Security, legal or vendor risk at the company about to buy. Did not choose Signet. Decides whether it is allowed in.
Seeding strength: PARTIAL on voice, STRONG on what we answer.
Security, legal or vendor-risk at the company that is about to buy. They did not choose Signet. An engineer or a founder chose it, and their job is to decide whether it can be allowed in.
They will spend four minutes on the homepage at most, and only to find the links. Then they go straight to the pack. Everything that persuades the other four readers is noise to this one.
They know their own checklist by heart. Subprocessors, data residency, breach notification, exit, DPA, whether anyone has attested anything.
They do not know or care what makes us different from any other vendor. They are not evaluating quality. They are looking for reasons to say no, and the fastest reason is a missing answer.
Being the person who approved the vendor that caused the incident. Everything else follows from that.
They also know the ritual is expensive on both sides:
"SaaS vendors that manage PII data needs to go through the - security questionnaires, privacy assessments, vendor risk reviews, procurement due diligence, evidence requests - sent by the customer security team." — HN 49241155
"Unfortunately, carrying a SOC 2 attestation won't save you from vendor questionnaires (and one-off security asks), but it will make them easier." — HN 44363217
"Could I email you a Vendor Security Questionnaire to see if we can try it out?" — HN 18125993
And a warning that bears directly on our price point:
"if you priced the exact same product at $200 vs $20,000 ACV, most enterprises wouldn't consider the $200 price-point because they would have a really hard time justifying the cost of their security & procurement team's time." — HN 31816707
That last one is worth sitting with. At our hosted price, this reader's own review process may cost their employer more than the subscription. The pack is not a courtesy. It is what makes us cheap enough to approve.
Subprocessor. DPA. Data residency. Attestation. Breach notification. Safe harbour. Escrow. MSA. Click-through terms. Evidence request. They will use "vendor", never "product". They ask what we hold, not what we do.
Verified by fetching https://signetauth.com/buy.json on 2026-08-21. This is a genuinely strong surface and this reader is the one it was built for:
not_claimed ledger, which is the rarest thing on the page: no third-party compliance certification, no pen test yet, no SLA outside a signed contract, operating envelope not measured.young_vendor: true, declared by us before they can discover it.Finding all of it in one place, in under four minutes, without emailing anyone. The not_claimed ledger is the strongest asset we have with this reader, because it converts our weakest facts into evidence that the rest of the document is accurate.
"Where is the pack?"
That is the entire job. This reader does not need the homepage to persuade them. They need one visible, unambiguous route to /buy, and everything else on the first screen is correctly ignored.
The "what we answer" half is strong: fetched live from /buy.json, not remembered.
The voice half is partial. My first 539-item corpus contained zero procurement language, because it was seeded with vendor-choice queries. I ran a second targeted search (126 comments) to get the quotes above. They are real procurement voice, but they are generic SaaS procurement, not auth-specific procurement.
Consequence for the panel: this persona is reliable on whether an answer exists and unreliable on how a real security reviewer would word an objection. Do not use it to judge tone. Use it to judge coverage.
Surface under test: "Land the enterprise deal. / Keep the same bill." with the login-system lede and "Get an instance". This reader ran on Sol (GPT-5).
They comprehended the product. Persuasion was noise for the job they came to do. "Buy" read as an ambiguous label for a vendor-risk pack, and they could not tell from that screen what data Signet holds. Their route was Buy, then Security.
| Q1 what is it | Q2 do you care | Q3 what next | Left cold by headline |
|---|---|---|---|
| PASS | PASS | PASS | Yes |
What is this? "An authentication vendor. Login-as-a-service. It's a dev tool. Somebody on our engineering side already picked it; my job starts after that."
Do you care? "Not about any of this screen. I don't score products, I clear vendors."
What next? "Click 'Security' in the top nav. That's the one word in that bar that's in my vocabulary. If that page doesn't get me subprocessors and a DPA in under a couple clicks, I try 'Buy' next."
What stops you? "Nothing on this screen stops me - there's nothing here for me to get stuck on, because there's nothing here for me at all."
That last answer is the bar the brief set, not a failure. This reader is cold to every headline by design.
From the run-03 record: "They score cold on every headline by design and their route is the Security link in the nav. The enterprise quiet line is about billing, not their checklist. Running it would have produced 'nothing here for me', which run 02 already recorded. I skipped it rather than manufacture a data point."
Source: readers/03-procurement-gatekeeper.md