAMP, where the current version feels a bit more 90s. And it is unclear if he will get the traction to succeed. [SPEAKER_00] Yeah. But he's fighting the good fight and he gets it. [SPEAKER_00] But even if they do that, I find it hard to imagine the Society of Accountants just copying the new FedRAMP, lock, stock and barrel. I don't think they will.
SPEAKER_00
[SPEAKER_01] Yeah. [SPEAKER_01] I think you're just going to have even more divergence between these things. [SPEAKER_01] Yeah. [SPEAKER_01] You're just less control over the app.
SPEAKER_01
[SPEAKER_00] Yeah, I feel your life is the XKCD of we have 15 standards. It is standards and the answer is the 16th.
SPEAKER_00
[SPEAKER_01] Yes. Yes, yes. [SPEAKER_01] Yeah, yeah.
SPEAKER_01
That is also my answer when people are like, well, is Vanta going to make a standard?
SPEAKER_00
[SPEAKER_01] Couldn't you make a better one?
SPEAKER_01
[SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] I mean, we couldn't, we have that posted on the office wall.
SPEAKER_01
[SPEAKER_00] Yeah, yeah, yeah, because it is your life. [SPEAKER_00] Yes.
SPEAKER_00
But okay, going back to the effects of the European strictness, it doesn't show up in the form of maybe American companies previously were looking to check the SOC 2 box versus now they're, okay, it's really important. I don't cross this actually quite strict European rule.
SPEAKER_01
Right, right. Whereas I think now and I think in, it's funny, we are starting Vanta, Vanta as what it is now today in spring of 2018, which is when GDPR was going into effect.
SPEAKER_00
Mm-hmm.
SPEAKER_01
And so I was running around and being like, will you talk to me about compliance?
SPEAKER_00
Yeah, yeah.
SPEAKER_01
And everyone said yes, I was having this great luck.
SPEAKER_00
[SPEAKER_01] And then I'd show up and I'd be like, so SOC 2. [SPEAKER_01] And they'd be like, GDPR is a priority, next please. Yep.
SPEAKER_01
And that energy is mostly dissipated, especially in the United States. [SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] I think because the theory at the time was GDPR is written by lawyers at a very high level.
SPEAKER_01
It's not a spec you can enter an engineer, comically bad as an engineering spec.
SPEAKER_00
[SPEAKER_01] But it's fine, we will clarify that in court over the next 10 years.
SPEAKER_01
And now we're seven, eight years in. Yeah. Hasn't really happened. [SPEAKER_00] Yes, yes. It still is hand wavy. [SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] For an engineer at least to go implement as it ever was.
SPEAKER_01
[SPEAKER_00] And how does this work with agentic coding where the honest answer to the number of human reviewers this code is zero? [SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] How should it work?
SPEAKER_01
Because right now it is like, well, somebody needs to be like, I did code well. Yeah. Right now it's agent writes code, human or agent puts up PR.
SPEAKER_00
[SPEAKER_01] Yes.
SPEAKER_01
Maybe human or agent reviews it.
SPEAKER_00
[SPEAKER_01] Yes. [SPEAKER_01] And I think to a naive SOC audit, you're like, those seem like two user IDs had that conversation. Yeah, yeah. [SPEAKER_01] And so we can go forward.
SPEAKER_01
[SPEAKER_00] But it's more about having two throats to choke as opposed to, we read the code of this ATM software and guaranteed that you didn't introduce an infinite money glitch. Yeah.
SPEAKER_00
[SPEAKER_01] Yeah.
SPEAKER_01
And so maybe that's my macro answer is just go through the SOC 2 controls and be like, what are we trying to do here?
SPEAKER_00
Yes, yes.
SPEAKER_01
And be like, okay, great. Let's design for that. [SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] And that may or may not be how it's written today.
SPEAKER_01
[SPEAKER_00] That's a good question because on all the insider threat stuff, having two reviewers is one way to do it.
SPEAKER_00
[SPEAKER_01] Yes.
SPEAKER_01
[SPEAKER_00] Does SOC 2 mandate exactly a lot of other insider threat stuff? [SPEAKER_00] Yeah. [SPEAKER_00] Because presumably you should be logging a lot of activity, auditing a lot of activity. [SPEAKER_00] There should be process that you have in place. Yeah. No.
SPEAKER_00
[SPEAKER_01] And I think this is where you get to the technical standard made by folks who often aren't.
SPEAKER_01
[SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] As in their depth in engineering.
SPEAKER_01
Yes, yes.
SPEAKER_00
[SPEAKER_01] SOC 2 is the controls for there are a bunch of logging and monitoring controls that are suggested. [SPEAKER_01] Yes.
SPEAKER_01
One thing maybe I also mentioned, unlike PCI, SOC 2 doesn't have a prescribed control list. [SPEAKER_00] Mm-hmm. So PCI is different and it's like, you must do X, you must buy this tool whether or not it is useful to you. [SPEAKER_00] Yes, yes. [SPEAKER_00] I'm sure you have your own story with that. Yes. SOC 2 is like, you must log useful events and have a system to look at them. [SPEAKER_00] I see.
SPEAKER_00
[SPEAKER_01] But it is up to you to decide what the heck that means.
SPEAKER_01
[SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] Which sometimes it's helpful.
SPEAKER_01
[SPEAKER_00] Yeah, yeah. One thing maybe I also mentioned, unlike PCI, SOC 2 doesn't have a prescribed control list. [SPEAKER_00] Mm-hmm.
SPEAKER_00
[SPEAKER_01] So PCI is different and it's like, you must do X, like you must buy this tool whether or not it is useful to you.
SPEAKER_01
[SPEAKER_00] Yes, yes. [SPEAKER_00] I'm sure you have your own story with that.
SPEAKER_00
[SPEAKER_01] Yes.
SPEAKER_01
SOC 2 is like, you must log useful events and have a system to look at them.
SPEAKER_00
I see.
SPEAKER_01
But it is up to you to decide what that means.
SPEAKER_00
Yeah, yeah, yeah. [SPEAKER_01] Which sometimes it's helpful. Yeah, yeah. [SPEAKER_01] I think for a startup that's never done this, it is unhelpful because it opens up a maze in a way that's just not great.
SPEAKER_01
Yes. And that's why I'm being prescriptive. I think part of Vanta's initial product market fit is actually largely due to that. [SPEAKER_00] Yes, yes.
SPEAKER_00
[SPEAKER_01] In a way that that wasn't the plan.
SPEAKER_01
[SPEAKER_00] Yeah. But I think it's figuring out how to take that high level guidance and bring it down in some places. Yes. In a way that actually makes sense. [SPEAKER_00] And that's why I think it's like, it actually has a lease tax, which applies to SaaS companies too, since you're leasing out software.
SPEAKER_00
Stripe Tax is built to automate all of this.
SPEAKER_01
[SPEAKER_00] With one integration, it knows what you're selling, when and where you have to collect transactional taxes, and how to register and file on your behalf.
So if you want to sell globally, without becoming an expert in tax rules, check out Stripe Tax. The kind of joking reference that everyone makes as they talk about competition from cloud code for software products is, you're not just going to code your ex in a weekend. [SPEAKER_00] But obviously, something like SOC 2 is actually the kind of thing that LLMs or coding agents are good at working with, because there's so much training data out there. [SPEAKER_00] Yeah. [SPEAKER_00] And it's a codified set of rules.
SPEAKER_00
So how is AI helping with what you're doing?
SPEAKER_01
[SPEAKER_00] And what is your plan for?
SPEAKER_00
You were describing some of the scale economies you have and having seen other customers.
SPEAKER_01
[SPEAKER_00] And I'm curious, what the defenses are against.
SPEAKER_00
A customer could, in theory, say, hey, Claude, give me the plan for our SOC 2 compliance.
SPEAKER_01
[SPEAKER_00] Make no mistakes. [SPEAKER_00] That is a thing you can contemplate. Right.
SPEAKER_00
[SPEAKER_01] And I think there's the defensive thing, but actually, the very defensive thing is, right, but this is the place where you don't want to get stuff wrong.
SPEAKER_01
Spending much time on it does not make your beer taste better.
SPEAKER_00
[SPEAKER_01] Right?
SPEAKER_01
Is this really the place? Even if you really want to code a bunch of stuff, is this really what you want to code? Yes.
SPEAKER_00
[SPEAKER_01] Whatever. [SPEAKER_01] Ignore them all. [SPEAKER_01] So I think where the LLMs are excellent and a little dangerous in a build versus buy, but then we just need to build better experiences on top of this, is, hey, Claude, I'm going to give you a mess of data. [SPEAKER_01] You go make sense of it to me. [SPEAKER_01] And get me ready.
SPEAKER_00
Yep. Right? [SPEAKER_01] I'm just going to give you a bunch of AWS screenshots or API calls. [SPEAKER_01] I'm going to give you all my policy documentation. [SPEAKER_01] I'm going to give you my existing JIRA workflow. [SPEAKER_01] Go turn it into a thing. [SPEAKER_01] And so you can go do that today. [SPEAKER_01] So if you're going to say, we are building, this is our onboarding flow or will be our onboarding flow, which is, oh, you have an existing program that's already running. [SPEAKER_01] Oh, that's cool. [SPEAKER_01] Give you all the stuff. [SPEAKER_01] We will go map it into the Vanta world. Yes. [SPEAKER_01] And then in Claude, we're on LM.
SPEAKER_00
[SPEAKER_01] It's okay, cool.
SPEAKER_01
Now you get, I don't know, files in a folder structure that you then box share that over to EY and call that your audit. Fine. [SPEAKER_01] You can do that. In a Vanta world, the outcome is now, hopefully, we have your program mapped and is observable and monitored and alerted. And so you have continuous control monitoring. You get your dashboards. You always know what is in place and what is not. And yes, you can go send a share link to your auditor here, too, and they can log in. And see everything. [SPEAKER_00] Yep. And so we sort of think about it as they have lowered the initial audit prep. [SPEAKER_00] Yeah.
SPEAKER_01
[SPEAKER_01] Inside or outside Vanta, or if they're not inside Vanta, what are we doing? So building that.
SPEAKER_00
[SPEAKER_01] But the continuous monitoring piece. Yes, yes.
SPEAKER_01
That you're not going to get out of at least LM chat. You've got to code that whole system. [SPEAKER_00] Okay. [SPEAKER_00] So you're saying that everyone just wants, no one enjoys spending time in SOC 2. [SPEAKER_00] Everyone wants to have been SOC 2 compliant as of yesterday. [SPEAKER_00] Yes. [SPEAKER_00] And so you're saying part of the advantage here in this new landscape is you can just take a whole bunch of unstructured stuff and empty it into the Vanta hopper. [SPEAKER_00] Right. [SPEAKER_00] And Vanta will make sense of it. Yeah, then we'll get widgets out. [SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
And I presume part of the defensibility comes from the fact that preference amongst practitioners, in this case, the auditors that are reviewing your SOC 2 materials, is a very strong effect.
SPEAKER_01
[SPEAKER_00] That is very true. [SPEAKER_00] And both QuickBooks and Xero, to some extent, really grew off accountants becoming familiar with those pieces of software. [SPEAKER_00] And companies could have opinions about what they were using, but those opinions are not that strong and they were overridden by the opinions of the auditors. [SPEAKER_00] And so- We have a version of that. It's not as strong as Zoldefex yet, at least. But even again, we've seen 20,000 audits and thousands for particular firms. And so you're like, to control, we now do AI evidence evals. [SPEAKER_00] That is very true.
SPEAKER_01
[SPEAKER_00] And both QuickBooks and Xero, to some extent, really grew off accountants becoming familiar with those pieces of software. [SPEAKER_00] And companies could have opinions about what they were using, but those opinions are not that strong and they were overridden by the opinions of the auditors.
SPEAKER_00
And so—
SPEAKER_01
We have a version of that.
SPEAKER_00
[SPEAKER_01] It's not as strong as Zoldefex yet at least.
SPEAKER_01
But we've seen 20,000 audits and thousands for particular firms. And to control, we now do AI evidence evals. So you're going to provide this piece of evidence.
SPEAKER_00
[SPEAKER_01] We can just tell you, is it going to work for this auditor?
SPEAKER_01
Did you upload a cat picture? Did you upload a screenshot without a timestamp on it?
SPEAKER_00
[SPEAKER_01] And you're going to get told to put the timestamp back, just like that feedback loop. [SPEAKER_01] We already have that, and we've thought about doing things for auditors as well with that. [SPEAKER_01] But it moves in the direction of an AI internal audit at least. It feels like the data you have of anonymized prior audits is an incredibly powerful network effect that cannot be replicated because it doesn't exist in the public internet. The AIs don't have it available to them because it's just private data. And just like Stripe's advantage because we have all the fraud data. We know what a normal buying pattern looks like versus not.
SPEAKER_01
[SPEAKER_00] And so we can offer the best anti-fraud performance just because we're working with a larger data set than other people.
SPEAKER_00
Similarly, people going through an audit, you can tell them that this will work and this won't. [SPEAKER_01] Yes, this is our radar. Yeah, exactly. In a way that you cannot do even if you decide to buy it yourself. [SPEAKER_01] Yes. Yeah.
SPEAKER_01
It's a big deal. Yeah, it's cool. [SPEAKER_00] Where else have you seen that be useful? In relationships between a software vendor and buyer. [SPEAKER_00] Mm-hmm. Right? And so Vanta core we think of ourselves as broadly, and what we're best known for is serving software vendors. People who make software and want to sell it to the world. And you ask, do you have security work? Is it secure? Great.
SPEAKER_00
[SPEAKER_01] Okay. [SPEAKER_01] Then we have this third party risk product. [SPEAKER_01] But it's basically, you're an organization. [SPEAKER_01] Maybe it's tech, maybe it's not tech. [SPEAKER_01] You're buying software and you're going to put a bunch of your customer's data in it. [SPEAKER_01] You want that software to be secure because if not, you have to turn around and tell your customers, I lost your data, but it's actually our email provider, but you don't care if our email provider is the issue.
SPEAKER_01
You think it's me and I have to send you an email.
SPEAKER_00
[SPEAKER_01] Yeah. [SPEAKER_01] Anyway, right?
SPEAKER_01
No one wants to send that email.
SPEAKER_00
[SPEAKER_01] So there's a whole world of third party risk or vendor reviews and we build a product for those folks.
SPEAKER_01
[SPEAKER_00] But is there a compliance versus security tension here as you're doing this stuff? We haven't seen as much.
SPEAKER_00
[SPEAKER_01] What we have seen is the person buying software, you know, they might work at a tech company and be quite savvy and up to date on those threats.
SPEAKER_01
They might work when our customer is a hotel, literally a hotel chain.
SPEAKER_00
[SPEAKER_01] Right?
SPEAKER_01
And they certainly don't get compliance themselves because they don't build software. Right? But they buy it. [SPEAKER_00] Yep. Fine. And so what we generally see is some companies will come in with their set of questions they want to ask. And maybe I will read your SOC 2 to you, maybe I will not, but I really want to ask you questions one through ten. Some companies don't have that. And there's some part of the value proposition—we'll prescriptively guide you. And so we have a product principle just around reasonable defaults. Yes.
SPEAKER_01
And it's, can we make the reasonable default questionnaire in this case something that leads into security versus compliance or versus, you know, do you have a policy to X? Yes. And you're asking, can you just ask them if they X if you care? [SPEAKER_00] Yes. And so that's a place where we've tried to, on the margin, nudge the buyer questions toward more security, knowing that will change the economic incentive of the vendor. [SPEAKER_00] One of the big debates people are having right now is how AI productivity gains show up. Yes.
SPEAKER_00
And I feel you could have an opinion on this because we have filled out a lot of security questionnaires at Stripe.
SPEAKER_01
[SPEAKER_00] And I think we'd be very happy if the machines could take over from here. [SPEAKER_00] We really don't need to—we filled out enough. [SPEAKER_00] We should talk about this. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah. [SPEAKER_00] But one case you could make is the machines are getting quite good. [SPEAKER_00] Yeah.
SPEAKER_00
They can understand what Stripe is and is and can do and can't do.
SPEAKER_01
[SPEAKER_00] Yeah. [SPEAKER_00] And so every time we get a security questionnaire, AI can fill it out. [SPEAKER_00] The counter argument you could say is maybe Jevon's paradox will show up. [SPEAKER_00] Yes. [SPEAKER_00] And there'll be even more exhaustive and elaborate and custom security questionnaires. [SPEAKER_00] And so the total amount will increase. [SPEAKER_00] But how do you see AI productivity showing up here on the effect? So the questionnaire is actually a great example because we tried to build this product in 2018, actually before SOC 2, because it seems easier, but the language models were not good enough.
SPEAKER_01
And then we tried again in early 2021, when BERT came out and you're thinking, is there a moment, but it was not good enough. And now it is good enough.
SPEAKER_00
[SPEAKER_01] So GitHub gets 92% of all the questionnaires they receive answered through Vanta.
SPEAKER_01
You're not at 100, but it's GitHub.
SPEAKER_00
Yeah.
SPEAKER_01
They have AI tools, they have Copilot, it's a lot.
SPEAKER_00
[SPEAKER_01] And so we are absolutely seeing this—the models are definitely good enough. [SPEAKER_00] I'm sorry, people asked GitHub to fill out the security questionnaires before using GitHub. And now they can mostly turn around and return those security questionnaires. [SPEAKER_01] Exactly. With 92% filled out. [SPEAKER_01] And now it is good enough. [SPEAKER_01] So to that actually, GitHub gets 92% of all of the questionnaires they receive answered through Vanta. [SPEAKER_01] And so you're like, not at 100, but you're like, it's GitHub. Yeah. [SPEAKER_01] They have AI tools, Copilot. [SPEAKER_01] It's a lot.
SPEAKER_00
[SPEAKER_01] And so we are absolutely seeing this, the models are definitely good enough. I'm sorry, people asked GitHub to fill out the security questionnaires before using GitHub. And now they can mostly turn around and return those security questionnaires. [SPEAKER_01] Exactly. With 92% filled out. Filled out. [SPEAKER_01] And we have a kind of human, but just it's review and approve. Yeah, yeah, yeah.
SPEAKER_01
[SPEAKER_00] Right. And then the confidence scores on prioritizing even for the reviewer. It's like, you probably want to look at the section if you want, but you kind of don't have to. Whereas will you really look at these 10? [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] Yeah.
SPEAKER_00
[SPEAKER_01] And so all of that work, our product does that.
SPEAKER_01
[SPEAKER_00] Yes. [SPEAKER_00] Yes. [SPEAKER_00] That's cool.
SPEAKER_00
Okay. So where do you think it goes broadly?
SPEAKER_01
I think so much of the work of a compliance team is keeping things in sync, keeping different sorts of text in sync.
SPEAKER_00
Yes, yes. [SPEAKER_01] Right?
SPEAKER_01
Adding new compliance regimes, which is just adding controls.
SPEAKER_00
Yes. [SPEAKER_01] And then really, do you want to map the new ones to the old ones and figure out what the duplicates are?
SPEAKER_01
That's actually a huge part classically of the work of a compliance team. [SPEAKER_00] Mm-hmm. And so I think there are so many opportunities for LMs at agentic workflows in Vanta's business.
SPEAKER_00
[SPEAKER_01] And we've probably have a couple dozen of them. [SPEAKER_01] And if I think about our roadmap, knock on all the things, well, hundreds by the end of the year.
SPEAKER_01
[SPEAKER_00] Yes, yes.
SPEAKER_00
[SPEAKER_01] But it's just, what we've been doing is breaking down what folks do, right? [SPEAKER_01] And so you're like, okay, there's a questionnaire piece. [SPEAKER_01] If you send out a questionnaire, someone has to read it on the other side. Yes, yes. [SPEAKER_01] And then you have to think about it and figure out where does it work, where does it not?
SPEAKER_01
[SPEAKER_00] Yes. Oh, I have this new policy update. I need to put this thing in a policy. I need to, we're going to start doing, I don't know, ISO 42001, which is a new AI standard. And so how do I map that in? [SPEAKER_00] Yes. I need to rerun a risk assessment. I'm going to change my risk score. Anyway, all of these things, all of these tasks are just workflows that you could have an AI do, write an eval against with subject matter experts, and then hill climb. [SPEAKER_00] Yes. [SPEAKER_00] And so it feels like you can reason about the number of people in a profession, especially at a certain stage of company changing. [SPEAKER_00] Yes.
SPEAKER_00
Like if you think back to ancient times, I don't know the year 2000, if you had a 10 person company with 10 Gateway 2000 beige workstations.
SPEAKER_01
Yeah, yeah. [SPEAKER_00] They probably would have had an IT person. [SPEAKER_00] They probably would have. [SPEAKER_00] And that IT person would have had.
SPEAKER_00
[SPEAKER_01] The servers in the closet.
SPEAKER_01
Yeah, exactly. [SPEAKER_00] Servers in the closet, they had Microsoft Access database. [SPEAKER_00] Right. [SPEAKER_00] They had to do software updates for all the machines. [SPEAKER_00] Right. [SPEAKER_00] Occasionally lint and stuff would get stuck in the mouse ball. [SPEAKER_00] Oh, yeah, yeah. [SPEAKER_00] You have to take it out. [SPEAKER_00] I've thought of that one time. [SPEAKER_00] And all those kind of things. [SPEAKER_00] So IT was a real job. [SPEAKER_00] Yes. [SPEAKER_00] Now, I don't think a 10 person company really has an IT person.
SPEAKER_00
No. Because the hardware is super reliable. You just buy a new version every now and then.
SPEAKER_01
[SPEAKER_00] Everything's in the cloud, so there's no porting data over.
SPEAKER_00
Yes. You just use Google Workspace for everything. It works really nicely.
[SPEAKER_00] And so IT still exists as a profession. [SPEAKER_00] There are lots of interesting things. [SPEAKER_00] Yeah. But Stripe has a bunch of IT people. You don't need a bunch of IT people at the 10. [SPEAKER_01] You've had to mail laptops to how many countries in the world, which is actually kind of hard. Yeah. We have some IT challenges. But again, we're 10,000 people. And again, it naively feels like you will have a similar effect with compliance as we had with IT. Where the professional very much stays around. It actually gets more skilled rather than the stuff we do in IT is harder than the basic IT that a 10 person company would have done.
SPEAKER_00
[SPEAKER_00] I think that's true. Is that basically where compliance is going? [SPEAKER_01] I think that's basically true, yes. [SPEAKER_01] So one model we've thought about with Vanta, even pre-AI, is we will delay the point at which you have to bring on a full-time security compliance person. [SPEAKER_01] Or a kind of consultant who's spending meaningful time. Yeah. [SPEAKER_01] But you know, in the past, if you're an enterprise company, maybe you did that at 50, 100. [SPEAKER_01] And it's like, can we actually push that further out? Yes. [SPEAKER_01] Because what we see is that an engineering leader or someone in the engineering org can manage more of this.
SPEAKER_00
[SPEAKER_01] Because they kind of have the mental models and they're usually system thinkers and they can. And they're responsible for it so they can change the stuff. Exactly. [SPEAKER_01] Yeah. [SPEAKER_01] And so you have this, or persona if you call them Amelia engineers, but you have the Amelia engineers going further here. Yeah.
SPEAKER_01
And then you can bring on a unified security and compliance person versus, oh, you have your security person, your IT person, your compliance person.
SPEAKER_00
Yeah. Yes. [SPEAKER_01] Because what we see is that an engineering leader or someone in the engineering org can manage more of this. [SPEAKER_01] Because they have the mental models and they're usually system thinkers and they can. And they're responsible for it so they can change the stuff. Exactly. [SPEAKER_01] Yeah. [SPEAKER_01] And so you have this persona if you call them Amelia engineers, but you have the Amelia engineers just going further here. Yeah.
SPEAKER_01
And then you bring on a unified security and compliance person versus having your security person, your IT person, your compliance person. [SPEAKER_00] Yeah. But it's similar to what we're seeing in the engineer PM designer collapse. So you have the security compliance IT collapse into one role. [SPEAKER_00] So you can keep them unified for longer.
SPEAKER_00
[SPEAKER_01] Exactly.
SPEAKER_01
If you can give them good tools. [SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] Right, they can do that. [SPEAKER_01] Okay, fine.
SPEAKER_01
And then again, pre-AI, but over time that team starts to grow and then you have a GRC team and you have CISO and all this. What we're talking about now and we haven't seen yet, but if I had the future cast and guess, is we're going to see those GRC teams collapse a bit more into these single threaded owners.
SPEAKER_00
Mm-hmm.
SPEAKER_01
Okay, you can have a GRC team today.
SPEAKER_00
[SPEAKER_01] There's maybe one person answering questionnaires, one person just reviewing new software vendors.
SPEAKER_01
Right? And you look at those and you're like, okay, I think you can mostly agent the work and then have someone oversee it with 20% of your time.
SPEAKER_00
[SPEAKER_01] But okay, great, you've collapsed two into 40%, right?
SPEAKER_01
And you have some person who's responsible for bothering the engineers to get evidence for them for the audit or to get the control in place because they don't own the control but they own the program. So they have to go to the engineer and be like, hello, I noticed you have a new database that is not encrypted.
SPEAKER_00
[SPEAKER_01] And will you please encrypt it?
SPEAKER_01
Right? And you can just have software go nag that person. Anyway, it collapses. And so I do think we will see smaller GRC teams managing agents, but actually in the future.
SPEAKER_00
[SPEAKER_01] Yeah.
SPEAKER_01
And then they are doing more. I'm not doing the security reviews. I'm thinking about the findings and overall managing this risk portfolio, just like vendor risk portfolio versus being like, oh, this vendor doesn't have this thing and I need to go get it from. [SPEAKER_00] Yeah, I think what you're saying is there's a strategy component to how should we be doing things? [SPEAKER_00] Yes. [SPEAKER_00] And then there's an hourly labor component to compliance, which is like, oh, we did 10 times as many sales. [SPEAKER_00] We need 10 times as many bodies on the security reviews.
SPEAKER_01
[SPEAKER_00] And you're saying that AI will eat up a lot of the hourly labor part of compliance and leave people doing the strategy work. Yes. [SPEAKER_00] Yeah. I do think that. [SPEAKER_00] What changes are coming down the pike in the world of compliance? I think there is, to the XKCD, there's lots of folks both trying to make new compliance standards, but it's a little bit like, what's the difference with the 22nd one? From a Vanta perspective, we've taken a like, we will support them all because we have built a machine where it is easy to add a new one in. [SPEAKER_00] Yeah.
SPEAKER_01
[SPEAKER_00] But obviously, you only want to support ones that customers actually want to comply with. [SPEAKER_00] So you're not-
SPEAKER_00
[SPEAKER_01] Well, yeah. [SPEAKER_01] But what we do actually, we used to spend a bunch of time debating which ones those would be. [SPEAKER_01] And it was honestly so frustrating. And you just lob them all in. [SPEAKER_01] Exactly.
SPEAKER_01
Now you're just like, build the machine that just lobs them in.
SPEAKER_00
[SPEAKER_01] And so the debate and the document you would write-
SPEAKER_01
[SPEAKER_00] It's like us with payment methods.
SPEAKER_00
Do you want to support this payment method?
SPEAKER_01
Sure. Sure.
SPEAKER_00
Whatever. Yeah, exactly. [SPEAKER_01] We did that with compliance standards and integrations because the prioritization debates were just too intense.
SPEAKER_01
[SPEAKER_00] Yes, yes. We can take all of that debate time. And anyway.
SPEAKER_00
[SPEAKER_01] So there's a bunch of those.
SPEAKER_01
I would bet on any of them. If you really pressed me, I would say ISO 42001 just because it's the European one. [SPEAKER_00] I don't know that ISO. [SPEAKER_00] You gotta-
SPEAKER_00
[SPEAKER_01] You gotta- It's a good one.
SPEAKER_01
[SPEAKER_00] It's a good one. My recommendation is bedtime reading.
SPEAKER_00
[SPEAKER_01] So ISO, you know this, but the European standards body, and it is their version of what one should care about with AI. [SPEAKER_01] It ends up being pretty data privacy focused and pretty high level.
SPEAKER_01
[SPEAKER_00] Yeah.
SPEAKER_00
[SPEAKER_01] Those are the counters.
SPEAKER_01
The pros are that European enterprises are the ones that care the most about AI and this is where they would turn. And so it's the thing that has the most market traction so far. [SPEAKER_00] But again, none of these are- None of them have product market fit. [SPEAKER_00] And none of them are regulatory.
SPEAKER_00
They're all- [SPEAKER_01] Correct.
SPEAKER_01
[SPEAKER_00] You opt into-
SPEAKER_00
Exactly. [SPEAKER_01] It is this market has roughly agreed you might need this thing.
SPEAKER_01
So there's that. I think the, okay. I'm kind of proud of this.
SPEAKER_00
[SPEAKER_01] They're trust centers, if you remember the trust centers?
SPEAKER_01
They're the security status pages. [SPEAKER_00] Oh, sure. [SPEAKER_00] Yeah, yeah, yeah.
SPEAKER_00
[SPEAKER_01] Like trust.blahblahblah.
SPEAKER_01
Trust.vanta.com.
SPEAKER_00
[SPEAKER_01] Trust.vanta.com. I didn't know they're called trust centers.
SPEAKER_01
[SPEAKER_00] It's just a status page.
SPEAKER_00
[SPEAKER_01] Yeah. [SPEAKER_01] But they're for your security posture.
SPEAKER_01
Sure. So you get the green bars or green traffic lights or yellow traffic lights. [SPEAKER_00] lights. But it's for your controls. [SPEAKER_00] I see. And I-
SPEAKER_00
But then they always say the same thing. A status page is red, amber, green.
SPEAKER_01
[SPEAKER_00] Right. [SPEAKER_00] Whereas hopefully the trust center always says we're a compliant boss. Usually-
SPEAKER_00
Yeah, yeah, exactly. It's just like a status page.
SPEAKER_01
Yeah. But they're for your security posture. Sure. So you get the green bars or green traffic lights or yellow traffic lights.
Lights. [SPEAKER_01] But it's for your controls. [SPEAKER_00] I see.
SPEAKER_00
[SPEAKER_01] And I-
SPEAKER_01
[SPEAKER_00] But then they always say the same thing.
SPEAKER_00
A status page is red, amber, green. Right. Whereas hopefully the trust center always says we're a real compliant boss. [SPEAKER_01] Usually-
SPEAKER_01
[SPEAKER_00] Yeah, yeah, exactly.
SPEAKER_00
[SPEAKER_01] And so there's a version of that.
SPEAKER_01
And so if nothing else, what they actually are, they're ticket deflection for the GRC team. [SPEAKER_00] I see.
SPEAKER_00
[SPEAKER_01] Because one, your sales team sends them out and you're like, doesn't it look good?
SPEAKER_01
And then if you have any questions, here you go. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] But it-
SPEAKER_00
It's the pre-filled questionnaire. [SPEAKER_01] It's the pre- yes, exactly. [SPEAKER_01] It's here's the binder of information.
SPEAKER_01
Please read it. [SPEAKER_00] Yeah. And if you have questions for me thereafter, I am here.
SPEAKER_00
Yeah.
SPEAKER_01
[SPEAKER_00] Does that work?
SPEAKER_00
[SPEAKER_01] It does actually. [SPEAKER_01] And I think part of it is the just show of strength.
SPEAKER_01
[SPEAKER_00] Yeah, yeah, yeah. And the show of I'm on top of it.
SPEAKER_00
Yeah, yeah.
SPEAKER_01
And then there's yeah, read things first.
SPEAKER_00
[SPEAKER_01] And then if you want to ask me, go for it.
[SPEAKER_00] That's cool. [SPEAKER_00] Has outbound selling gotten harder now that everyone has a million AI bots spamming everyone? [SPEAKER_01] I think it has. [SPEAKER_01] What I have heard is phone calls work.
SPEAKER_01
In a way that I wouldn't expect- [SPEAKER_00] For now, right? [SPEAKER_00] Until one year from now.
SPEAKER_00
But now with emails, a million AI bots. [SPEAKER_01] And how many ChatGPT-written emails do you get in your inbox a day? [SPEAKER_01] But outbound phone calls are currently working.
SPEAKER_01
[SPEAKER_00] Got it. [SPEAKER_00] Yes.
SPEAKER_00
But again, it's only a matter of time until- [SPEAKER_01] It's only a matter of time. [SPEAKER_01] And I think then you're just back to events, right?
SPEAKER_01
[SPEAKER_00] Yeah, yeah. [SPEAKER_00] And especially small curated events.
SPEAKER_00
Yes. A topic we talk about sometimes here is on-demand software. Patrick's taken to saying that software should be like pizza, delivered fresh piping hot. But why are you using software that someone coded five years ago rather than just the computer deciding what to render to you at that moment. Yes. [SPEAKER_00] Is that coming to Vanta? [SPEAKER_01] It is. [SPEAKER_01] It's something we're playing with internally but really excited about is having an agent that maybe is guiding you through the process or doing something and then needs the user to render an opinion or make a connection or do something.
SPEAKER_00
[SPEAKER_01] And you're like, can the agent just generate UI specific for that task so the user completes it and then move on. [SPEAKER_01] Yes. [SPEAKER_01] And you get this bespoke agent generated, hand generated UI just for that.
SPEAKER_01
Yes. [SPEAKER_00] But are you talking about, because maybe people have a little bit of experience with agentic UI where an AI chat interface is people's first experience. [SPEAKER_00] Has some stuff in it. [SPEAKER_00] Yeah. [SPEAKER_00] And maybe there's three options you can choose. [SPEAKER_00] Right.
SPEAKER_00
That's an agentic UI. But you're talking about a full UI. [SPEAKER_01] Or maybe you have that agentic chat bar on half of the page or a third of the page and then the other two thirds would be a SaaS app. [SPEAKER_01] You can imagine a data table with a view and columns and rather than just customizing it, you're like, no, no, no, I would just want you to do this thing and I will take over that right side canvas of the page. Yeah, yeah. [SPEAKER_01] Generate the UI for the thing or generate the report. [SPEAKER_01] I think reporting is another great use here. And what step of the process would this be in?
SPEAKER_01
[SPEAKER_00] Would this be you have 14 things you need to fix to get to. [SPEAKER_00] Yeah. So we thought about it in two ways.
SPEAKER_00
[SPEAKER_01] So in the you're setting it up and you're going through.
SPEAKER_01
And actually reporting is another, I think, great case. It's no one wants more knobs and whistles on their reporting tool.
SPEAKER_00
Yes, yes. [SPEAKER_01] And also no one really wants to learn SQL. Yeah, yeah.
SPEAKER_01
You just want, I want to report for this, go generate it. [SPEAKER_00] Yeah, yeah, yeah. Not quite right, take this out. [SPEAKER_00] That's cool.
SPEAKER_00
So when will we be seeing generated UI in Vanta?
SPEAKER_01
This summer.
SPEAKER_00
Wow.
SPEAKER_01
[SPEAKER_00] Okay.
SPEAKER_00
What has worked well from a go to market perspective for you guys?
SPEAKER_01
Brand spend honestly.
SPEAKER_00
[SPEAKER_01] The billboards. Yeah.
SPEAKER_01
We do all the stuff people do of zip code tracking and all of that.
SPEAKER_00
[SPEAKER_01] Gong call mentions. [SPEAKER_01] So recorded sales, mentions of the word billboard on recorded sales calls. [SPEAKER_01] And then you can track.
SPEAKER_01
[SPEAKER_00] To measure the billboard. [SPEAKER_00] Exactly. Then you track those deals through to closed one.
SPEAKER_00
And you're ultimately doing a geo splash.
SPEAKER_01
[SPEAKER_00] You're looking at the locations where you had a billboard versus not. [SPEAKER_00] Exactly. And then just, does the prospect say the word billboard in a call at some point. [SPEAKER_00] I see.
SPEAKER_00
[SPEAKER_01] Yeah, yeah, yeah. [SPEAKER_01] So some of that podcasts have been, podcast advertising has been exceedingly effective for us.
SPEAKER_01
It's funny because we started doing it in late 2020 and our first salesperson, Eric, who's still at the company.
SPEAKER_00
[SPEAKER_01] We really wanted to advertise on This Week in Startups. [SPEAKER_01] Right. [SPEAKER_01] And I thought it was silly because my model is the only companies that advertise on podcasts are founders who want to hear about themselves.
SPEAKER_01
[SPEAKER_00] Like this is just nonsense.
SPEAKER_00
Exactly.
SPEAKER_01
And then does the prospect say the word billboard?
SPEAKER_00
I see.
SPEAKER_01
In a call at some point. [SPEAKER_00] Yeah, yeah, yeah. So some of those podcasts have been, podcast advertising has been exceedingly effective for us. It's funny because we started doing it in late 2020 and our first salesperson, Eric, who's still at the company. We really wanted to advertise, I think on This Week in Startups.
SPEAKER_00
[SPEAKER_01] Right. [SPEAKER_01] And I thought it was silly because my model is the only companies that advertise on podcasts are founders who want to hear about themselves. This is just nonsense.
SPEAKER_01
[SPEAKER_00] Or mattress companies. [SPEAKER_00] Exactly. Or mattress companies. Exactly. But we are neither. Right. Doesn't everybody really need to talk to you? Anyway. And so Paul, he came to me and was, I want to spend $60,000 on this ad. And my deal with him was, fine, but you got to sell four more Vantas because Vanta basically costs $15,000. And the next month he sold 34 more Vantas because of the podcast ads.
SPEAKER_00
[SPEAKER_01] And that was one where you're, well, I know nothing. [SPEAKER_01] You should just keep going. I call this, by the way, I think there's a real founder negative value out at times. Yes, exactly. Founders have these incredibly strong views that are wrong. That are just deeply wrong. But it's really hard to remember. It's good that you let them go and do it. Yeah. Because sometimes I think some people would have said, no, we're not doing that.
SPEAKER_01
[SPEAKER_00] Right.
SPEAKER_00
It's silly and it would have taken many more years to learn the message. [SPEAKER_01] Yeah, no, the deal is you have to sell four extras. Yeah, yeah, yeah. I feel like I've heard you on the Acquired podcast.
SPEAKER_01
[SPEAKER_00] We do, yeah, Acquired.
SPEAKER_00
Yeah.
SPEAKER_01
We do invest in the best.
SPEAKER_00
Yeah.
SPEAKER_01
Yeah. [SPEAKER_00] I like those.
SPEAKER_00
[SPEAKER_01] And I think in the early days, so this was helpful and then deeply unhelpful, but in the early days, before we had competitors, we tried to basically make this call response of someone says SOC 2, someone says Vanta. [SPEAKER_01] And this really close association, which in the early days, when we were just competing against consultants.
SPEAKER_01
[SPEAKER_00] You wanted to own the term SOC 2 basically. [SPEAKER_00] Yeah.
SPEAKER_00
[SPEAKER_01] Which worked really well until we had competitors who were, well, we do SOC 2, but we're Vanta, but cheaper, but worse, but better.
SPEAKER_01
And then you're, oh, that got, now we're all pointing at a thing we don't own.
SPEAKER_00
Yeah.
SPEAKER_01
And that's bad. [SPEAKER_00] Yeah. And so there was a great reframe on that one.
SPEAKER_00
[SPEAKER_01] Yeah.
SPEAKER_01
That's it. [SPEAKER_00] What did you learn working with Fred Wilson?
SPEAKER_00
[SPEAKER_01] USV is a very special place in lots of ways.
SPEAKER_01
And I think USV is fundamentally about ideas. [SPEAKER_00] More so than other venture firms.
SPEAKER_00
[SPEAKER_01] Yes.
SPEAKER_01
I think most venture firms are great man, great person firms.
SPEAKER_00
Yeah. [SPEAKER_01] They're about the person and this person will do the thing. I have no idea what this is, but I like the cut of his jib.
SPEAKER_01
[SPEAKER_00] Exactly. [SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] And I think USV is in a way, it's not black and white, but it's the opposite.
SPEAKER_01
[SPEAKER_00] Hmm. Whatever person can walk in, but if it is an idea that is interesting and compelling and intellectually engaging and networked, that is classic USV. That matches with great people. I don't mean that, but the first, second, and third thing is the idea. And so really pressing on that. That piece was very important. I think the second part is market sizing is bullshit. You can be as academic or whatever, strategery-ish as you want about it. And the market size today is only a predictor of the market size today. And I deeply learned that. Because if you looked at the SOC 2 market in 2018, my best estimate was there was $10 million spent globally.
SPEAKER_01
And you would never start a startup on that. But the theory of Vanta was, if we can make this thing easier to get and take down the cost of dollars, but really time, more people will get them. Yep. And you're, that ended up being deeply true. But that was not a market, especially for startups. The market for startups getting SOC 2 in 2018 was $0. [SPEAKER_00] Yes, yes.
SPEAKER_00
[SPEAKER_01] Truly zero.
SPEAKER_01
[SPEAKER_00] Yes.
SPEAKER_00
Okay, so Vanta is an example of the kind of company that being too granular. Yeah, you would not come up with it. [SPEAKER_01] And now it's, oh, but of course everyone gets it.
SPEAKER_01
[SPEAKER_00] And you're, right.
SPEAKER_00
[SPEAKER_01] But in 2017.
SPEAKER_01
[SPEAKER_00] Yes.
SPEAKER_00
[SPEAKER_01] Again, when did Stripe get SOC 2?
SPEAKER_01
[SPEAKER_00] Probably reasonably early on because it's so core.
SPEAKER_00
It's not a small part of your stack, but definitely before 2017. It's very interesting framing on USV where I feel like you can see this a little bit in Fred's blog and stuff. To ideas. It's clear, yeah, exactly. Attraction to ideas and a prepared mind for when something crypto comes along. Exactly, comes along. You're, that thing. You're ready to strike. And is that across the firm or is that Fred in particular? [SPEAKER_01] It's Fred and Brad, for sure. [SPEAKER_01] Brad is the undersung Fred partner.
SPEAKER_01
I mean, they started the firm together. [SPEAKER_00] Oh, you're talking about the Fred and Brad relationship? Yeah, yeah.
SPEAKER_00
[SPEAKER_01] Brad Burnham is a venture capitalist, mostly retired now, but also excellent, incredible track record.
SPEAKER_01
He and Fred started Union Square Ventures in, I think, 2002. First fund was 2004. [SPEAKER_00] Exactly, comes along. [SPEAKER_00] You're like that thing. [SPEAKER_00] You're ready to strike. [SPEAKER_00] And is that across the firm or is that Fred in particular? It's Fred and Brad, for sure. Brad is the undersung Fred partner.
SPEAKER_00
[SPEAKER_01] They started the firm together.
SPEAKER_01
[SPEAKER_00] Oh, you're talking about the Fred and Brad relationship?
SPEAKER_00
[SPEAKER_01] Yeah, yeah.
SPEAKER_01
Brad Burnham is a venture capitalist, mostly retired now, but also excellent, incredible track record. He and Fred started Union Square Ventures in, I think, 2002. First fund was 04. Took him two years to raise that fund. If you go look up USV 04 Vintage, God, we all should have invested in that.
SPEAKER_00
[SPEAKER_01] But it was the two of them and then Albert came on as a venture partner, I think in 06.
SPEAKER_01
I think he was on the fund as a partner.
SPEAKER_00
Going real deep here, sorry.
SPEAKER_01
But it was the two of them and there is just, it's not yin-yang, it's not the right frame, but- [SPEAKER_00] Complementarity.
SPEAKER_00
[SPEAKER_01] Yeah.
SPEAKER_01
So many of the ideas of the firm were back and forth between them. And then Fred was excellent at articulating those ideas in a way the rest of the world could understand, which he did on ABC.
SPEAKER_00
[SPEAKER_01] Yes. [SPEAKER_01] But I think one of the underappreciated things is how much back and forth there was in the creation there. Yes. [SPEAKER_01] And that pairing is, I think, probably should be in the annals of venture pairings.
SPEAKER_01
[SPEAKER_00] Yeah. Maybe something like the Coastal Door pairing. [SPEAKER_01] These venture pairings where you had two people who could play off one another. [SPEAKER_00] Yeah. And they were just that. I think Brad and Fred had that for a decade and a half.
SPEAKER_00
What's the difference in person? Because Doug and Mike Moritz at Sequoia are very different people.
SPEAKER_01
[SPEAKER_00] Yes. [SPEAKER_00] And again, I think that's part of how it works. Yeah.
SPEAKER_00
[SPEAKER_01] I don't think Fred and Brad are as different as those two are.
SPEAKER_01
But Brad is cerebral, philosophical, academic, so interesting to talk to.
SPEAKER_00
[SPEAKER_01] And you have this wonderful conversation and you'll be wondering if there are any ties to the business world of math.
SPEAKER_01
But then Fred could go back and forth and say, "Oh, freemium."
SPEAKER_00
And then run with freemium.
SPEAKER_01
[SPEAKER_00] Yes. Right.
SPEAKER_00
[SPEAKER_01] But it wasn't just I'm going to market this term. [SPEAKER_01] It was a back and forth and then the communication out.
SPEAKER_01
[SPEAKER_00] Wait, did Fred coin the term freemium?
[SPEAKER_01] He did. Yeah. [SPEAKER_01] In a blog post in 2009, I don't know, 08, 09, something. [SPEAKER_00] Yeah. Right. Doesn't that feel like it was always a term?
SPEAKER_00
Yeah, exactly.
SPEAKER_01
[SPEAKER_00] That's what it's called. In 1952, didn't they talk about freemium? [SPEAKER_00] Yeah. [SPEAKER_00] It's when you learn those things like, did you know, "saying the quiet part out loud," that term comes from the Simpsons. [SPEAKER_00] In what ways are you a different CEO coming from your experience as an investor?
SPEAKER_00
[SPEAKER_01] I wouldn't have done it is a real answer.
SPEAKER_01
That's a good start. [SPEAKER_00] Yeah. I was really lucky in approximately nine million ways with them. One of the ways was for two years, I just met 15 founders a week for two years straight. Yes. And I think whatever model I had of what a founder is or does was, yeah, that exists. Yeah.
SPEAKER_00
But look at all the ways one can do it.
SPEAKER_01
Yeah.
SPEAKER_00
[SPEAKER_01] And there's some coming out, some more successful, but there's a lot of ways to do this thing. [SPEAKER_01] Yes.
SPEAKER_01
And I think that exposure was super helpful for me because you got to see people who I felt more affinity or similarity to in whatever dimension also do it. Yes. And it was the role model thing, but not one person. You meet a thousand of them.
SPEAKER_00
Yes.
And you can pick out the pieces. [SPEAKER_00] Having all that training data, what passions do you think you see in people who went on to be successful? Or maybe conversely, what anti-patterns do you see in the people who—
SPEAKER_01
I think there is a truth-seeking piece of it. Sometimes you can bend reality to your will, but often reality is reality and you got to embrace it and figure out how to work around it. Reality sometimes it's an immovable object.
SPEAKER_00
[SPEAKER_01] And I think there was a— There's a delusion to the unsuccessful founders. [SPEAKER_01] Exactly. I've noticed that. [SPEAKER_01] Yeah, yeah. [SPEAKER_01] The like, "Oh no, but I can change this." [SPEAKER_01] And you're like, that one, I don't know, gravity's gravity. Yes, yes. Yeah.
[SPEAKER_00] The version of this I talked about with Des Treanor is I feel like investor updates with a lot of words and no metrics. [SPEAKER_00] Oh yeah, those are bad. Those are bad.
SPEAKER_01
[SPEAKER_00] And actually no investor updates is fine.
SPEAKER_00
Like you didn't have to send me—
SPEAKER_01
[SPEAKER_00] No is either way.
SPEAKER_00
Yeah, yeah, exactly.
SPEAKER_01
No is either very good or very bad.
Metrics is fine, but a lot of words and no metrics is almost a sure sign of failure. [SPEAKER_01] Bad. [SPEAKER_00] Yes. Yep. [SPEAKER_00] Because again, I think it gets at that delusion. Right. [SPEAKER_00] Failure to truth seek tendency.
[SPEAKER_01] What else? [SPEAKER_01] There are things that came with Etsy and Kickstarter, but a bunch of these companies of this era, stories where I think I developed this huge appreciation for product market fit. [SPEAKER_01] That sounds so dumb. [SPEAKER_01] But now it's like if you think you have it, you don't framing. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] But you're just like— [SPEAKER_00] Or if you're asking whether you have it, you don't. [SPEAKER_00] You don't, yes. Yep. [SPEAKER_00] Because again, I think it gets at that delusion.
SPEAKER_00
[SPEAKER_01] Right.
SPEAKER_01
[SPEAKER_00] Failure to truth seek tendency.
SPEAKER_00
[SPEAKER_01] What else? [SPEAKER_01] There are things that came with Etsy and Kickstarter, but a bunch of these companies of this era stories, [SPEAKER_01] where I think I developed this huge appreciation for product market fit. [SPEAKER_01] That sounds so dumb.
SPEAKER_01
But now it's if you think you have it, you don't framing.
SPEAKER_00
Yeah, yeah, yeah.
SPEAKER_01
[SPEAKER_00] But you're just like- [SPEAKER_00] Or if you're asking whether you have it, you don't.
SPEAKER_00
You don't, yes. [SPEAKER_01] And so Etsy, great example.
SPEAKER_01
Co-founder CEO spent 80% of his time for years making people desks.
SPEAKER_00
[SPEAKER_01] Because they had this lovely cultural thing.
SPEAKER_01
When you joined, you were getting homemade bespoke desks because they sold homemade bespoke things.
SPEAKER_00
So there's a thing, Yancey would make people a desk?
SPEAKER_01
Rob, I think it was Rob Palin at Etsy. [SPEAKER_00] Okay.
SPEAKER_00
Yeah, yeah. Sorry, I'm getting confused between Kickstarter and Etsy.
SPEAKER_01
[SPEAKER_00] Yeah, yeah. This is the Etsy version.
SPEAKER_00
Yeah, yeah.
And you're just like, now 80% of a CEO's time is making desks and the business is on fire. [SPEAKER_00] See, Amazon had it figured out where you had to make your own desk. Your own desk.
SPEAKER_01
Exactly.
SPEAKER_00
It's a much more scalable way.
SPEAKER_01
Rob made the desks. [SPEAKER_00] Yeah. But you're just like, it's a funny story, but the business was fine. [SPEAKER_00] Yeah, yeah, yeah, yeah.
SPEAKER_00
Exactly. [SPEAKER_01] You know, so there are just these things that have their own physical, their own movable objects. Yeah, yeah, yeah.
SPEAKER_01
And you can be making desks for people all the time.
SPEAKER_00
Yeah, yeah, yeah. [SPEAKER_01] It doesn't matter. Yeah, yeah. [SPEAKER_01] And if you don't have that, it's not that we should all go make desks.
SPEAKER_01
I don't know.
SPEAKER_00
[SPEAKER_01] How do you, would you make, would you spend time making desks at this stage?
SPEAKER_01
[SPEAKER_00] I don't know woodworking is very, I don't do it, but I did it as a kid. [SPEAKER_00] It was satisfying. [SPEAKER_00] So. Yeah. [SPEAKER_00] Last question. [SPEAKER_00] Does Vanta expand from here beyond security? [SPEAKER_00] Do you start helping people apply with everything else? [SPEAKER_00] Do you continue taking over the world until all the world runs on Vanta? Yeah. [SPEAKER_00] What's the plan? Definitely taking over the world, making desks along the way.
SPEAKER_00
[SPEAKER_01] No.
SPEAKER_01
I think right now we do think about, especially in this world where in theory code has become much cheaper, which was two things. So one, it's can we add different pillars or verticals? And so there's a whole lot in security, especially for a small business or a mid-market business.
SPEAKER_00
[SPEAKER_01] I think enterprise is a different ballgame there, but there's things there. [SPEAKER_01] And then when we think about it, we really think about, I guess, we think about parts of the CISO organization versus for the most part, other parts of an organization. [SPEAKER_01] But we would think about enterprise risk or internal audit. [SPEAKER_01] Financial audit is adjacent and interesting.
SPEAKER_01
[SPEAKER_00] What can you do in internal audit or financial audit? So internal audit is easier for us, given what we've built in a way. It's we have all of this and currently we're packaging material and sending it to the auditor. But you can imagine packaging it and sending it to an internal audit.
SPEAKER_00
And it's the same thing, it's a controls platform, right?
SPEAKER_01
[SPEAKER_00] It's decide what it is that you should do and then validate that you're doing this.
SPEAKER_00
Prove that you're doing it, exactly. [SPEAKER_01] Financial audit is the system is similar.
[SPEAKER_01] It's a different set of integrations on data. [SPEAKER_01] And so it's thinking through, okay, what is the right point to start building out those ERP integrations, appointments integrations, all of that to get that sort of data to parcel this in.