Boardroom Answers · People & Operations · Sustainability & ESG
Last question, and it is about you, not the product: you sell governance. Show me yours. How is a one-founder company governed, and how would I ever know if something went wrong inside it?
The question a Chief Sustainability Officer (CSustO) asks.
The short answer
Machine-enforced controls — CI gates, database-enforced isolation, append-only audit logs — plus public status, changelog, trust and subprocessor pages. Governance you can check, not governance I claim; external attestation sequenced on contractable milestones.
The full executive answer
Fair question, and my answer is that at this stage, credible governance means machine-enforced controls and radical transparency rather than committee theatre — a one-person board committee would be exactly that. The enforced controls: every change to the platform passes an automated quality gate — type checks, accessibility linting, 344 test suites of roughly 3,577 tests, security audit — before it can deploy; tenant isolation is enforced by the database with an automated test that fails the build if any table forgets it; audit logs are append-only by construction; and untrusted text is stripped of PII before any AI model sees it. None of these depend on my discipline on a bad day — that is the point of them.
The transparency: the surfaces where you would find out something went wrong are public and permanent — the status page with incident history, a changelog that includes a security category, the trust and AI-governance pages, the subprocessor register, and a security.txt with a committed acknowledgement window for external researchers who find what I missed. Our own SLA page distinguishes measured numbers from targets in writing. The company's honesty policy is legible in its published artefacts, which is a stronger signal than any org chart.
And the roadmap, stated as governance always should be: external accountability grows with the company — SOC 2 attestation, an advisory structure around the founder, and a formal support organisation are sequenced against revenue milestones I am willing to contract. Judge us the way you would judge any ESG report: not on the maturity we claim, but on whether the disclosed state matches the observed one. Everything I have told this panel today is checkable against a public page or a live demo — that consistency is my governance evidence.
Grounded in: ISSB S1-style governance disclosure logic applied to the vendor itself: disclose the actual governance state, controls, and transition plan rather than performing maturity; ITIL 4 continual improvement for the milestone sequencing.
The natural next questions
Related governed answers
- Show me the green-AI module properly. My organisation is deploying AI everywhere — how would I use this to govern the carbon cost of that estate?
- Our supplier code of conduct requires ESG disclosures from vendors — emissions data, labour practices, governance. Most startups fail this. Will you?
- Concretely, what does your platform do for MY job — ESG strategy, disclosure readiness, assurance? Or is ESG a checkbox slide in your deck?
Want this answered live, on your data?