100+ products built.
Security was the crack in most.

Greywatch did not start as a security company. It started as a pattern we could not stop seeing.

A 20-minute conversation with a founder. No pitch deck, no SDR.

Where this started

Tequity.

Before Greywatch we ran Tequity, a product studio. More than 100 products went through it - some we built from nothing, others we took over from an existing dev team to maintain and extend.

The common thread had nothing to do with who wrote the code. Products today are better than they have ever been: better design, better engineering, shipped in weeks rather than years. They are also weaker than they have ever been, because security arrives as an afterthought instead of a foundation.

You can see it in what gets skipped. Never the feature. Always the boundary around it. Object references nobody checked. Storage rules nobody tightened. A role field the server trusted because the client had always sent the right one.

Then the attacks started. Not against the large names in the portfolio, but against products barely past their first launch, with a few thousand users and nothing that looked worth stealing. Early enough that nobody had thought to look yet.

This is not something you patch product by product, at the end. It needs a different solution.

The experiment

30 startups. No inside access.

To find out whether what we were seeing inside our own portfolio held outside it, we pointed the harness at 30 startups from Product Hunt in May 2026. No source code, no credentials, nothing they had not already put on the internet themselves. Roughly 20 minutes per target, a surface sweep rather than a full engagement, then we moved on.

30targets, chosen for nothing but being recently launched
21had a serious, exploitable hole
14of those were critical or severe

Account takeover. Customer records readable by anyone who changed a number in a URL. Credentials sitting in shipped JavaScript.

More than 2 in 3. From the outside. In under 20 minutes each.

It was not a portfolio problem. None of those companies were negligent and none of them were unusual - they were shipping at the speed the market now demands, while their security testing ran on a schedule set by a procurement cycle.

Why we built it

The gap was never care. It was cadence.

Founders are not indifferent to this. They are usually the ones who raise it first, and they are right to. A breach at this stage is not a bad quarter, it is the end of the company.

What they do not have is anyone attacking the product on the same clock as the people who eventually will. That is not a knowledge problem. It is a staffing and timing problem, and another report does not solve it.

So we stopped fixing these one product at a time and built the thing that finds them at scale.

Who built it

2 people who kept running into the same wall.

Rahul Dharan, co-founder and CTO of Greywatch
Rahul Dharan
Co-founder, CTO
Ran the security pass on everything that came through Tequity, and spent a decade before that taking other people's products apart. He designed the harness and the review process behind it.
Ajay Kumar, co-founder of Greywatch
Ajay Kumar
Co-founder, product & GTM
Founded Tequity and watched the same failure repeat across 100+ products. Greywatch is the attempt to fix it once, at the front, instead of a hundred times at the end.
Get in touch

Talk to the founder.

Tell us what you're building and what you're worried about. You'll hear back from a founder, not a sales rep.

✓ Thanks for reaching out. We'll be in touch shortly.