← ClaudeAtlas

security-pagelisted

Build a credible security/trust page for a developer tool before SOC 2 — concrete controls, encryption specifics, subprocessor list, responsible disclosure, data lifecycle, and honest scoping of what you can claim. Use when the user wants a security page, trust page, or trust center, asks "do we need SOC 2", got a vendor security questionnaire, or is losing deals to security review. Also use when they mention a DPA, subprocessors, security.txt, responsible disclosure, or "enterprise readiness", even if they never say "security page".
alexpate/devtool-skills · ★ 0 · Code & Development · score 67
Install: claude install-skill alexpate/devtool-skills
# Security Page A security page is the sales asset engineering can ship in a week. Buyers' security reviewers read it before they email you, and a concrete one closes early- and mid-market deals that a badge wall never will. The bar is Tailscale: their page leads with their actual trust model and gets technical fast, because their audience can tell the difference. This skill produces a page that survives vendor review without an auditor. ## Before you start Check for `.agents/devtool-context.md` and read it if present (stage, stack, and buyer persona decide how deep the page goes). If absent, ask: 1. What customer data do you hold, and what's the *worst* thing you could leak or break for a customer? 2. What's actually true today: cloud provider, encryption defaults, who on the team can touch production, which vendors see customer data? 3. Has anyone asked for SOC 2 yet, or is this preemptive? Question 2 matters most: this page can only contain things that are true. The interview surfaces both the claims you can make and the gaps that become the backlog artifact. ## The page, in order of consequence ### 1. Lead with your most sensitive surface Every generic security page opens with "we take security seriously." That phrase is a tell, because reviewers pattern-match it to "nothing specific to say." Ban it. Instead, identify the worst thing you could leak or break for a customer, and open the page with exactly how you protect *that*: - A feature-flag service leads with