helping founders and operators build leverage community. prev: product @koalafi, @mastercard, APT. Duke. aspiring NYT crossword author

Joined June 2020
190 Photos and videos
Ann Marie Guzzi retweeted
I just open sourced my "Is this slop?" simple test
115
1,045
19,178
453,040
in my culture it’s incredibly offensive to schedule an intro meeting for an hour
4
159
To be incredibly clear, it’s not just VCs subsidizing AI, it’s the public markets as well
1
2
39
this is not uber or airbnb or the 2010s largesse. It’s so much more.
37
back to the good old days of IPOs happening <6 years from the company being founded
Anthropic has confidentially submitted a draft S-1 registration statement to the Securities and Exchange Commission. Pending completion of SEC review, this gives us the option to pursue an initial public offering. Read more: anthropic.com/news/confident…
65
4.8 this 4.8 that I’m still using 4.6 like 99% of the time I’m using Opus
25
Ann Marie Guzzi retweeted
Everything I say is a joke Unless you agree And in that case Speak to me privately I have even crazier ideas
29
12,765
59,459
1,118,210
Ann Marie Guzzi retweeted
May 20
i have become middle manager orchestrator of agents
54
1,235
20,512
411,729
Gmail search is so bad that I now use Claude Code to search Gmail for me.
100
Ann Marie Guzzi retweeted
TMZ joins the Randy Clarke fan club.
There’s not enough talk about how incredible DC’s public transit system is
48
1,186
45,656
amazing what some good PR does for a cron job
2
72
DC Twitter, help. Why is there a Frito-Lay campaign about lower prices blanketing the metro right now? What does this do for the warfighter?
2
4
222
no it’s okay it’s two women talking about AI so it passes the Bechdel test
1
50
hey you guys all know the software platform doesn’t actually DO the audits right? they just orchestrated a ring of wink wink nudge nudge auditors
1
85
RFT.
The Delve scandal is the perfect excuse for me to write my long-simmering rant about SOC-2 and InfoSec. 1. 90% of SOC-2 is security theater. We couldn't pass audit until we had completed an annual performance review (absurd requirement for a team of 4). It is mind-boggling to me that we collectively decided to adopt an accounting framework (and accounting firms) to validate infosec. 2. SOC-2 startups are (at least in part) culpable for this mess, thanks to Jevon's Paradox. It's now "easier" to get it, so getting the certification is table stakes for an enterprise contract. "But Hari, startups can now sell to enterprise more easily" — nope. 3. I would argue that the approach for selling to enterprise was *better* prior to 2017: — Enterprises were more open to doing pilots without SOC-2, because it was harder to do and not table stakes. This is, obviously, a more efficient way to transact and explore ad hoc relationships. — You'd simply have to do actually useful things like pentesting, security questionnaires, etc. to show you were serious about security... which you have to do today anyway, because SOC-2 is a terrible proxy for real security. And enterprises have gotten easier to sell into, because they realized they need to be more tech forward. Correlation, not causation. SOC-2-as-table-stakes killed a more pragmatic, trust-based sales motion. All in all, the introduction of SOC-2 as an industry standard introduced *more* friction into the process, racked up *higher* costs for their customers, for ultimately the *same or worse* security outcomes. We would all be better off if we threw the standard in the trash, because then we might actually come up with something sensible. 4. Perhaps the Delve takedown was penned by a competitor, but — if the facts hold up — that doesn't make it any less valid. This is a wildly competitive space, and I've seen some truly nasty stuff happen, from an observer's seat. But people are using that to discredit the piece, even though the facts so far are pretty damning (regardless of the biases of the speaker). 5. All of the SOC-2 companies are roughly equivalent (no matter what they tell you), and you should optimize for a good service at a reasonable price and grit your teeth and get it done when you think you have enough PMF where enterprises might want it. 6. Don't even get me started on GDPR and CCPA. Cookie banners take quality-adjusted years off peoples' lives, just like cigarettes and the DMV. And just like SOC-2 is security theater, they are privacy theater. 7. Most importantly: getting dinged because you didn't pass security reviews has nothing to do with security. It means your buyer / champion didn't care enough to push it through. If you're sorely lacking, it might be an actual issue. You should (obviously) do the important stuff (vulnerability scans, pentests, 2FA, be careful with phishing), but after that... Spend your time building something that buyers want to rip out of your hands. Your security problems will start disappearing.
1
119