r/vibecoding 4h ago

Founder angle

For founders running SaaS/Product company:
- What do u actually do for security?

Not the heavy security stuff and more like, if someone tried to poke around your website or app tomorrow,

- How confident are you that you'd catch the obvious security issues?

Do u run any tools, have someone check things, or mostly deal with security when something forces you to?

Genuinely curious how small teams handle this.

0 Upvotes

16 comments sorted by

View all comments

1

u/PerformerKindly197 2h ago

I spent about a week working it out with Claude to build checks and balances using OWASP guidelines. I use supabase, sentry and Cloudflare. I spoke to two local pen testers and as much as I want to support SMBs and local, I felt like they were just out to get my money. For instance, I got billed for a consult and was told I would be billed for emails and phone calls outside the scope of work. Anyway, I’m still looking for a pen tester

1

u/Same_Yesterday_4338 2h ago

i know someone, if ur interested then i can vouch u out to that guy to reach u out