Greywatch did not start as a security company. It started as a pattern we could not stop seeing.
A 20-minute conversation with a founder. No pitch deck, no SDR.
Before Greywatch we ran Tequity, a product studio. More than 100 products went through it - some we built from nothing, others we took over from an existing dev team to maintain and extend.
The common thread had nothing to do with who wrote the code. Products today are better than they have ever been: better design, better engineering, shipped in weeks rather than years. They are also weaker than they have ever been, because security arrives as an afterthought instead of a foundation.
You can see it in what gets skipped. Never the feature. Always the boundary around it. Object references nobody checked. Storage rules nobody tightened. A role field the server trusted because the client had always sent the right one.
Then the attacks started. Not against the large names in the portfolio, but against products barely past their first launch, with a few thousand users and nothing that looked worth stealing. Early enough that nobody had thought to look yet.
This is not something you patch product by product, at the end. It needs a different solution.
To find out whether what we were seeing inside our own portfolio held outside it, we pointed the harness at 30 startups from Product Hunt in May 2026. No source code, no credentials, nothing they had not already put on the internet themselves. Roughly 20 minutes per target, a surface sweep rather than a full engagement, then we moved on.
Account takeover. Customer records readable by anyone who changed a number in a URL. Credentials sitting in shipped JavaScript.
More than 2 in 3. From the outside. In under 20 minutes each.
It was not a portfolio problem. None of those companies were negligent and none of them were unusual - they were shipping at the speed the market now demands, while their security testing ran on a schedule set by a procurement cycle.
Founders are not indifferent to this. They are usually the ones who raise it first, and they are right to. A breach at this stage is not a bad quarter, it is the end of the company.
What they do not have is anyone attacking the product on the same clock as the people who eventually will. That is not a knowledge problem. It is a staffing and timing problem, and another report does not solve it.
So we stopped fixing these one product at a time and built the thing that finds them at scale.


Tell us what you're building and what you're worried about. You'll hear back from a founder, not a sales rep.