Two-Person Startup, Full Security Stack

β–Ά Watch (0:20)

Alex Chantavy and Kunaal Sikka are co-founders of SubImage, a hosted version of Cartography, the open-source security graph Alex built at Lyft. After raising a $4.2M seed round and landing enterprise customers, they operated as a two-person startup with a full security stack: Okta, MDM, EDR, password managers, and AWS GuardDuty. They thought this gave them credibility. Their YC partners told them not to invest in security until product-market fit. They ignored that advice.

A Database Migration Triggers a Panic

β–Ά Watch (7:03)

The incident began with a routine move from EC2 to ECS Fargate. They migrated a subset of customer data to a new Neo4j Aura database. Two days before the incident, their laptop lost the ability to authenticate. They assumed a typo and moved on. The next day, logs showed a successful login they did not recognize. With enterprise DPAs requiring 72-hour breach notification, the clock started.

Panic-Driven Decisions That Made Everything Worse

β–Ά Watch (15:16)

In panic, they wiped both laptops instead of quarantining them. Alex deleted the Neo4j database to contain a potential attacker, which also deleted all security logs. They had no centralized log forwarding. They worked parallel threads (endpoint and database), going silent. They slept only a couple hours. They prepared breach notifications for customers, fearing the company was dead.

The β€œAttack” Was a Stored Username Typo

β–Ά Watch (18:42)

Neo4j support restored the logs and joined a call. They showed the successful login came from ECS Fargate, their own production container. The failed logins were from local dev. The root cause: the password manager had saved the Neo4j username incorrectly. The password was correct. No breach occurred. No unauthorized authentication. The 48-hour panic was over a typo.

Lessons: Centralized Logging, Playbooks, and Customer Empathy

β–Ά Watch (23:07)

The experience changed how they build SubImage. They made queries 10x faster, turning multi-second loads into milliseconds. They hired a designer to improve usability. They added integrations for every tool to eliminate blind spots. Their key advice: use playbooks, centralize all logs, test EDR before an incident, and never wipe devices. The hardest lesson: even two people who knew their infrastructure inside out got lost because data was siloed.

Notable Quotes

panic absolutely made us blind Alex Chantavy Β· β–Ά 23:09

we had the username wrong Alex Chantavy Β· β–Ά 19:49

we had all the data the whole time, but because all of these different entities were separate, we couldn’t make sense of anything Alex Chantavy Β· β–Ά 24:56

two people who knew their infra inside and out, we still got lost Alex Chantavy Β· β–Ά 25:15

we thought we were invincible Kunaal Sikka Β· β–Ά 25:31

Key Takeaways

  • Panic blinds even experienced practitioners; use playbooks to stay disciplined.
  • Centralize all logs before an incident; siloed data is useless under pressure.
  • Test security tools like EDR regularly; trust requires proof they work.

About the Speaker(s)

Alex Chantavy is Co-founder & CEO at SubImage. Former Staff Engineer at Lyft, where he created Cartography, the open source security graph. He built a first-of-its-kind container scanning and remediation platform and served as a Security Engineer on the Microsoft Red Team.

Kunaal Sikka is Co-founder at SubImage. Previously Member of Technical Staff at Anthropic and Staff Engineer at Lyft, where he architected SIEM, insider abuse, and vulnerability management platforms.