Startup Security Program
7 guides
Before there is a security team there are still security decisions, and most of them get made by default. These guides cover the minimum viable stack at each headcount, what SOC 2 costs a seed-stage company in reality, and how to evaluate the consulting market when the gap is bigger than the team.
Start here
The Solo Founder's Identity & Security Stack
The minimum viable identity and security stack for a 1 to 5 person B2B SaaS, in priority order, with an honest do-now-vs-defer table and what to deliberately skip.
Explainers
All explainers→Best Cybersecurity Consulting Firms in the US (2026)
intro · 12 minA tiered directory of the specialised US cybersecurity consultancies worth a CISO's shortlist, from Optiv and Coalfire down to the boutiques, plus five questions that predict engagement quality.
How to Choose a Cybersecurity Compliance Consulting Firm
practitioner · 11 minA decision framework rather than another listicle: four compliance problem types, industry matching, five predictive evaluation criteria, and 2026 pricing benchmarks.
How-To & Implementation
All how-to & implementation→Playbooks
All playbooks→Migration
All migration→Migrate Supabase Postgres to Neon
practitioner · 9 minA Postgres to Postgres runbook: the version match and restore flags that decide whether it works, which extensions survive, how the connection string changes, and the free-tier limit that takes you offline.
Migrate from Supabase to Firebase
practitioner · 10 minTwo migrations share this name and cost very different amounts. Firestore means giving up SQL entirely; Firebase SQL Connect is Postgres to Postgres with an instance fee. Plus the bcrypt import that makes auth almost free.