3 ms·
I wouldn't consider them as "edge cases" per say. It's an end to end session management solution that aims to be secure and covers all needs for simple and comp
by rishabhpoddar 6y ago
I wouldn't consider them as "edge cases" per say. It's an end to end session management solution that aims to be secure and covers all needs for simple and complex apps.
- eganist 6y agoI suppose that depends on perspective. An argument can be made that a subset of the 50% of your YC batch are doing session management wrong if they're building a new app and feel they have to home-grow a solution. That said, considering the standard guidance around session management is "don't do it yourself," then by delegating to you, your customers also distribute that risk to you and gain some amount of indemnity as a result. So using SuperTokens would be a valid risk management strategy provided firms are: 1. fine with what's essentially indefinite vendor lock-in (at least until they ditch the software platform they've written that relies on SuperTokens), and 2. doing their diligence around your security controls. And if they've met those conditions and feel that paid session management gives them extra UX cases that they don't have available to them for building out their solution, then more power to them. The only implicit guidance in all of this that I'll make explicit is to make sure you're investing in the security of your platform considering it's the product you're selling. Many of your customers who would consider buying into this service would do so knowing that it essentially comes with some amount of indemnification regardless of whether or not you disclaim it. Final thought: it'll help you a lot if you clearly define a Shared Responsibility Model that outlines the security responsibilities SuperTokens will own v. the security responsibilities the implementing customer will own. What'll help even further is if you can then cement your Shared Responsibility Model and prove the controls you claim to have with e.g. a SOC2 type 2 that defines Complementary User Entity Controls. There's a market for what you're offering, but you'll have to be strategic about capitalizing on it and not potentially becoming a victim of your own success as you acquire customers who themselves will be the targets of attacks- ergo attacks against your platform.
- rishabhpoddar 6y agoNoted. Thank you for the suggestions. I may reach out to you sometime in the future :)
- eganist 6y agoWish you the best in any case :)