Postern.
A postern is a small back gate. Built into the wall of a fortress, used by the people who know it's there. It exists for the people inside, not as a front-door spectacle.
This is a self-assessment tool for early-stage founders. We ask the questions a thoughtful peer would ask, give you a roadmap grounded in the work other people have already done thinking about this problem, and stay out of your way.
What it isn't. Not a compliance tool. Not a SOC 2 generator. Not a vendor. We don't store your responses for anyone but you, we don't share your data, and we don't run ads.
Sources we draw from, credited inline.
- CIS Critical Security Controls v8.1 (Center for Internet Security)
- Day Zero Normal CISO Brief (Rob Fuller, April 2026)
- OWASP Top 10 for LLM Applications 2025
- OWASP Top 10 Web 2021
- Start-Up Secure (Chris Castaldo, Wiley 2021)
Who's behind it.
A small team that has watched too many founders treat security as a problem for after Series A. The product is what we'd have wanted at seed. Feedback, corrections, and arguments: use our contact form.