{"id":1170,"date":"2026-09-11T08:24:15","date_gmt":"2026-09-11T08:24:15","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1170"},"modified":"2026-09-11T08:32:04","modified_gmt":"2026-09-11T08:32:04","slug":"handpickd-15m-series-a-investor-security-requirements-2","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/case-studies\/handpickd-15m-series-a-investor-security-requirements-2\/","title":{"rendered":"How Handpickd met investor security requirements and closed a $15M Series A without losing momentum"},"content":{"rendered":"\n<!-- OSTO CASE STUDY | handpickd-investor-security-series-a-v8 | replaces content at the existing live URL, keep the slug -->\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n<div class=\"og\">\n<p class=\"dek\">Handpickd had a Series A term sheet in hand and an investor security checklist standing between it and a signed deal. This is what the investors asked for, what Osto put in place, and why the $15M round did not slip.<\/p>\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Case study<\/span><\/li>\n  <li><span class=\"tag t-sage\">Series A<\/span><\/li>\n<\/ul>\n<div class=\"short\">\n  <p class=\"k\">TL;DR<\/p>\n  <p>Handpickd&#8217;s $15M Series A, led by Bertelsmann India Investments, came with an investor security checklist as a condition of shareholder due diligence. Two items carried the weight: an independent penetration test and documented cloud infrastructure findings. Osto ran the VAPT end to end and switched on CSPM, the evidence went back inside the diligence window, and the round closed without delay.<\/p>\n<\/div>\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">$15M Series A<\/p>\n    <p class=\"g\">Led by Bertelsmann India Investments<\/p>\n    <p>Titan Capital Winners Fund and existing investors also came in.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">2 of 2 cleared<\/p>\n    <p class=\"g\">Investor security checklist items<\/p>\n    <p>Penetration testing and cloud findings, both backed by documented evidence.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">No delay<\/p>\n    <p class=\"g\">Round closed on schedule<\/p>\n    <p>The security work finished well inside the investor timeline.<\/p>\n  <\/div>\n<\/div>\n<p>Most founders expect the first serious security question to come from an enterprise buyer. For Handpickd, it came from the people writing the cheque.<\/p>\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#condition\">A term sheet with a condition attached<\/a><\/li>\n    <li><a href=\"#handpickd\">What Handpickd is<\/a><\/li>\n    <li><a href=\"#checklist\">What the investor security checklist asked for<\/a><\/li>\n    <li><a href=\"#deployed\">What Osto put in place<\/a><\/li>\n    <li><a href=\"#both\">Why one test was not enough<\/a><\/li>\n    <li><a href=\"#results\">The results<\/a><\/li>\n    <li><a href=\"#lessons\">What other founders can take from this<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"condition\">A term sheet with a condition attached<\/h2>\n<p>The investors were lined up. Bertelsmann India Investments would lead, Titan Capital Winners Fund and existing backers would follow, and $15M would go into growing Handpickd across its cities. Then shareholder due diligence opened, and with it came a mandatory investor security checklist.<\/p>\n<p>Nothing on the list was unusual for a round of this size. Funds deploying this much capital answer to their own limited partners, and a breach inside a portfolio company is their problem too. What made it urgent was the rule attached to it. Until the checklist was cleared, the term sheet would not convert into a signed agreement.<\/p>\n<p>Security had moved off the roadmap and onto the critical path of the raise.<\/p>\n\n<h2 id=\"handpickd\" class=\"c-sage\">What Handpickd is<\/h2>\n<p>Handpickd was founded in 2024 by Anant Goel, who earlier co-founded Milkbasket, together with Nitin Gupta and Sahil Madan. Anant runs the company as founder and CEO, and Nitin leads technology as co-founder and CTO. The company calls itself India&#8217;s first zero-stock fresh commerce platform, and the model is defined by what it refuses to hold.<\/p>\n<table class=\"h-sage\">\n  <thead>\n    <tr><th style=\"width:30%\">At a glance<\/th><th>Handpickd<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Founders<\/td><td>Anant Goel (Founder and CEO), Nitin Gupta (Co-founder and CTO), Sahil Madan (Co-founder)<\/td><\/tr>\n    <tr><td>Headquarters<\/td><td>Gurugram, India<\/td><\/tr>\n    <tr><td>Cities served<\/td><td>Gurugram, Noida and Bengaluru<\/td><\/tr>\n    <tr><td>Industry<\/td><td>Fresh commerce, zero-stock model<\/td><\/tr>\n    <tr><td>Funding<\/td><td>$15M Series A led by Bertelsmann India Investments<\/td><\/tr>\n  <\/tbody>\n<\/table>\n<p>There is no inventory, no warehouse, no dark store and no demand forecast. Customers order first. Handpickd then buys the exact quantity from farmers and delivers to homes early the next morning, with the full cycle from purchase to doorstep running in six to seven hours by the company&#8217;s own account. Customers can set ripeness, sweetness, crunch, size and pesticide-free preferences down to the individual piece of fruit.<\/p>\n<p>That model has no buffer. With nothing sitting in storage to sell instead, demand collection, farmer procurement, routing and personalisation all run in software every single night. A compromise here would hit tomorrow morning&#8217;s deliveries as well as customer data. Investors could see that, which is why they treated the investor security review as a real diligence question rather than a formality.<\/p>\n\n<h2 id=\"checklist\" class=\"c-plum\">What the investor security checklist asked for<\/h2>\n<p>The checklist covered several parameters. Two of them were substantive enough to hold up the round on their own.<\/p>\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Checklist item<\/th><th>Status<\/th><th>What satisfies it<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Independent penetration testing<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> report from a qualified assessor, covering each finding, its severity, the affected surface and the remediation<\/td><\/tr>\n    <tr><td>Cloud infrastructure findings<\/td><td><span class=\"pill p-req\">Required<\/span><\/td><td>A documented view of cloud misconfigurations and how each one is tracked to closure<\/td><\/tr>\n    <tr><td>Other security parameters<\/td><td><span class=\"pill p-ask\">Asked<\/span><\/td><td>Part of the wider checklist, though none carried the weight of the first two<\/td><\/tr>\n  <\/tbody>\n<\/table>\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"The path from the Series A term sheet to a closed round: the investor security checklist splits into a penetration test report and cloud findings, answered by Osto VAPT and Osto CSPM, and both lead to the round closing.\">\n  <defs><marker id=\"hpA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n  <rect x=\"14\" y=\"92\" width=\"120\" height=\"66\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"74\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">Series A<\/text>\n  <text x=\"74\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">term sheet<\/text>\n  <line x1=\"138\" y1=\"125\" x2=\"154\" y2=\"125\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#hpA)\"\/>\n  <rect x=\"160\" y=\"92\" width=\"130\" height=\"66\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"225\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">Investor security<\/text>\n  <text x=\"225\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">checklist<\/text>\n  <path d=\"M294,125 C312,125 312,62 326,62\" stroke=\"#4a52a8\" stroke-width=\"2\" fill=\"none\" marker-end=\"url(#hpA)\"\/>\n  <path d=\"M294,125 C312,125 312,188 326,188\" stroke=\"#4a52a8\" stroke-width=\"2\" fill=\"none\" marker-end=\"url(#hpA)\"\/>\n  <rect x=\"332\" y=\"30\" width=\"150\" height=\"64\" rx=\"13\" fill=\"#f0e6f3\"\/>\n  <text x=\"407\" y=\"57\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Pen test report<\/text>\n  <text x=\"407\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">From a qualified assessor<\/text>\n  <rect x=\"332\" y=\"156\" width=\"150\" height=\"64\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"407\" y=\"183\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6a89\">Cloud findings<\/text>\n  <text x=\"407\" y=\"202\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Tracked to closure<\/text>\n  <line x1=\"486\" y1=\"62\" x2=\"506\" y2=\"62\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#hpA)\"\/>\n  <line x1=\"486\" y1=\"188\" x2=\"506\" y2=\"188\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#hpA)\"\/>\n  <rect x=\"512\" y=\"30\" width=\"110\" height=\"64\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"567\" y=\"57\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">Osto VAPT<\/text>\n  <text x=\"567\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Run end to end<\/text>\n  <rect x=\"512\" y=\"156\" width=\"110\" height=\"64\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"567\" y=\"183\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">Osto CSPM<\/text>\n  <text x=\"567\" y=\"202\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Live from day one<\/text>\n  <path d=\"M626,62 C642,62 642,125 652,125\" stroke=\"#3a6f5d\" stroke-width=\"2\" fill=\"none\" marker-end=\"url(#hpA)\"\/>\n  <path d=\"M626,188 C642,188 642,125 652,125\" stroke=\"#3a6f5d\" stroke-width=\"2\" fill=\"none\" marker-end=\"url(#hpA)\"\/>\n  <rect x=\"658\" y=\"92\" width=\"90\" height=\"66\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"703\" y=\"120\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Round<\/text>\n  <text x=\"703\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">closed<\/text>\n<\/svg>\n<\/div>\n<figcaption>Each checklist line mapped to a single Osto module, so every piece of evidence had one owner and one source.<\/figcaption>\n<\/figure>\n<div class=\"callout\">\n  <p class=\"k\">The calendar was the real risk<\/p>\n  <p>Neither requirement was hard to understand. The problem was lead time. A team that starts looking for a testing vendor after the term sheet lands has to scope, contract, test, report and fix while the investors wait, and every week of that is a week the investor security review keeps the round unsigned.<\/p>\n<\/div>\n\n<h2 id=\"deployed\" class=\"c-sky\">What Osto put in place<\/h2>\n<p>Handpickd came to Osto with the investor security checklist in hand and a clock already running. There was no vendor search and no integration project to get through first. The work started on the requirements themselves.<\/p>\n<p><strong>VAPT for the testing line.<\/strong> Osto ran a structured <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration test<\/a> across Handpickd&#8217;s application and infrastructure and delivered a report that listed every finding with its severity, where it sat and how it was fixed. That report is the artefact investors expect against the testing requirement, and nothing else stands in for it.<\/p>\n<p><strong>CSPM for the cloud line.<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">Cloud security posture management<\/a> went live across Handpickd&#8217;s cloud environment, scanning for the misconfigurations that build up in fast-moving infrastructure, from publicly reachable storage to over-permissive access and missing logging. Each finding was flagged and tracked to closure, which gave the investors a working control and a written record in one.<\/p>\n<div class=\"callout c-plum\">\n  <p>&#8220;When our Series A term sheet came with a mandatory security checklist, Osto stepped in, gave us cloud posture visibility from day one, and ran the full VAPT end to end. The work was completed well within the investor timeline, and our deal did not get delayed.&#8221;<\/p>\n  <p><strong>Nitin Gupta<\/strong>, Co-founder and CTO, Handpickd<\/p>\n<\/div>\n\n<h2 id=\"both\" class=\"c-apri\">Why one test was not enough<\/h2>\n<p>A pen test is a snapshot. It shows what a skilled tester could do against a defined scope on one date. CSPM is a running record of configuration state and every drift since. The investor security checklist asked for both because each covers the gap the other leaves, and together they answer what investors are really asking: will this team notice when something changes?<\/p>\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 210\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Timeline comparing a penetration test, which is a single snapshot on one date, with CSPM, which watches the cloud environment continuously and catches a new resource launched after the test date.\">\n  <defs><marker id=\"hpB\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n  <text x=\"30\" y=\"58\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Pen test<\/text>\n  <line x1=\"130\" y1=\"54\" x2=\"730\" y2=\"54\" stroke=\"#eceef5\" stroke-width=\"2\"\/>\n  <circle cx=\"230\" cy=\"54\" r=\"11\" fill=\"#6b4576\"\/>\n  <text x=\"230\" y=\"32\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">One date, one scope<\/text>\n  <text x=\"30\" y=\"128\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">CSPM<\/text>\n  <rect x=\"130\" y=\"116\" width=\"600\" height=\"20\" rx=\"10\" fill=\"#e3f0e9\"\/>\n  <circle cx=\"190\" cy=\"126\" r=\"5\" fill=\"#3a6f5d\"\/>\n  <circle cx=\"300\" cy=\"126\" r=\"5\" fill=\"#3a6f5d\"\/>\n  <circle cx=\"410\" cy=\"126\" r=\"5\" fill=\"#3a6f5d\"\/>\n  <circle cx=\"620\" cy=\"126\" r=\"5\" fill=\"#3a6f5d\"\/>\n  <rect x=\"470\" y=\"98\" width=\"56\" height=\"56\" rx=\"10\" fill=\"#1c267a\"\/>\n  <text x=\"498\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" font-weight=\"700\" fill=\"#ffffff\">New<\/text>\n  <text x=\"498\" y=\"137\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" font-weight=\"700\" fill=\"#ffffff\">resource<\/text>\n  <line x1=\"498\" y1=\"92\" x2=\"498\" y2=\"66\" stroke=\"#6b4576\" stroke-width=\"1.5\" stroke-dasharray=\"4 4\"\/>\n  <text x=\"498\" y=\"84\" text-anchor=\"start\" dx=\"8\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#6b4576\">Outside the report<\/text>\n  <text x=\"498\" y=\"176\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#3a6f5d\">Inside CSPM view<\/text>\n  <line x1=\"130\" y1=\"194\" x2=\"722\" y2=\"194\" stroke=\"#4a52a8\" stroke-width=\"1.5\" marker-end=\"url(#hpB)\"\/>\n  <text x=\"130\" y=\"188\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Time<\/text>\n<\/svg>\n<\/div>\n<figcaption>A cloud resource launched the week after a test never appears in the pen test report, but CSPM picks it up on its next scan.<\/figcaption>\n<\/figure>\n\n<h2 id=\"results\" class=\"c-sage\">The results<\/h2>\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Stage<\/th><th>Status<\/th><th>What happened<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Investor security checklist<\/td><td><span class=\"pill p-yes\">Done<\/span><\/td><td>VAPT report and CSPM findings submitted, both critical items cleared with documented evidence<\/td><\/tr>\n    <tr><td>Series A<\/td><td><span class=\"pill p-yes\">Done<\/span><\/td><td>$15M round closed with Bertelsmann India Investments, Titan Capital Winners Fund and existing investors<\/td><\/tr>\n    <tr><td>Source code review<\/td><td><span class=\"pill p-yes\">Done<\/span><\/td><td>The engagement moved into the codebase, going past what the checklist required<\/td><\/tr>\n    <tr><td>Further modules<\/td><td><span class=\"pill p-exp\">Next<\/span><\/td><td>More coverage as Handpickd adds cities, customers and supplier data<\/td><\/tr>\n  <\/tbody>\n<\/table>\n<p>The last two rows are the ones worth noticing. Investor security work that begins as a diligence response usually stops the day the money lands. Handpickd kept going, because a platform that coordinates farmers, routes and households every night only carries more data as it grows.<\/p>\n\n<h2 id=\"lessons\">What other founders can take from this<\/h2>\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Investors ask too<\/p>\n    <p class=\"g\">Not only enterprise buyers<\/p>\n    <p>At Series A and beyond, security often sits inside shareholder due diligence, and it can be written in as a condition of signing.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Artefacts close checklists<\/p>\n    <p class=\"g\">Reports and findings logs<\/p>\n    <p>A pen test report and a tracked findings record answer a checklist line. A plan to get them does not.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Start before the term sheet<\/p>\n    <p class=\"g\">Lead time is the risk<\/p>\n    <p>Controls that are already running turn an investor security review into a hand-over of evidence.<\/p>\n  <\/div>\n<\/div>\n<p>The same pattern shows up on the customer side. <a href=\"https:\/\/www.osto.one\/resources\/case-studies\/insybit-security-questionnaire-48-hours-insurance-deal\/\">Insybit answered an insurer&#8217;s security questionnaire in 48 hours<\/a> and closed the deal for the same reason: the evidence already existed when the request arrived.<\/p>\n\n<h2 id=\"osto\" class=\"c-sky\">How Osto handles investor security reviews<\/h2>\n<p>Osto is one platform built and run in one stack: <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web and API protection<\/a>, cloud posture, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">endpoint protection<\/a>, VAPT, code security with <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a>, and compliance automation for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a>. When an investor security checklist or a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">security questionnaire<\/a> lands, the answer to each line comes from one place, owned by one team.<\/p>\n<p>That is what made Handpickd&#8217;s timeline hold. The controls went in first, and the evidence followed from them. The certificate is a byproduct of the security, not the other way around.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Be ready before the checklist arrives<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto puts VAPT, cloud posture, endpoint and compliance evidence in one platform, so your next investor security review starts with the evidence already in place.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">One platform, everything &middot; Security without slowing down<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n<details>\n  <summary>What do investors ask for in a Series A security review?<\/summary>\n  <p>It varies by fund, but the recurring items are an independent penetration test report, visibility into cloud infrastructure and how misconfigurations are handled, and completed security questionnaires. Some investors also ask about SOC 2 or ISO 27001 status. For Handpickd, penetration testing and cloud infrastructure findings were the two investor security items that could hold up the round.<\/p>\n<\/details>\n<details>\n  <summary>Can an investor security checklist delay a funding round?<\/summary>\n  <p>Yes, when clearing it is a condition of signing. The requirements are rarely complicated, but the work behind them takes time: a pen test has to be scoped, run, reported and remediated. If sourcing a vendor only starts after the term sheet arrives, that lead time lands directly on the closing timeline.<\/p>\n<\/details>\n<details>\n  <summary>How did Handpickd clear its investor security checklist without delaying the round?<\/summary>\n  <p>Osto ran the VAPT end to end and switched on CSPM for continuous cloud posture visibility, using modules that were already built into the platform. The evidence went back to the investors inside the diligence window. In Nitin Gupta&#8217;s words, the work was completed well within the investor timeline and the deal did not get delayed.<\/p>\n<\/details>\n<details>\n  <summary>Is a VAPT report enough for an investor security review?<\/summary>\n  <p>Rarely on its own. A penetration test report covers one scope on one date. It says nothing about how the cloud environment is configured day to day or how access and endpoints are managed. That is why Handpickd&#8217;s checklist asked for cloud infrastructure findings alongside the test.<\/p>\n<\/details>\n<details>\n  <summary>When should a startup put security in place before fundraising?<\/summary>\n  <p>Before diligence opens. Controls that are already running let a team hand over evidence instead of starting a project mid-raise. Timing also matters for anything measured over a period: a SOC 2 Type II report covers controls operating across an observation window, so the earlier they go live, the more there is to show.<\/p>\n<\/details>\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">Penetration Testing<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/\">Vulnerability Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sast\/\">SAST<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/security-questionnaire\/\">Security Questionnaire<\/a><\/p>\n<\/div>\n\n<script type=\"application\/ld+json\">\n{\n \"@context\": \"https:\/\/schema.org\",\n \"@type\": \"FAQPage\",\n \"mainEntity\": [\n  {\n   \"@type\": \"Question\",\n   \"name\": \"What do investors ask for in a Series A security review?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"It varies by fund, but the recurring items are an independent penetration test report, visibility into cloud infrastructure and how misconfigurations are handled, and completed security questionnaires. Some investors also ask about SOC 2 or ISO 27001 status. For Handpickd, penetration testing and cloud infrastructure findings were the two investor security items that could hold up the round.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Can an investor security checklist delay a funding round?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Yes, when clearing it is a condition of signing. The requirements are rarely complicated, but the work behind them takes time: a pen test has to be scoped, run, reported and remediated. If sourcing a vendor only starts after the term sheet arrives, that lead time lands directly on the closing timeline.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"How did Handpickd clear its investor security checklist without delaying the round?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Osto ran the VAPT end to end and switched on CSPM for continuous cloud posture visibility, using modules that were already built into the platform. The evidence went back to the investors inside the diligence window. In Nitin Gupta's words, the work was completed well within the investor timeline and the deal did not get delayed.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"Is a VAPT report enough for an investor security review?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Rarely on its own. A penetration test report covers one scope on one date. It says nothing about how the cloud environment is configured day to day or how access and endpoints are managed. That is why Handpickd's checklist asked for cloud infrastructure findings alongside the test.\"\n   }\n  },\n  {\n   \"@type\": \"Question\",\n   \"name\": \"When should a startup put security in place before fundraising?\",\n   \"acceptedAnswer\": {\n    \"@type\": \"Answer\",\n    \"text\": \"Before diligence opens. Controls that are already running let a team hand over evidence instead of starting a project mid-raise. Timing also matters for anything measured over a period: a SOC 2 Type II report covers controls operating across an observation window, so the earlier they go live, the more there is to show.\"\n   }\n  }\n ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>Handpickd had a Series A term sheet in hand and an investor security checklist standing between it and a signed\u2026<\/p>\n","protected":false},"author":8,"featured_media":1173,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42],"tags":[125],"class_list":["post-1170","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies","tag-investor-security"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1170","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1170"}],"version-history":[{"count":2,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1170\/revisions"}],"predecessor-version":[{"id":1174,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1170\/revisions\/1174"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1173"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1170"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1170"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1170"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}