Trust Is an Engineering Problem
SnapLedger's biggest challenge isn't AI or accounting or competition — it's trust. And trust isn't bought or certified. It's engineered, one deliberate decision at a time.
People often ask me what I think will be the biggest challenge for SnapLedger.
Surprisingly, I don't think it's AI. I don't think it's accounting. And I don't think it's competition.
I think it's trust.
After all, SnapLedger asks customers to store some of their most sensitive business information with us—receipts, invoices, payroll records, employment contracts, bank statements, tax documents. These files don't just describe a business; in many ways, they are the business.
So why should anyone trust a startup with all of that?
I've spent a lot of time thinking about this question, and I came to three conclusions.
1. The data is already in the cloud
The first is that the question today is no longer whether your data should live in the cloud. For almost all of us, it already does.
Our emails, photos, calendars, banking apps, company documents, and source code all live somewhere in the cloud. Modern business simply wouldn't function without cloud services.
The real question is: how well is your data protected once it's there?
2. Security isn't about company size
The second realization is that security has surprisingly little to do with the size of a company.
Many people naturally assume that a large company is more secure than a startup. I don't.
Security comes from engineering discipline. A small company can build an excellent security architecture, while a large company can still make poor engineering decisions. Good security is the result of thousands of deliberate design choices, not thousands of employees.
3. Stand on the best foundation available
That leads to my third conclusion. As a startup, we shouldn't try to invent our own security infrastructure. We should build on top of the best security infrastructure already available.
That's why SnapLedger is built on Google Cloud Platform. Google has spent decades and billions of dollars building one of the most secure cloud infrastructures in the world. Every day, billions of people rely on it for products like Gmail, Google Drive, and Google Photos. Standing on that foundation allows us to focus on building great financial software instead of trying to reinvent cloud security ourselves.
Security is designed, not purchased
Of course, using Google Cloud doesn't automatically make an application secure. Security isn't something you purchase. It's something you design.
From the very beginning, we decided that security would become part of SnapLedger's architecture rather than something added later. Today, that means things such as:
- Data encrypted both in transit and at rest.
- Multi-factor authentication protecting administrative access.
- Strict Identity and Access Management (IAM) following the Principle of Least Privilege.
- Continuous backups and disaster recovery mechanisms.
- Individual administrator identities instead of shared privileged accounts.
- Continuous security monitoring and auditing.
Another important design decision was our deployment architecture. SnapLedger is designed as a globally deployed platform rather than a single centralized server.
As we expand internationally, customer data can be deployed and stored in the appropriate geographic regions to satisfy local regulatory requirements, such as GDPR in Europe and PDPL in the UAE. We believe customers shouldn't have to choose between modern AI software and regulatory compliance—they should have both.
Certificates come after the thinking, not before
People sometimes ask whether we'll eventually pursue certifications such as ISO 27001 or SOC 2. The answer is yes. Those certifications are valuable because they demonstrate that security processes are consistently followed.
But I don't believe trust starts with a certificate hanging on the wall. Trust starts much earlier. It starts when engineers ask themselves one simple question before every design decision:
"If this were my own financial data, would I be comfortable storing it this way?"
If the answer is no, we redesign it.
Ultimately, I don't think trust is something you can ask customers to give you. It's something you earn—through thousands of engineering decisions, hundreds of product decisions, and complete transparency about why those decisions were made.
That's one of the reasons I'm writing this Founder Diary. I don't expect people to trust SnapLedger simply because we say we're secure. I hope they'll gradually trust the way we think.
Everything else can be built on top of that.
Security isn't something you purchase. It's something you design.
If this were your own financial data, would you be comfortable storing it this way?
Lesson of the day: Trust isn't a certificate on the wall — it's earned through thousands of deliberate engineering decisions.