What It's Like Being the Only Security Startup in Your YC Batch

Alex Chantavy (Subimage), Kunaal Sikka

BSides NYC 2025 (0x05) · Day 1 · Entrepreneur

Overview

This talk provides a candid and insightful look into the challenging yet rewarding journey of founding a security startup, Subimage, and navigating the highly competitive Y Combinator (YC) accelerator program. Presented by co-founders Alex Chantavy and Kunaal Sikka, both former staff security engineers at Lyft, the session delves into the unique hurdles faced by a deep-tech enterprise security company within a batch often dominated by consumer-focused or AI-driven startups. Their narrative offers a rare glimpse into the realities of product development, sales, fundraising, and cultural adaptation required to succeed in the fast-paced startup ecosystem.

Watch on YouTube

Visual summary for What It's Like Being the Only Security Startup in Your YC Batch by Alex Chantavy, Kunaal Sikka
Visual summary for What It's Like Being the Only Security Startup in Your YC Batch by Alex Chantavy, Kunaal Sikka

Key moments

  1. 0:00 Speakers' background, Cartography, and Subimage introduction
  2. 2:00 Motivation for starting a company and applying to YC
  3. 3:10 YC application, interview process, and co-founder importance
  4. 5:15 YC acceptance, moving to SF, and "no LLM" comment
  5. 6:10 YC program overview and their divergent experience

What It's Like Being the Only Security Startup in Your YC Batch

Speakers: Alex Chantavy (Subimage), Kunaal Sikka

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=6SZ3yic6yaY

Overview

This talk provides a candid and insightful look into the challenging yet rewarding journey of founding a security startup, Subimage, and navigating the highly competitive Y Combinator (YC) accelerator program. Presented by co-founders Alex Chantavy and Kunaal Sikka, both former staff security engineers at Lyft, the session delves into the unique hurdles faced by a deep-tech enterprise security company within a batch often dominated by consumer-focused or AI-driven startups. Their narrative offers a rare glimpse into the realities of product development, sales, fundraising, and cultural adaptation required to succeed in the fast-paced startup ecosystem.

Chantavy and Sikka illuminate the critical differences between building security software for large enterprises and the typical YC startup trajectory, where rapid customer acquisition and short sales cycles are paramount. They highlight the strategic advantages derived from their open-source roots with cartography, a widely adopted infrastructure mapping tool, and the necessity of shifting a technical founder's mindset towards relentless customer engagement and value proposition articulation. The talk serves as an invaluable guide for aspiring security entrepreneurs, offering practical advice on everything from securing initial funding to closing crucial enterprise deals, all while maintaining authenticity and resilience amidst significant pressure.

Ultimately, this presentation is a testament to the power of perseverance, the importance of a strong co-founder relationship, and the profound learning curve inherent in transforming a security vision into a viable commercial entity. It underscores that while the path is fraught with self-doubt and unexpected challenges, the autonomy and impact of building something truly impactful from the ground up can be immensely fulfilling, especially when addressing a pervasive and critical need in the cybersecurity landscape.

Background

▶ Watch: Speakers' background, Cartography, and Subimage introduction (0:00)

Alex Chantavy and Kunaal Sikka's journey to Subimage began with a shared history as staff engineers on Lyft's security team. During their tenure, they were instrumental in bootstrapping Lyft's vulnerability management program, taking it from "zero to one." A cornerstone of this effort was the development of cartography (or cgraphy), an open-source tool launched in 2019. Cartography's purpose was to map infrastructure assets and visualize potential attack paths within an organization's environment. This tool quickly gained traction, being adopted by over 70 companies, demonstrating a clear market need for comprehensive infrastructure visibility.

The genesis of Subimage stemmed from their direct experience with a common pain point: the difficulty in answering seemingly simple security questions, such as "is our Kubernetes API server open to the internet?" Such inquiries often sparked protracted internal discussions due to a lack of a unified, real-time view of their infrastructure. Recognizing the widespread appreciation for cartography and the persistent challenges in enterprise security visibility, Chantavy and Sikka saw an opportunity to commercialize their expertise. They envisioned Subimage as an open-core alternative to Wiz, aiming to provide robust, introspectable security software that maps infrastructure, differentiating itself from closed-source platforms that often lead to vendor lock-in and "pay-to-play" mechanisms for integrating different security providers.

Their decision to apply to Y Combinator was a "million to one shot," initiated by a text message and culminating in a rigorous application process. This involved filling out a detailed form, submitting a 1-minute video (which required at least 23 takes to perfect), and choosing a company name – Subimage itself being an inside joke from their Lyft days referencing container images. The subsequent 10-minute YC interview was described as intensely stressful, highlighting the importance of a strong co-founder dynamic, as YC explicitly favors teams over solo founders, with solo applicants facing a 90% lower chance of acceptance. Despite the emotional rollercoaster, including a late-night acceptance email, their journey into YC marked the beginning of a profound learning experience, forcing them to adapt their engineering-centric mindsets to the demanding world of startup entrepreneurship.

Key Findings

▶ Watch: Motivation for starting a company and applying to YC (2:00)

The speakers articulated several critical findings from their experience, particularly the stark contrasts between the typical YC startup environment and the realities of building an enterprise security company:

  • YC Culture vs. Security Startup Fit: The average YC batch is characterized by young founders (often 19-year-olds) building B2C or AI-driven products, such as "AI vacuums" or "dog walking agents." Subimage, as a deep-tech enterprise security startup, found itself in a niche. Their YC batchmates were not potential customers, unlike a dev tools company that could readily find users within the cohort. This created a significant challenge as early-stage companies prioritize product-market fit over security, typically not investing in security tools until they reach a $1 billion valuation or a Series D funding round.
  • Enterprise Sales Cycle Mismatch: YC's 12-week program emphasizes rapid revenue generation to demonstrate traction for Demo Day. However, a typical enterprise security sales cycle spans 6 to 12 months, creating a fundamental conflict. Investors in YC demand "pen on paper" revenue, a metric that is incredibly difficult for security startups to achieve within the accelerator's short timeframe. This forced Subimage to focus intensely on accelerating their sales process.
  • The Startup Grind and Resourcefulness: The daily life of a startup founder is a relentless grind, punctuated by self-doubt. The core mantra became: "you're either talking to customers or you're writing code." As technical founders, they had to consciously shift their focus towards customer validation. The $500,000 investment from YC, while substantial, proved insufficient for the marketing and travel expenses typical of a security company. This necessitated extreme resourcefulness, from leveraging free trials (Delta Business Traveler, Industrious co-working space) to improvising office furniture with reams of paper.
  • Leveraging Open Source as a Strategic Advantage: Their prior work on cartography proved invaluable. It served as a powerful marketing angle, allowing them to "skip a couple of steps" in the sales process by engaging with companies already familiar with their work or the problems they solve. They realized that running an open-source project cultivates many of the same "muscles" required for a startup: outreach, understanding user needs, and proactive engagement.
  • The Art of Selling for Technical Founders: Transitioning from engineering to sales was "very uncomfortable," likening it to "Jesse Pinkman selling SAS." They learned that authenticity was key; a highly personalized, trust-building approach (even flying internationally to meet clients) was far more effective than generic, mass-email campaigns. In-person meetings were crucial for building trust, especially when competing against established players like Wiz, whose sales teams would present "massive beautiful product[s] and this demo." The demands on vendors are also significantly higher than internal teams, requiring near-instant responses (e.g., within 10 minutes for 9-5 inquiries) and treating clients like part of their team via shared Slack channels.
  • Procurement as a Bottleneck: Even after a CISO committed to a purchase, enterprise procurement proved to be a "bear," taking eight weeks for their first deal to finalize. This delay was particularly problematic during their "hell week" of fundraising, as they had nothing concrete to show investors until the contract was officially signed.
  • Fundraising Dynamics: YC provided significant inbound investor interest, leading to a "hell week" with 70 back-to-back calls. The signing of their first major enterprise contract on a Tuesday at 12:30 AM was a pivotal moment, transforming their fundraising prospects. They successfully raised and closed a $4.2 million seed round before Demo Day, led by Funders Club, Y Combinator, and Transport Platform. A key YC lesson was to "overengineer things for your customers, not for your investors," and to aim for less than 15% dilution to keep founders incentivized.
  • Emotional and Learning Journey: The co-founders emphasized the profound emotional rollercoaster of startup life, with extreme highs and lows. The support from other founders in the YC network was a "highlight." The biggest upside was the autonomy and immense learning curve, spanning from engaging with executives and CISOs to debugging complex technical issues. The biggest lesson was "building the right thing at the right time," optimizing for speed and demonstrating capabilities rather than building for a 3-5 year lifespan, and focusing on the "why" – the outcome and value proposition for customers – over just the "what" and "how."

Technical Deep Dive

▶ Watch: YC application, interview process, and co-founder importance (3:10)

Subimage's technical foundation is deeply rooted in the co-founders' prior work on cartography, an open-source project developed during their time at Lyft. Cartography's primary function is to provide comprehensive visibility into complex infrastructure environments by mapping assets and identifying potential attack paths. This involves ingesting data from various sources – cloud providers, identity systems, network configurations, and more – and building a unified graph database that represents the organization's entire digital footprint. This graph allows security teams to query relationships between assets, understand dependencies, and pinpoint vulnerabilities that could be exploited. For instance, answering a seemingly simple question like "is our Kubernetes API server open to the internet?" becomes trivial with a well-mapped infrastructure graph.

Subimage extends this concept, positioning itself as an open-core alternative to Wiz. The "open-core" model implies that while a foundational version of their software might be open source (or derived from their open-source heritage), the commercial offering includes proprietary features, enterprise-grade support, and advanced capabilities tailored for large organizations. This approach offers significant technical advantages:

  1. Introspection and Transparency: Unlike closed-source platforms, an open-core model allows customers to inspect the underlying logic, understand how their data is processed, and potentially extend the platform to fit their unique requirements. This transparency builds trust and reduces the "black box" syndrome often associated with proprietary security tools.
  2. Avoidance of Vendor Lock-in: By providing an open foundation, Subimage aims to mitigate the "pay-to-play mechanism" prevalent in the industry, where customers might be forced to pay different vendors to get their data integrated or covered within a single dashboard. This empowers customers with greater control over their security posture and data.
  3. Community-Driven Innovation: Leveraging an open-source base can foster a community of contributors, leading to faster iteration, broader compatibility with new technologies, and a more robust, battle-tested codebase.

During the initial phase of their startup, the technical focus was heavily influenced by the need for rapid customer validation. Alex Chantavy noted that he "barely wrote any code" during the YC batch, instead dedicating his time to customer discovery and sales. Kunaal Sikka handled most of the initial coding, but even his efforts were razor-focused on building minimal viable features that directly addressed customer pain points rather than extensive architectural overhauls. This approach reflects a core startup philosophy: optimize for speed and learning. In contrast to big tech companies where engineers might build systems to last "three, five years," Subimage's strategy was to "build the right system right now, throwing it away, building it again" if necessary. This agile, iterative development cycle allowed them to quickly demonstrate capabilities, gather feedback, and adapt their product to market demands, rather than getting bogged down in premature scaling or over-engineering. The emphasis was on proving the "why" – the value proposition – before fully committing to the "what" and "how" of large-scale technical development.

Demo / Proof of Concept

▶ Watch: YC acceptance, moving to SF, and "no LLM" comment (5:15)

While the talk does not detail a specific live demonstration or proof of concept of Subimage's commercial product during their YC journey, the very existence and success of their open-source predecessor, cartography, served as a powerful, pre-existing proof of concept. Cartography, having been adopted by over 70 companies and developed by the speakers during their time at Lyft, validated the core technical premise: that a comprehensive, graph-based mapping of infrastructure assets could dramatically improve security visibility and identify attack paths. This established a strong foundation of credibility and technical capability even before Subimage’s commercial offering was fully mature.

The speakers leveraged this open-source background extensively in their sales process. Rather than relying on elaborate product demos of an early-stage commercial offering, they focused on building trust and engaging with potential customers who were already familiar with cartography or understood the fundamental problems it aimed to solve. Their approach involved demonstrating a deep understanding of enterprise security challenges and showcasing their proven track record with cartography. This allowed them to "skip a couple of steps" in the sales cycle, moving directly into substantive conversations about their vision for an open-core alternative to platforms like Wiz. While explicit details of a Subimage product demo were not discussed, the implicit proof of concept was the successful deployment and utility of cartography in real-world enterprise environments, providing a tangible example of their expertise and the value their technology could deliver.

Defensive Implications

▶ Watch: YC program overview and their divergent experience (6:10)

The insights shared by Alex Chantavy and Kunaal Sikka offer several critical defensive implications for security practitioners and organizations:

  1. Prioritize Infrastructure Visibility: The core problem Subimage addresses—the lack of comprehensive, actionable visibility into infrastructure assets and attack paths—remains a fundamental challenge for defenders. Organizations must invest in tools and processes that provide a unified, real-time view of their digital footprint. Solutions that map dependencies, identify misconfigurations, and visualize potential attack vectors are crucial for proactive defense.
  2. Embrace Open-Source Security Solutions: The success of cartography highlights the power of open-source tools in cybersecurity. Defenders should actively explore and contribute to open-source projects, as they often offer transparency, inspectability, and community-driven innovation that proprietary solutions may lack. An open-core model, like Subimage's, can provide the best of both worlds: the flexibility of open source combined with commercial support and advanced features. This approach can reduce vendor lock-in and allow for greater customization to specific organizational needs.
  3. Understand the Vendor Landscape and Sales Dynamics: Defenders should recognize the unique challenges faced by security startups, particularly the extended enterprise sales cycles (often 6-12 months) and complex procurement processes. This understanding can foster more realistic expectations and efficient engagement when evaluating new security technologies. Building trust with vendors, as emphasized by the speakers, is paramount, and goes beyond just feature checklists.
  4. Advocate for Proactive Security Investment: The talk points out that early-stage companies often defer significant security investments until they achieve substantial valuation (e.g., $1 billion) or later funding rounds (e.g., Series D). Defenders within organizations, especially those undergoing rapid growth, must proactively advocate for security as an enabler of business rather than an afterthought. Demonstrating the value of security in terms of risk reduction, compliance, and operational efficiency can help secure necessary resources earlier.
  5. Demand Transparency and Flexibility from Vendors: The "pay-to-play mechanism" mentioned by the speakers, where vendors might charge for integration or coverage on their dashboards, is a real concern. Defenders should seek out solutions that offer open APIs, robust integration capabilities, and a commitment to interoperability, avoiding tools that create data silos or impose restrictive ecosystems.
  6. Focus on Outcomes, Not Just Features: The lesson of focusing on the "why" (customer outcomes) rather than just the "what" and "how" (features and technical implementation) is equally relevant for defenders. When evaluating security tools, prioritize those that clearly articulate how they will solve specific pain points, reduce risk, or improve operational efficiency, rather than being swayed solely by an extensive feature list.
  7. Build a Strong Internal Security Engineering Capability: The speakers' background in building Lyft's vulnerability management program from the ground up underscores the importance of internal security engineering talent. Organizations benefit immensely from security teams capable of developing custom tooling, integrating diverse systems, and adapting solutions to their unique environments, rather than relying solely on off-the-shelf products.

Key Takeaways

  • Open source is a powerful launchpad for security startups: Leveraging existing open-source projects like cartography provides market validation, builds a community, and offers a significant marketing advantage, making it easier to engage with potential customers.
  • Technical founders must prioritize customer engagement over coding: The shift from focusing on the "what" and "how" of technology to understanding the "why" – the customer's pain points and desired outcomes – is crucial for market fit and survival, even if it means less initial product development.
  • Enterprise security sales are a marathon, not a sprint: Expect sales cycles of 6 to 12 months and protracted procurement processes (e.g., eight weeks for a single deal), which demand immense patience, resilience, and strategic planning for fundraising.
  • Authenticity and in-person trust-building are paramount in competitive markets: Against well-funded incumbents, personalized interactions, flying to meet clients, and treating them as part of your team (e.g., via shared Slack channels) are essential for forging strong relationships and differentiating your offering.
  • Y Combinator offers unique advantages but requires significant adaptation for security startups: While YC provides capital (e.g., $500,000) and investor access (leading to a $4.2 million seed round), security companies must navigate a culture geared towards faster, often B2C or AI-driven, revenue models and adjust their strategy accordingly.
  • The entrepreneurial journey is an intense, emotional learning curve: Be prepared for extreme highs and lows, embrace continuous learning across all business domains (sales, engineering, finance), and recognize the invaluable support of co-founders and the broader founder network.

About the Speaker(s)

Alex Chantavy is a co-founder of Subimage, a security startup focused on mapping infrastructure and identifying attack paths. Prior to founding Subimage, he served as a staff engineer on the security team at Lyft, where he was instrumental in developing the open-source infrastructure mapping tool cartography.

Kunaal Sikka is also a co-founder of Subimage. He previously worked alongside Alex Chantavy as a staff engineer on Lyft's security team. During his tenure at Lyft, Kunaal played a key role in bootstrapping the company's vulnerability management program from its nascent stages and was a co-creator of the widely adopted open-source project, cartography.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A candid, honest war story from two credible practitioners who built something real and survived YC to talk about it. Good lane for BSides NYC, decent signal for security founders in the room, but this is squarely a case study talk — not research — and it never pretends otherwise.

Heather Calloway (CISO) — WEAK

A candid founder story with some genuine texture, but this is a startup journey talk, not a security talk. The governance, defender, and operational dimensions are almost entirely absent — the defensive implications section reads like it was written to justify the session's presence at a security conference, not extracted from the actual content.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)