Skip to main content

Boardroom Answers · People & Operations · Sustainability & ESG

Last question, and it is about you, not the product: you sell governance. Show me yours. How is a one-founder company governed, and how would I ever know if something went wrong inside it?

The question a Chief Sustainability Officer (CSustO) asks.

The short answer

Machine-enforced controls — CI gates, database-enforced isolation, append-only audit logs — plus public status, changelog, trust and subprocessor pages. Governance you can check, not governance I claim; external attestation sequenced on contractable milestones.

The full executive answer

Fair question, and my answer is that at this stage, credible governance means machine-enforced controls and radical transparency rather than committee theatre — a one-person board committee would be exactly that. The enforced controls: every change to the platform passes an automated quality gate — type checks, accessibility linting, 344 test suites of roughly 3,577 tests, security audit — before it can deploy; tenant isolation is enforced by the database with an automated test that fails the build if any table forgets it; audit logs are append-only by construction; and untrusted text is stripped of PII before any AI model sees it. None of these depend on my discipline on a bad day — that is the point of them.

The transparency: the surfaces where you would find out something went wrong are public and permanent — the status page with incident history, a changelog that includes a security category, the trust and AI-governance pages, the subprocessor register, and a security.txt with a committed acknowledgement window for external researchers who find what I missed. Our own SLA page distinguishes measured numbers from targets in writing. The company's honesty policy is legible in its published artefacts, which is a stronger signal than any org chart.

And the roadmap, stated as governance always should be: external accountability grows with the company — SOC 2 attestation, an advisory structure around the founder, and a formal support organisation are sequenced against revenue milestones I am willing to contract. Judge us the way you would judge any ESG report: not on the maturity we claim, but on whether the disclosed state matches the observed one. Everything I have told this panel today is checkable against a public page or a live demo — that consistency is my governance evidence.

Grounded in: ISSB S1-style governance disclosure logic applied to the vendor itself: disclose the actual governance state, controls, and transition plan rather than performing maturity; ITIL 4 continual improvement for the milestone sequencing.

Want this answered live, on your data?