Two-Person Startup, Full Security Stack
Alex Chantavy and Kunaal Sikka are co-founders of SubImage, a hosted version of Cartography, the open-source security graph Alex built at Lyft. After raising a $4.2M seed round and landing enterprise customers, they operated as a two-person startup with a full security stack: Okta, MDM, EDR, password managers, and AWS GuardDuty. They thought this gave them credibility. Their YC partners told them not to invest in security until product-market fit. They ignored that advice.
A Database Migration Triggers a Panic
The incident began with a routine move from EC2 to ECS Fargate. They migrated a subset of customer data to a new Neo4j Aura database. Two days before the incident, their laptop lost the ability to authenticate. They assumed a typo and moved on. The next day, logs showed a successful login they did not recognize. With enterprise DPAs requiring 72-hour breach notification, the clock started.
Panic-Driven Decisions That Made Everything Worse
In panic, they wiped both laptops instead of quarantining them. Alex deleted the Neo4j database to contain a potential attacker, which also deleted all security logs. They had no centralized log forwarding. They worked parallel threads (endpoint and database), going silent. They slept only a couple hours. They prepared breach notifications for customers, fearing the company was dead.
The βAttackβ Was a Stored Username Typo
Neo4j support restored the logs and joined a call. They showed the successful login came from ECS Fargate, their own production container. The failed logins were from local dev. The root cause: the password manager had saved the Neo4j username incorrectly. The password was correct. No breach occurred. No unauthorized authentication. The 48-hour panic was over a typo.
Lessons: Centralized Logging, Playbooks, and Customer Empathy
The experience changed how they build SubImage. They made queries 10x faster, turning multi-second loads into milliseconds. They hired a designer to improve usability. They added integrations for every tool to eliminate blind spots. Their key advice: use playbooks, centralize all logs, test EDR before an incident, and never wipe devices. The hardest lesson: even two people who knew their infrastructure inside out got lost because data was siloed.
Notable Quotes
panic absolutely made us blind Alex Chantavy Β· βΆ 23:09
we had the username wrong Alex Chantavy Β· βΆ 19:49
we had all the data the whole time, but because all of these different entities were separate, we couldnβt make sense of anything Alex Chantavy Β· βΆ 24:56
two people who knew their infra inside and out, we still got lost Alex Chantavy Β· βΆ 25:15
we thought we were invincible Kunaal Sikka Β· βΆ 25:31
Key Takeaways
- Panic blinds even experienced practitioners; use playbooks to stay disciplined.
- Centralize all logs before an incident; siloed data is useless under pressure.
- Test security tools like EDR regularly; trust requires proof they work.
About the Speaker(s)
Alex Chantavy is Co-founder & CEO at SubImage. Former Staff Engineer at Lyft, where he created Cartography, the open source security graph. He built a first-of-its-kind container scanning and remediation platform and served as a Security Engineer on the Microsoft Red Team.
Kunaal Sikka is Co-founder at SubImage. Previously Member of Technical Staff at Anthropic and Staff Engineer at Lyft, where he architected SIEM, insider abuse, and vulnerability management platforms.