Two in three startups publish no security page at all

When an enterprise buyer's security reviewer opens a vendor's website for the first time, they are usually not reading the pricing page yet. They are looking for one specific thing: a security or trust page. A few honest sentences about how the company handles data, what it is doing about certifications, and where to report a vulnerability. It costs a startup almost nothing to build — an afternoon, not an engineering sprint — and it is the cheapest trust signal on the entire site. So we wanted to know how many startups actually have one.
We passively scanned 705 US-based B2B SaaS companies (YC-seed stage, 5–50 employees) using only public data, checking each reachable site for a published security or trust page. Here is what we found.
Two in three reachable startups — 65.9% of the 705 we scanned — publish no security or trust page at all. Not a thin one, not a stale one from two funding rounds ago: nothing. For a reviewer working through a vendor shortlist, that means the company's first impression, before a single feature is evaluated, is a blank.
Why the blank page costs more than it looks like
Picture a 30-person analytics tool mid-funnel with a mid-market prospect. Their AE has a warm champion, a scoped pilot, and a verbal yes from the buyer's team. Then the buyer's security reviewer does what reviewers always do before a contract moves: they open the vendor's site looking for a security page. There is none. Now the reviewer has to email and ask, which adds a step, a delay, and a first impression of "we didn't think about this" before the vendor has said a word about what they actually do. None of that is really about security posture yet — it is about whether the company looked ready. A blank page reads as unready even when the underlying practices are fine.
The fix is not a compliance program. It does not require a SOC 2 report or a completed pentest. A short, honest page — what data is collected, how it is protected, a contact for a vulnerability report, and an "in progress" line for whatever certification is on the roadmap — closes the gap for the two-thirds of companies that currently show up as a blank.
What to actually do about it
- Publish a page, even a short one. A single page at
/securityor/trustbeats no page every time. It does not need to be polished to do its job. - Say what data you collect and how it's protected in plain language — encryption in transit and at rest, where data is hosted, who can access it.
- Add a way to report a vulnerability. A single email address is enough. Reviewers specifically look for this, and its absence is its own red flag.
- List what's in progress, not just what's done. "SOC 2 Type II in progress, target Q1" reads as further along than silence.
- Link the page from your footer and your pricing page — a security page a reviewer can't find is close to not having one.
How we know this
This number comes from a passive external scan of 705 US B2B SaaS companies matching the profile above (YC-seed stage, 5–50 employees), aggregated 2026-08-21. We read only public information — each company's own public website — with no scanning, probing, or logins, and no individual company is identified in the dataset. It's the same passive check we run as the first step of an external security posture assessment.
Curious how your own site looks to a buyer's reviewer? Our External Security Posture Assessment checks your public-facing posture — trust page included — and hands you a plain-English report with the fixes. It's passive and external-only; we never touch your systems.