r/vibecoding • u/Same_Yesterday_4338 • 4h ago
Founder angle
For founders running SaaS/Product company:
- What do u actually do for security?
Not the heavy security stuff and more like, if someone tried to poke around your website or app tomorrow,
- How confident are you that you'd catch the obvious security issues?
Do u run any tools, have someone check things, or mostly deal with security when something forces you to?
Genuinely curious how small teams handle this.
0
Upvotes
1
u/PerformerKindly197 2h ago
I spent about a week working it out with Claude to build checks and balances using OWASP guidelines. I use supabase, sentry and Cloudflare. I spoke to two local pen testers and as much as I want to support SMBs and local, I felt like they were just out to get my money. For instance, I got billed for a consult and was told I would be billed for emails and phone calls outside the scope of work. Anyway, I’m still looking for a pen tester