Open Reader

Compliance at scale and why TAM is a distraction with Christina Cacioppo of Vanta

completed 57:38 Mar 31, 2026 Watch on YouTube

Current Status

completed

Video ID

lPtn-TVi97Q

RAG / Chat

Enabled
Compliance at scale and why TAM is a distraction with Christina Cacioppo of Vanta
Description

Christina Cacioppo, founder and CEO of Vanta, joins the pub to discuss building the future of agentic trust. She explains why compliance has a “vitamin vs painkiller” dynamic, the drama behind their famous 101-billboard campaign, and why she believes "market sizing is bullshit." They cover the tension between vibe coding and rigorous security, how Vanta is using agents to generate UI, and why the best founders are relentless truth-seekers. Full transcript on Substack: https://open.substack.com/pub/cheekypint/p/compliance-at-scale-and-why-tam-is Subscribe to Cheeky Pint Spotify: https://open.spotify.com/show/2IHbGJJ... Apple Podcasts: https://podcasts.apple.com/us/podcast... Substack: https://cheekypint.substack.com/ Key moments 00:00:17 Vanta 00:12:30 How compliance works 00:15:06 Breaches 00:23:52 Stripe Tax 00:24:43 AI and compliance 00:44:50 Go-to-market 00:47:22 Lessons from USV

Summary

Generated by claude-haiku-4-5-20251001

Compliance at Scale and Why TAM is a Distraction with Christina Cacioppo of Vanta

Main Topics

  • Vanta's Mission and Market: Creating a trust management category by automating security compliance for SaaS companies
  • Compliance vs. Security: How compliance (not security) is the actual buying moment for startups
  • Market Size Misconceptions: Why traditional TAM analysis fails for compliance products
  • AI and Automation in Compliance: How LLMs and agentic workflows are transforming compliance work
  • Future of Compliance Teams: The evolution from specialized roles to consolidated, AI-assisted teams
  • Go-to-Market Insights: Effective strategies including billboards and podcast advertising

Key Points

The Compliance Opportunity

  • The buying trigger: Customers don't ask for security—they ask for compliance (SOC 2). This is the actual entry point for startups
  • Two-part value proposition:
  • Guiding companies on what controls they need (reducing from thousands to applicable rules)
  • Monitoring controls continuously so companies stay audit-ready year-round
  • Real origin story: Problem discovered at Dropbox Paper, where new products couldn't sell to Dropbox's 100M customers without compliance certifications

Market Sizing Lessons

  • SOC 2 market in 2018 was approximately $10 million globally—yet Vanta is now a $15B+ company
  • The market for startups getting SOC 2 was literally $0 in 2018
  • USV (investors) taught that "market sizing is bullshit"—today's market size doesn't predict tomorrow's
  • The strategy: Make compliance easier and cheaper, expand the addressable market through democratization

Product Architecture

Vanta = Unit Tests for Compliance

  • Built "tests" that automatically verify controls using GitHub/GitLab integration
  • Example: Pull requests are checked to ensure separate doers and approvers
  • Controls are monitored continuously, not just at audit time

Multiple Compliance Frameworks

  • SOC 2: Primary framework (65% alignment with ISO 27001)
  • ISO 27001: Required for European enterprises
  • AI standards (ISO 42001), healthcare (HIPAA), PCI DSS
  • Approach: Support all frameworks rather than debate which ones matter

AI's Role in Compliance

Current Capabilities

  • GitHub achieves 92% automated questionnaire completion through Vanta's AI
  • AI can handle: questionnaire responses, evidence evaluation, policy updates, vendor reviews
  • Evidence validation: AI tells users if their documentation will pass audit (e.g., "Your screenshot needs a timestamp")

Future Applications

  • LLMs excel at: Making sense of unstructured data (policies, JIRA tickets, AWS screenshots)
  • AI cannot replace: Strategic decisions, insider threat policies, architectural changes
  • Defensive moat: Vanta's 30,000+ completed audits provide training data LLMs don't have access to

Jevons Paradox Risk

  • Counter-argument: AI might enable more elaborate questionnaires rather than reducing total compliance work
  • Reality so far: Models are good enough; productivity gains are real

Buyer Personas and Pricing

  • Early stage (founders): Want TurboTax-like guidance ("tell me what to do")
  • Enterprise: Want "Datadog for compliance" (dashboards, real-time monitoring, auto-remediation)
  • Buyer evolution: CFO/GC → CISO-led unified GRC organization
  • Revenue: All 15,000 customers acquired through direct sales

The Billboard Story

  • Famous billboard: "Compliance that doesn't suck too much"
  • Attributed hundreds of millions in market cap value
  • Lost the billboard to a startup that an ad agency introduced to (ironically, that startup was referred by Vanta)
  • Lesson: Sometimes founder intuition is wrong—a junior employee was right

Compliance's Real Goal

SOC 2 fundamentally aims to: Ensure customer data is protected

  • Named after Java/JavaScript analogy: Rebranding security as compliance for market appeal
  • Problem: Major companies (Equifax, AT&T) maintain SOC 2 despite massive breaches—no market accountability
  • Investors bet on: No one will actually churn due to breaches (cynically correct)

Geographic and Political Dynamics

  • Europe: Takes compliance more seriously culturally; Vanta performs better there
  • GDPR impact: Initial excitement (2018) has dissipated; still hand-wavy for engineers
  • US regulation: At "total nadir"—even state-level CCPA enthusiasm down
  • FedRAMP modernization: Current administration pushing AI/automation; Pete Wasserman leading updates to make 2020s version vs. 1990s version

Agentic Coding and SOC 2 Tension

The problem: Code written by agents, reviewed by agents (PR) looks like "two user IDs" but may have zero human review

Real goal: Don't need to read code for correctness—need "two throats to choke" (accountability)

Solution approach: Understand why SOC 2 requires separate reviewers (insider threat detection), then design systems that actually achieve that goal whether via humans or agents

Notable Quotes

> "Compliance is the buying moment for startups. Your customers never ask you for security, but they do ask you for compliance."

> "Market sizing is bullshit. The market size today is only a predictor of the market size today."

> "If you think you have product-market fit, you don't."

> "Compliance that doesn't suck too much."

— Vanta's famous billboard

> "We have probably 30,000 audits completed. We can go back and say, for a company that looks like you and for this auditor often, what sorts of controls are there?"

> "Unit tests for compliance" (how Vanta's tests work)

> "There are just so many opportunities for LMs and agentic workflows in Vanta's business. We've probably got a couple dozen of them."

> "I would bet on ISO 42001 just because it's the European one... It's bedtime reading."

Takeaways

For Founders

  • Look for inflection points, not TAM: The biggest markets often don't exist until you create demand through a better product
  • Founder intuition is often wrong: Set bets with team members and let them prove you wrong (podcast advertising case)
  • Real problems vs. passion: Don't start a company because you're passionate about compliance—start because you found a real, expensive pain point
  • Product-market fit clarity: If you're asking whether you have it, you don't

For Businesses Using Compliance Tools

  • Continuous monitoring > point-in-time audits: Stay audit-ready year-round rather than cramming before deadlines
  • Automation scales: AI can handle 92% of questionnaires; focus humans on strategy, not busywork
  • Understand the "why": Know what compliance rules are trying to accomplish, then design solutions that achieve that goal

For the Industry

  • Compliance is collapsing into fewer roles: Future is smaller GRC teams managing agents, not armies of checklist workers
  • Network effects matter: Auditor preferences and experience with tools (like QuickBooks/Xero) create defensible moats
  • Standards proliferation continues: Rather than debate which standards matter, build systems flexible enough to support them all
  • Agentic UI coming: Expect bespoke, dynamically-generated interfaces rather than static dashboards (launching summer 2024)

Go-to-Market Insights

  • Billboards work (surprisingly)
  • Podcast advertising highly effective (despite founder skepticism)
  • Phone calls still work in an AI-bot-spam world (for now)
  • Events + curated communities = future channel as email becomes noise

Transcript

11253 words en Processed in 538.4s

Christina Cassioppo founded Vanta in 2018 to solve a problem most founders didn't even know they had: compliance. Under her leadership, the company has defined the trust management category, growing to over 15,000 customers. Cheers. Good to see you. Tell the Vanta story. We help companies start or build out their security programs and then get credit for all that work through an audit, through a security questionnaire, a trust center. It's get all the work to improve your security and then go get credit for that with your customers. All the Vanta billboards I see use the word compliance rather than security. Yes. What's going on there? It is one of those where you're thinking vitamin versus painkiller, right? Compliance is SOC 2, which is a word that no one knows what it means until they deeply know it, and then they want it. When they know they have to do it this quarter. Exactly. Yeah. One of the original founding hypotheses of the company is if you want to start a security company for startups, you should actually start a compliance company. Because your customers never ask you for security, but they do ask you for compliance. So compliance is the buying moment for startups. [SPEAKER_00] I see. [SPEAKER_01] Exactly. And then when you're going through that, you have to implement a bunch of best practices, maybe buy some tooling. Yes. But you don't do it before that moment, even if you want to. [SPEAKER_00] Yeah, yeah. [SPEAKER_01] Because you're doing the thing the customer wants. [SPEAKER_00] And I guess at a later stage, the buyer would be different, where security would be the CISO versus compliance would be the CFO, GC, something like that. [SPEAKER_01] I actually think Stripe is a little different in what I see, which is biased. Compliance is usually part of this unified GRC—governance risk and compliance function—and that lives in the CISO org. [SPEAKER_00] Okay. [SPEAKER_01] It'll centralize internal audit, it'll centralize enterprise risk. [SPEAKER_00] Okay, so you're mostly— [SPEAKER_01] You put those teams together. [SPEAKER_00] Yes. [SPEAKER_01] Third party risk. Those teams are all together in the CISO org. [SPEAKER_00] So you're mostly selling to CISOs. Yes. Okay. How did you wake up in the morning and decide you were passionate about starting a compliance company? [SPEAKER_01] When I was three years old, it was my first word. Yeah, exactly. We joked in the early days, we'd never be able to pull that story off. I don't know, I heard training businesses are good. [SPEAKER_00] I've heard more absurd founding myths. Yeah. So I think you could just go for it. [SPEAKER_01] Yeah, go. [SPEAKER_00] Yeah. [SPEAKER_01] No, the real story is twofold. One, prior to Vanta, I worked at Dropbox. I worked on what at the time was a new product, Dropbox Paper. We were trying to take it to market and didn't take it to market as well as we could have for several reasons. One of which was, turned out at the time, all the Dropbox contracts had written into them that we're secure, we're compliant, we're pen tested, we're XYZ. Our new thing had none of those. So in order to talk to someone with a Dropbox account, which was 100 million people or whatever it was, we had to go through this process. And then a year and a half later, just talking to startups and founders about security, trying to figure out why is there a company to be built here? How do you get more startups to care about security? And I came across companies that either did nothing for security but felt really badly about it, and then companies that had a lot of stuff in place because they'd gotten a questionnaire from an enterprise customer. [SPEAKER_00] Yeah. And that was the thing. [SPEAKER_00] Yes. I remember that being crazy, onerous, and terrible, but also if you do it, that's like pass go, collect $200—a huge benefit on the other side. Yeah, yeah. And it was the combo of those two things. Yeah. [SPEAKER_00] What you're describing is so commonly the experience of founders who start companies. I mean, it was our experience with Stripe as well, where we had run into the problem before. [SPEAKER_00] But it's funny, I often run into people in university who are excited about starting a startup. And there are lots of success stories of people who dropped out of college to start something. Yeah. And it's generally a bad time because university students' ideas for companies are often half-baked. Find my friends. Yeah. It's a college textbook exchange app. Yeah, college apps. Yeah, yeah, yeah. It's one of five apps. Yeah. [SPEAKER_01] Whereas what frequently happens is people go out and build successful products in the world, do Dropbox Paper or get some experience. And it turns out there are huge markets available with problem spaces that most normal people have not heard of, with things like SOC 2. But you have to spend a while seeing how the value flows in the real world work to discover those big opportunities. [SPEAKER_01] Okay, so how do you feel when you go to YC now and you have these founders who've dropped out and they're like, my passion is sales enablement. [SPEAKER_01] But they actually do know surprisingly much about it. [SPEAKER_01] Yeah. I mean, if you truly manage to learn enough about sales enablement to field a strong product there, then good on you. I just think you're more likely to discover those areas after five or 10 years. [SPEAKER_00] What stage is the business at now? We have 15,000 customers. Our growth rate has actually quickened the last couple of years and quarters and months. It's been 60% annual plus for the last couple of years since that milestone. [SPEAKER_01] So a ballpark number there. Yeah, yeah, yeah. [SPEAKER_01] Yeah, it's a proper business. [SPEAKER_00] Yeah. [SPEAKER_00] Mostly. [SPEAKER_00] If you truly manage to learn enough about sales enablement to be able to field a strong product there, then good on you. I just think you're more likely to discover those areas after five or 10 years. What stage is the business at now? We have 15,000 customers. Our growth rate's actually quickened the last couple of years and quarters and months. And so it's been 60% annual plus for the last couple of years since that milestone. So a ballpark number there. Yeah, yeah, yeah. Yeah, it's a proper business. Yeah. Mostly. And you go to market, it's all sold. [SPEAKER_01] All sales. Yeah. Yeah, yeah, just one of the blessings and curses of them. With what company sizes? All, so we do the call them the two founders on the couch, but it's the two founders on the couch are building their thing and someone asks them for SOC 2 and they're working on it on Friday night. Because when else are you going to do the thing? All the way up to at least one member of the Fortune 50. [SPEAKER_01] Hmm. [SPEAKER_00] I would have thought that compliance is very different for founders who have never even heard of it versus companies who have a lot of existing teams here with opinions and stuff built out. So how does that work? Yeah, that's true. So down market, I kind of, we're not quite TurboTax, but I think that is the experience a founder wants. [SPEAKER_00] I see. [SPEAKER_01] It's like, this is high stakes and I don't want to get it wrong and I don't really know, but just guide me through. Yes. And then, so that's more of the product experience and then the output is a set of controls with security rules you follow that are monitored on an ongoing basis. And because of that, whenever you're constantly audit ready, you always have everything in place. Great. And so that's the experience a founder wants, but the output is still a security program that's monitored all the time. Up market, I, especially when I'm talking to an engineer, it's more Datadog for your compliance controls, right? You're like, I have my program, I have my thing, but it lives in a spreadsheet, it lives in Jira, custom Jira, it lives in something like that. And I want real time dashboards and visibility. I see. And deviations and auto remediation and I want that world. [SPEAKER_00] Okay. So there's almost two layers to Vanta. There is what your controls should be and then how the controls are monitored and implemented. [SPEAKER_00] And early stage companies want both. [SPEAKER_01] Yeah. [SPEAKER_00] Later stage companies may want more of the latter. Exactly. [SPEAKER_00] Yeah, yeah. Exactly. And then the tie to audit is great. Well, in some ways it's if controls are monitored, you just pass the logs to an auditor. It's more complicated than that, but that's the base model. [SPEAKER_00] Yes. Well, okay, you're getting to a question I had, which was compliance at some level is not a thing you can just buy. It's a thing you have to do. And so if you actually talk about all these rules, I don't know about SOC 2 in particular, but for example, a lot of compliance regimes have this notion of doer and approver being separate for something. And so it's the- [SPEAKER_00] Prover view is the famous one. [SPEAKER_00] Yeah. [SPEAKER_00] The nuclear submarine where you have to have the two keys turned simultaneously to launch the PR, I guess, in this analogy. And again, Vanta can't do that for you. Right. [SPEAKER_00] And so what you do is, one, for say a startup, you actually just let them know the complete list of things they actually need to do. And I presume there's some, maybe you can talk about, there's some logic of only telling them the stuff that actually applies to them. [SPEAKER_01] Yep, exactly. And then there's actually, how do you enforce, say, separate doers and approvers in something like code review? [SPEAKER_01] Yeah, so for something like, so this is where the first thing we built and we call it test, so it's advanced, but modeled after unit tests. You're turning each of these controls into a unit test. Yes. And so pull from version, GitHub, GitLab, whatever, look at every pull request and check these fields or this thing or run some logic over it. [SPEAKER_00] Yep. [SPEAKER_01] And that is our test for the control. Ah. [SPEAKER_01] And so that was the first thing we built were these tests. But tests are just ways to prove control. Ah, so you're just a test suite. You're the battery of unit tests for the compliance rules. Exactly. Ah, why don't you just say that? [SPEAKER_01] Sorry. Why don't you just billboard say that? There was a niche audience in San Francisco that would be, oh, now I understand. [SPEAKER_00] Yeah, but I think for the 101 billboards, what's the controversy with your 101 billboard? [SPEAKER_01] Oh my goodness. How much do we want to do this? We had a great 101. Great billboard. You just drive by it every day. Yeah, yeah. [SPEAKER_01] Compliance that doesn't suck too much. [SPEAKER_01] Yeah. [SPEAKER_01] Arguably, hundreds of millions of dollars in market cap attributed to that billboard. It's funny, that was just in the annuals and Vanta startups. The person who came up with that billboard, very pleased with herself, as she should have been. Yeah, yeah, yeah. [SPEAKER_01] 100% right. Yeah, yeah, yeah. [SPEAKER_01] Her manager at the time was very skeptical of that billboard. That's a C-level type line. Are we negging our users? [SPEAKER_01] Yeah, yeah. Is this okay? Are we too far over the line? Yeah. Anyway, you can guess which one of those people is still at Vanta today. Not just because of that. Yeah, yeah, yeah. But it was a good. [SPEAKER_00] Yeah, it's a cultural test. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] Her manager at the time was very skeptical of that billboard. [SPEAKER_00] That's a can level type line. [SPEAKER_00] Are we negging our users? Yeah, yeah. [SPEAKER_01] Is this okay? Are we too far over the line? Yeah. [SPEAKER_01] Anyway, you can guess which one of those people is still at Vantan today. [SPEAKER_01] Not just because of that. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] But it was a good. [SPEAKER_00] Yeah, it's a cultural test. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] Anyway, so we had this billboard. It was great. For many years. For many years. [SPEAKER_01] Yeah. [SPEAKER_01] I used to joke that we've had it locked up for years. [SPEAKER_01] Turns out we didn't, and I'm an idiot. [SPEAKER_00] Oh, you forgot to renew it. Not even. I wish. [SPEAKER_00] You should have had a little Vantan check for that. [SPEAKER_00] I know, it was like your domain, and you're just like good thing you're not supposed to. [SPEAKER_01] Yeah, exactly. [SPEAKER_01] It was slightly better, but still bad. The agency we worked with, one, I should have caught this, our contract was just written in Crayon. Oh. And we got locked people asked about our billboard. [SPEAKER_01] We'd introduced them to lots of startups. [SPEAKER_01] Some of those startups were also buying with that agency. [SPEAKER_00] Wow. And so that agency— [SPEAKER_00] A startup you introduced to them went and took your billboard. [SPEAKER_01] They didn't even do it on purpose. [SPEAKER_00] Yeah, yeah, yeah. The agency went to them and was like, oh, we have this great inventory. Would you like it? [SPEAKER_01] And then we found out. [SPEAKER_01] Yeah. Okay. Hmm. That's rough. [SPEAKER_00] But people will learn about— This is the drama in the compliance world. [SPEAKER_00] People will learn about Vantan in other ways. They do learn. We do mark it. [SPEAKER_00] Yeah. [SPEAKER_00] Yeah. Okay. [SPEAKER_00] And then going back to the other part of the question. [SPEAKER_00] So how does the layer work for the rulebook might be a thousand pages long, compiling that rulebook into the steps that are actually actionable for me because I am not a farm. And so all the farm parts of the rulebook don't apply to me. [SPEAKER_01] Yeah. [SPEAKER_01] Okay. So the initial version of it actually was, this is like back when we were founders on a couch, was getting as many SOC tools as we could. So it's like Salesforce, Slack, AWS, right? [SPEAKER_00] Yeah. Whatever. And actually opening them all and just comparing them. Yes. And trying to extract what was common and doing it that way. So that was the first cut. What we do now is hopefully more advanced, but there's a bit of, now that we have probably 30,000 audits completed. Yes. We can just go back and be like, okay, for a company that looks like you and for this auditor often, what sorts of controls are there? Yep. So we have that input in. [SPEAKER_01] Then we can also layer in both for a company in particular and in general, you get questionnaires. What are the things and the questions you're being asked? [SPEAKER_00] Yes. We just launched a new commitments product that ingests contracts and scans the contracts for things that are contracted. That's cool. So you can then pull them out and say, hey, this should be a control. [SPEAKER_00] Yes. [SPEAKER_01] And, you know, God forbid something happens, but you're like, what are my obligations to my customers? Yes. [SPEAKER_01] And you can just have, you know, you basically have all that structured data. [SPEAKER_01] But one of the most important things, they just want to see progression over time and increase maturity over time. And you've probably had this at Stripe where you want to do some cool new tool that had no security posture. Yes. And a contingent, say, heck that baby. But one part of it was, oh, can you just walk this up over time and show me you're making progress. Yes. Yes. Is SOC 2 the main Bible, the book from which you read? [SPEAKER_01] Basically, I mean, we don't, it's funny, we don't break it out by framework anymore because it's all just inputs into the system. Sure, but ultimately you need to comply with some specific things. [SPEAKER_01] Yeah, yeah, yeah. [SPEAKER_01] But yes, most customers will come to us for that first. Yeah. Number two is ISO 2701, which is if you partner, you're a SOC 2. [SPEAKER_00] Who demands ISO 2701? [SPEAKER_00] European? [SPEAKER_00] European enterprises. [SPEAKER_00] Okay. [SPEAKER_01] Yeah, yeah, yeah. And so if you're a European company selling to Europeans, you will start with that. If you're European selling to Americans, you'll start with SOC 2. Okay. [SPEAKER_00] How aligned are they? I think our mapping is 60-ish, 65%. [SPEAKER_00] Okay. And the additional ISO stuff is often documentation. Okay. Which is a great place for software to help you out. [SPEAKER_00] Sounds like Europe, yeah. [SPEAKER_01] Yeah, yeah, yeah, exactly. There's less, you know, please implement these six more rules. [SPEAKER_00] Okay, so is SOC 2 and its international equivalence basically capturing most of what you're doing? It is probably plurality, not majority. Okay. And so we see a lot of growth. And there's this whole host thousand flowers bloom of AI standards right now. [SPEAKER_00] Yeah. It's the whole thing there. [SPEAKER_01] There's the healthcare specific things. [SPEAKER_00] Sure. There's the PTI piece, which I know you're very familiar with. [SPEAKER_01] There's that. Yeah, yeah, yeah, exactly. There's less. Please implement these six more rules. Okay, so is it SOC 2 and its international equivalence basically that captures most of what you're doing? [SPEAKER_01] It is probably plurality, not majority. Okay. And so we see a lot of growth. And there's this whole host thousand flowers bloom of AI standards right now. Yeah. It's the whole thing there. There's the healthcare specific things. [SPEAKER_01] Sure. [SPEAKER_01] There's the PTI piece, which I know you're very familiar with. [SPEAKER_01] There's that. [SPEAKER_00] On healthcare, is this which? There's HIPAA, which is US law. [SPEAKER_01] You can just declare yourself compliant with HIPAA. [SPEAKER_00] Mm-hmm. [SPEAKER_00] Yeah, self-certification. Yeah, exactly. The downside of doing that is if you do that and are breached, the fines are enormous. [SPEAKER_01] And so that's the check that there's some semi-market check there. Can you describe the policy goals that something like SOC 2 seems to accomplish? And you might say, oh, it's simple. It's just security. But as we know, there's many different facets to that. [SPEAKER_00] And so it could be preventing information leaks or it could be preventing fraud against the customer. [SPEAKER_00] Or it could be all these different things. [SPEAKER_00] And so if you're at a stack rank, what is SOC 2 actually trying to accomplish at a policy level? [SPEAKER_01] I would say it is trying to ensure customer data is protected. [SPEAKER_01] I think that is what it is trying to do. [SPEAKER_00] And to round out the point of your Java, JavaScript comparison is that Java was a very popular language before the emergence of web browsers with JavaScript. [SPEAKER_00] And so when they invented JavaScript, they wanted to ride off the Java halo as an easy-to-do programming language. [SPEAKER_00] Despite the fact Java and JavaScript share no commonality at all. [SPEAKER_00] But it was just good branding. [SPEAKER_00] And what you're saying is that is similar with SOC 2 here. Okay. [SPEAKER_00] So you're saying the primary goal is to ensure that the data that you are giving this company, your software provider, whatever, is adequately protected. [SPEAKER_00] Many companies have had humongous data breaches. Equifax was a great example. Yeah, Equifax, AT&T, I believe. [SPEAKER_00] Yeah. All of them. [SPEAKER_00] Exactly. [SPEAKER_00] Assuming every big company has SOC 2. Yeah, yeah. [SPEAKER_00] But the difference between some data was leaked in some context versus in the Equifax case, sorry, we lost all of your data. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] We didn't fix the database. [SPEAKER_00] Which data did you lose? All of it. [SPEAKER_00] Yeah. [SPEAKER_00] It's very hard to find that moment in the Equifax stock price chart. [SPEAKER_01] Yes. What's going on there? As in, we think society cares. [SPEAKER_00] Society should care. [SPEAKER_00] Yes. It's valuable to not lose this data. And yet, it does not seem to impair what investors deem to be the terminal value of the company. [SPEAKER_01] Yes. [SPEAKER_01] What are investors betting on? [SPEAKER_01] They're betting on will anyone churn off of Equifax because this happens? [SPEAKER_01] And I think the cynical but correct take is no. [SPEAKER_01] Sometimes because you're Equifax or Delta, you're not going to stop. I'm not going to stop flying Delta, especially 10 to 15 years into this where you're another one. [SPEAKER_00] I'll add an eighth credit monitoring service, right? [SPEAKER_01] Yeah, exactly. [SPEAKER_01] And I think there is a cynicism there that is probably correct. Yes. The other thing that feels like it's changing in this ecosystem is that the costs of having data breaches are going up because Europe in particular is getting very strict about notifications and sometimes fines around these breaches. How is that changing your world? [SPEAKER_01] We see more. [SPEAKER_01] So we also cover some of the data privacy standards. [SPEAKER_01] So your GDPR, your CCPA, there's Brazil, there's a whole alphabet soup of acronyms here. [SPEAKER_01] It goes, honestly, we see demand for that that goes in waves. [SPEAKER_01] And it kind of tracks what you expect. It's higher in Europe. Yeah. [SPEAKER_01] Vanta as a product in general does better in Europe and better than you would guess for an American, for a California company that doesn't have European roots. Yeah, yeah, yeah. [SPEAKER_01] And I do think there's some cultural affinity and just seriousness there. Yes, yes. Versus the easy critique of Americans and compliance is I'm just checking. Yeah, yeah. [SPEAKER_01] You tell me where the bar is and I'll meet your bar. But the box checking. Exactly. [SPEAKER_01] Where it is culturally something that is more important. [SPEAKER_01] You can tell me where the bar is and I'll meet it. [SPEAKER_01] But I also have my own internal bar, which is more the European way. [SPEAKER_01] But we see demand for say CCPA, which is the California version of GDPR, quote unquote, go in waves. [SPEAKER_01] And right now it is definite. I mean, all the American regulation is at a total nadir, but it's down right now. Yeah. Well, it's down at a federal level. Is it also down at a state level, the energy around the CCPA type things? Yes, it is. [SPEAKER_01] Even with it's not clear what California is going to do and it could go multiple ways. [SPEAKER_01] But I think the national politics casts a larger shadow, even over a state like California. [SPEAKER_00] Oh, that's interesting. [SPEAKER_00] Yeah. [SPEAKER_00] Okay. And then on the national side, the current administration is very into streamlining regulation through automation and AI. [SPEAKER_00] Yeah. That is the catchphrase that they deeply believe in and are driving. I would have thought that this is just too boring to be caught up in any reform initiative or will this be streamlined? I think there's very hardworking folks in DC, in particular across the board, but in GSA, in the Office of Management and Budget trying to do this. And the primary lever they're using is FedRAMP. Yes. Oh, that's interesting. Yeah. [SPEAKER_00] Okay. And then on the national side, current administration is very into streamlining regulation through automation and AI. [SPEAKER_00] Yeah. That is the catchphrase that they deeply believe in and are driving. [SPEAKER_00] I would have thought that this kind of stuff is just too boring to be caught up in any reform initiative or will this be streamlined? I think there's very hardworking folks in DC, in special across the board, but in GSA, in the Azure Arc Office trying to do this. [SPEAKER_01] And the primary lever they're using is FedRAMP. [SPEAKER_00] Yes. [SPEAKER_00] Yeah, I know this. Yeah. [SPEAKER_01] And which broadly I would think of, I'd talk to for the federal government, but a very onerous set of both controls and requirements and documentation in order to begin trying to think about selling to federal and often states and sometimes even local governments. [SPEAKER_00] How do you think state and local governments also use FedRAMP as their fuel set? [SPEAKER_01] The state ramps? [SPEAKER_00] Yeah, yeah. [SPEAKER_01] So there's literally Texas ramps. But they conform to FedRAMP. Yeah, yeah. And there is a part of GSA and one team in particular led by a guy called Pete Wasserman, who is trying to modernize FedRAMP, but I would say make a 2020 version of FedRAMP, where the current version feels a bit more 90s. And it is unclear if he will get the traction to succeed. [SPEAKER_00] Yeah. But he's fighting the good fight and he gets it. [SPEAKER_00] But even if they do that, I find it hard to imagine the Society of Accountants just copying the new FedRAMP, lock, stock and barrel. I don't think they will. [SPEAKER_01] Yeah. [SPEAKER_01] I think you're just going to have even more divergence between these things. [SPEAKER_01] Yeah. [SPEAKER_01] You're just less control over the app. [SPEAKER_00] Yeah, I feel your life is the XKCD of we have 15 standards. It is standards and the answer is the 16th. [SPEAKER_01] Yes. Yes, yes. [SPEAKER_01] Yeah, yeah. That is also my answer when people are like, well, is Vanta going to make a standard? [SPEAKER_01] Couldn't you make a better one? [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] I mean, we couldn't, we have that posted on the office wall. [SPEAKER_00] Yeah, yeah, yeah, because it is your life. [SPEAKER_00] Yes. But okay, going back to the effects of the European strictness, it doesn't show up in the form of maybe American companies previously were looking to check the SOC 2 box versus now they're, okay, it's really important. I don't cross this actually quite strict European rule. Right, right. Whereas I think now and I think in, it's funny, we are starting Vanta, Vanta as what it is now today in spring of 2018, which is when GDPR was going into effect. Mm-hmm. And so I was running around and being like, will you talk to me about compliance? Yeah, yeah. And everyone said yes, I was having this great luck. [SPEAKER_01] And then I'd show up and I'd be like, so SOC 2. [SPEAKER_01] And they'd be like, GDPR is a priority, next please. Yep. And that energy is mostly dissipated, especially in the United States. [SPEAKER_00] Yes. [SPEAKER_01] I think because the theory at the time was GDPR is written by lawyers at a very high level. It's not a spec you can enter an engineer, comically bad as an engineering spec. [SPEAKER_01] But it's fine, we will clarify that in court over the next 10 years. And now we're seven, eight years in. Yeah. Hasn't really happened. [SPEAKER_00] Yes, yes. It still is hand wavy. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] For an engineer at least to go implement as it ever was. [SPEAKER_00] And how does this work with agentic coding where the honest answer to the number of human reviewers this code is zero? [SPEAKER_00] Yes. [SPEAKER_01] How should it work? Because right now it is like, well, somebody needs to be like, I did code well. Yeah. Right now it's agent writes code, human or agent puts up PR. [SPEAKER_01] Yes. Maybe human or agent reviews it. [SPEAKER_01] Yes. [SPEAKER_01] And I think to a naive SOC audit, you're like, those seem like two user IDs had that conversation. Yeah, yeah. [SPEAKER_01] And so we can go forward. [SPEAKER_00] But it's more about having two throats to choke as opposed to, we read the code of this ATM software and guaranteed that you didn't introduce an infinite money glitch. Yeah. [SPEAKER_01] Yeah. And so maybe that's my macro answer is just go through the SOC 2 controls and be like, what are we trying to do here? Yes, yes. And be like, okay, great. Let's design for that. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] And that may or may not be how it's written today. [SPEAKER_00] That's a good question because on all the insider threat stuff, having two reviewers is one way to do it. [SPEAKER_01] Yes. [SPEAKER_00] Does SOC 2 mandate exactly a lot of other insider threat stuff? [SPEAKER_00] Yeah. [SPEAKER_00] Because presumably you should be logging a lot of activity, auditing a lot of activity. [SPEAKER_00] There should be process that you have in place. Yeah. No. [SPEAKER_01] And I think this is where you get to the technical standard made by folks who often aren't. [SPEAKER_00] Yes. [SPEAKER_01] As in their depth in engineering. Yes, yes. [SPEAKER_01] SOC 2 is the controls for there are a bunch of logging and monitoring controls that are suggested. [SPEAKER_01] Yes. One thing maybe I also mentioned, unlike PCI, SOC 2 doesn't have a prescribed control list. [SPEAKER_00] Mm-hmm. So PCI is different and it's like, you must do X, you must buy this tool whether or not it is useful to you. [SPEAKER_00] Yes, yes. [SPEAKER_00] I'm sure you have your own story with that. Yes. SOC 2 is like, you must log useful events and have a system to look at them. [SPEAKER_00] I see. [SPEAKER_01] But it is up to you to decide what the heck that means. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] Which sometimes it's helpful. [SPEAKER_00] Yeah, yeah. One thing maybe I also mentioned, unlike PCI, SOC 2 doesn't have a prescribed control list. [SPEAKER_00] Mm-hmm. [SPEAKER_01] So PCI is different and it's like, you must do X, like you must buy this tool whether or not it is useful to you. [SPEAKER_00] Yes, yes. [SPEAKER_00] I'm sure you have your own story with that. [SPEAKER_01] Yes. SOC 2 is like, you must log useful events and have a system to look at them. I see. But it is up to you to decide what that means. Yeah, yeah, yeah. [SPEAKER_01] Which sometimes it's helpful. Yeah, yeah. [SPEAKER_01] I think for a startup that's never done this, it is unhelpful because it opens up a maze in a way that's just not great. Yes. And that's why I'm being prescriptive. I think part of Vanta's initial product market fit is actually largely due to that. [SPEAKER_00] Yes, yes. [SPEAKER_01] In a way that that wasn't the plan. [SPEAKER_00] Yeah. But I think it's figuring out how to take that high level guidance and bring it down in some places. Yes. In a way that actually makes sense. [SPEAKER_00] And that's why I think it's like, it actually has a lease tax, which applies to SaaS companies too, since you're leasing out software. Stripe Tax is built to automate all of this. [SPEAKER_00] With one integration, it knows what you're selling, when and where you have to collect transactional taxes, and how to register and file on your behalf. So if you want to sell globally, without becoming an expert in tax rules, check out Stripe Tax. The kind of joking reference that everyone makes as they talk about competition from cloud code for software products is, you're not just going to code your ex in a weekend. [SPEAKER_00] But obviously, something like SOC 2 is actually the kind of thing that LLMs or coding agents are good at working with, because there's so much training data out there. [SPEAKER_00] Yeah. [SPEAKER_00] And it's a codified set of rules. So how is AI helping with what you're doing? [SPEAKER_00] And what is your plan for? You were describing some of the scale economies you have and having seen other customers. [SPEAKER_00] And I'm curious, what the defenses are against. A customer could, in theory, say, hey, Claude, give me the plan for our SOC 2 compliance. [SPEAKER_00] Make no mistakes. [SPEAKER_00] That is a thing you can contemplate. Right. [SPEAKER_01] And I think there's the defensive thing, but actually, the very defensive thing is, right, but this is the place where you don't want to get stuff wrong. Spending much time on it does not make your beer taste better. [SPEAKER_01] Right? Is this really the place? Even if you really want to code a bunch of stuff, is this really what you want to code? Yes. [SPEAKER_01] Whatever. [SPEAKER_01] Ignore them all. [SPEAKER_01] So I think where the LLMs are excellent and a little dangerous in a build versus buy, but then we just need to build better experiences on top of this, is, hey, Claude, I'm going to give you a mess of data. [SPEAKER_01] You go make sense of it to me. [SPEAKER_01] And get me ready. Yep. Right? [SPEAKER_01] I'm just going to give you a bunch of AWS screenshots or API calls. [SPEAKER_01] I'm going to give you all my policy documentation. [SPEAKER_01] I'm going to give you my existing JIRA workflow. [SPEAKER_01] Go turn it into a thing. [SPEAKER_01] And so you can go do that today. [SPEAKER_01] So if you're going to say, we are building, this is our onboarding flow or will be our onboarding flow, which is, oh, you have an existing program that's already running. [SPEAKER_01] Oh, that's cool. [SPEAKER_01] Give you all the stuff. [SPEAKER_01] We will go map it into the Vanta world. Yes. [SPEAKER_01] And then in Claude, we're on LM. [SPEAKER_01] It's okay, cool. Now you get, I don't know, files in a folder structure that you then box share that over to EY and call that your audit. Fine. [SPEAKER_01] You can do that. In a Vanta world, the outcome is now, hopefully, we have your program mapped and is observable and monitored and alerted. And so you have continuous control monitoring. You get your dashboards. You always know what is in place and what is not. And yes, you can go send a share link to your auditor here, too, and they can log in. And see everything. [SPEAKER_00] Yep. And so we sort of think about it as they have lowered the initial audit prep. [SPEAKER_00] Yeah. [SPEAKER_01] Inside or outside Vanta, or if they're not inside Vanta, what are we doing? So building that. [SPEAKER_01] But the continuous monitoring piece. Yes, yes. That you're not going to get out of at least LM chat. You've got to code that whole system. [SPEAKER_00] Okay. [SPEAKER_00] So you're saying that everyone just wants, no one enjoys spending time in SOC 2. [SPEAKER_00] Everyone wants to have been SOC 2 compliant as of yesterday. [SPEAKER_00] Yes. [SPEAKER_00] And so you're saying part of the advantage here in this new landscape is you can just take a whole bunch of unstructured stuff and empty it into the Vanta hopper. [SPEAKER_00] Right. [SPEAKER_00] And Vanta will make sense of it. Yeah, then we'll get widgets out. [SPEAKER_00] Yeah, yeah, yeah. And I presume part of the defensibility comes from the fact that preference amongst practitioners, in this case, the auditors that are reviewing your SOC 2 materials, is a very strong effect. [SPEAKER_00] That is very true. [SPEAKER_00] And both QuickBooks and Xero, to some extent, really grew off accountants becoming familiar with those pieces of software. [SPEAKER_00] And companies could have opinions about what they were using, but those opinions are not that strong and they were overridden by the opinions of the auditors. [SPEAKER_00] And so- We have a version of that. It's not as strong as Zoldefex yet, at least. But even again, we've seen 20,000 audits and thousands for particular firms. And so you're like, to control, we now do AI evidence evals. [SPEAKER_00] That is very true. [SPEAKER_00] And both QuickBooks and Xero, to some extent, really grew off accountants becoming familiar with those pieces of software. [SPEAKER_00] And companies could have opinions about what they were using, but those opinions are not that strong and they were overridden by the opinions of the auditors. And so— We have a version of that. [SPEAKER_01] It's not as strong as Zoldefex yet at least. But we've seen 20,000 audits and thousands for particular firms. And to control, we now do AI evidence evals. So you're going to provide this piece of evidence. [SPEAKER_01] We can just tell you, is it going to work for this auditor? Did you upload a cat picture? Did you upload a screenshot without a timestamp on it? [SPEAKER_01] And you're going to get told to put the timestamp back, just like that feedback loop. [SPEAKER_01] We already have that, and we've thought about doing things for auditors as well with that. [SPEAKER_01] But it moves in the direction of an AI internal audit at least. It feels like the data you have of anonymized prior audits is an incredibly powerful network effect that cannot be replicated because it doesn't exist in the public internet. The AIs don't have it available to them because it's just private data. And just like Stripe's advantage because we have all the fraud data. We know what a normal buying pattern looks like versus not. [SPEAKER_00] And so we can offer the best anti-fraud performance just because we're working with a larger data set than other people. Similarly, people going through an audit, you can tell them that this will work and this won't. [SPEAKER_01] Yes, this is our radar. Yeah, exactly. In a way that you cannot do even if you decide to buy it yourself. [SPEAKER_01] Yes. Yeah. It's a big deal. Yeah, it's cool. [SPEAKER_00] Where else have you seen that be useful? In relationships between a software vendor and buyer. [SPEAKER_00] Mm-hmm. Right? And so Vanta core we think of ourselves as broadly, and what we're best known for is serving software vendors. People who make software and want to sell it to the world. And you ask, do you have security work? Is it secure? Great. [SPEAKER_01] Okay. [SPEAKER_01] Then we have this third party risk product. [SPEAKER_01] But it's basically, you're an organization. [SPEAKER_01] Maybe it's tech, maybe it's not tech. [SPEAKER_01] You're buying software and you're going to put a bunch of your customer's data in it. [SPEAKER_01] You want that software to be secure because if not, you have to turn around and tell your customers, I lost your data, but it's actually our email provider, but you don't care if our email provider is the issue. You think it's me and I have to send you an email. [SPEAKER_01] Yeah. [SPEAKER_01] Anyway, right? No one wants to send that email. [SPEAKER_01] So there's a whole world of third party risk or vendor reviews and we build a product for those folks. [SPEAKER_00] But is there a compliance versus security tension here as you're doing this stuff? We haven't seen as much. [SPEAKER_01] What we have seen is the person buying software, you know, they might work at a tech company and be quite savvy and up to date on those threats. They might work when our customer is a hotel, literally a hotel chain. [SPEAKER_01] Right? And they certainly don't get compliance themselves because they don't build software. Right? But they buy it. [SPEAKER_00] Yep. Fine. And so what we generally see is some companies will come in with their set of questions they want to ask. And maybe I will read your SOC 2 to you, maybe I will not, but I really want to ask you questions one through ten. Some companies don't have that. And there's some part of the value proposition—we'll prescriptively guide you. And so we have a product principle just around reasonable defaults. Yes. And it's, can we make the reasonable default questionnaire in this case something that leads into security versus compliance or versus, you know, do you have a policy to X? Yes. And you're asking, can you just ask them if they X if you care? [SPEAKER_00] Yes. And so that's a place where we've tried to, on the margin, nudge the buyer questions toward more security, knowing that will change the economic incentive of the vendor. [SPEAKER_00] One of the big debates people are having right now is how AI productivity gains show up. Yes. And I feel you could have an opinion on this because we have filled out a lot of security questionnaires at Stripe. [SPEAKER_00] And I think we'd be very happy if the machines could take over from here. [SPEAKER_00] We really don't need to—we filled out enough. [SPEAKER_00] We should talk about this. [SPEAKER_00] Exactly. [SPEAKER_00] Yeah. [SPEAKER_00] But one case you could make is the machines are getting quite good. [SPEAKER_00] Yeah. They can understand what Stripe is and is and can do and can't do. [SPEAKER_00] Yeah. [SPEAKER_00] And so every time we get a security questionnaire, AI can fill it out. [SPEAKER_00] The counter argument you could say is maybe Jevon's paradox will show up. [SPEAKER_00] Yes. [SPEAKER_00] And there'll be even more exhaustive and elaborate and custom security questionnaires. [SPEAKER_00] And so the total amount will increase. [SPEAKER_00] But how do you see AI productivity showing up here on the effect? So the questionnaire is actually a great example because we tried to build this product in 2018, actually before SOC 2, because it seems easier, but the language models were not good enough. And then we tried again in early 2021, when BERT came out and you're thinking, is there a moment, but it was not good enough. And now it is good enough. [SPEAKER_01] So GitHub gets 92% of all the questionnaires they receive answered through Vanta. You're not at 100, but it's GitHub. Yeah. They have AI tools, they have Copilot, it's a lot. [SPEAKER_01] And so we are absolutely seeing this—the models are definitely good enough. [SPEAKER_00] I'm sorry, people asked GitHub to fill out the security questionnaires before using GitHub. And now they can mostly turn around and return those security questionnaires. [SPEAKER_01] Exactly. With 92% filled out. [SPEAKER_01] And now it is good enough. [SPEAKER_01] So to that actually, GitHub gets 92% of all of the questionnaires they receive answered through Vanta. [SPEAKER_01] And so you're like, not at 100, but you're like, it's GitHub. Yeah. [SPEAKER_01] They have AI tools, Copilot. [SPEAKER_01] It's a lot. [SPEAKER_01] And so we are absolutely seeing this, the models are definitely good enough. I'm sorry, people asked GitHub to fill out the security questionnaires before using GitHub. And now they can mostly turn around and return those security questionnaires. [SPEAKER_01] Exactly. With 92% filled out. Filled out. [SPEAKER_01] And we have a kind of human, but just it's review and approve. Yeah, yeah, yeah. [SPEAKER_00] Right. And then the confidence scores on prioritizing even for the reviewer. It's like, you probably want to look at the section if you want, but you kind of don't have to. Whereas will you really look at these 10? [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] Yeah. [SPEAKER_01] And so all of that work, our product does that. [SPEAKER_00] Yes. [SPEAKER_00] Yes. [SPEAKER_00] That's cool. Okay. So where do you think it goes broadly? I think so much of the work of a compliance team is keeping things in sync, keeping different sorts of text in sync. Yes, yes. [SPEAKER_01] Right? Adding new compliance regimes, which is just adding controls. Yes. [SPEAKER_01] And then really, do you want to map the new ones to the old ones and figure out what the duplicates are? That's actually a huge part classically of the work of a compliance team. [SPEAKER_00] Mm-hmm. And so I think there are so many opportunities for LMs at agentic workflows in Vanta's business. [SPEAKER_01] And we've probably have a couple dozen of them. [SPEAKER_01] And if I think about our roadmap, knock on all the things, well, hundreds by the end of the year. [SPEAKER_00] Yes, yes. [SPEAKER_01] But it's just, what we've been doing is breaking down what folks do, right? [SPEAKER_01] And so you're like, okay, there's a questionnaire piece. [SPEAKER_01] If you send out a questionnaire, someone has to read it on the other side. Yes, yes. [SPEAKER_01] And then you have to think about it and figure out where does it work, where does it not? [SPEAKER_00] Yes. Oh, I have this new policy update. I need to put this thing in a policy. I need to, we're going to start doing, I don't know, ISO 42001, which is a new AI standard. And so how do I map that in? [SPEAKER_00] Yes. I need to rerun a risk assessment. I'm going to change my risk score. Anyway, all of these things, all of these tasks are just workflows that you could have an AI do, write an eval against with subject matter experts, and then hill climb. [SPEAKER_00] Yes. [SPEAKER_00] And so it feels like you can reason about the number of people in a profession, especially at a certain stage of company changing. [SPEAKER_00] Yes. Like if you think back to ancient times, I don't know the year 2000, if you had a 10 person company with 10 Gateway 2000 beige workstations. Yeah, yeah. [SPEAKER_00] They probably would have had an IT person. [SPEAKER_00] They probably would have. [SPEAKER_00] And that IT person would have had. [SPEAKER_01] The servers in the closet. Yeah, exactly. [SPEAKER_00] Servers in the closet, they had Microsoft Access database. [SPEAKER_00] Right. [SPEAKER_00] They had to do software updates for all the machines. [SPEAKER_00] Right. [SPEAKER_00] Occasionally lint and stuff would get stuck in the mouse ball. [SPEAKER_00] Oh, yeah, yeah. [SPEAKER_00] You have to take it out. [SPEAKER_00] I've thought of that one time. [SPEAKER_00] And all those kind of things. [SPEAKER_00] So IT was a real job. [SPEAKER_00] Yes. [SPEAKER_00] Now, I don't think a 10 person company really has an IT person. No. Because the hardware is super reliable. You just buy a new version every now and then. [SPEAKER_00] Everything's in the cloud, so there's no porting data over. Yes. You just use Google Workspace for everything. It works really nicely. [SPEAKER_00] And so IT still exists as a profession. [SPEAKER_00] There are lots of interesting things. [SPEAKER_00] Yeah. But Stripe has a bunch of IT people. You don't need a bunch of IT people at the 10. [SPEAKER_01] You've had to mail laptops to how many countries in the world, which is actually kind of hard. Yeah. We have some IT challenges. But again, we're 10,000 people. And again, it naively feels like you will have a similar effect with compliance as we had with IT. Where the professional very much stays around. It actually gets more skilled rather than the stuff we do in IT is harder than the basic IT that a 10 person company would have done. [SPEAKER_00] I think that's true. Is that basically where compliance is going? [SPEAKER_01] I think that's basically true, yes. [SPEAKER_01] So one model we've thought about with Vanta, even pre-AI, is we will delay the point at which you have to bring on a full-time security compliance person. [SPEAKER_01] Or a kind of consultant who's spending meaningful time. Yeah. [SPEAKER_01] But you know, in the past, if you're an enterprise company, maybe you did that at 50, 100. [SPEAKER_01] And it's like, can we actually push that further out? Yes. [SPEAKER_01] Because what we see is that an engineering leader or someone in the engineering org can manage more of this. [SPEAKER_01] Because they kind of have the mental models and they're usually system thinkers and they can. And they're responsible for it so they can change the stuff. Exactly. [SPEAKER_01] Yeah. [SPEAKER_01] And so you have this, or persona if you call them Amelia engineers, but you have the Amelia engineers going further here. Yeah. And then you can bring on a unified security and compliance person versus, oh, you have your security person, your IT person, your compliance person. Yeah. Yes. [SPEAKER_01] Because what we see is that an engineering leader or someone in the engineering org can manage more of this. [SPEAKER_01] Because they have the mental models and they're usually system thinkers and they can. And they're responsible for it so they can change the stuff. Exactly. [SPEAKER_01] Yeah. [SPEAKER_01] And so you have this persona if you call them Amelia engineers, but you have the Amelia engineers just going further here. Yeah. And then you bring on a unified security and compliance person versus having your security person, your IT person, your compliance person. [SPEAKER_00] Yeah. But it's similar to what we're seeing in the engineer PM designer collapse. So you have the security compliance IT collapse into one role. [SPEAKER_00] So you can keep them unified for longer. [SPEAKER_01] Exactly. If you can give them good tools. [SPEAKER_00] Yes. [SPEAKER_01] Right, they can do that. [SPEAKER_01] Okay, fine. And then again, pre-AI, but over time that team starts to grow and then you have a GRC team and you have CISO and all this. What we're talking about now and we haven't seen yet, but if I had the future cast and guess, is we're going to see those GRC teams collapse a bit more into these single threaded owners. Mm-hmm. Okay, you can have a GRC team today. [SPEAKER_01] There's maybe one person answering questionnaires, one person just reviewing new software vendors. Right? And you look at those and you're like, okay, I think you can mostly agent the work and then have someone oversee it with 20% of your time. [SPEAKER_01] But okay, great, you've collapsed two into 40%, right? And you have some person who's responsible for bothering the engineers to get evidence for them for the audit or to get the control in place because they don't own the control but they own the program. So they have to go to the engineer and be like, hello, I noticed you have a new database that is not encrypted. [SPEAKER_01] And will you please encrypt it? Right? And you can just have software go nag that person. Anyway, it collapses. And so I do think we will see smaller GRC teams managing agents, but actually in the future. [SPEAKER_01] Yeah. And then they are doing more. I'm not doing the security reviews. I'm thinking about the findings and overall managing this risk portfolio, just like vendor risk portfolio versus being like, oh, this vendor doesn't have this thing and I need to go get it from. [SPEAKER_00] Yeah, I think what you're saying is there's a strategy component to how should we be doing things? [SPEAKER_00] Yes. [SPEAKER_00] And then there's an hourly labor component to compliance, which is like, oh, we did 10 times as many sales. [SPEAKER_00] We need 10 times as many bodies on the security reviews. [SPEAKER_00] And you're saying that AI will eat up a lot of the hourly labor part of compliance and leave people doing the strategy work. Yes. [SPEAKER_00] Yeah. I do think that. [SPEAKER_00] What changes are coming down the pike in the world of compliance? I think there is, to the XKCD, there's lots of folks both trying to make new compliance standards, but it's a little bit like, what's the difference with the 22nd one? From a Vanta perspective, we've taken a like, we will support them all because we have built a machine where it is easy to add a new one in. [SPEAKER_00] Yeah. [SPEAKER_00] But obviously, you only want to support ones that customers actually want to comply with. [SPEAKER_00] So you're not- [SPEAKER_01] Well, yeah. [SPEAKER_01] But what we do actually, we used to spend a bunch of time debating which ones those would be. [SPEAKER_01] And it was honestly so frustrating. And you just lob them all in. [SPEAKER_01] Exactly. Now you're just like, build the machine that just lobs them in. [SPEAKER_01] And so the debate and the document you would write- [SPEAKER_00] It's like us with payment methods. Do you want to support this payment method? Sure. Sure. Whatever. Yeah, exactly. [SPEAKER_01] We did that with compliance standards and integrations because the prioritization debates were just too intense. [SPEAKER_00] Yes, yes. We can take all of that debate time. And anyway. [SPEAKER_01] So there's a bunch of those. I would bet on any of them. If you really pressed me, I would say ISO 42001 just because it's the European one. [SPEAKER_00] I don't know that ISO. [SPEAKER_00] You gotta- [SPEAKER_01] You gotta- It's a good one. [SPEAKER_00] It's a good one. My recommendation is bedtime reading. [SPEAKER_01] So ISO, you know this, but the European standards body, and it is their version of what one should care about with AI. [SPEAKER_01] It ends up being pretty data privacy focused and pretty high level. [SPEAKER_00] Yeah. [SPEAKER_01] Those are the counters. The pros are that European enterprises are the ones that care the most about AI and this is where they would turn. And so it's the thing that has the most market traction so far. [SPEAKER_00] But again, none of these are- None of them have product market fit. [SPEAKER_00] And none of them are regulatory. They're all- [SPEAKER_01] Correct. [SPEAKER_00] You opt into- Exactly. [SPEAKER_01] It is this market has roughly agreed you might need this thing. So there's that. I think the, okay. I'm kind of proud of this. [SPEAKER_01] They're trust centers, if you remember the trust centers? They're the security status pages. [SPEAKER_00] Oh, sure. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_01] Like trust.blahblahblah. Trust.vanta.com. [SPEAKER_01] Trust.vanta.com. I didn't know they're called trust centers. [SPEAKER_00] It's just a status page. [SPEAKER_01] Yeah. [SPEAKER_01] But they're for your security posture. Sure. So you get the green bars or green traffic lights or yellow traffic lights. [SPEAKER_00] lights. But it's for your controls. [SPEAKER_00] I see. And I- But then they always say the same thing. A status page is red, amber, green. [SPEAKER_00] Right. [SPEAKER_00] Whereas hopefully the trust center always says we're a compliant boss. Usually- Yeah, yeah, exactly. It's just like a status page. Yeah. But they're for your security posture. Sure. So you get the green bars or green traffic lights or yellow traffic lights. Lights. [SPEAKER_01] But it's for your controls. [SPEAKER_00] I see. [SPEAKER_01] And I- [SPEAKER_00] But then they always say the same thing. A status page is red, amber, green. Right. Whereas hopefully the trust center always says we're a real compliant boss. [SPEAKER_01] Usually- [SPEAKER_00] Yeah, yeah, exactly. [SPEAKER_01] And so there's a version of that. And so if nothing else, what they actually are, they're ticket deflection for the GRC team. [SPEAKER_00] I see. [SPEAKER_01] Because one, your sales team sends them out and you're like, doesn't it look good? And then if you have any questions, here you go. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] But it- It's the pre-filled questionnaire. [SPEAKER_01] It's the pre- yes, exactly. [SPEAKER_01] It's here's the binder of information. Please read it. [SPEAKER_00] Yeah. And if you have questions for me thereafter, I am here. Yeah. [SPEAKER_00] Does that work? [SPEAKER_01] It does actually. [SPEAKER_01] And I think part of it is the just show of strength. [SPEAKER_00] Yeah, yeah, yeah. And the show of I'm on top of it. Yeah, yeah. And then there's yeah, read things first. [SPEAKER_01] And then if you want to ask me, go for it. [SPEAKER_00] That's cool. [SPEAKER_00] Has outbound selling gotten harder now that everyone has a million AI bots spamming everyone? [SPEAKER_01] I think it has. [SPEAKER_01] What I have heard is phone calls work. In a way that I wouldn't expect- [SPEAKER_00] For now, right? [SPEAKER_00] Until one year from now. But now with emails, a million AI bots. [SPEAKER_01] And how many ChatGPT-written emails do you get in your inbox a day? [SPEAKER_01] But outbound phone calls are currently working. [SPEAKER_00] Got it. [SPEAKER_00] Yes. But again, it's only a matter of time until- [SPEAKER_01] It's only a matter of time. [SPEAKER_01] And I think then you're just back to events, right? [SPEAKER_00] Yeah, yeah. [SPEAKER_00] And especially small curated events. Yes. A topic we talk about sometimes here is on-demand software. Patrick's taken to saying that software should be like pizza, delivered fresh piping hot. But why are you using software that someone coded five years ago rather than just the computer deciding what to render to you at that moment. Yes. [SPEAKER_00] Is that coming to Vanta? [SPEAKER_01] It is. [SPEAKER_01] It's something we're playing with internally but really excited about is having an agent that maybe is guiding you through the process or doing something and then needs the user to render an opinion or make a connection or do something. [SPEAKER_01] And you're like, can the agent just generate UI specific for that task so the user completes it and then move on. [SPEAKER_01] Yes. [SPEAKER_01] And you get this bespoke agent generated, hand generated UI just for that. Yes. [SPEAKER_00] But are you talking about, because maybe people have a little bit of experience with agentic UI where an AI chat interface is people's first experience. [SPEAKER_00] Has some stuff in it. [SPEAKER_00] Yeah. [SPEAKER_00] And maybe there's three options you can choose. [SPEAKER_00] Right. That's an agentic UI. But you're talking about a full UI. [SPEAKER_01] Or maybe you have that agentic chat bar on half of the page or a third of the page and then the other two thirds would be a SaaS app. [SPEAKER_01] You can imagine a data table with a view and columns and rather than just customizing it, you're like, no, no, no, I would just want you to do this thing and I will take over that right side canvas of the page. Yeah, yeah. [SPEAKER_01] Generate the UI for the thing or generate the report. [SPEAKER_01] I think reporting is another great use here. And what step of the process would this be in? [SPEAKER_00] Would this be you have 14 things you need to fix to get to. [SPEAKER_00] Yeah. So we thought about it in two ways. [SPEAKER_01] So in the you're setting it up and you're going through. And actually reporting is another, I think, great case. It's no one wants more knobs and whistles on their reporting tool. Yes, yes. [SPEAKER_01] And also no one really wants to learn SQL. Yeah, yeah. You just want, I want to report for this, go generate it. [SPEAKER_00] Yeah, yeah, yeah. Not quite right, take this out. [SPEAKER_00] That's cool. So when will we be seeing generated UI in Vanta? This summer. Wow. [SPEAKER_00] Okay. What has worked well from a go to market perspective for you guys? Brand spend honestly. [SPEAKER_01] The billboards. Yeah. We do all the stuff people do of zip code tracking and all of that. [SPEAKER_01] Gong call mentions. [SPEAKER_01] So recorded sales, mentions of the word billboard on recorded sales calls. [SPEAKER_01] And then you can track. [SPEAKER_00] To measure the billboard. [SPEAKER_00] Exactly. Then you track those deals through to closed one. And you're ultimately doing a geo splash. [SPEAKER_00] You're looking at the locations where you had a billboard versus not. [SPEAKER_00] Exactly. And then just, does the prospect say the word billboard in a call at some point. [SPEAKER_00] I see. [SPEAKER_01] Yeah, yeah, yeah. [SPEAKER_01] So some of that podcasts have been, podcast advertising has been exceedingly effective for us. It's funny because we started doing it in late 2020 and our first salesperson, Eric, who's still at the company. [SPEAKER_01] We really wanted to advertise on This Week in Startups. [SPEAKER_01] Right. [SPEAKER_01] And I thought it was silly because my model is the only companies that advertise on podcasts are founders who want to hear about themselves. [SPEAKER_00] Like this is just nonsense. Exactly. And then does the prospect say the word billboard? I see. In a call at some point. [SPEAKER_00] Yeah, yeah, yeah. So some of those podcasts have been, podcast advertising has been exceedingly effective for us. It's funny because we started doing it in late 2020 and our first salesperson, Eric, who's still at the company. We really wanted to advertise, I think on This Week in Startups. [SPEAKER_01] Right. [SPEAKER_01] And I thought it was silly because my model is the only companies that advertise on podcasts are founders who want to hear about themselves. This is just nonsense. [SPEAKER_00] Or mattress companies. [SPEAKER_00] Exactly. Or mattress companies. Exactly. But we are neither. Right. Doesn't everybody really need to talk to you? Anyway. And so Paul, he came to me and was, I want to spend $60,000 on this ad. And my deal with him was, fine, but you got to sell four more Vantas because Vanta basically costs $15,000. And the next month he sold 34 more Vantas because of the podcast ads. [SPEAKER_01] And that was one where you're, well, I know nothing. [SPEAKER_01] You should just keep going. I call this, by the way, I think there's a real founder negative value out at times. Yes, exactly. Founders have these incredibly strong views that are wrong. That are just deeply wrong. But it's really hard to remember. It's good that you let them go and do it. Yeah. Because sometimes I think some people would have said, no, we're not doing that. [SPEAKER_00] Right. It's silly and it would have taken many more years to learn the message. [SPEAKER_01] Yeah, no, the deal is you have to sell four extras. Yeah, yeah, yeah. I feel like I've heard you on the Acquired podcast. [SPEAKER_00] We do, yeah, Acquired. Yeah. We do invest in the best. Yeah. Yeah. [SPEAKER_00] I like those. [SPEAKER_01] And I think in the early days, so this was helpful and then deeply unhelpful, but in the early days, before we had competitors, we tried to basically make this call response of someone says SOC 2, someone says Vanta. [SPEAKER_01] And this really close association, which in the early days, when we were just competing against consultants. [SPEAKER_00] You wanted to own the term SOC 2 basically. [SPEAKER_00] Yeah. [SPEAKER_01] Which worked really well until we had competitors who were, well, we do SOC 2, but we're Vanta, but cheaper, but worse, but better. And then you're, oh, that got, now we're all pointing at a thing we don't own. Yeah. And that's bad. [SPEAKER_00] Yeah. And so there was a great reframe on that one. [SPEAKER_01] Yeah. That's it. [SPEAKER_00] What did you learn working with Fred Wilson? [SPEAKER_01] USV is a very special place in lots of ways. And I think USV is fundamentally about ideas. [SPEAKER_00] More so than other venture firms. [SPEAKER_01] Yes. I think most venture firms are great man, great person firms. Yeah. [SPEAKER_01] They're about the person and this person will do the thing. I have no idea what this is, but I like the cut of his jib. [SPEAKER_00] Exactly. [SPEAKER_00] Yes. [SPEAKER_01] And I think USV is in a way, it's not black and white, but it's the opposite. [SPEAKER_00] Hmm. Whatever person can walk in, but if it is an idea that is interesting and compelling and intellectually engaging and networked, that is classic USV. That matches with great people. I don't mean that, but the first, second, and third thing is the idea. And so really pressing on that. That piece was very important. I think the second part is market sizing is bullshit. You can be as academic or whatever, strategery-ish as you want about it. And the market size today is only a predictor of the market size today. And I deeply learned that. Because if you looked at the SOC 2 market in 2018, my best estimate was there was $10 million spent globally. And you would never start a startup on that. But the theory of Vanta was, if we can make this thing easier to get and take down the cost of dollars, but really time, more people will get them. Yep. And you're, that ended up being deeply true. But that was not a market, especially for startups. The market for startups getting SOC 2 in 2018 was $0. [SPEAKER_00] Yes, yes. [SPEAKER_01] Truly zero. [SPEAKER_00] Yes. Okay, so Vanta is an example of the kind of company that being too granular. Yeah, you would not come up with it. [SPEAKER_01] And now it's, oh, but of course everyone gets it. [SPEAKER_00] And you're, right. [SPEAKER_01] But in 2017. [SPEAKER_00] Yes. [SPEAKER_01] Again, when did Stripe get SOC 2? [SPEAKER_00] Probably reasonably early on because it's so core. It's not a small part of your stack, but definitely before 2017. It's very interesting framing on USV where I feel like you can see this a little bit in Fred's blog and stuff. To ideas. It's clear, yeah, exactly. Attraction to ideas and a prepared mind for when something crypto comes along. Exactly, comes along. You're, that thing. You're ready to strike. And is that across the firm or is that Fred in particular? [SPEAKER_01] It's Fred and Brad, for sure. [SPEAKER_01] Brad is the undersung Fred partner. I mean, they started the firm together. [SPEAKER_00] Oh, you're talking about the Fred and Brad relationship? Yeah, yeah. [SPEAKER_01] Brad Burnham is a venture capitalist, mostly retired now, but also excellent, incredible track record. He and Fred started Union Square Ventures in, I think, 2002. First fund was 2004. [SPEAKER_00] Exactly, comes along. [SPEAKER_00] You're like that thing. [SPEAKER_00] You're ready to strike. [SPEAKER_00] And is that across the firm or is that Fred in particular? It's Fred and Brad, for sure. Brad is the undersung Fred partner. [SPEAKER_01] They started the firm together. [SPEAKER_00] Oh, you're talking about the Fred and Brad relationship? [SPEAKER_01] Yeah, yeah. Brad Burnham is a venture capitalist, mostly retired now, but also excellent, incredible track record. He and Fred started Union Square Ventures in, I think, 2002. First fund was 04. Took him two years to raise that fund. If you go look up USV 04 Vintage, God, we all should have invested in that. [SPEAKER_01] But it was the two of them and then Albert came on as a venture partner, I think in 06. I think he was on the fund as a partner. Going real deep here, sorry. But it was the two of them and there is just, it's not yin-yang, it's not the right frame, but- [SPEAKER_00] Complementarity. [SPEAKER_01] Yeah. So many of the ideas of the firm were back and forth between them. And then Fred was excellent at articulating those ideas in a way the rest of the world could understand, which he did on ABC. [SPEAKER_01] Yes. [SPEAKER_01] But I think one of the underappreciated things is how much back and forth there was in the creation there. Yes. [SPEAKER_01] And that pairing is, I think, probably should be in the annals of venture pairings. [SPEAKER_00] Yeah. Maybe something like the Coastal Door pairing. [SPEAKER_01] These venture pairings where you had two people who could play off one another. [SPEAKER_00] Yeah. And they were just that. I think Brad and Fred had that for a decade and a half. What's the difference in person? Because Doug and Mike Moritz at Sequoia are very different people. [SPEAKER_00] Yes. [SPEAKER_00] And again, I think that's part of how it works. Yeah. [SPEAKER_01] I don't think Fred and Brad are as different as those two are. But Brad is cerebral, philosophical, academic, so interesting to talk to. [SPEAKER_01] And you have this wonderful conversation and you'll be wondering if there are any ties to the business world of math. But then Fred could go back and forth and say, "Oh, freemium." And then run with freemium. [SPEAKER_00] Yes. Right. [SPEAKER_01] But it wasn't just I'm going to market this term. [SPEAKER_01] It was a back and forth and then the communication out. [SPEAKER_00] Wait, did Fred coin the term freemium? [SPEAKER_01] He did. Yeah. [SPEAKER_01] In a blog post in 2009, I don't know, 08, 09, something. [SPEAKER_00] Yeah. Right. Doesn't that feel like it was always a term? Yeah, exactly. [SPEAKER_00] That's what it's called. In 1952, didn't they talk about freemium? [SPEAKER_00] Yeah. [SPEAKER_00] It's when you learn those things like, did you know, "saying the quiet part out loud," that term comes from the Simpsons. [SPEAKER_00] In what ways are you a different CEO coming from your experience as an investor? [SPEAKER_01] I wouldn't have done it is a real answer. That's a good start. [SPEAKER_00] Yeah. I was really lucky in approximately nine million ways with them. One of the ways was for two years, I just met 15 founders a week for two years straight. Yes. And I think whatever model I had of what a founder is or does was, yeah, that exists. Yeah. But look at all the ways one can do it. Yeah. [SPEAKER_01] And there's some coming out, some more successful, but there's a lot of ways to do this thing. [SPEAKER_01] Yes. And I think that exposure was super helpful for me because you got to see people who I felt more affinity or similarity to in whatever dimension also do it. Yes. And it was the role model thing, but not one person. You meet a thousand of them. Yes. And you can pick out the pieces. [SPEAKER_00] Having all that training data, what passions do you think you see in people who went on to be successful? Or maybe conversely, what anti-patterns do you see in the people who— I think there is a truth-seeking piece of it. Sometimes you can bend reality to your will, but often reality is reality and you got to embrace it and figure out how to work around it. Reality sometimes it's an immovable object. [SPEAKER_01] And I think there was a— There's a delusion to the unsuccessful founders. [SPEAKER_01] Exactly. I've noticed that. [SPEAKER_01] Yeah, yeah. [SPEAKER_01] The like, "Oh no, but I can change this." [SPEAKER_01] And you're like, that one, I don't know, gravity's gravity. Yes, yes. Yeah. [SPEAKER_00] The version of this I talked about with Des Treanor is I feel like investor updates with a lot of words and no metrics. [SPEAKER_00] Oh yeah, those are bad. Those are bad. [SPEAKER_00] And actually no investor updates is fine. Like you didn't have to send me— [SPEAKER_00] No is either way. Yeah, yeah, exactly. No is either very good or very bad. Metrics is fine, but a lot of words and no metrics is almost a sure sign of failure. [SPEAKER_01] Bad. [SPEAKER_00] Yes. Yep. [SPEAKER_00] Because again, I think it gets at that delusion. Right. [SPEAKER_00] Failure to truth seek tendency. [SPEAKER_01] What else? [SPEAKER_01] There are things that came with Etsy and Kickstarter, but a bunch of these companies of this era, stories where I think I developed this huge appreciation for product market fit. [SPEAKER_01] That sounds so dumb. [SPEAKER_01] But now it's like if you think you have it, you don't framing. [SPEAKER_00] Yeah, yeah, yeah. [SPEAKER_00] But you're just like— [SPEAKER_00] Or if you're asking whether you have it, you don't. [SPEAKER_00] You don't, yes. Yep. [SPEAKER_00] Because again, I think it gets at that delusion. [SPEAKER_01] Right. [SPEAKER_00] Failure to truth seek tendency. [SPEAKER_01] What else? [SPEAKER_01] There are things that came with Etsy and Kickstarter, but a bunch of these companies of this era stories, [SPEAKER_01] where I think I developed this huge appreciation for product market fit. [SPEAKER_01] That sounds so dumb. But now it's if you think you have it, you don't framing. Yeah, yeah, yeah. [SPEAKER_00] But you're just like- [SPEAKER_00] Or if you're asking whether you have it, you don't. You don't, yes. [SPEAKER_01] And so Etsy, great example. Co-founder CEO spent 80% of his time for years making people desks. [SPEAKER_01] Because they had this lovely cultural thing. When you joined, you were getting homemade bespoke desks because they sold homemade bespoke things. So there's a thing, Yancey would make people a desk? Rob, I think it was Rob Palin at Etsy. [SPEAKER_00] Okay. Yeah, yeah. Sorry, I'm getting confused between Kickstarter and Etsy. [SPEAKER_00] Yeah, yeah. This is the Etsy version. Yeah, yeah. And you're just like, now 80% of a CEO's time is making desks and the business is on fire. [SPEAKER_00] See, Amazon had it figured out where you had to make your own desk. Your own desk. Exactly. It's a much more scalable way. Rob made the desks. [SPEAKER_00] Yeah. But you're just like, it's a funny story, but the business was fine. [SPEAKER_00] Yeah, yeah, yeah, yeah. Exactly. [SPEAKER_01] You know, so there are just these things that have their own physical, their own movable objects. Yeah, yeah, yeah. And you can be making desks for people all the time. Yeah, yeah, yeah. [SPEAKER_01] It doesn't matter. Yeah, yeah. [SPEAKER_01] And if you don't have that, it's not that we should all go make desks. I don't know. [SPEAKER_01] How do you, would you make, would you spend time making desks at this stage? [SPEAKER_00] I don't know woodworking is very, I don't do it, but I did it as a kid. [SPEAKER_00] It was satisfying. [SPEAKER_00] So. Yeah. [SPEAKER_00] Last question. [SPEAKER_00] Does Vanta expand from here beyond security? [SPEAKER_00] Do you start helping people apply with everything else? [SPEAKER_00] Do you continue taking over the world until all the world runs on Vanta? Yeah. [SPEAKER_00] What's the plan? Definitely taking over the world, making desks along the way. [SPEAKER_01] No. I think right now we do think about, especially in this world where in theory code has become much cheaper, which was two things. So one, it's can we add different pillars or verticals? And so there's a whole lot in security, especially for a small business or a mid-market business. [SPEAKER_01] I think enterprise is a different ballgame there, but there's things there. [SPEAKER_01] And then when we think about it, we really think about, I guess, we think about parts of the CISO organization versus for the most part, other parts of an organization. [SPEAKER_01] But we would think about enterprise risk or internal audit. [SPEAKER_01] Financial audit is adjacent and interesting. [SPEAKER_00] What can you do in internal audit or financial audit? So internal audit is easier for us, given what we've built in a way. It's we have all of this and currently we're packaging material and sending it to the auditor. But you can imagine packaging it and sending it to an internal audit. And it's the same thing, it's a controls platform, right? [SPEAKER_00] It's decide what it is that you should do and then validate that you're doing this. Prove that you're doing it, exactly. [SPEAKER_01] Financial audit is the system is similar. [SPEAKER_01] It's a different set of integrations on data. [SPEAKER_01] And so it's thinking through, okay, what is the right point to start building out those ERP integrations, appointments integrations, all of that to get that sort of data to parcel this in.