Episode 762 ·

The Power of Partnership in Startup Ecosystems with Gil Feig from Merge & Daniel Marashlian from Drata

Today we’re talking to Gil Feig, Co-Founder at Merge, and Daniel Marashlian, Co-Founder & CTO at Drata. Gil and Daniel explore automating compliance, enhancing SaaS support, and the art of building high-EQ tech teams. Their conversation is a roadmap for aspiring CTOs, emphasizing innovation and strategic partnerships. A must-listen for those navigating the tech startup ecosystem.

All of this right here, right now, on the Modern CTO Podcast! 

To learn more about Merge, visit their website here.

To learn more about Drata, visit their website here.

Have feedback about the show? Let us know here.

Produced by ProSeries Media.

For booking inquiries, email [email protected]

About Gil Feig

Gil Feig is a technology entrepreneur with a track record of identifying and solving real-world problems through innovative tech solutions. His approach to startup success involves deeply understanding customer needs, leveraging diverse industry feedback for product validation, and prioritizing team motivation to foster a strong company culture. Gil’s leadership style emphasizes the importance of aligning team efforts with core business objectives to drive growth and scalability.

About Merge

Merge is one API to add hundreds of integrations to your product. Merge’s platform makes secure data access easy by offering Unified APIs across key software categories, including HRIS, accounting, CRM, file storage, and more. Merge handles the full integrations lifecycle — from an easy initial build taking just weeks to providing integration observability tools ensuring customer delight, and fully owning the maintenance of integrations.

Thousands of companies use Merge to power their integrations, enabling them to unblock sales, reduce customer churn, accelerate time to market for new products, and save engineering costs and resources.

Merge is backed by $75 million in funding from Accel, NEA, and Addition. Merge was founded in 2020 by Shensi Ding and Gil Feig and is proudly built in San Francisco, New York City, and Berlin.

About Daniel Marashlian

Founder. Technologist. Serial Entrepreneur. Investor.

Chief Technology Officer and Co-Founder at Drata, Daniel Marashlian specializes in tech integration and SaaS customer support, driving success through strategic partnerships and customer-centric product development.

About Drata

Replace manual GRC efforts, reduce costs, and save time preparing for audits and maintaining compliance. Drata is the world’s most advanced security and compliance automation platform with the mission to help companies earn and keep the trust of their users, customers, partners, and prospects. We help thousands of companies streamline compliance for SOC 2, ISO 27001, HIPAA, GDPR, your own custom frameworks, and many more through continuous, automated control monitoring and evidence collection. Drata is backed by ICONIQ Growth, Alkeon, Salesforce Ventures, GGV Capital, Okta Ventures, SVCI (Silicon Valley CISO Investments), Cowboy Ventures, Leaders Fund, Basis Set Ventures, SV Angel, and many key industry leaders. Drata is based in San Diego, CA with team members across the globe.

Transcript

(Intro Narrator at 00:00:00) Today, we're talking to Gil, cofounder at Merge, and Daniel, cofounder at Drata, about the art of building high EQ teams and the power of partnership. You're listening to Joel Beasley, Modern CTO.

(Joel Beasley at 00:00:19) So how did you two meet each other?

(Gil at 00:00:21) Actually, Daniel, I don't know how you found Merge to begin with. The day he became a customer of us really early on, and then we became Drata customers. Yeah, so we've known each other for like three years or so.

(Daniel at 00:00:31) Three years or so, yeah. Nice. Yeah, it was, I think, honestly, Gil knows this. So I was using a competitive tool, kind of still in evaluation mode a bit, but it wasn't working for us as well. And then, honestly, I kind of forget. I'm sure I could go maybe find an email chain, but I think it was just through a Google search is how I found it. Yeah.

(Joel Beasley at 00:00:53) How did you cross that bridge of using each other's products? Did you get on sales calls with each other? Like, how did you actually come to meet?

(Daniel at 00:01:01) The first call was, yeah, I reached out as like, hey, I'm using your competitor, and this looks super interesting. Let's talk. And, you know, within, I think, five minutes, I got a response from both Gil and Shensi. And it was like, alright, let's talk. And, you know, within the hour or whatever, we were on the phone and talking about challenges, not only the issues that we were trying to solve at Drata, but then challenges with one of their competitors and why they differ. And I could just tell Gil and Shensi were cut from the same cloth as me and just the attention to their customers, their care, their product, especially on Gil's side, the technical knowledge he had about his space. It was like, oh, wow. Like, I could see myself, vice versa, working with Gil or Gil working with me, like, tomorrow. And it's like, well, he has this amazing company, and it's exactly what we need. Let's partner up.

(Joel Beasley at 00:01:52) Can you give me the super high-level overview of the problem you were experiencing, why it wasn't solved, and how they were the solution?

(Daniel at 00:01:59) Yeah, for sure. So at Drata, we help companies automate their compliance programs, more specifically by automatically gathering the security control evidence. So if your company says they do something, how do you prove that you do that? And a lot of times it's through screenshots and meetings and files and just boring stuff that no one wants to do. And so what we do is we integrate with all these infrastructure tools and version control and HR systems and all the things that operate a technology company. And in infrastructure, there's a bunch of players, but primarily, there's three players, AWS, Azure, and GCP, the Google, Microsoft, AWS, Amazon. And then, you know, in version control, kind of the same. There's three major players with the long tail of niche players. And then, but in the HR world, there's like, once I dove into it, it was like, there's like 40 players. And it wasn't like, I think in some sectors of small business versus large business, there's clear winners. But at large, it's very fragmented. And so from my side, I needed to integrate with them to go automatically gather this evidence for your compliance program. And it was, like, again, Azure, GCP, AWS. It was like, alright, like, we'll go integrate with them. No big deal. That's what we do as a core business. But once it came to the HR world, we integrated with one or two, and it was just like these companies, I think by large, they're like HR companies. They're not like deep technology companies. So they don't either have APIs or their partner programs were kind of not as mature, and so it was hard to work with them. So I got introduced to a competitor through one of my investors. And, you know, I worked with them. I was like, oh my god. This tool, God sent, is exactly what we needed. And so then I started integrating with it, and I just kind of realized it was like, well, you know, a great startup and cool tech. It just wasn't exactly what we needed at the pace that we were growing in a very early stage even still with us. And the technical knowledge and depth that these very unique problems in the HR world had, it was like we just kept running into issues that, you know, company kind of just wasn't as attentive as we needed them to be from a partnership, a customer support perspective. So I was like, I wonder if there's something better out there. And that's, again, how then I found Merge and Gil and Shensi, and I could just tell within five minutes, it was like, oh, they really understand this problem. They really understand the nuance of humans and the way that you would object model all the intricacies of an employment engagement with the company from, you know, your employment status to start date, end date, and the ever-changing flow of contractor to full-time and back and forth and furlough and all this crazy stuff that we all deal with running companies. So but to automate all of that from an engineering compliance perspective, it's like we do really need to understand all these details. And then every single company is unique and different in the way they model that. And so that's kind of the point of what Merge did is they unified all of that. So that was, it just made it easier. I think, again, we kind of are cut from the same cloth, solving boring problems in a way that engineers don't want to do. It's like, just solve it for me. Like, I don't want to think about that space. So in that world, like, I didn't want to go integrate with 40 plus HR systems. And now, you know, we're using Merge even more from the identity side and ticketing side. It's like, I don't want to deal with that. Just let me integrate with Merge once and move on so I can go build my product and solve my customer problems.

(Joel Beasley at 00:05:43) Nice. And then, Gil, you're a customer of that product. Tell me about his product.

(Gil at 00:05:47) Yeah. So Daniel described Drata well, but it's been absolutely massive for us. We use it to automate all of our compliance. And for Merge, we knew that we were going to need our SOC 2 certification before we ever even really came out of stealth. And that's just because we deal with really sensitive data. We have PII. We have employees. Some of our newer categories like ticketing, we have full roadmaps with our CRM. We pull in people's entire sales data. Everyone they've ever sold to or spoken with, all of that data is accessible. And so we have to be on top of security compliance, and without Drata, it just wouldn't have been possible. And what's really cool is, you know, it automated all of our evidence collection. So that helped us get SOC 2 Type 2. But what we didn't expect was as we went along, we got asked for more. So we got asked for ISO 27001. We sell now into the medical field. So we've been asked for HIPAA certifications or HIPAA compliance. We've been asked for GDPR. And every single, you know, I think what's been really cool is because Drata kind of compiles all that evidence into one place, as we had our first one, getting the next one, it was like, hey, you are already 80% complete. You know, like, when they say automation, they mean it. Right? It's really kind of everything's tied together. So you can see on the circle, like, you're 80% of the way towards, you know, ISO 27001 because you have your SOC 2 Type 2. And then we just went in, filled in the blanks, did the last few things. Our auditor was able to go into Drata and view most of the evidence, so we didn't have to manually hand that over. And we've just continued using it more and more. It's really cool because we get asked for new ones now, and our security team can actually just come to us and be like, this is going to take us exactly x amount of time, and I can see that in Drata. So use it from the beginning. Plan on continuing to use it. It's been really, really exciting for us and huge for selling our product as well.

(Joel Beasley at 00:07:29) Nice. Nice. Dude, you guys are your companies like similar levels of maturity? It sounds like it.

(Daniel at 00:07:35) Yeah. Pretty similar. I think we're just a little ahead of them, but not by major. Not by major. I think the programs, like, yeah, we have more employees, but I think the programs and the process, both of us, I think Gil and I had the same mentality. Like, I was going into starting Drata as like, we're building a cybersecurity company. Like, we better be on top of our shit. And for the same reason, like, we are holding, you know, the vulnerabilities of our customers and the issues and their risks of their business. And so not only do we need to secure that data as much as possible, we're also building a tool for the industry. So we want to put our best foot forward to show the industry how to do it. So from day one, we were using it and building the program and people around it. I think Gil had the same mentality of building what they did. So, like, from very early on, whether Gil managed it himself, and I know he now has security, you know, team, but it's like the program and the process was always there. You know, but I think in terms of just, you know, maybe company momentum and stuff, we're a little ahead of them. But, you know, you guys are trailing right behind us. So—

(Gil at 00:08:38) Yeah. Drata's doing really well. I think one thing that's been really noticeable to me too, and I think me and Shensi both attribute a lot of our success to Drata and their early team especially because, you know, like, of course, they were an early customer, but I think they also sort of beat this quality mentality into our culture. They have an awesome team. From the beginning, they brought along some of the best people that they knew. Their QA engineer was so hard on us, but for such good reason. We still are so thankful for that. In fact, you know, when they came to us, they were just like, we want a reliable product. And I was, Daniel doesn't know this. I was actually at a friend's engagement party, and you guys were just onboarding onto Merge. And one of their QA engineers was going through and found one little bug, just like a slight mapping issue. I turned to my friends. I was like, I'm leaving. I'm going home right now.

(Joel Beasley at 00:09:31) Woah.

(Gil at 00:09:31) Me and Shensi got on the phone. We drove home, and we fixed it together and had it working within like twenty minutes.

(Daniel at 00:09:37) Yeah.

(Gil at 00:09:37) But I think that was really important to us because that stuff does matter. It's those things that people notice. Merge, I think it just came out today. We're the only leader in the G2 quadrant, and it's because we obsess over our customers. We viscerally feel it when there's something wrong, and we will not let it stand. We'll go fix it immediately.

(Joel Beasley at 00:09:56) Now were you, Daniel, were you sad when Gil left you guys and moved to the East Coast?

(Daniel at 00:10:03) Totally. But, no, I think they've done a great job at, you know, I think splitting between the country and they still have a good office presence. So anytime I'm in New York or San Francisco, I always try to reach them out and get lunch or something like that.

(Joel Beasley at 00:10:19) Yeah. I'm assuming you guys, like, have hung out in person.

(Daniel at 00:10:22) Yeah. Yeah. A couple of times.

(Joel Beasley at 00:10:23) Cool. Yeah. So those are some of the best relationships ever. Yeah. I've been doing this podcast for like seven years, 700 something episodes. And there's like a handful of people that I've gotten to meet and be friends with in person. And those relationships are just always so interesting. You always before you have them, you always kind of, like, imagine what they'll be like, and then you're like, oh, it's kind of like work friend thing, but the only friends I have kind of are like work friends or my kids' sports friends and things like that. Because it's cool. You gotta spend, work is long. You gotta spend time with great people. Yeah. We have a lot of CTOs and technical leaders that listen to the show. They're listening for a variety of reasons, learn about new products, learn about what you guys are doing, find interesting people, getting to hang out with them on their commute or whatnot or their run. And they always reach out and ask us questions. They want advice, things like that. So I've just got a couple advice-for-CTO questions if that's okay with you guys, and I'll let you just jump in and take it. Alright. How do you source feedback on features after launching them?

(Daniel at 00:11:29) So we use a tool called ProductBoard. I guess, shout out to ProductBoard. It's almost like this Reddit-style voting thing of, like, you know, seeing the roadmap, voting on more importance to you. Also, you can submit, you know, your ideas and your asks. And then behind the scenes, right, we attribute who that is, what customer, what's your ARR, for prospective customers or current customers. And it really helps our product team kind of gather and group the importance of this. Like, we have a little north of 4,000 customers now, and it's, you know, one person saying one thing, while very important, like, I need to measure that across 4,000 other customers. While at the same time, again, just like Gil said, we are customer obsessed. And it's like, I need to make sure that that one customer is heard, but at the same time, because what I don't want to do is just, like, our product team just kind of count them off because it's one customer versus 4,000. So it's like this ever, you know, ebbs and flows balance of this really important idea versus the aggregate of a whole to understand, like, oh, this is attributing to $10 million of ARR. That's a more important problem than a, you know, $200,000 ARR problem from a retention perspective or something like that. So there's always that balance that we have to do, but I think that's a super important one that we do is we use a tool, and that ProductBoard tool to kind of judge that a bit. And then the other thing that we do is we actually have dedicated two teams. It depends on the domain of the work, but we call them our customer obsession teams. And what that is is all of the input from our tech support, from our solutions architecture, from our sales engineers. Like, if there's an actual issue or a really good idea that's not like a major product feature, just like a little delighter or something, those go into the queue of this customer obsession group. Every single day, our head of sales engineering, solution architecture, and the product managers of those teams meet. They continuously measure the impact, like I said, through ProductBoard and ARR and all that stuff. And then they, almost in a kanban style, rank the importance. And those two pods, those two teams will attack those issues, those customer delighters, and those teams crank. Because usually, a lot of times, it's like, like Gil said, it's a little mapping issue or it's a little, I'll just be silly here, like, make this button over here, whatever it is. Right? Those things, you know, sometimes when you're going to go build the major integration, like, so, actually, we just enabled, I think, like 25 or something integrations with Merge the other day. You know, that was a project. We had to go build it and test it and whatever. A little feature or little tiny customer issue might not ever win in terms of priority of that big feature that that one team is working on. So we have two dedicated teams that just work on those little things. So, again, feedback, consistent feedback, whether positive or negative. If there's an issue, we triage those extremely fast for a larger organization that we are. So I would say those are two kind of ways that we listen to customers and address it as fast as possible.

(Gil at 00:14:36) Yeah, I would actually weigh in here. I think we have a pretty similar process, albeit at a smaller scale. Of course, we're smaller. And the customer obsession, I think it stems from a real problem of things pop up that you can't necessarily just stick into your priority stack, but they have to get done.

(Gil at 00:14:52) And that's where we are too. Obviously, we're not asking our team to leave engagement parties anymore to go fix a small bug. So we handle this view of what we call responderships. It's like a second on-call. So we have on-call. That's uptime. Are things working? But then we have one called responder, and this is mapping issues, bugs, small little things, potentially ones that are getting in the way of users being able to do what they want, but probably not a P0 downtime. That goes to the responder. They handle that. They tackle it. And I think it accomplishes a similar thing. And with scale, that will likely become a team or a bigger group of people, I would say.

(Gil at 00:15:29) The other one that Shancy and I have both been doing is we felt, I think, going through a lot of our product board feedback, that we could see a big picture. We could really understand the ARR, but I felt like we had lost the visceral touch with our customers of really understanding that pain. So I try to, at least twice a week, do a 15 to 30 minute call with a customer in varying stages of NPS. So sometimes I'm talking to someone really happy. Sometimes I'm talking to someone who recently ran into a bug and is relatively upset. And just hearing from them, the words they choose to use, the emotion that comes from that, I feel like I've been able to really associate what I see in product board with that sentiment and understand a little bit beyond the dollar value. It's not perfect. We can't just fix something because someone's angry, but it at least gives us that additional nuance.

(Joel Beasley at 00:16:18) Are you doing the net promoter surveys? Are you running those? How often do you run those?

(Gil at 00:16:24) So we keep ours in our product permanently, and we surface it. I think it's upon a certain action. So once you've gotten beyond a certain point of implementation, that's when their feedback really matters to us. And it just pops up for everyone in the platform. We make it super easy. It sends to our entire team on Slack for them to all understand. Everyone's responsible for NPS, so we want everyone to be in the loop there.

(Daniel at 00:16:46) Yeah, very similar. It's in product. It's based on a certain onboarding threshold. And then I think it's every six months after that or something. I forget the exact setting, but it's something like that. And we're actually looking into a different tool to deliver those from what we use today. And I think from that other tool, we can also deliver them out on email and stuff like that. But for right now, it's just in-app.

(Joel Beasley at 00:17:12) Oh, very cool. Very cool. So that's one of the key things that you guys do to manage your customer satisfaction and retention, in-product and soon to be in-product plus email.

(Gil at 00:17:24) Yep, exactly. And if someone rates below a certain score, we immediately reach out. We want to understand. We had something automated, and I think we weren't quite getting the responses we wanted. And it's really hard to manage at scale. But right now, we do have someone manually reaching out being like, "Hey, this is your use case. Just so you know, I'm not a robot. Let me talk to you about why you rated us poorly."

(Daniel at 00:17:44) Yeah. I think one other thing we do, there is the tooling and the surveying, and that's to report on it. But other things that we do is, we have a whole data team that pipes in all of the product usage data, sentiment data from NPS, and overall, just your customer health. And as those, from our algorithm call it, turn from green to yellow to red, we're taking a very close eye on that. And most of our customers have a CSM. I think if you're under a certain dollar threshold, you're kind of in a shared CSM pool. But for the medium larger customers, you all have a designated CSM. And so from there, those that book of business that that CSM has, and also the pairing account manager, they're looking at those health scores and we understand, and then we double-click. And so now you double-click and you look at their NPS. You look at their product board feedback. You look at their sentiment with support and their conversations there. And it's like, okay, here's the theme of what's going on. How can I better aid, better touch point? And it sounds like that's what Gil is doing as well on his side.

(Gil at 00:18:51) Yep, that's exactly it. It sounds like we have the same process. We basically have a formula. We use a platform that does, alright, 20% of the score is influenced by have they onboarded to this point? 20% of the score is influenced by just their CSM's read on their sentiment. How many support tickets? All that just totals up to what could be 100%, and then they get green, yellow, red scored based on that.

(Joel Beasley at 00:19:12) Yep. Do you both use the same customer health platform?

(Daniel at 00:19:15) I don't know. What do you guys use?

(Gil at 00:19:16) We use Vitally.

(Daniel at 00:19:18) Oh, okay. No. We're using, oh my god, what's it called? Catalyst. Catalyst.

(Joel Beasley at 00:19:23) Catalyst.

(Daniel at 00:19:23) No, I think a lot of them are similar, right? And they have different features and purposes, but no, we're on Catalyst.

(Joel Beasley at 00:19:32) So that's pretty cool, like an API and all your different platforms, and it can check your customer across everything.

(Daniel at 00:19:37) Yeah. Sometimes, on our side, just the various data inputs, we have some of it pipes in from the data warehouse, and there's a model around that. But, again, that's 20% of the overall, like you said.

(Joel Beasley at 00:19:52) And how do you stay, Daniel, how do you stay connected with the customers? Do you do regular customer calls?

(Daniel at 00:19:57) I try. So what we have at Drata, again, across the larger base is a little hard to talk to everyone. But especially on the—

(Joel Beasley at 00:20:05) You can't talk to 4,000 people in a day, right?

(Daniel at 00:20:07) I'd love to.

(Gil at 00:20:09) What are you doing this weekend?

(Joel Beasley at 00:20:10) I know. Yeah.

(Daniel at 00:20:10) That's true. Coding. But no, what we do is we actually have an executive sponsorship program for a certain dollar threshold. So if you're over a certain threshold, I actually forget what it is nowadays, amongst all the VP-pluses, there's a distribution of you're attached to one of these accounts. So, sure, to be there at times of trouble, absolutely. But hopefully it's even when they're green and, more importantly, when they're in a healthy state, is just to build that relationship and to, therefore, if anything ever comes up, right, they know the face. They know who to go to. They know how to escalate through an executive channel. So of those accounts that I'm attached to, I try to talk to, I rotate those, and every quarter I touch base with all of them. I think I have 20 assigned to me. And then when I go to trips, San Francisco and New York, I usually try to line up one or two of them. The last time I was in New York, I actually, for a co-event we did with Merge, then I think the day after, I went and saw four different customers at their offices or coffee or whatever. It was awesome. It was so good.

(Gil at 00:21:14) Four in a day was insane. I was like, "Daniel, when are you leaving?" He was like, "Yeah, I have four customers." So I was like, "Next week?" "No, tomorrow."

(Joel Beasley at 00:21:20) Yeah, tomorrow. At least you stayed the night, right? That would be crazy. Four customers, then a flight out, you'd—

(Daniel at 00:21:25) No, I did actually. Yeah, that actually—

(Joel Beasley at 00:21:28) Dude, do you have a family? Do you have wife, kids?

(Daniel at 00:21:30) I have a wife. No kids or anything, but she's understanding for sure. But it was a short trip. I think I went, it was just like a three-day trip to New York, so it's nice.

(Joel Beasley at 00:21:39) Nice. Promises when you're pitching new clients. This is a common age-old tale of, "Yeah, we can do that," and then running back to engineering. "Hey, we need to learn how to do that." How do you guys handle that? Are you past that? Is that still happening out there in the marketplace?

(Gil at 00:21:54) I personally have a rule: no dates. We don't share dates with anyone. We don't promise dates. We can give people approximates, but we have very specific wording that our team is required to share, and it must be completely honest. We think it's better to not sign a customer than to have a pissed customer. So we don't want to lie. We don't want to end up in a bad situation. So generally what we'll do is we have a public roadmap. We're willing to share what comes up. We say, "Look, subject to change, things can be inserted above it, but this is where it lies. This is how many people have asked for it." We try to be as open as possible with that information. And, candidly, we are always building. We are always launching new things. But there's nothing worse, and I'm sure all of us have been in this position, but nothing worse than a situation where a customer comes here and, "You promised this was coming, and it's not here. Your platform is either useless to us or," maybe they'll exaggerate, "but it's useless to us or just, I don't want to be a part of it anymore."

(Daniel at 00:22:44) Yeah. We've all been there. That ever-ending battle between engineering and sales. But Drata's in the business of trust. That's literally our ethos. That's our number one core value. And so when we started that, it was a very strict conversation with the sales leaders and the sales members, too, of, "We cannot do that age-old—" Even in the very early, our first 20, 30, 40 sales, like, I get it, you're going to future-sell. But at the same time, and I'm all for that. But I think at the same time, as long as there's a very clear understanding of what that roadmap is in the next quarter, if you're selling something beyond the quarter that's already actively being worked on by engineering, we need to not do that. And we've held a really good job. I think, to be honest, what that happened one time. And it was from a sales member, and we worked with that person and corrected that customer, and that wasn't fun. But it was a great lesson to learn for everyone. I think that was when we were a little larger, right? And, you know, whatever. Again, salespeople will do that, close the deal, get the commission. But nevertheless, it was a minor issue, and it was resolved. But I think with us is I actually am a little bit more open to future-selling, but as long as it's within that quarter and engineers and the R&D team is already actively working on it. Again, yeah, we won't say "This is on the seventeenth, and it'll be live then." But it's like, "No, we're actively working on it. We have a pod or two working on this, and our plan is this quarter," right? And therefore, I'm totally okay. And because a lot of times what happens is by the time you sell, you close the deal, you implement, you go do the basics of Drata of connecting your identity provider, setting up your policies, by the time that's all done, that month or six-week window has already passed, and you're good to go.

(Daniel at 00:24:17) What we've done actually twice in the history of Drata is, to close a deal, engineering didn't, or sorry, sales did need to come to R&D and say, "Hey, should we walk, or can we do this?" And then it's a decision of product and engineering leadership and looking at the roadmap and saying, "Okay, well, we really want this logo. What has to slip?" And we have actually made that decision twice, and it was in the contract by a certain date. And we've hit them both, which is great. But those are very strategic decisions. And so we have certain fields, we use Salesforce, certain fields, and it is in this review of what was promised or what's contractual. We, again, we tried never to do anything contractual. We've done it twice. But then if that happens, it's like, okay, it's a very strategic thing, and we move other things out of the roadmap.

(Joel Beasley at 00:25:25) Yeah. When you get some of that more money, you get more money. Yeah, it's like, how much is it possible? "If you guys want to build a rocket ship, it's possible. Yeah, just write a check. We'll get started."

(Daniel at 00:25:35) Yes. Yeah, yeah, exactly. But, I mean, you know, sometimes that, even though how big the check is, it disrupts for one customer, it disrupts, in our case, the 4,000 others. So yeah, so it's a big strategic decision.

(Gil at 00:25:48) Yeah, we've also, one other thing that we've done on that case, like Daniel said, there's certain deals that we just don't want to lose, and the team's going to come and ask, "Can we commit to this?" We've had a couple where we were able to do little workarounds, which is not something we'll do often, but we'll do it for a larger contract. There's one instance where someone just wanted really advanced analytics that we didn't have built into the platform. We didn't want to build out dashboards, but we literally already had an internal Looker dashboard that showed exactly what they wanted. So we just set that on a schedule to email them weekly. We'll do things like that. As long as the customer agrees to it, we can move forward. So we've had workarounds with that, workarounds that required a little bit of manual intervention until we were able to build something in the product.

(Joel Beasley at 00:26:28) Dude, what does Drata mean?

(Daniel at 00:26:29) That's a fun story. Do you want to hear the fun story or the boring story?

(Joel Beasley at 00:26:33) The fun one. Leave the boring one at home.

(Daniel at 00:26:35) It stands for Daniel Really Automates the Audit.

(Joel Beasley at 00:26:41) Did you really, are you serious? You're going to be a dad. That's such a dad joke.

(Gil at 00:26:44) That's what it stands for?

(Joel Beasley at 00:26:45) That's what it stands for?

(Gil at 00:26:47) That's real?

(Joel Beasley at 00:26:47) That's real.

(Daniel at 00:26:48) That's real. That's what it stands for.

(Gil at 00:26:49) Wow.

(Joel Beasley at 00:26:51) Do you have a co-founder?

(Daniel at 00:26:53) Yeah, we have two other co-founders. Yeah.

(Joel Beasley at 00:26:55) And they were cool with that?

(Daniel at 00:26:56) They were.

(Joel Beasley at 00:26:56) Are you the primary co-founder?

(Daniel at 00:26:58) Question is, why is A the logo mark of Drata? And the secret to that is because the name stands for me, right? It's Daniel Really Automates the Audit. Adam, our CEO and co-founder, I was like, "Well, the A is kind of the coolest character out of all of them." So I was like, "Alright, A will be the logo." So A for Adam.

(Joel Beasley at 00:27:16) It does kind of look like a spaceship company or something on its own. It looks cool.

(Daniel at 00:27:20) So that's a, yeah, there's a little subtle space theme everywhere is Adam, our CEO and co-founder, he's a former rocket scientist literally for NASA, space shuttle program, all that stuff. So there's always a little homage to him and a little—

(Joel Beasley at 00:27:36) Tell him Joel picked up on the space name. I like it.

(Daniel at 00:27:39) Well—

(Joel Beasley at 00:27:40) Oh, man. Alright. So how do you keep your engineers happy?

(Daniel at 00:27:45) Yeah. You know, I think a lot of it on our side—we're a remote company, a little different than Gil's, so maybe I'll have a different answer there. But, so we have about, just purely engineering, so anyone under me, is about 250 or so. There's another 50-ish on product, product design, whatever.

(Daniel at 00:28:02) So how do we keep them happy? I think we do twice a year, I think, definitely once a year, big gathering of the entire team, which is a lot. So we have a technical and the technology group, the strategic offsite there. We're actually doing it upcoming here in March, which is great.

(Daniel at 00:28:20) And so I think just those personal gatherings are really cool locations, but strategic nevertheless and still have a little bit of fun time together. That's great. I mean, they know what they signed up for. They know they're in a remote company. And then we do twice a year more for the product side and then engineering leadership, kind of a product strategy as we look forward every six months on the roadmap.

(Daniel at 00:28:42) So I think there's—you know, very high level answer though is, you know, I think specific team gatherings there and strategic offsites. That's one way. But also more at the technical level is, again, just that whole—I think a lot of people have said it in different ways, but that kind of one-way door versus two-way door decision kind of matrix. It's like push the decisions as far down as you can in the org. And so giving the engineers autonomy, letting the pods make those decisions. And, I mean, still needs to align to the overall strategy of the directorship of that domain or the whole org. But I think a lot of people enjoy that. And shipping daily and not just working on stuff that goes to waste.

(Daniel at 00:29:28) And, you know, I think, I mean, no offense to the larger companies out there—

(Gil at 00:29:32) Yeah.

(Daniel at 00:29:33) Y'all are large for a reason, but, you know, I've heard too many stories of engineers where it's like, I worked on something for a year, and we just threw it away. Like, that's just not fun. Imagine, like, painting your masterpiece and then someone just burning it at the end of the year. So I think, like, that value of, go build something, literally ship it the same day if you're ready. I don't care.

(Daniel at 00:29:54) So I think that's a really fun thing for people to do as engineers.

(Joel Beasley at 00:29:58) Yeah. As an engineering leader, I remember one of the best compliments that I'd gotten was someone said, oh, it's so much fun working on a product that actually has users. Yeah. I was like, oh, wow. In the startup world, you build a lot of stuff for many years just wasn't getting out there until it became popular to ship fast and to get users quickly, until, you know, lean startup, until all that stuff hit the mainstream.

(Joel Beasley at 00:30:22) People were holding things, you know, in stealth modes for, like, infinity, and they were never seeing the light of day. And so that's—my job is to make the customers happy. Right? You just get someone the product as quickly as possible and then watch how they're using it.

(Daniel at 00:30:36) Absolutely.

(Joel Beasley at 00:30:38) Now people talking about a single role such as PM or PMM being the voice of the customer—agree or disagree?

(Gil at 00:30:46) I disagree. I think everybody at the company is the voice of the customer. We all need to be familiar. We have our engineers watching Gongs. I don't think it's right to shield anyone at the company from what people are saying, good or bad. And I think everyone has a responsibility to be really connected, especially, you know, like Daniel mentioned, we're not trying to dictate exactly what all of our employees should be building, but they have to make good decisions, and that means they need all the data available to them. So I think, you know, going to the team with, our goal is to get NPS up 10 points, or our goal is to increase average contract value or to reduce churn or whatever it is—our team needs to understand, first of all, why. So why is this thing coming up?

(Gil at 00:31:27) If they know our customers and if they know how everyone feels about our product, they understand those goals innately. But then from there, they're actually able to come up with the right tasks, the right action items. And we've seen that. We've really moved away from dictating top-down what we're doing, and even dictating top-down what our goals are, and more so—you know, I think we have high-level company goals, but more so letting the teams come up with their personal team goals and individual goals that level up to that. And that's been really, really important for us.

(Joel Beasley at 00:31:55) And what are Gongs?

(Gil at 00:31:57) Gong. So we use Gong, which is a recording tool. They're also a Merge customer. But, essentially, it joins all of our sales calls and it records. And the purpose of it is not for us to be creepy and rewatch calls or anything like that. It really is AI-driven coaching. It does give our team a chance to really understand what's going on. So, yeah, we have engineers who are like, you know, I'll have them come to me and be like, I don't understand why we're building this feature that only one customer asked for. And I'm like, go search Gong for the name of this feature, and you'll see it's come up in 50 calls. You can push play, and it'll jump to the moment the customer says what they want and why they want it.

(Gil at 00:32:33) And it gives people a visceral understanding of how our customers feel beyond anything that any internal doc could really do.

(Joel Beasley at 00:32:40) Whoa. That's pretty cool.

(Daniel at 00:32:41) So we've used Gong since we started Drata, coincidentally. And, you know, over the—I don't even know the count of companies we've talked to now, probably 10,000, 15,000 or something. And every single one of those conversations has been recorded. And imagine being able to, as you said, search for a specific phrase or competitor name or whatnot, being able to, as a new sales member, as a new engineer, be able to go watch that. How did—how does—how did my peers—or let me go watch, hey, who's the—I'm a new sales member at Drata. Who's our top rep? Oh, it's this person. I'm gonna go watch their Gongs for the past, you know, their recorded sales conversations for the past 90 days. Like, how did they close that one deal?

(Daniel at 00:33:24) What is—what's their methodology? How are they successful at Drata? There is a very direct correlation. And then internally, as an administrator of Gong, you see, like, who's watching what and hours played or whatever. There's a very direct correlation of the better successful account managers, customer success managers, account executives—there's a correlation of who watches Gong and recorded videos the most. So it's like it's learning, and it's adapting, and it's not coming into just, I know how to do things my way. It's like, what's working in this company, and how can I put my spin on it and make it even better?

(Gil at 00:33:57) Yeah. And not to gush about Gong more, but before the LLM boom recently, like, they were the only great example of AI that I have among the tools I use. Like, they really brought AI into true functionality that had real cash ROI. It was incredible. And now they've added LLM and some other, you know, new features on top. And you can do things like, hey, you know, Gong, what are the chances that this deal closes this year? And it'll be like, well, in the second call, this person said this, but they don't seem like an advocate for Merge. And the detractor in the deal said this in this call. I trust them more. I would say it's very unlikely they're gonna close this year.

(Gil at 00:34:36) It's really good.

(Joel Beasley at 00:34:38) That's crazy. Now here's my view, not research-backed, not intelligent at all. Here's just what's in my head as far as Gong. I was following these guys. This is years ago. I was following these guys and they were doing a couple different projects, and some of the different projects had good branding, and one of them was Gong. And there was, like, this super basic, like, probably MVP day one landing page. And I saw it and I was like, that looks really cool. That looks crazy. And it did something—I can't remember exactly what it did, but it was kind of in the area. And then, like, three or four months go by, and then I saw it again, and then I saw it again, and then it kind of emerged, and it was doing some, like, audio detection. And they were, like, real big, I'm like, audio, audio, audio, audio. And then it was, like—and I just kept coming across it, I think because I follow one of the founders. I'm not sure, though. And then it just turned into this, like, giant thing that, like, everybody knew about really, really, really quickly. And you're exactly right. They figured out, probably because they started with audio from—in my brain, they did. They figured out the speech-to-text stuff and then how to do cool things real early.

(Joel Beasley at 00:35:40) And then now, now it's just gonna be commoditized, but they're still the leader. They're still gonna lead the rest of the world. So that's my view of them.

(Daniel at 00:35:47) Yeah. They're doing a good job.

(Joel Beasley at 00:35:48) Do you know them? Do you know their CTO?

(Daniel at 00:35:51) I don't. Yeah.

(Joel Beasley at 00:35:52) I know them.

(Gil at 00:35:53) They're—I mean, their team's as impressive as their product. And we've evaluated competitors. Like, when we were going in, we didn't—just nothing compares. Their competitors keep getting acquired and then just, you know, run down to the ground. And they're the only ones really just doing it super well.

(Daniel at 00:36:08) Yep.

(Joel Beasley at 00:36:08) Nice. Are they are they technical guys by default, or are they sales guys? Like, are the founders sales guys? I think the founders are sales guys.

(Gil at 00:36:15) Yeah. Yeah. Yeah. But their CTO now is super impressive. Like, they just have it all around, just well-rounded good team.

(Joel Beasley at 00:36:22) Yeah. Well, the sales guys make the money, so you can hire really great people.

(Gil at 00:36:26) And they're good at sales. So—

(Joel Beasley at 00:36:28) They're great at sales. Yeah. So it's kind of cool to watch them and a couple products that they were around or whatever and then see that one emerge and take off. And, you know, I've seen so many smart people that will hire bad teams and then their products just don't do well. And then you've gotta have that mix of, like, the smart people and the smart money and the great team and the market pressure, and it's actually kind of hard.

(Joel Beasley at 00:36:51) That's why—

(Daniel at 00:36:51) Oh, yeah.

(Joel Beasley at 00:36:52) The VCs gamble.

(Gil at 00:36:55) I've watched some of my favorite products that I thought were the best product that had ever been built in a certain space. I was like, they sold us this product for way too cheap, and then it was gone a year later.

(Joel Beasley at 00:37:07) Oh, no. Yeah. Oh, no.

(Gil at 00:37:08) Gotta be able to sell too.

(Joel Beasley at 00:37:11) What is—one that is 100% accurate. That that's my life the past seven years has been learning how to sell. So, Daniel, I don't know if I shared this with Gil, but previously—so I have software engineer 15 years, built engineering teams, then wrote the book and the podcast and all that happened. But through that, I built some engineering teams up to about 30 people a couple times. And I was always, like, the technical cofounder. Yep. Just the nerd guy that could make it happen. Yep. And the sales business partner. Problem is every time this company's kept selling or exiting or whatever would happen to them, they made all the money. I didn't make any of the money.

(Joel Beasley at 00:37:46) I mean, I made some money, but, like, not compared to what they did. Right? And that's because they knew sales. They knew how to do sales. They knew how to grow the business, sell the business. And so I said, alright. This is what I'm gonna do now. And so now I'm on that adventure now. So it's crazy.

(Daniel at 00:38:00) Yeah. I've always said to a lot of CTO, like, you know, aspiring CTOs, entrepreneurs, especially on more of the technical end that I have a deep connection with, it's like it obviously depends on the situation in the business. Like, if your cofounder or partner put a million dollars in and you're just coming in with your skill set, like, there's something—cash is still king. I get that. But all things equal, like, there should be an equal share, right, on the technology side. Like, you guys are gonna be building a technology company together. The technical part and the leadership and sales side is equally as important. So that's how we all started Drata. And, again, like, in our last company, the same founders at Drata were founding of a company about a decade ago called Portfolium in the educational technology space.

(Daniel at 00:38:47) And Adam, our CEO now, CEO then, you know, he started the company, invested in the company, like, about two years prior to me joining. He was kind of bootstrapping himself, and there's a lot of value to that. Like, I wasn't there. I didn't put up money. I didn't not get paid for two years. Like, when I started with him, even though as a cofounder, I was making money. Like, I was—I forget. I think it was still, like, $75,000 or something. But, like, you know, I think he was, like, on paper—because we had a real company—had to pay him something.

(Daniel at 00:39:18) So he was making minimum wage for, like, a year. Right? Until we raised a round or whatever. So, you know, I valued that a lot, and so we didn't have an equal share there. But in situations prior to that and then at Drata when we started the company, it was an equal share kind of situation because we all had equal parts even though different disciplines.

(Joel Beasley at 00:39:36) Yeah. What is one commonly held belief in the SaaS industry about customer-centric innovation that you think is wrong?

(Gil at 00:39:44) I think one thing we just kind of went over was that you need to drop everything for your customers at any minute. You really do need to prioritize. You know, you're gonna have people just asking for a lot of things all the time. You can't do all of it. One big lesson for us along the way has been really just listen to the problems, not the solutions that they bring to you. A lot of times, you know, they come to you—your customer comes to you with a problem. You have solutions that are actually gonna tackle multiple problems at once or solve in a much better way. And that's why I think it's really important to centralize all of these incoming, you know, requests and asks. And, you know, like Daniel said, they use Productboard.

(Gil at 00:40:16) We use something very similar. By doing that, we're able to figure out what we can knock out with one stone. So, yeah, just—you can't do everything. You have to do what's gonna be the highest impact. You have to be really smart about how you do it.

(Daniel at 00:40:29) I heard this quote once, and it was funny to me, but I think it's—after, you know, two decades of building companies—it's so true, is that the customer is God and the customer is weak. And I think it's—they don't—they are like the—it's that customer service mentality, and you need to service your customer and make them happy. They're the one paying you. They're the one renewing your bill. A lot of times, the customer doesn't know exactly what they want, and you need to guide them down the path to the future. So, even though they have these requests and needs, a lot of times, as example, in a larger organization, maybe it's the more ICs, right, the individual contributors and the people owning the tool or doing some process versus the strategic buyer at the executive level that's like, no, we need to adapt this methodology and this tool to make us there. And there's a gap even internally in their organization. So while the feature requests or conversations are happening from the ICs, you know, always tying it back to the economic buyer, the strategic champion within the company.

(Daniel at 00:41:35) I think that's a super important lesson to just, like, don't just do everything that everyone's telling you to do. Let's make sure that we align on the success criteria, why you purchased our software. What were your goals of—you know, how can we help you achieve what you're doing, and are we doing that or not? And if we're not, absolutely. Let's talk to the ICs and to the execs.

(Daniel at 00:41:56) Let's go fix that. But if we are, I think it's about aligning to a bigger strategy there.

(Joel Beasley at 00:42:03) Yeah. I'm not a fan of the customer is always right. Like, everyone's so protective, so protective. Like, you can't not agree with that.

(Joel Beasley at 00:42:10) It's like, well, I mean, I don't know. There's great arguments on both sides.

(Daniel at 00:42:16) There's great—

(Joel Beasley at 00:42:16) arguments for it, and there's great arguments against it. But I've never heard that "customer has got it, customer is weak" thing until just now. Yeah. Nice. And what's your call to action? Do you have a free consultation sign up? Like, how do you get people into the web?

(Daniel at 00:42:29) Yeah. There's various inbound marketing techniques there. But I would say from drata.com, it's super easy to understand and sign up to go talk to someone. We currently do not have a self-service kind of motion. We are working on that, especially for the lower end, smaller companies, make it easier for them just to get going as fast as possible.

(Daniel at 00:42:51) But I would say the biggest call to action is, it's better to start earlier. The bigger you get, the more complex—people you have, the lines of, the permutations of communication and software and version control and infrastructure you have is just gonna grow. So the earlier you can start this process, the better because then it's easier. And then what happens is it actually gets baked into your process, your onboarding process, your employees, your infra—like, the way your infrastructure teams think about it. And therefore, it starts becoming easier and easier even as you get bigger.

(Daniel at 00:43:25) Otherwise, if you're a 500 person company and now you have to go do SOC 2 for the first time, it's not the easiest task. And Drata makes it way easier. On average, it takes a company about 500 hours to get their SOC 2 Type 2, and we want to reduce that down to about an hour a week. So it's a big, like a 90% time saving. But it's even easier early on. So that's my big ask to everyone is think about starting earlier.

(Joel Beasley at 00:43:52) You got to run an ad with, like, a video that has these guys, sales dudes, like, future selling the fact that they do have these certifications, and they get off the sales call and, like, oh, crap. And then the answer is to call Drata. Yeah. Yeah.

(Daniel at 00:44:06) That's a good one.

(Joel Beasley at 00:44:07) You can have that one for free and tell your marketing team to give me a call. For Merge, what's your call to action? What do you got for them?

(Gil at 00:44:15) So merge.dev is our website, D-E-V, for developers. We have a self-serve sign up on our website as well as requesting a demo. We like to talk to most of our customers just to understand, make sure that they're comfortable knowing how they're gonna onboard. And we're there to answer questions around what functionality they need. I think integrations can be a pretty scary problem for people similar to compliance.

(Gil at 00:44:36) And so, for us, we want to make sure we're there. But pretty easy for a developer to just come in, sign up, go through our onboarding flow, embed, start integrating customers without ever talking to us as well.

(Joel Beasley at 00:44:46) Love it. Guys, we did it. We made a podcast. How do you feel?

(Gil at 00:44:51) Great. Great.

(Joel Beasley at 00:44:53) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.