Founder · Texas Public Radio
Don't Be the Next Tea: Defense in Depth For Founders
- When
- Thu, Oct 1 · 11:30 AM – 12 PM
- Where
- Texas Public Radio
In 2025, the Tea app went from App Store darling to cautionary tale in under a week. A misconfigured storage bucket exposed tens of thousands of users' selfies and ID photos, the exact data the app promised to protect. It wasn't a sophisticated attack. It was a missing access control, no defense in depth, and a team moving fast without guardrails. This talk is for the new generation of founders shipping product with AI tools doing most of the development work. You can move faster than any generation of founders before you, but speed doesn't tell you what questions to ask. If you don't have a security background, you don't know what you don't know, and that gap is exactly where breaches like Tea's happen. After a CS degree, a stint working in cybersecurity for the DoD, and founding two software companies, I'll walk through the layers of defense that close that gap: authentication that doesn't rely on obscurity, least-privilege data access, secrets management that survives a GitHub leak, and monitoring that catches problems before your users do. No compliance checkboxes, no security theater. Just the list every founder needs before your users' trust becomes someone else's headline.

