What your agent reads.
- name
- pmf-signals-in-security
- description
- Product-market fit signals for a cybersecurity company, read off what cost the buyer something rather than what they said. Use when a founder is asking whether the company has fit or only polite design partners, whether a clean win-loss record is good news, why retention is excellent while new logos stall, whether expansion is consumption or renegotiation, whether a headline breach counts as demand, whether off-profile revenue should be booked, or which of the six round-pricing measures the company is weakest on. Not for validating the problem before building (buyer-discovery), structuring pilots (design-partners), platform absorption of the category (platform-annexation-check), or sizing the round the signals must fund (cyber-seed-benchmarks).
- title
- Product-market fit in security
- question
- Do I have product-market fit, or just polite design partners?
- subtitle
- A pipeline with no losses in it is a warning, not a good quarter.
- summary
- You cannot read product-market fit in security from what buyers say, because they are polite, deals slip rather than die, and design partners say yes because yes is free. Read it from what cost the buyer something: a paid production deployment, a recorded loss, a new customer from a cold source, and expansion nobody asked for.
- group
- company
- verified
- 2026-09-08
- order
- 59
754 / 1024 characters
This is the top of the SKILL.md file, exactly as it downloads. Your agent reads the description field to decide when to load this skill. The rest of this page is for you.
You are asking a question the general advice answers with a survey, and in security the survey lies. Buyers here are polite, deals slip rather than die, and design partners say yes because yes is free. What we have watched separate the companies that had fit from the ones that only had friends is a short list of things that cost the buyer something.
No losses is the warning sign.
You will hear "we have not lost a deal" in your own board meeting and report it as strength. It is the single most reliable warning sign in an early-stage security forecast. The dominant failure in enterprise security selling is not losing. It is slipping. Deals do not get declined. They go quiet, because a no costs the buyer a relationship and requires a justification they have no reason to write. A pipeline with no losses in it is a pipeline nobody has qualified, and the forecast is carrying every deal in it.
Force the no. End every stalled opportunity with a request that can be refused, a date, a name, a document, and record the refusals. A loss column with entries in it is the first sign you are selling to a market rather than to a mood.
Perfect retention is not fit.
You will be told that net revenue retention is the definitive measure of product-market fit in enterprise software. In security it can stay excellent inside a market too small to matter, for years. We have watched companies hold effectively no churn, expand steadily, and close almost nothing new for quarter after quarter, while the retention line let everyone in the room tell themselves the business was fine. The thing that would have told them the truth was new customers.
Report new customers separately from retention, and read that line first. Expansion inside existing accounts hides a broken new-customer engine for as long as the accounts last.
Watch what expands without being asked.
Expansion revenue gets counted all the same way, and it should not be. The accounts that grew repeatedly in our portfolio were the ones that had wired the product into a pipeline or a recurring workflow. Everything else was a static seat count that moved only when someone renegotiated it. If your expansion comes from renegotiation rather than from use, you have a tool rather than a dependency, and only a dependency survives when the buyer consolidates vendors.
Find the one product behavior that separates the accounts you keep from the accounts you lose, and make onboarding drive it. Where it was measured, the accounts that had encoded their own process into the product, through automation, extensions, or a wired-in pipeline, stayed at a dramatically higher rate than the accounts that never did. Logins and active users track effort, not value. The accounts that touch you least are often the healthiest.
The rename is the market's answer.
Iterating on positioning feels like diligence, and each new framing feels like progress. A company that cycles through category names, reopens pricing and packaging at every crisis, and rewrites its value proposition every few quarters is describing a market that is not pulling for it. Count the iterations. Past two or three, the thing being tested is not the message. The product you keep re-explaining is the product nobody asked for.
Fear is not fit.
The next breach gets planned around as if it were a growth channel. A headline incident can unstick deals already in motion and generate a wave of inbound interest, and it will not create a budget line. We have watched companies whose exact domain suffered repeated high-profile breaches get press cycles and inbound curiosity and no measurable change in revenue across years. Never build a plan whose demand assumption is the next incident.
Off-profile revenue is a loan.
Deals outside your ideal customer get taken to make the quarter, and early revenue is treated as good regardless of where it comes from. Book those deals separately. Accounts outside your profile churn at a much higher rate, and the most damaging losses arrive without warning, when a large customer cuts tools from a list rather than evaluating them one by one. Booked with the rest, they corrupt the retention numbers you will later use to judge whether the business works.
The six measures move together.
You are priced at every round against six measures moving together: revenue, growth, gross margin, an efficiency ratio, a churn ceiling, and a payback period, and the company is judged on its weakest one. There is a churn ceiling above which you do not have fit, whatever else is true. High churn is not a retention problem to fix later. It is evidence that the business is unproven. Payback tightens as you raise, and a persistently long one is a structure rather than a phase. Net churn after expansion is the number that describes the business, and which churn figure you lead with is a real choice.
The test on one page.
You have fit in security when you can point to buyers who paid, deployed in production, and expanded without being asked, who came from sources that did not already trust you, under a pitch that has held for two quarters, with a loss column that has entries in it. Polite design partners produce none of those. If you cannot point to that buyer, you have friends, and friends are not a market.
Working the question.
- Add a loss column, and force a no on every stalled deal with a request that can be refused.
- Report new customers separately from retention, and read that line first.
- Split expansion into use and renegotiation. Find the behavior your retained accounts share, and drive onboarding toward it.
- Count your positioning changes in the last two years. Past three, stop renaming and read the market.
- Mark off-profile revenue separately from the day it is booked.
- Find your weakest of the six measures before your next investor does.
Working with an agent.
Give your agent every deal you have worked this year, won and lost. Ask it how many you actually recorded as losses. A pipeline with no losses means nobody has told you no yet, which usually means nobody has been asked.
Install the skill.
You are reading the skill itself — this page and the download are the same files. Unzip it into ~/.claude/skills/ (or a project’s .claude/skills/) and Claude Code loads it when the question comes up; so does any agent that reads Agent Skills.
mkdir -p ~/.claude/skills && cd ~/.claude/skills && curl -sLO https://techoperators.com/skills/pmf-signals-in-security.zip && unzip -oq pmf-signals-in-security.zip && rm pmf-signals-in-security.zippmf-signals-in-security/SKILL.md
No terminal? Download pmf-signals-in-security.zip and drop into your assistant’s project files.
