Skip to content

Independent advisors for security founders.

The company calls you’ve never made before — first key hires, GTM, positioning, product and engineering strategy, and the acquirer’s call. We made them building Vectrix (YC S20) and running Cloudflare’s enterprise security products.

How it starts

Start with the challenge you have this week.

Start with a free 45-minute conversation. Bring the decision that’s live right now and we’ll get into it far enough that you leave with a clearer next step, and a real feel for how we work. There is no pitch and no obligation.

Hiring & your first leaders.

When do I hire my first engineering or security leader, and how do I spot an operator behind a polished résumé?

Your first engineering or security leader either compounds for three years or costs you one. Decide when to hire, how to recognize an operator behind a polished résumé, and what must be true in their first 90 days.

Go-to-market & early sales.

How do I sell to security buyers without spending practitioner credibility I can’t buy back?

Security buyers do not buy like other buyers. Find the motion that fits them: pricing, pipeline, and your first two reps. Do it without spending practitioner credibility you cannot buy back.

Category & positioning.

How do I name what we do so the right buyer gets it in one sentence?

Name what you do so the right buyer gets it in a sentence and an investor gets it in a slide. Prepare for the Gartner question and for the moment an incumbent puts your product at the top of its roadmap.

Technical & product strategy.

Is my point solution ready to become a platform, and what do I cut to get there?

Decide what to build, how to architect it, what to cut, and how to sequence the work, including when your point solution is ready to become a platform and how to build moats. Judgment from shipping security products at Internet scale.

Fundraising & the board.

How do I run my board so it works for the company instead of becoming the work?

Build the right fundraising narrative, deliver bad news clearly, and focus on the metrics a security startup is actually judged on. Run the board so it works for the company instead of becoming the work.

Corp dev & the acquirer’s call.

An acquirer just called. What do I do in the next thirty days?

Work through partnerships, build-versus-buy decisions, and the message from corp dev that reshapes your year. Our perspective comes from sitting on the buy side of three security acquisitions.

“I'm not even kidding, that was the most helpful founder conversation I've ever had, bar none, since starting this thing two years ago.”
Seed-stage security founder · shared anonymously

Founder. Seller. Operator. Buyer.

We've been in your seat and across from it.

Austin, Texas

Corey Mahan

FocusCEO Advisor

Corey has spent over 15 years in cybersecurity: first as a practitioner living with other people's product decisions, then as a founder making them, and then as a VP scaling them globally.

He started as the buyer, running cloud, infrastructure, network, incident response, and SOC teams at Vimeo, Tyro, and others. Those are the teams that live with a vendor's promises after the contract is signed, and they gave him a clear view of what actually earns trust, which signals are real, and why technically excellent products so often fail to land. He turned those insights into Vectrix (YC S20), which Cloudflare acquired within 18 months. There, Corey rose to Vice President of Product, leading Cloudflare One (SASE and Zero Trust), where he doubled revenue, scaled a team of 30+ product managers, and sponsored three acquisitions on the buy side.

That arc is why he works with founders today. Through Cleartext Advisory, Corey helps Seed and Series A security founders with the hardest parts of the business: reading customer signals, shaping a category, navigating investors and boards, and preparing for the acquirer conversations most founders only have once. He has sat on every side of the table, and he's most useful on the decisions that are hardest to make alone.

San Diego, California

Matt Lewis

FocusCTO Advisor

Matt started in offensive security, ranking on HackerOne for finding vulnerabilities in flagship SaaS products, earning his OSCP, and running a boutique security consultancy. He moved to the blue team after that, spending years as a security engineer across cloud and infrastructure, appsec and vulnerability management, and detection and response at Autodesk and Vimeo. Vimeo is where he met Corey.

They kept getting pulled into the same incident: SaaS everywhere, no visibility into any of it, and no guardrails. They left Vimeo, went through Y Combinator's S20 batch, and built Vectrix as a modern CASB to fix it. Cloudflare acquired the company in 2022, and Vectrix became foundational to Cloudflare's Zero Trust and SSE portfolio. Matt grew into Director of Engineering there, running six product lines and an organization of more than 50 engineers. He also ran technical due diligence on Cloudflare's acquisitions, and stayed hands-on through all of it, still shipping at Internet scale.

Matt figured out the path from security engineer to senior R&D leader the hard way, mostly learning himself. Cleartext Advisory is one of a few things he's doing after Cloudflare, built to be the bench of knowledge he wishes he'd had.

Beyond just security

Building successful security companies is hard.

Deciding what gets your time when customers, investors, and employees all want something different, while you're still finding product market fit or scaling up the business.

01

Find clarity before choosing a direction.

Turn competing demands into a clear view of what to do now, what can wait, and what evidence would change the answer.

02

Build the product and the business together.

Make product, architecture, and engineering calls that create a product customers want and a company capable of delivering it, all without outrunning the team, the market, or the runway.

03

Put the company's attention where it matters.

Sequence hiring, fundraising, GTM, partnerships, and operations around the constraint that matters most, not whichever demand arrived last.

04

Define success on your terms.

Decide whether success means an acquisition, an IPO, or a durable profitable company, then make today's choices consistent with that destination.

Practical questions, direct answers

What we get asked the most.

Not covered here? Email us at hello@cleartextadvisory.com.

Who is this for?

First-time founders building security companies, seed through Series A, under $50M raised. You know security cold. Running the company is the new part.

What do we actually talk about?

We talk about whatever consequential decision is live now or taking shape: a senior hire, architecture and technical debt, product sequencing, pricing, early sales, the board, a co-founder issue, fundraising, or a call from an acquirer. This is a sounding board, not a curriculum.

Are you a vCISO or staff augmentation?

No. You already know security. We advise the founder on the company-building, product, technical, and leadership calls around it. We do not become your outsourced security team.

Is this consulting or coaching?

Neither, really. Consulting typically centers on a defined project and deliverable. Coaching helps leaders arrive at their own answers. Cleartext is advisory: we learn the context, bring an operator’s perspective, and help you make the call.

What does this cost?

We charge an hourly rate or provide a fixed fee ongoing engagement option. We’ll talk about rates and the monthly retainer path that includes an in-person kickoff during the intro call. No minimums in either case.

Do you take equity or a board seat?

We do not take equity, board seats, or vendor kickbacks. Independence is what makes the relationship safe and the advice useful.

Who will I work with?

You will work with Corey, Matt, or both, depending on the topic. The roster stays deliberately small; there is no junior consultant or account-team handoff.

What if an acquirer has reached out?

Mention it when you book the call. We route that to a focused sprint for a high-consequence process that most founders navigate only once.