Compliance at scale and why TAM is a distraction, with Christina Cacioppo of Vanta
TL;DR
Christina Cacioppo explains how Vanta turned compliance from a bureaucratic burden into a scalable security platform serving 15,000+ customers, revealing why compliance—not security—is the true forcing function for startup infrastructure and how automated monitoring transforms periodic audits into continuous readiness.
🎯 Compliance as the Security Gateway 3 insights
Painkiller beats vitamin positioning
Startups only implement security when enterprise customers force them via SOC 2 requests, making compliance the actual buying moment rather than abstract security tools.
Dropbox Paper origin story
Cacioppo discovered the problem when launching Dropbox Paper required a year-and-a-half security review despite Dropbox's existing scale, revealing how compliance friction blocks revenue.
Unified GRC migration
While early-stage companies buy compliance to close deals, enterprise customers centralize Governance Risk and Compliance functions within CISO organizations.
⚙️ Technical Architecture & Scale 3 insights
Unit testing for compliance controls
Vanta treats compliance controls as automated unit tests that pull data from GitHub and GitLab to verify enforcement of rules like separate doers and approvers.
Dual-layer product strategy
Downmarket customers receive a guided TurboTax-like experience for control implementation, while enterprises get Datadog-style real-time dashboards and auto-remediation.
Scope-based rule filtering
Using 30,000 completed audits, Vanta filters thousand-page rulebooks to show only actionable controls relevant to a company's specific industry and infrastructure.
🌍 Global Regulatory Landscape 3 insights
SOC 2 versus ISO 27001 mapping
SOC 2 dominates US enterprise sales while ISO 27001 serves European markets, sharing approximately 60-65% control overlap with additional documentation requirements in Europe.
Cultural compliance divergence
American companies treat compliance as box-checking to meet external bars, while European firms maintain higher internal standards regardless of regulatory requirements.
Data breach economic reality
Major breaches like Equifax demonstrate minimal long-term impact on terminal company value or customer churn, though European notification laws and fines are increasing enforcement costs.
📈 Business Growth & Lessons 3 insights
Accelerating enterprise adoption
Vanta serves 15,000 customers ranging from two-person startups to Fortune 50 companies, maintaining 60%+ annual growth that has quickened in recent quarters.
The billboard cautionary tale
After years of displaying the famous "Compliance that doesn't SOC 2 much" billboard, Vanta lost the space when a startup they introduced to the agency accidentally claimed the inventory.
Domain expertise timing
Cacioppo argues that discovering "boring" high-value markets like compliance requires 5-10 years of industry experience rather than undergraduate brainstorming.
Bottom Line
Build continuous compliance monitoring into your infrastructure from day one using automated testing, treating audits as permanent states of readiness rather than periodic events to cram for.
More from Stripe
View all
Stripe Sessions 2026 | Keynote
Stripe Sessions 2026 marked the company's most ambitious product launch day in history, centered on building economic infrastructure for the AI era. The keynote revealed a parabolic spike in new business formation since January 2026 and introduced tools including the Machine Payment Protocol, Link wallet for agents, and Stripe Projects to enable autonomous agent-to-agent commerce.
Sam Altman in conversation with Patrick Collison
Sam Altman discusses the recent 'parabolic' inflection in AI capabilities, particularly for coding with GPT 5.5 and Codex, while outlining OpenAI's evolution into a massive-scale 'intelligence utility' provider focused on automating general computer work through agents like OpenClaw.
Nat Friedman and Daniel Gross in conversation with John and Patrick Collison
Nat Friedman and Daniel Gross describe the current era as the 'slow part' of the singularity, predicting that AI will drive massive economic shifts, force continuous security hardening, and enable a new golden age of personal hardware tinkering where AI agents reverse engineer proprietary systems in hours.
Stripe Sessions 2026 | Indexing the economy
Stripe co-founder John Collison and Head of Data Emily Sans analyze 2026 economic data revealing that AI is driving unprecedented business formation and global scaling among lean solopreneurs, while commerce rapidly evolves toward autonomous agent-to-agent transactions using stablecoin micropayments.