<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: Deepak Prabhakara</title>
    <description>The latest articles on Forem by Deepak Prabhakara (@deepakprab).</description>
    <link>https://forem.com/deepakprab</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F646719%2Fb6413e1e-bfb6-4375-90d7-75ee16f8f603.png</url>
      <title>Forem: Deepak Prabhakara</title>
      <link>https://forem.com/deepakprab</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/deepakprab"/>
    <language>en</language>
    <item>
      <title>BoxyHQ - The must-have for your startup's next enterprise customer</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Thu, 20 Jul 2023 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/boxyhq-the-must-have-for-your-startups-next-enterprise-customer-1n85</link>
      <guid>https://forem.com/boxyhq/boxyhq-the-must-have-for-your-startups-next-enterprise-customer-1n85</guid>
      <description>&lt;p&gt;Add plug-and-play features to your SaaS product with BoxyHQ's product suite. Become enterprise-ready!&lt;/p&gt;

&lt;p&gt;&lt;a href="https://boxyhq.com/enterprise-sso"&gt;&lt;br&gt;
&lt;br&gt;
  &lt;br&gt;
  &lt;br&gt;
  &lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--ragCp0cM--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://github.com/boxyhq/jackson/assets/66887028/b40520b7-dbce-400b-88d3-400d1c215ea1" class="article-body-image-wrapper"&gt;&lt;img alt="BoxyHQ Banner" src="https://res.cloudinary.com/practicaldev/image/fetch/s--ragCp0cM--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://github.com/boxyhq/jackson/assets/66887028/b40520b7-dbce-400b-88d3-400d1c215ea1" width="800" height="320"&gt;&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Introduction​Intro
&lt;/h2&gt;

&lt;p&gt;BoxyHQ enables you to add plug-and-play enterprise-ready features to your SaaS product.&lt;/p&gt;

&lt;h2&gt;
  
  
  The WhyThey why​
&lt;/h2&gt;

&lt;p&gt;It initially started with identifying the pain of developers having a TON of responsibility — right from infrastructure to actually building the product.&lt;/p&gt;

&lt;p&gt;And with the growing cybersecurity attacks, they need to start thinking about security as well.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--7lZxB4v0--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-locks-7a1184b1ed203b49651e2f1ddb95dda5.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--7lZxB4v0--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-locks-7a1184b1ed203b49651e2f1ddb95dda5.jpeg" alt="locks" width="800" height="534"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Photo by &lt;a href="https://unsplash.com/@flyd2069?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;FLY:D&lt;/a&gt; on &lt;a href="https://unsplash.com/@flyd2069?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyTex"&gt;Unsplash&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;[Cyber-crimes are predicted to cost $10.5 trillion annually by 2025]&lt;/p&gt;

&lt;p&gt;The goal is to help smaller startups become &lt;strong&gt;enterprise-ready.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Because until there’s an enterprise client coming in, security is usually an &lt;em&gt;afterthought.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;But they (enterprise customers) are the ones who question your security posture, compliances and more — as a company.&lt;/p&gt;

&lt;p&gt;[About 70% of development teams skip crucial security steps due to time pressures.]&lt;/p&gt;

&lt;p&gt;That’s where BoxyHQ comes in.&lt;/p&gt;

&lt;h4&gt;
  
  
  &lt;em&gt;But wait… What is enterprise-readiness?&lt;/em&gt;​
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--zicsEkLu--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-question-5674e22de525d906508173e251350ac9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--zicsEkLu--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-question-5674e22de525d906508173e251350ac9.png" alt="Question" width="800" height="534"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In a nutshell, it’s being secure, scalable, stable, and easy to run in production.&lt;/p&gt;

&lt;p&gt;According to &lt;strong&gt;Sama — Carlos Samame (Co-Founder)&lt;/strong&gt;, there are 2 paths for startups towards the need to be enterprise-ready:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Initially focused on smaller customers and now looking to expand.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Building a new product and targeting enterprise customers from Day 1.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;em&gt;But how do things look like from the enterprises’ end?&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Enterprise customers are often apprehensive (concerned) about trusting startups vs. established businesses. Because the stakes are usually much higher.&lt;/p&gt;

&lt;h4&gt;
  
  
  They’re mainly looking for 2 things:​
&lt;/h4&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Your other enterprise customers (helps credibility)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Whether you follow the compliance requirements (key necessity)&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;They look for quite a few standards to be met in a solution provider 👇🏻&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--zXGsLqOQ--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-enterprise-ready1-1834463a2c9946a0349a34649f1a5a20.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--zXGsLqOQ--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-enterprise-ready1-1834463a2c9946a0349a34649f1a5a20.webp" alt="enterprise-ready1" width="800" height="637"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Source &lt;a href="https://www.enterpriseready.io/"&gt;EnterpriseReady.io&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--CYB1oL2R--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-enterprise-ready2-d301dacbf42162783f0e4383dc56134e.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--CYB1oL2R--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-enterprise-ready2-d301dacbf42162783f0e4383dc56134e.webp" alt="enterprise-ready2" width="800" height="655"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Source &lt;a href="https://www.enterpriseready.io/"&gt;EnterpriseReady.io&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;Before you feel overwhelmed, he further adds that you don’t need to start building all of this, and focus on 3 key areas:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
#### Customer obsession​
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Understand their current needs, pains, motivations, processes, and most importantly — whether the plenty of software they already use will work smoothly with yours.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
#### Time to market​
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Invest in off-the-shelf enterprise readiness solutions that you can integrate into your SaaS app vs. spending months building in-house. Spend more time on your core product vs. non-core features.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
#### Reduced engineering costs​
&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Investing in external solutions saves developer time spent on coding, fixing bugs, and the overall learning curve.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“People’s time is more expensive than developer tools.”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;A great way is to rely on open easily available open source solutions.&lt;/p&gt;

&lt;p&gt;Source: &lt;a href="https://boxyhq.com/blog/three-reasons-not-to-build-enterprise-features"&gt;Be enterprise-ready: 3 reasons not to build enterprise features!&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The BoxyHQ suite — in the chronological order of release.​
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Open Source SAML Jackson​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--h7-sbU8G--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal-02cc1a4cd113f7227c802a8ab6557e03.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--h7-sbU8G--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal-02cc1a4cd113f7227c802a8ab6557e03.jpeg" alt="Admin Portal" width="800" height="520"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Yep, that’s the product’s name. Pulp Fiction fans get the reference but for others–&lt;/p&gt;

&lt;p&gt;💡 &lt;em&gt;Pulp Fiction is a 1994 American crime film written and directed by Quentin Tarantino. Samuel Jackson starred in a leading role.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;SAML SSO was the first product created by Team BoxyHQ — pioneering their vision for enterprise readiness. (Launched on August 4, 2022)&lt;/p&gt;

&lt;p&gt;SAML: Security Assertion Markup Language SSO: Single Sign-on&lt;/p&gt;

&lt;h4&gt;
  
  
  What does it do?​
&lt;/h4&gt;

&lt;p&gt;It offers an out-of-the-box solution for deploying SAML quickly and efficiently — helping your &amp;lt;!-- --&amp;gt;*&amp;lt;!-- --&amp;gt;enterprise customers manage access controls on their systems.&lt;/p&gt;

&lt;h4&gt;
  
  
  How does it work?​
&lt;/h4&gt;

&lt;p&gt;Just connect your product to BoxyHQ and everything else is managed for you!&lt;/p&gt;

&lt;p&gt;BoxyHQ connects to almost every identity providers for you to go from the first line of code to fully support SAML in just a week!&lt;/p&gt;

&lt;h3&gt;
  
  
  What are its benefits?​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--7KvRtlbi--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal2-f78e4a630ae5627b897db98d565478dc.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--7KvRtlbi--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal2-f78e4a630ae5627b897db98d565478dc.jpeg" alt="Admin Portal" width="800" height="520"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  Centralized management and increased security 🔒​
&lt;/h4&gt;

&lt;p&gt;Enable your customers to manage access control on their own systems so they can:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Have the right access&lt;/li&gt;
&lt;li&gt;Prevent password sharing&lt;/li&gt;
&lt;li&gt;Easily grant and revoke access as needed&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  Better user experience ✨​
&lt;/h4&gt;

&lt;p&gt;Just need to log in once to access all the external services on a dashboard with a single click. It’s simple and easy to use.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Saves users’ time&lt;/li&gt;
&lt;li&gt;Improves your product’s UX&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  Reduces cost​s💲​
&lt;/h4&gt;

&lt;p&gt;All the account information is maintained and managed by the IdP vs. multiple services. This helps in saving costs.&lt;/p&gt;

&lt;p&gt;(IdP is the identity provider — the single point that let its users access all the services from it)&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“The idea behind SAML SSO is that by centralizing your access to an external system you can better manage access and permission as well as improve security.”&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;em&gt;Aswin Venugopal, Senior Software Engineer&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  TL;DR​
&lt;/h3&gt;

&lt;h4&gt;
  
  
  Without BoxyHQ’s SAML SSO, on the user side 😔​
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--RdQ4VPkw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection-475fb944937992f866738af225e20f43.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--RdQ4VPkw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection-475fb944937992f866738af225e20f43.webp" alt="SSO connection without BoxyHQ" width="800" height="419"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Without BoxyHQ&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Spend a long time to build a SAML integration&lt;/li&gt;
&lt;li&gt;Create integrations for each of your customer’s identity providers (IdP)&lt;/li&gt;
&lt;li&gt;Spend time, energy, focus, and resources away from your core product&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  With BoxyHQ’S SAML SSO authentication 🤠​
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--zxdlayYB--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection2-9393b0b3ae889c41d3c5e1ff026b3e16.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--zxdlayYB--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection2-9393b0b3ae889c41d3c5e1ff026b3e16.webp" alt="SSO connection with BoxyHQ" width="800" height="419"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;With BoxyHQ&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Centralize management&lt;/li&gt;
&lt;li&gt;Improve security&lt;/li&gt;
&lt;li&gt;Enhance user experience&lt;/li&gt;
&lt;li&gt;Increase productivity&lt;/li&gt;
&lt;li&gt;Save time, reduce costs&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  On the solution provider’s side, it looks like:​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--3h_W3Bzw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection3-728f29eee05af16861f16fa466eb7fc9.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--3h_W3Bzw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection3-728f29eee05af16861f16fa466eb7fc9.webp" alt="SSO connection without BoxyHQ" width="800" height="505"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Without BoxyHQ&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--S9Yoa287--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection4-fe896577d90c12df0c18b1661c5d7daa.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--S9Yoa287--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-sso-connection4-fe896577d90c12df0c18b1661c5d7daa.webp" alt="SSO connection with BoxyHQ" width="800" height="505"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;With BoxyHQ&lt;/p&gt;

&lt;p&gt;Here, you only have to connect your product with a direct integration to BoxyHQ and then it manages and connects you to all the IDPs. You can deploy SAML SSO with just a few lines of code!&lt;/p&gt;

&lt;p&gt;🔗 The sources are linked &lt;a href="https://boxyhq.com/blog/understanding-saml-sso-the-basics-from-the-user-side"&gt;here&lt;/a&gt; and &lt;a href="https://boxyhq.com/blog/understanding-saml-sso-the-basics-from-the-solution-providers-side"&gt;here&lt;/a&gt; (official BoxyHQ blogs)&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“Deepak (Co-Founder) himself helped us implement SSO SAML in cal.com and we’re more than happy about it! it’s great to finally see an open source project tackle enterprise-ready features!”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;— Peer Richelsen, Co-Founder at Cal.com&lt;/p&gt;

&lt;p&gt;Note: Team BoxyHQ recently re-launched the enhanced &lt;a href="https://www.producthunt.com/products/boxyhq#open-source-saml-sso-by-boxyhq-2"&gt;SAML SSO on Product Hunt&lt;/a&gt;! 🚀&lt;/p&gt;

&lt;h3&gt;
  
  
  2. Open Source Directory Sync​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--NjJRdu8c--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-ds-connection-6aa258ce3f0bc3811ca69fd8161c8c46.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--NjJRdu8c--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-ds-connection-6aa258ce3f0bc3811ca69fd8161c8c46.webp" alt="Directory Sync Connection" width="800" height="344"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Organizations use directories from different providers to manage user access to organization resources.&lt;/p&gt;

&lt;p&gt;BoxyHQ’s Directory Sync lets orgs activate and deactivate user accounts, create groups, and keep their app in sync with the user directory in real time.&lt;/p&gt;

&lt;p&gt;💡 &lt;em&gt;In an enterprise customer context, a directory is a central repository that holds information about employees, customers, and other resources in a company.&lt;/em&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  In simple words, you enable your customers to:​
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Have higher security standards&lt;/li&gt;
&lt;li&gt;Centrally manage their user’s access lifecycle&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It supports the SCIM 2.0 protocol&lt;/p&gt;

&lt;p&gt;SCIM: System for Cross-domain Identity Management&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“Directory Sync streamlines the user lifecycle management process by saving valuable organizational hours, creating a single truth source of the user identity data, and facilitating them to keep the data secure.”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;-&lt;em&gt;BoxyHQ Official Docs&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Learn more: &lt;a href="https://boxyhq.com/docs/directory-sync/examples"&gt;Examples &amp;amp; Resources (Directory Sync)&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Open Source Audit Logs​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--ItpKZXMR--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-audit-logs-8ebf5892b1fdadffb31f65832b12c33e.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--ItpKZXMR--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-audit-logs-8ebf5892b1fdadffb31f65832b12c33e.webp" alt="Open Source Audit Logs" width="800" height="588"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;BoxyHQ’s Audit Logs ‘Retraced’ offer your enterprise customers the ability to record and search events that happen on your application.&lt;/p&gt;

&lt;p&gt;Note: Retraced was initially built by Replicated and has been enhanced by BoxyHQ.&lt;/p&gt;

&lt;p&gt;They provide a detailed record of user actions, and can be used to monitor potential security breaches, compliance violations, and other issues.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“The world’s best SaaS companies offer detailed Audit Logs, your SaaS should too as you move into serving the enterprise segment.”&lt;/em&gt; -&lt;em&gt;Vanshika Srivastava&lt;/em&gt;&lt;/p&gt;

&lt;h4&gt;
  
  
  Why are Audit Logs important?​
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--Nubp3iqN--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-audit-logs2-7c8816f7d05ce34b4feb6b0c677def0a.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--Nubp3iqN--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-audit-logs2-7c8816f7d05ce34b4feb6b0c677def0a.jpeg" alt="Open Source Audit Logs2" width="800" height="462"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;For most companies, the ability to monitor the flow of data and be alerted to any breaches is super essential.&lt;/p&gt;

&lt;p&gt;Audit logs help to pinpoint any misuse of information and ensure that data policies are followed ✅&lt;/p&gt;

&lt;p&gt;This one simple API helps you become compliant fast, and ensure your customers get all the functionality and safety they need.&lt;/p&gt;

&lt;h3&gt;
  
  
  4. Admin Portal​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--CIbQBUWs--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal3-b148491eef73ed45f92dce5cf1d5f995.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--CIbQBUWs--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal3-b148491eef73ed45f92dce5cf1d5f995.jpeg" alt="Admin Portal3" width="800" height="441"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Manage Enterprise SSO, Directory Sync, and Audit Logs products via an easy-to-use web interface.&lt;/p&gt;

&lt;p&gt;It can help you streamline your workflows and increase productivity.&lt;/p&gt;

&lt;p&gt;You can use the authentication method of your choice (Magic Link, Email and Passsword, SAML/OIDC Single-sign-on)&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--4Te4SGO7--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal4-75a7906e4c1bc97e12151ab78310cfeb.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--4Te4SGO7--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-admin-portal4-75a7906e4c1bc97e12151ab78310cfeb.jpeg" alt="Admin Portal4" width="800" height="446"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;BoxyHQ’s future products (where relevant) will also be available in the Admin Portal.&lt;/p&gt;

&lt;p&gt;To enable the Admin Portal, you need to deploy &lt;a href="https://boxyhq.com/docs/jackson/deploy/service"&gt;Jackson as a service&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  5. Data Privacy Vault​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--OxRmVREw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-privacy-vault-81d1c7995e501eaba4b63668ac8d5e43.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--OxRmVREw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-privacy-vault-81d1c7995e501eaba4b63668ac8d5e43.webp" alt="Privacy Vault" width="800" height="369"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In the day and age of high cyber-crime, and increasingly sensitive data– you need to protect your customer’s data &lt;em&gt;and&lt;/em&gt; trust.&lt;/p&gt;

&lt;p&gt;Privacy vault is BoxyHQ’s open-source solution to centralize, isolate, and govern all the sensitive data you collect.&lt;/p&gt;

&lt;h4&gt;
  
  
  With the Privacy Vault, you can:​
&lt;/h4&gt;

&lt;ul&gt;
&lt;li&gt;Identify all the sensitive data from clients’ application database and move it to the vault.&lt;/li&gt;
&lt;li&gt;Replace the sensitive data in their application database with (exchangeable) opaque tokens.&lt;/li&gt;
&lt;li&gt;Gain control over where the sensitive data goes, who has access to it and for what duration.&lt;/li&gt;
&lt;li&gt;Create access policies that adhere to data regulations and geographic regulations.&lt;/li&gt;
&lt;li&gt;Get the ability to respond to DSRs (Data Subject Requests) from customers.&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  What users are saying 💬​
&lt;/h4&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--WXv8OKHd--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-calcom-8630ca3cd90c4211f24b1f301b3f0dc8.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--WXv8OKHd--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-calcom-8630ca3cd90c4211f24b1f301b3f0dc8.webp" alt="Cal.com" width="800" height="428"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“It let our team focus on what we do best (democratizing scheduling for everyone) without getting distracted by the needs of our enterprise customers. Did I mention it’s open-source and free?”&lt;/em&gt;&lt;br&gt;
 &lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--DsVcO5jH--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/img/blog/scoutflo-blog-supertokens.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--DsVcO5jH--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/img/blog/scoutflo-blog-supertokens.webp" alt="" width="400" height="400"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Super Tokens — An open-source authentication solution&lt;/p&gt;

&lt;p&gt;&lt;em&gt;“We at SuperTokens needed to provide SAML login to our users, and instead of building it from scratch, we found the perfect open source project — BoxyHQ!”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--k8XkMsju--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-news-b56814dbbbea5f26ad6eca1c8d1a06d7.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--k8XkMsju--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-news-b56814dbbbea5f26ad6eca1c8d1a06d7.webp" alt="News" width="800" height="252"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Media Features&lt;/p&gt;

&lt;h3&gt;
  
  
  Meet the Founders ✨​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--BeLVCsLl--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-founders-deepak-17432483315ecac8ac2a6f80e89fc80f.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--BeLVCsLl--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-founders-deepak-17432483315ecac8ac2a6f80e89fc80f.webp" alt="Founders - Deepak" width="800" height="777"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Deepak Prabhakara, CEO &amp;amp; Co-founder&lt;/p&gt;

&lt;p&gt;&lt;a href="https://twitter.com/deepakprab"&gt;Deepak&lt;/a&gt; has over 2 decades of experience in design, architecture and development of complex software products across different SaaS and mobile platforms.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--Exi8T7GP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-founders-sama-8ccb70c6cdd901b54872e2fbe6899f84.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--Exi8T7GP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-founders-sama-8ccb70c6cdd901b54872e2fbe6899f84.webp" alt="Founders - Sama" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://twitter.com/caloique"&gt;Sama&lt;/a&gt; has 15+ years of experience working at tech companies across different business areas and continents.&lt;/p&gt;

&lt;h3&gt;
  
  
  The BoxyHQ Pledge 📜​
&lt;/h3&gt;

&lt;p&gt;&lt;em&gt;“As long-time users and contributors to the open-source ecosystem, we want to do the right thing for the community. That means we will make sure that our core open-source code stays open. We will also strive to use open standards where possible. We want to collaborate with the community to build towards our vision to make security, compliance and privacy easy for developers so they can focus on their core product while being compliant...”&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Learn more here: &lt;a href="https://boxyhq.com/pledge"&gt;BoxyHQ pledges to keep our core open-source code open&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  What’s Next for BoxyHQ 🚀​
&lt;/h3&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--NkD_0Rfh--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-features-c29a80a484e382b2d08e43e3b2f6f0af.webp" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--NkD_0Rfh--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/scoutflo-blog-features-c29a80a484e382b2d08e43e3b2f6f0af.webp" alt="Features" width="800" height="487"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;You can &lt;a href="https://boxyhq.com/saas-registration"&gt;sign up for the waitlist&lt;/a&gt; before August 1, and make the most of this limited-time offer.&lt;/p&gt;

&lt;p&gt;Check out BoxyHQ’s &lt;a href="https://github.com/boxyhq"&gt;GitHub page&lt;/a&gt;, official &lt;a href="https://boxyhq.com/docs"&gt;documentation&lt;/a&gt;, and &lt;a href="https://twitter.com/boxyhq"&gt;Twitter&lt;/a&gt; profile. 🚀&lt;/p&gt;

&lt;p&gt;And don’t forget to follow &lt;a href="https://atlas-home.scoutflo.com/?ref=blog.scoutflo.com"&gt;Scoutflo&lt;/a&gt; on &lt;a href="https://twitter.com/scout_flo?ref=blog.scoutflo.com"&gt;Twitter&lt;/a&gt; if you haven’t already! ✨&lt;/p&gt;

&lt;p&gt;We’re also active on LinkedIn 💙&lt;/p&gt;

&lt;p&gt;Cover photo by &lt;a href="https://unsplash.com/@danny144?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Dan Nelson&lt;/a&gt; on &lt;a href="https://unsplash.com/photos/ah-HeguOe9k?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Unsplash&lt;/a&gt;&lt;/p&gt;

</description>
      <category>enterprise</category>
      <category>security</category>
    </item>
    <item>
      <title>The new era of Application Security: Security Building Blocks for Developers</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Mon, 10 Jul 2023 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/the-new-era-of-application-security-security-building-blocks-for-developers-5din</link>
      <guid>https://forem.com/boxyhq/the-new-era-of-application-security-security-building-blocks-for-developers-5din</guid>
      <description>&lt;h2&gt;
  
  
  The new era of Application Security: Security Building Blocks for Developers​
&lt;/h2&gt;

&lt;p&gt;With the proliferation of data breaches and cyber-attacks, developers must take a proactive approach to security. BoxyHQ's Security Building Blocks for Developers are designed to help developers build and deploy secure applications with minimal effort and expertise.&lt;/p&gt;

&lt;p&gt;In addition to their core products security teams are finding it hard to keep pace with new no-code and low-code apps that are being created in the company. The arrival of Generative AI and ChatGPT has complicated the landscape even further.&lt;/p&gt;

&lt;p&gt;The importance of integrating robust security measures into software applications cannot be overstated. BoxyHQ, a security-focused platform for developers, is leading the way with its Security Building Blocks for Developers, inspired by the concept of &lt;a href="https://mvsp.dev/mvsp.en/"&gt;Minimum Viable Security&lt;/a&gt; (MVS) championed by &lt;a href="https://mvsp.dev"&gt;mvsp.dev&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;BoxyHQ is set to revolutionize application security. Drawing insights from industry pioneers such as Twilio, Stripe, HashiCorp, and Snyk, BoxyHQ's open-source Security Building Blocks offer a comprehensive solution that empowers developers to build secure software products with ease and efficiency.&lt;/p&gt;

&lt;h2&gt;
  
  
  Building and Shipping Secure Software Products in Hours, Not Months​
&lt;/h2&gt;

&lt;p&gt;Building and shipping security features in hours instead of months is now a reality. In the fast-paced world of software development, time is of the essence. Traditional approaches to security often involve time-consuming and complex implementations. However, by embracing BoxyHQ's Security Building Blocks, developers can now build and ship secure software products in a fraction of the time it would take to develop these features from scratch. This not only saves valuable time but also accelerates time-to-market, giving businesses a competitive edge.&lt;/p&gt;

&lt;h2&gt;
  
  
  Democratizing Secure Development: Making Security Accessible to All​
&lt;/h2&gt;

&lt;p&gt;The developer community has long embraced the open-source movement. Open-source software fosters collaboration, innovation, and rapid evolution. By offering Security Building Blocks as open-source projects, BoxyHQ empowers developers to contribute, customize, and tailor security features to suit their specific needs. This flexibility not only enables developers to address unique requirements but also creates an ecosystem where best practices and security advancements are shared, benefiting the entire community. We hypothesize that in the future many of these security features will be a commodity, and will be implemented by any software product, not just the ones that need to be enterprise-grade.&lt;/p&gt;

&lt;h2&gt;
  
  
  Minimum Viable Security (MVS): Building a Strong Foundation​
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--M_F8PNC8--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/purple-building-blocks-8ea95b3166a7dea1ad63c19b72820f3f.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--M_F8PNC8--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/purple-building-blocks-8ea95b3166a7dea1ad63c19b72820f3f.jpg" alt="Security Building Blocks" width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Photo by &lt;a href="https://unsplash.com/@theshubhamdhage?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Shubham Dhage&lt;/a&gt; on &lt;a href="https://unsplash.com/?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Unsplash&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Minimum Viable Security (MVS) is a concept focused on identifying and implementing the essential security measures necessary to protect an application from common threats. BoxyHQ embraces the principles of MVS and provides developers with Security Building Blocks that address these foundational security needs. By adopting an MVS approach, developers can prioritize the integration of critical security features, ensuring a solid foundation for their applications while minimizing unnecessary complexity and overhead.&lt;/p&gt;

&lt;h2&gt;
  
  
  Comprehensive Integration: Uniting Security Features for Maximum Effectiveness​
&lt;/h2&gt;

&lt;p&gt;BoxyHQ's Security Building Blocks integrate multiple security components, each designed to address a specific aspect of application security. By combining these features, developers can create a comprehensive security framework for their applications. Whether it's the secure authentication facilitated by the Enterprise Single Sign-On (SSO) product, the real-time synchronization provided by Directory Sync, the compliant logs generated by Audit Logs (Retraced), or the encrypted storage capabilities of the Data Privacy Vault (PII, PCI, PHI compliant), these components seamlessly work together to strengthen the overall security posture of applications.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing the Gap Between Compliance and Security​
&lt;/h2&gt;

&lt;p&gt;One of the key advantages of BoxyHQ is its ability to bridge the gap between compliance and security. With the increasing focus on cybersecurity vulnerabilities, compliance alone is not sufficient to protect against threats. BoxyHQ's comprehensive suite of open-source security components ensures that developers can not only meet compliance requirements but also implement robust security measures. By integrating these building blocks, businesses can confidently navigate the complex landscape of security and compliance, safeguarding their data and systems while staying ahead of potential threats. Aligned with this vision we consolidated a list of free &lt;a href="https://github.com/boxyhq/awesome-oss-devsec"&gt;awesome open-source developer-first security tools&lt;/a&gt; that includes security principles and controls relevant to popular compliance certifications. (like ISO27001, SOC2, MVSP, etc)&lt;/p&gt;

&lt;p&gt;The security building blocks for developers are supported by extensive documentation, an admin portal for easy management, and customer support and advice for each customer's unique needs. BoxyHQ's products represent a significant step forward for developers looking to improve the security of their applications.&lt;/p&gt;

&lt;p&gt;In conclusion, BoxyHQ aims to make a significant impact on the industry. By providing simple and efficient integrations for minimum viable security features, BoxyHQ is helping to ensure that developers and businesses of all sizes can protect their sensitive data and systems against threats, ultimately making the internet a safer place for everyone.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>SSO "Wall of Shame" vs "Wall of Fame"</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Thu, 30 Mar 2023 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/sso-wall-of-shame-vs-wall-of-fame-4609</link>
      <guid>https://forem.com/boxyhq/sso-wall-of-shame-vs-wall-of-fame-4609</guid>
      <description>&lt;p&gt;Unless you have been living under a rock, you have probably heard of the SSO Wall of Shame. This is a list of vendors that treat single sign-on as a luxury feature, not a core security requirement. There have been numerous complaints regarding the companies that have made it onto this list, and rightfully so. In a downturn economy and in times when security and privacy are critical, many organizations see an opportunity to generate even more revenue.&lt;/p&gt;

&lt;p&gt;This is a small example, listed in alphabetical order of some of the most well-known companies that have ended up on the “Wall of Shame” (see the screenshot below). You can find more information and the full list at &lt;a href="https://sso.tax"&gt;sso.tax&lt;/a&gt;. It is clear that raising prices for enterprise SSO and other security features, such as Audit Logs (to track critical events), is just part of their revenue model.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--qemHBq53--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/sso-tax-list-b0ccee4c71a8d09fad40792e3739a5b9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--qemHBq53--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/sso-tax-list-b0ccee4c71a8d09fad40792e3739a5b9.png" alt="sso tax list" width="800" height="866"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;But is this the right thing to do? It’s hard to judge from the outside, and clearly companies need to make a profit while showing growth, especially when you are backed by Venture Capital. Having said that, at BoxyHQ we believe that we can all do better (we are also Venture funded). Nonetheless, cybersecurity taxes should stop, and we should all focus on increasing our security posture and making a positive impact. Take for example, Hubspot charging 6300% more for SSO functionality! That is a clear example of how absurd and abusive some companies can be.&lt;/p&gt;

&lt;p&gt;Now, we ask ourselves, how about the “Wall of Fame”? This is a separate list of companies that lead by example and don’t take advantage of their customer base. If you do a quick search, you will find some interesting companies listed. Grafana, Cal.com, and Sumo Logic, just to name a few.&lt;/p&gt;

&lt;p&gt;To understand why startups normally lean this way, it’s important to consider the enterprise deal process. With RFPs, security questionnaires, and other compliance-related procedures, closing an enterprise deal becomes all-consuming for a startup. This can justify an enterprise pricing tier. Given a startups early evolution of products, , Enterprise SSO becomes an easy candidate to distinguish the pricing tier gap between charging SMBs and what they can charge enterprises. But building and maintaining SSO is expensive and time-consuming. SAML is not necessarily the easiest protocol implementation to get right. And add to this the customer support issues that come with onboarding large enterprise teams onto the product. But as a startup matures the product needs to have enough core enterprise features and not merely depend on undifferentiated features like SSO.&lt;/p&gt;

&lt;p&gt;To take it full circle, it would be nice to see a full list of the SSO Wall of Fame. Then we could ensure support for the companies with integrity, who have clearly not been overtaken by greed. Unfortunately because of our bandwidth, we can not commit to full ownership of this initiative, but can offer some practical advice on how companies could start offering SSO pricing tiers for free or at a nominal price increase:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Charge for other core enterprise features instead of SSO. If your product is not quite to that level of maturity, please read on.&lt;/li&gt;
&lt;li&gt;Instead of charging for SSO, charge for the security process’s that comes with enterprise deals. If a company wants you to go through its security and compliance process, rather pay a premium to enhance its security posture and reduce compliance risk from its vendors.&lt;/li&gt;
&lt;li&gt;If that scenario isn’t possible then consider segmenting SSO pricing based on the number of users or seats. SMBs will not have a very large number of seats so this could be a possible way to separate your pricing.&lt;/li&gt;
&lt;li&gt;If your Enterprise tier is not based on seats, a natural progression is to base pricing on usage.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We are trying to do our part by providing a free open–source enterprise-grade SSO (called SAML Jackson), that any developer, team, or organization can plug into with just a few lines of code. Check out the GitHub repo &lt;a href="https://github.com/boxyhq/jackson"&gt;here&lt;/a&gt;. Feedback is much appreciated and a star will help us raise security awareness. 🙂&lt;/p&gt;

&lt;p&gt;Stay safe, do good, and avoid the dark side of the SSO tax!&lt;/p&gt;

</description>
      <category>sso</category>
      <category>enterprise</category>
    </item>
    <item>
      <title>Exploring the open-source business model and how companies monetize it</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/exploring-the-open-source-business-model-and-how-companies-monetize-it-2hai</link>
      <guid>https://forem.com/boxyhq/exploring-the-open-source-business-model-and-how-companies-monetize-it-2hai</guid>
      <description>&lt;p&gt;With the rise of open-source solutions and solution providers, one of the biggest questions asked is, how do businesses monetize while giving away the source code for free?&lt;/p&gt;

&lt;h2&gt;
  
  
  What is an open-source company?​
&lt;/h2&gt;

&lt;p&gt;An open-source company is an organization that develops software but makes the source code freely available to the public. This means that others can copy the code and engine, deploy it themselves, develop it, fix bugs and more. This allows the software not only to be widely accessible for free but also to evolve in a very collaborative way.&lt;/p&gt;

&lt;h2&gt;
  
  
  If everything is free then how can it be monetized?​
&lt;/h2&gt;

&lt;p&gt;We don't have to look very far to find examples of open-source companies that have become unicorns and continue to grow. Some great examples are Elastic ($608 million in revenue, 2021), HashiCorp ($320 million in revenue, 2021), and RedHat ($3.4 billion in revenue, 2021). All these companies operate an open-source business model but have huge revenues and valuations. This is what we are going to look at.&lt;/p&gt;

&lt;p&gt;There are many different ways that open-source companies can monetize - ultimately this comes down to the goals of the business. We are going to explore a few of the options available but keep in mind that these are just some of the ways it can be done and open-source continues to develop and grow at a rapid pace.&lt;/p&gt;

&lt;h3&gt;
  
  
  Donations​
&lt;/h3&gt;

&lt;p&gt;One of the most popular models is to offer the source code and documentation completely free and let its users donate at their discretion. This is normally done for smaller projects and donations can be solicited in various ways, such as a button on the website, a link in a newsletter, a Github donation, or one that I like - buymeacoffee.com. The latter allows you to embed an option into your website or interface and donate at the value of a coffee. Although donations are a great way to monetize some projects, this method is not feasible for bigger companies that have complex solutions and large overheads.&lt;/p&gt;

&lt;h3&gt;
  
  
  Support​
&lt;/h3&gt;

&lt;p&gt;Paid Support or Premium Care, as it’s commonly termed, is a very common business model that has done very well for larger commercial companies. This model allows users to still access the code and deploy it for free but also enables an option for companies/users to pay for additional support. This monetized plan often includes perks such as help deploying the software, customization and ongoing support for general use. Just because the source code of a project is open, it doesn’t mean it's easy to deploy or manage. This is where companies such as Red Hat have been successful and use this particular model to great effect.&lt;/p&gt;

&lt;p&gt;The benefits of this model are, as Red Hat has demonstrated, you can build a revenue-generating company that can be scaled effectively. The drawback is, some companies only make the open-source code available with a paid plan, which goes against the open-source ethos. To truly use this model effectively, companies should offer the source code for free regardless of an option for additional support.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--LEg16us9--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/christine-roy-ir5MHI6rPg0-unsplash-e0d643aefffdf762ebac0aa4c8f5d78e.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--LEg16us9--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://boxyhq.com/assets/images/christine-roy-ir5MHI6rPg0-unsplash-e0d643aefffdf762ebac0aa4c8f5d78e.jpg" alt="OSS Monetization" width="640" height="428"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Photo by &lt;a href="https://unsplash.com/fr/@agent_illustrateur?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Christine Roy&lt;/a&gt; on &lt;a href="https://unsplash.com/images/things/money?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Unsplash&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Licensing​
&lt;/h3&gt;

&lt;p&gt;Open-source companies can also license their open-source software, which applies rules to how their software can be used, edited, distributed and copied. Some open-source companies will allow individuals and smaller organizations to use their software for free while charging larger companies a fee to deploy it. Normally a license fee comes with additional benefits, such as support and training, etc. There are also two main types of licensing that open-source companies can utilize.&lt;/p&gt;

&lt;p&gt;-Copyleft license This is a type of license in which, if code is copied and modified it still retains the original license terms&lt;/p&gt;

&lt;p&gt;-Permissive license This grants licenses based on different needs and is much more diverse.&lt;/p&gt;

&lt;p&gt;Licensing and open-source licensing is a huge topic in itself and Snyk has done a fantastic job at explaining this. You can read more about it here.&lt;/p&gt;

&lt;h3&gt;
  
  
  Cloud-hosted Services​
&lt;/h3&gt;

&lt;p&gt;Finally, the last model we will look at is hosting. While open-source organizations can still offer their code for free, some may offer a hosted version which is much easier to set up and maintain. This means customers can effectively use their product like any other SaaS and they typically charge on a subscription basis.&lt;/p&gt;

&lt;p&gt;The hosted model is very popular as it now allows quick deployment but also reduces the level of maintenance and custom work developers need to carry out. The main limitation of offering a hosted model is, it will require the open-source company to offer web hosting and everything that goes along with it. This can require an enormous amount of maintenance and development.&lt;/p&gt;

&lt;h3&gt;
  
  
  The open-core model​
&lt;/h3&gt;

&lt;p&gt;The open core model is when a company releases the core software for anyone to use but then also controls things such as the roadmap and what commits are accepted into it. By doing this, the company can also charge for extra features which customers may want. Some examples could be functionality features or even security/compliance modules. This model has been very popular with open-source companies and is widely seen as a very fair way to operate. It is also very important to make sure that the open-core has enough value that developers will rally around the product from the get-go. Companies that offer very little value from the free version and charge for additional features, do not see great traction in the open-source community.&lt;/p&gt;

&lt;h2&gt;
  
  
  Controversial opinion​
&lt;/h2&gt;

&lt;p&gt;I personally believe that OSS is not a business model but a development model. We are debating this internally, so we would love to hear your feedback and opinions on this subject.&lt;/p&gt;

&lt;h2&gt;
  
  
  Summary​
&lt;/h2&gt;

&lt;p&gt;Although open-source code is widely free and available to use, it has become a popular choice for companies who also want to commercialize. The benefits of open-source are vast and with the variety of business models we discussed you can understand the various options to create a successful, revenue-generating business.&lt;/p&gt;

</description>
      <category>opensource</category>
    </item>
    <item>
      <title>Why does your SaaS application need audit logs?</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Wed, 18 Jan 2023 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/why-does-your-saas-application-need-audit-logs-2hm7</link>
      <guid>https://forem.com/boxyhq/why-does-your-saas-application-need-audit-logs-2hm7</guid>
      <description>&lt;p&gt;Audit logs are an important tool for keeping track of activity within your SaaS application. These logs provide a detailed record of the actions taken by users and can be used to monitor for potential security breaches, compliance violations, and other issues. Let’s explore some of the key reasons why you need audit logs for your SaaS app.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Compliance:&lt;/strong&gt; Many industries are subject to strict regulations that require organizations to maintain detailed records of their activities. Audit logs can be used to demonstrate compliance with these regulations, and to provide evidence in the event of an audit or investigation.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Cyber Insurance:&lt;/strong&gt; Obtaining cyber insurance usually comes with requirements around recording and retaining audit logs. These logs help with forensics during insurance claims, otherwise making investigation expensive and time-consuming for both insurers and the affected companies.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Security:&lt;/strong&gt; Audit logs can be used to detect and prevent security breaches. By monitoring for suspicious activity, such as repeated failed login attempts or changes to sensitive data, you can quickly identify and respond to potential threats. Additionally, audit logs can be used to reconstruct the events leading up to a security incident, which can help you identify the cause and prevent similar incidents in the future.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Accountability:&lt;/strong&gt; Audit logs make it possible to track the actions of individual users, which can be useful for identifying issues such as data breaches, compliance violations, and other problems. This information can be used to hold users accountable for their actions and to help you identify and address any issues that arise.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Troubleshooting:&lt;/strong&gt; Audit logs can be used to identify and diagnose issues that occur within your SaaS application. By reviewing the logs, you can see exactly what happened when a problem occurred, which can help you quickly identify the root cause and develop a solution.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Auditing:&lt;/strong&gt; Audit logs provide a record of the activities that occur within your SaaS application, which can be useful for internal audits. This information can be used to assess the effectiveness of your security controls and identify areas for improvement.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--Gt0AmDxo--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/audit-logs-widget-4a5818eebf50ad4d8229bbd3684e6667.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--Gt0AmDxo--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/audit-logs-widget-4a5818eebf50ad4d8229bbd3684e6667.png" alt="Audit Logs" width="880" height="681"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Audit logs are a powerful tool that can be used to improve the security, compliance, and overall performance of your SaaS application. By keeping detailed records of user activity, you can monitor for potential issues and quickly respond to problems as they arise. If your SaaS app doesn't have audit logs, you should consider implementing them as soon as possible to ensure the safety and security of your data and users. It is also becoming an important part of enterprise readiness.&lt;/p&gt;

&lt;h2&gt;
  
  
  Introducing our Audit Logs product​
&lt;/h2&gt;

&lt;p&gt;We are extremely thrilled to introduce our new Audit Logs product in collaboration with our friends at &lt;a href="https://replicated.com"&gt;Replicated&lt;/a&gt;. Retraced is a fully open-source audit log service that comes with an embeddable UI that's easily deployed to an infrastructure of your choice. We have spent years building and fine-tuning audit logs systems and think we have finally discovered an optimal solution to this nagging problem.&lt;/p&gt;

&lt;p&gt;It’s yet another important enterprise readiness feature to tick as you scale your offerings to the enterprise segment and complements our Enterprise SSO and Directory Sync products to give you a one-stop solution. Come check out the product at our &lt;a href="https://github.com/retracedhq/retraced"&gt;Github repo&lt;/a&gt;, we’d love to hear your feedback.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>The impact of open source on cybersecurity</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Mon, 14 Nov 2022 16:10:02 +0000</pubDate>
      <link>https://forem.com/deepakprab/the-impact-of-open-source-on-cybersecurity-g4i</link>
      <guid>https://forem.com/deepakprab/the-impact-of-open-source-on-cybersecurity-g4i</guid>
      <description>&lt;p&gt;Hey community, I’m trying to research the use of open-source components in the security space and figured this would be the best place to start.&lt;/p&gt;

&lt;p&gt;Had a few questions that I wanted to ask&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;What is your process for approving an open-source solution?&lt;/li&gt;
&lt;li&gt;Does your company secure it’s SDLC (software development life cycle)?&lt;/li&gt;
&lt;li&gt;What tools do you use to keep your SDLC secure?&lt;/li&gt;
&lt;li&gt;In your opinion, what are the biggest pros and cons of using open-source tools in cybersecurity?
Appreciate your time.&lt;/li&gt;
&lt;/ol&gt;

</description>
      <category>discuss</category>
      <category>cybersecurity</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>How low-code solutions are changing how we build products and workflows</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Tue, 25 Oct 2022 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/how-low-code-solutions-are-changing-how-we-build-products-and-workflows-2dk0</link>
      <guid>https://forem.com/boxyhq/how-low-code-solutions-are-changing-how-we-build-products-and-workflows-2dk0</guid>
      <description>&lt;p&gt;We have all heard the terms low-code or no-code being thrown around as buzzwords over the last few years but what does this mean and how is it changing the way businesses and individuals solve problems? I am going to use our product SAML Jackson to explain how low-code solutions are changing the way we build products.&lt;/p&gt;

&lt;p&gt;Low-code solutions are essentially products that provide you with building blocks so instead of building a solution from scratch you can simply combine the relevant building blocks to make a relevant solution for your business. Let’s take BoxyHQ and our SAML Jackson product as an example. Without the low-code product (SAML Jackson) the alternative for businesses would be to build a custom SAML integration which takes months and a ton of resources. This sounds ridiculous tho right? With the number of businesses who are deploying SAML for their customer, there must be some reusable parts that can be shared to reduce the time it takes each business. This is where low-code products like SAML Jackson come in. By building the SAML integrations as a reusable component, businesses only need to create one simple connection to the SAML Jackson to deploy SAML.&lt;/p&gt;

&lt;p&gt;Still with me? If not, don't worry. Essentially what low-code is taking advantage of is building in a way that can be shared so the amount of custom building is limited (or low) for common use cases.&lt;/p&gt;

&lt;h2&gt;
  
  
  So what is the difference between low-code and no-code?​
&lt;/h2&gt;

&lt;p&gt;Well while a lot of people would still group them together, the obvious difference is that low-code still needs some code to integrate the building blocks, whereas no-code doesn't. If we look at a product like Zapier for example, that requires no code at all and a non-technical person can use visual blocks to connect different data sources and outputs to build workflows. An example of this is as a non-technical person I can take data from forms such as Hubspot forms that are submitted on our website and create notifications for the team on Slack. Doing all of this without code and just using Zapier is what makes this a no-code solution.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why is low-code so important?​
&lt;/h2&gt;

&lt;p&gt;Lastly, let's take a quick look at the main benefits of having solid DevSecOps in place&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Speed speed speed&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Cost&lt;/strong&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--zBXfo8u1--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/lowcode-graph-e2965961a7d07cabf4bccc712e8accdd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--zBXfo8u1--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/lowcode-graph-e2965961a7d07cabf4bccc712e8accdd.png" alt="DevSecOps" width="640" height="427"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Are there any negatives to using low-code and no-code platforms?​
&lt;/h2&gt;

&lt;p&gt;The only main negative of these solutions I have identified is that because of the ease and speed of the platforms it can create a lack of transparency and some shadow IT as lots of people in the organization can be building solutions and data can be moving around without accountability. However, with the right IT processes and policies in place, this can be easily fixed.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why are we so excited about low-code and no-code?​
&lt;/h2&gt;

&lt;p&gt;We are very excited about low-code solutions because it drives innovation! We at BoxyHQ are building low-code solutions for enterprises to implement the important but standard features they need to be competitive and compliant with ease so they can focus on what they do best which is innovate. We have some great clients already and can’t wait to see what they do next without the hassle of building standard features such as SSO and Directory Sync.&lt;/p&gt;

</description>
      <category>lowcode</category>
      <category>nocode</category>
      <category>speedofdevelopment</category>
    </item>
    <item>
      <title>Developer-first Security sucks! Why it is essential to automate product security?</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Tue, 26 Jul 2022 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/developer-first-security-sucks-why-it-is-essential-to-automate-product-security-20p4</link>
      <guid>https://forem.com/boxyhq/developer-first-security-sucks-why-it-is-essential-to-automate-product-security-20p4</guid>
      <description>&lt;p&gt;Let’s start with some facts to understand why it sucks!&lt;/p&gt;

&lt;p&gt;On one hand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cybercrime went up 600% due to the COVID-19 Pandemic&lt;/li&gt;
&lt;li&gt;Data breaches and cyber attacks in 2021 were 5.1 billion breached records, this is 11% more than in 2020&lt;/li&gt;
&lt;li&gt;79% of companies have experienced at least one cloud data breach in the past 18 months&lt;/li&gt;
&lt;li&gt;Software supply chain attacks jumped over 300% in 2021&lt;/li&gt;
&lt;li&gt;It is estimated that worldwide, cyber crimes will cost $10.5 trillion annually by 2025.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;(Data from Purplesec, IT Governance, VentureBeat)&lt;/p&gt;

&lt;p&gt;On the other hand:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;70% of development teams always or frequently skip security steps due to time pressures when completing projects&lt;/li&gt;
&lt;li&gt;Almost 60% of devs are releasing code 2x faster, thanks to DevOps.&lt;/li&gt;
&lt;li&gt;In 2021, only 20% of organizations have fully integrated security into the development&lt;/li&gt;
&lt;li&gt;Security has low priority. 67% of developers surveyed by Secure Code Warrior admitted that they routinely left known vulnerabilities and exploits in their code&lt;/li&gt;
&lt;li&gt;Github expects the number of software developers using its platform (56 million in 2020), to grow to 100 million developers in 2025&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;(Invicti Security, Gitlab, Github, VentureBeat)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Security vs Developers&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Security teams focus on planning secure IT environments, but developers are asked to focus on productivity while they are also tasked with implementing these security plans. The main issue is that developers are often left out of security planning processes, creating a strained relationship between these two teams.&lt;/p&gt;

&lt;p&gt;It is important to build a healthy relationship where trust, communication, and collaboration are key to moving toward the organization’s north star. But traditional security teams sometimes see themselves as inspectors of the developer's work. And that attitude needs to change - “when you’re a hammer, everything is a nail”.&lt;/p&gt;

&lt;p&gt;Did you know that in “Gartner's Top Strategic Technology Trends for 2022: Cybersecurity Mesh”, the word "developer" is not included not even once? We were shocked about it; developers need to have a leading role in cybersecurity!&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;It’s “Shift Left Security” time!&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;With shift left security we mean moving security sooner in the development process. Teams should provide developers with the right tools to do their job securely; this is why it is essential to automate product security.&lt;/p&gt;

&lt;p&gt;But most of the new security solutions are focused on selling to the CISOs and their security teams, maybe because they are the ones with the budget for “security”; but what about developers? Most of their new solutions are oriented toward productivity, which makes sense since we live in an agile world, but what if there were new developer-first security solutions? Well, it is about time; a recent survey from Forrester shows that last year 27% of organizations had their development teams holding the budget for application security tools and that number has increased to 37% this year.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Developer-first security Tools&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;While some security tools for developers have started to appear, it is still early days. The ecosystem needs solutions to automate security for developers and most importantly, that is reliable. Our hypothesis is that the most important products will come from the open-source community; they have a genuine interest in supporting and empowering developers.&lt;/p&gt;

&lt;p&gt;We are consolidating a list of reliable open source developer-first security tools for security, if you know of a project we should consider, or if you would like to have access to this list, please send me an email: &lt;a href="//mailto:sama@boxyhq.com"&gt;sama@boxyhq.com&lt;/a&gt; or/and help us spread the word! 🙌&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--0otHTgjy--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/security-sucks-meme-dd5a67992f240bd0be67c6d4eb4b8284.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--0otHTgjy--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/security-sucks-meme-dd5a67992f240bd0be67c6d4eb4b8284.jpeg" alt="Security risks everywhere" width="500" height="716"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>developer</category>
      <category>security</category>
      <category>cybersecurity</category>
      <category>devsecops</category>
    </item>
    <item>
      <title>Be enterprise-ready: Three reasons not to build enterprise features!</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Tue, 19 Jul 2022 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/be-enterprise-ready-three-reasons-not-to-build-enterprise-features-1jol</link>
      <guid>https://forem.com/boxyhq/be-enterprise-ready-three-reasons-not-to-build-enterprise-features-1jol</guid>
      <description>&lt;p&gt;If you are thinking about building features to be enterprise-ready, there are typically two paths that brought you here:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Your team has initially focused on smaller customers and is now looking to expand, or&lt;/li&gt;
&lt;li&gt;Your team is building a new product and targeting enterprise customers from day 1&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Either way, you need to be aware that selling to enterprises is super exciting, especially if you like to play golf and you are ok with a long sales cycle - it could easily take you up to three years to close a deal.&lt;/p&gt;

&lt;p&gt;Enterprises can be scared to give startups a chance and startups often lose out to more established businesses. However, there are two great ways to make sure your business doesn't miss out:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;List of other enterprise customers (“show me more logos, we are not a guinea pig”)&lt;/li&gt;
&lt;li&gt;Compliance requirements (“a checklist to show my boss you are safe”)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--t1YJRo4L--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/security-risks-meme-2abc58d400ed487dc58bc9de5106af7a.jpeg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--t1YJRo4L--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/security-risks-meme-2abc58d400ed487dc58bc9de5106af7a.jpeg" alt="Security risks everywhere" width="403" height="247"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;But what is enterprise readiness? From a product perspective, &lt;a href="https://www.enterpriseready.io"&gt;EnterpriseReady.io&lt;/a&gt; identified common features that set enterprise software apart. You can do a free self-assessment &lt;a href="https://www.enterprisegrade.io/"&gt;here&lt;/a&gt;. The basics mean that your business meets the standards that enterprises look for in solution providers.&lt;/p&gt;

&lt;p&gt;Now, the good news is that to be enterprise-ready you don’t need to build these common undifferentiated features which can drain your resources and bank account. Here is why:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;Customer Obsession – You need to forget about product development and narrow your attention to customer development. You need to talk to potential enterprise customers and understand their current needs, pains, motivations, processes, etc. Remember that they’ve got plenty of software they already depend on that will need to work smoothly with yours. On top of learning how to navigate the enterprise, you need to identify Infosec barriers and consider how to mitigate them; if your solution needs to process internal data, things will be more complex.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Time to market – Instead of spending months building in-house enterprise-grade features, there are off-the-shelf enterprise readiness solutions that you can integrate into your SaaS app with just a few lines of code. There is no need to wait months to build Single Sign-On (SSO), Directory Sync, Audit Logs, Privacy Vault, and other boring stuff that enterprises ask for anymore, now you could plug them within hours. And your team can spend more time building your core product instead of non-core features that won’t add value to your customers’ main needs.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cut engineering costs – Out-of-the-box solutions will help your company save developers time. If you consider the learning curve, coding, fixing bugs, and all the hassle that your tech team needs to go through, you will realize that people’s time is more expensive than developer tools. And the good news is that there are reliable open source solutions that you could use at no cost. Free and trustworthy? That’s the beauty of open source communities. Self-hosting these solutions will allow your company to maintain a level of control that will simplify things if you need to be certified (SOC2, ISO 27001, HIPAA, etc).&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Here are 3 open-source solutions that could be interesting for you - BoxyHQ ( &lt;strong&gt;disclaimer, I'm a Co-Founder here&lt;/strong&gt; ), &lt;a href="https://supertokens.com"&gt;Supertokens&lt;/a&gt;, and &lt;a href="https://osohq.com"&gt;Oso&lt;/a&gt;. There are plenty of other solutions that are relevant, we are building a list and would love to learn about other projects you use, please share them with me.&lt;/p&gt;

&lt;p&gt;Let’s be sincere, will your engineers focus on building the best SAML SSO feature or will they just focus on checking the box? Compliance security could be expensive in the long term when working with large enterprises. Especially if things go wrong because being compliant doesn’t mean your SaaS app is unhackable.&lt;/p&gt;

&lt;p&gt;Remember that not all enterprises are the same. But working with a few design partners will help your team to define an efficient product roadmap, build a robust go-to-market strategy, and you will close more enterprise deals.&lt;/p&gt;

&lt;p&gt;Deals, deals, deals!&lt;/p&gt;

&lt;p&gt;If you know anyone that needs to build enterprise features we would love to hear from them and see how could we help, please feel free to share my email: &lt;a href="//mailto:sama@boxyhq.com"&gt;sama@boxyhq.com&lt;/a&gt; - Thank you!&lt;/p&gt;

</description>
      <category>enterprisereadiness</category>
      <category>startup</category>
      <category>enterprises</category>
      <category>corporates</category>
    </item>
    <item>
      <title>Understanding SAML SSO, the basics from the solution provider's side</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Thu, 30 Jun 2022 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/understanding-saml-sso-the-basics-from-the-solution-providers-side-ad1</link>
      <guid>https://forem.com/boxyhq/understanding-saml-sso-the-basics-from-the-solution-providers-side-ad1</guid>
      <description>&lt;p&gt;This article follows my first article in which I explain the basics of SAML from the users' side. If you haven't read that one already I would recommend reading that one first &lt;a href="https://dev.to/blog/understanding-saml-sso-the-basics-from-the-user-side"&gt;here&lt;/a&gt;. In this article, we are going to take a look at what SAML authentication and setup look like from the solution providers' perspective.&lt;/p&gt;

&lt;p&gt;If you are a B2B solutions provider and you plan to have enterprise customers they will likely ask that your product supports SAML SSO. This is because the customer will already be using an IDP to manage user access and security to their services. Anything outside this will be a risk and not fit into their user's workflows.&lt;/p&gt;

&lt;p&gt;Most larger solution providers have already invested a lot of time and money into building SAML integrations with IDP providers but this leaves smaller competitors with less time and resources at a disadvantage as they often haven't been able to prioritize enterprise security features over the core product build.&lt;/p&gt;

&lt;p&gt;The main reason why smaller companies don’t implement SAML as part of the standard build is that it traditionally takes a long time as they have to build a custom integration with each IDP provider their customers use. Well, this is now an old issue because we have created BoxyHQ which allows you to connect to our free product with one single integration that then connects to all the IDPs for you! Let's take a look at what the integrations with and without BoxyHQ look like first.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--oexwyfA9--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/without-boxyhq-743ff67cd6e4a2234e4cd650af2fb380.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--oexwyfA9--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/without-boxyhq-743ff67cd6e4a2234e4cd650af2fb380.png" alt="Without BoxyHQ" width="880" height="555"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In the diagram above we can see what it looks like when you build a custom SAML integration with each IDP. As you can see for each IDP you have to connect all the instances of your product and build a unique integration. This can take months and take the focus away from your team building your core product. We believe that enterprise readiness should be accessible and easy for businesses of all sizes so we built BoxyHQ. Let's see what that looks like.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--cel1y9FP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/with-boxyhq-1d1b6c59e97f1ff96b82319d48d016c7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--cel1y9FP--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/with-boxyhq-1d1b6c59e97f1ff96b82319d48d016c7.png" alt="With BoxyHQ" width="880" height="555"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;As you can see from the image above with BoxyHQ you only have to connect your product with a straightforward integration to BoxyHQ and then we manage and connect you to all the IDPs! It is that simple and you can deploy SAML SSO for your clients in as little as 8 days. We are also open source and free so you don't need to worry about big maintenance bills, we will even offer you custom support during the integration.&lt;/p&gt;

&lt;p&gt;If you are interested in becoming enterprise-ready without the hassle then let's chat! You can &lt;a href="https://meetings.hubspot.com/deepakprab/demo"&gt;book&lt;/a&gt; a free consultation call and chat with our CEO about how we can help. Let's start the journey together.&lt;/p&gt;

</description>
      <category>enterprisereadiness</category>
      <category>saml</category>
      <category>samljackson</category>
      <category>sso</category>
    </item>
    <item>
      <title>Understanding SAML SSO, the basics from the user side</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Thu, 30 Jun 2022 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/understanding-saml-sso-the-basics-from-the-user-side-1b8e</link>
      <guid>https://forem.com/boxyhq/understanding-saml-sso-the-basics-from-the-user-side-1b8e</guid>
      <description>&lt;p&gt;I have always worked in tech, so have always needed to understand the technical nature of the products we are building. This process has always been over-complicated for me so I now always try to write a guide for non-technical people like me. It turns out that once you understand it you can explain it to other non-technical people much easier! So here we go as I try to explain SAML (Security Assertion Markup Language) SSO (single sign-on) and why BoxyHQ makes it so easy to implement. Firstly you have probably heard of not only SAML but OAuth 2.0 and OIDC, these are all protocols that achieve the same result of providing SSO. There are a few nuances but those are out of scope for this article to keep things simple.&lt;/p&gt;

&lt;p&gt;Let's start with what SAML SSO is and what it does. An example of SAML SSO in action would be a user in your company signs into a single dashboard and inside that dashboard, they have all the icons for the external services they use such as their CRM (Hubspot) and accounting software (Xero). The user can now just log in to any of their services by clicking on them rather than logging into each one individually.&lt;/p&gt;

&lt;p&gt;But how does this work? Well, the idea behind SAML SSO is that by centralizing your access to an external system you can better manage access and permission as well as improve security. So in our example, the dashboard that allowed the user to just click an icon and log in was SAML in action. Because the company has connected to its external servicing using SAML it can now let its users access all the services from a single point. This single point of access is known as the IdP (Identity Provider) which authenticates the access to all the other services via SAML.&lt;/p&gt;

&lt;p&gt;The diagrams below show how this access flow would work with and without SAML: &lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--xEVdqaa8--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/without-saml-a11eafbd35ee0a5e117a8aa9aabf87bd.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--xEVdqaa8--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/without-saml-a11eafbd35ee0a5e117a8aa9aabf87bd.png" alt="Without SAML SSO" width="880" height="461"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In the diagram above we can see that the company is not using SAML so the user has to log into each of the services with an individual username and password. The username and password are managed by the service provider and access is also managed via an admin user on the service provider's side. The user must be given aces to each of the services from each of the services and remember the login details for each one.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--4pezuCjg--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/with-saml-f1491fc9f5e7f7c7946d252e0080fde6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--4pezuCjg--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/with-saml-f1491fc9f5e7f7c7946d252e0080fde6.png" alt="With SAML SSO" width="880" height="461"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In the image above we can see that the company is using an IdP such as Okta so the user simply has to log in once and then can access all the external services from a single dashboard. This also means that the company admins can manage access to the different services as they control the access directly from their IdP.&lt;/p&gt;

&lt;p&gt;Now, remember that this is just a high-level overview of SAML and the technical aspects behind the scenes can get a lot more complicated.&lt;/p&gt;

&lt;p&gt;We have been looking at SAML from a company user's perspective but it's also important to remember that these service providers also have to build a SAML integration to enable them to connect to their clients’ IdPs. This can be a very long and time-consuming process for service providers and this is where BoxyHQ comes in. Instead of service providers building a custom integration for each IdP their customers use which can take months, the service providers can use BoxyHQ and have all the connections to IdPs they need with a single integration! You can be SAML-ready in as little as 8 days! To understand how this looks check out my other blog &lt;a href="https://dev.to/blog/understanding-saml-sso-the-basics-from-the-solution-providers-side"&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;So what are the main benefits of SAML? Here are three of the most important ones I have identified.&lt;/p&gt;

&lt;h4&gt;
  
  
  Increased Security​
&lt;/h4&gt;

&lt;p&gt;SAML is at its heart a security standard and as it provides a single point of authentication that takes place in a secure environment it adds an extra layer of security to your service that most enterprise customers will ask for.&lt;/p&gt;

&lt;h4&gt;
  
  
  Improved user experience​
&lt;/h4&gt;

&lt;p&gt;As a user using SAML is very simple and pleasant to use as you only have to log in once and then you can access all your external services on a dashboard with a single click. This saves the user time and makes their overall experience of your product better.&lt;/p&gt;

&lt;h4&gt;
  
  
  Reduces cost​
&lt;/h4&gt;

&lt;p&gt;Without SAML you have to maintain account information across multiple services but when you use SAML this is all managed by the IdP.&lt;/p&gt;

&lt;p&gt;BoxyHQ is open source and our SAML SSO product, SAML Jackson is just the first product we have built to help companies become enterprise-ready. If you are interested in discussing your authentication strategy or deploying SAML SSO you can book a call with our CEO &lt;a href="https://meetings.hubspot.com/deepakprab/demo"&gt;here&lt;/a&gt; to discuss how we can support you.&lt;/p&gt;

&lt;p&gt;I hope you have found this high-level explanation of SAML and its use cases helpful. If you have any questions please don't hesitate to reach out to us on our live chat on our website &lt;a href="https://boxyhq.com/"&gt;https://boxyhq.com/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>enterprisereadiness</category>
      <category>saml</category>
      <category>samljackson</category>
      <category>sso</category>
    </item>
    <item>
      <title>How early-stage startups should sell to enterprises</title>
      <dc:creator>Deepak Prabhakara</dc:creator>
      <pubDate>Mon, 21 Feb 2022 00:00:00 +0000</pubDate>
      <link>https://forem.com/boxyhq/how-early-stage-startups-should-sell-to-enterprises-1djp</link>
      <guid>https://forem.com/boxyhq/how-early-stage-startups-should-sell-to-enterprises-1djp</guid>
      <description>&lt;p&gt;You have decided to quit your job and start something on your own, congratulations! Welcome to a new way of living, as our little green friend told us some years ago “do or do not, there is no try”. Resilience and perseverance will be your two new best friends now; we all know that starting a company is not hard at all, but something hard at the beginning of the journey is finding product-market fit, especially if you are selling to enterprises (if you are an open-source founder, make sure you prioritize project-community fit first).&lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--y9yviKUe--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/mulyadi-dDlvuSKUDZM-unsplash-2af769019719b26ec3771bf852d52bec.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--y9yviKUe--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://boxyhq.com/assets/images/mulyadi-dDlvuSKUDZM-unsplash-2af769019719b26ec3771bf852d52bec.jpg" alt="Star Wars Lego" width="640" height="427"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Photo by &lt;a href="https://unsplash.com/@mullyadii?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Mulyadi&lt;/a&gt; on &lt;a href="https://unsplash.com/?utm_source=unsplash&amp;amp;utm_medium=referral&amp;amp;utm_content=creditCopyText"&gt;Unsplash&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Having worked for companies like Amazon Web Services &amp;amp; O2-Telefónica connecting enterprises with startups around the world, there are some best practices that I would like to share. We just have to remember that enterprises are conformed by groups of people, and every person is different. So please, don’t expect the secret sauce or the “right way” to do it. Even though each case will be unique, always look for the patterns of what works best for your company. I like to use the process DIA (Discover – Imagine – Act) to overcome challenges, so let me take you through it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Discover​
&lt;/h2&gt;

&lt;p&gt;First, you have to understand the problem that you are solving. Is it really a problem or are you just in love with a good idea? Asking many times “why” will help you understand the hidden problem (the real one), and it will allow you to understand the needs that the enterprise has. Once you understand the needs of the enterprise, it is time to focus on understanding the needs of your user and your buyer, most of the time these are two different stakeholders within the organization. Is the need of the user a priority for the buyer, or is it just a distraction? You will see that in some organizations they are aligned and in others, they cannot even stand each other; so you must take the time to understand the dynamics between these stakeholders, and the culture of the enterprise itself (how they make decisions).&lt;/p&gt;

&lt;p&gt;Sales cycles are indeed long if you look at them from a startup’s point of view. Remember that this is the standard speed for enterprises. Startups speak AGILE and Enterprises speak SECURITY, and for many people, these two terms can’t go together (don’t worry, we are proving them wrong @BoxyHQ). Enterprises have got plenty of software they already depend on that needs to work with whatever your product can do for them. Their technology is usually old, I have seen many enterprises with Frankensteins, they think they need to create a third leg to run faster and they end up building unnecessary technologies that affect the quality and the speed of their solutions. You need to focus on the cost of the enterprise (time and resources) to integrate your solution, and to do that you have to make sure that the impact is big enough to be worth it.&lt;/p&gt;

&lt;p&gt;To make sure the impact you are generating is relevant to the enterprises focus on a few potential customers, as Jason Lemkin mentions “Almost all big companies now have innovation departments of some sort, as do many divisions and groups. The general idea is to bring in 1–2 new vendors a year that don’t risk taking the core business down but could have a material impact on the bottom line. If you truly can change the way they do business, you can often get a meeting. I’ve done this in both my start-ups in the earliest days with 10+ F500 companies in the first 90 days.”&lt;/p&gt;

&lt;p&gt;This Discovery stage is also perfect to understand what your solution needs to have to be compliant; security is key for them. Startups that are not compliant with the enterprises’ requirements could delay the sales cycle, or what is worse they could lose the deal.&lt;/p&gt;

&lt;h2&gt;
  
  
  Imagine​
&lt;/h2&gt;

&lt;p&gt;With all the information that you now have, it is time to visualize the future. Does your solution need some changes? Do you need new features to be compliant? Or could it be that maybe the enterprise doesn’t need all the features that you had in mind? Take some time to readjust your product as necessary, including how you are going to package it and how you are going to distribute it. Apply all the insights collected in the Discovery stage to test, measure, and iterate.&lt;/p&gt;

&lt;p&gt;A common error that I have seen from startups is not focusing on selecting the right partners, and just moving forward with inbound opportunities. Some of them could be good but overall is a distraction to say yes to anyone that wants to resell your solution, you need to plan ahead.&lt;/p&gt;

&lt;p&gt;Talking about planning, once you know who your internal sponsor is you need to facilitate the job for them. That is the person that will take your fights internally, so make sure you are giving them the right tools. If they see two concerns about integrating your solution, you should think of additional concerns and imagine how to mitigate each of them. You need to train your sponsor for unexpected scenarios that the decision committee will bring. Usually, enterprises ask for a “request for proposal” (RFP), the more you know about it, the better you will be prepared.&lt;/p&gt;

&lt;p&gt;As an imagination exercise, I love Amazon’s Working Backwards process and the PRFAQ - you can learn more about it &lt;a href="https://www.linkedin.com/pulse/applying-amazons-working-backwards-process-leaders-ian-mcallister/"&gt;here&lt;/a&gt;. It is helpful to visualize the impact you aim to have and work backwards from your customer needs to create a solution. It is similar to the Design Thinking process, but the PRFAQ adds the manifestation piece.&lt;/p&gt;

&lt;h2&gt;
  
  
  Act​
&lt;/h2&gt;

&lt;p&gt;Now is the time to act! But be careful, another mistake that many startups make is not executing at the right time, they spend too much time thinking (doing research) or they reach out to enterprises before making sure they are ready, burning your bridges. Timing is going to be key for you.&lt;/p&gt;

&lt;p&gt;They need to trust you and your solution, every contact point is an opportunity for them to trust you, so make sure to go to these meetings well prepared, doing the right questions but at the same time with some insights on the market, their competitors, technologies, etc. You should be an expert in your niche but at the same time, you should be smart enough to listen. The more you know about them, the better you can adapt your solution and at the same time influence them.&lt;/p&gt;

&lt;p&gt;Make sure you have the right metrics for your success cases, it doesn’t matter if you were selling to SMEs before or if you already had a few Proof of Concepts (POCs) with enterprises. Large companies don’t want to feel they are a guinea pig, if you did a POC and you didn’t move forward afterward most executives will not see it as unsuccessful, period.&lt;/p&gt;

&lt;p&gt;Be patient, agile enterprises could spend between 6 to 12 months in conversations before signing an agreement, but many could take years (I’ve seen one company spending 3+ years). While you are waiting, make sure you are at the top of their mind, always adding value, not asking for unnecessary coffees. Key people will resign, will get fired, will change roles, so make sure you find a way to navigate these transitions, you don’t want to start from scratch.&lt;/p&gt;

&lt;p&gt;Each enterprise is a different world, and there are more things you will find out while spending time with them, but I hope you find this blog post insightful. If you have any comments or questions you would like to discuss, please feel free to reach out. We have free Enterprise-Ready office hours to help startups be compliant and accelerate their sales cycle with enterprises.&lt;/p&gt;

</description>
      <category>startup</category>
      <category>enterprises</category>
      <category>corporates</category>
    </item>
  </channel>
</rss>
