Live data from Hacker News

Ask HN: Huge enterprise customer wants to see our source code

news.ycombinator.com

71–80 of 293 posts

Re: Ask HN: Huge enterprise customer wants to see our source code

#71
post #3

This is a complete no-no. There really is no justification for this whatsoever. What does "cover their bases" mean? As them to explain what they are trying to achieve and find other ways to assuage their concerns. The only legitimate thing is to have something in case you fail and they have "banked" on you. There is a legit way to solve that. basically if they want that tell them they should pay for an Escrow service…

It's entirely unreasonable for them to demand access to source code.

The government and large corporations apparently disagree, or Microsoft wouldn't have their Shared Source Initiative. And for any nay-sayers in the crowd, that should be all that need be known: Microsoft thinks it's okay, and they have a lot more to lose than you do.

The only legitimate thing is to have something in case you fail and they have "banked" on you.

Which might be the exact thing they're trying to avoid. If your "machine learning" algorithm amounts to a bunch of nested if statements, they'd probably rather not "bank on you" in the first place.

Re: Ask HN: Huge enterprise customer wants to see our source code

#72
What would you see this technology outright for if they just asked you to cash out and leave? Double or triple that amount and ask for it to be put in escrow as security, subject to release on the decision of an arbitration panel consisting of 3 academic computer scientists. They'll refuse of course, but it gives you something to negotiate with.

Re: Ask HN: Huge enterprise customer wants to see our source code

#74
post #52

This is just politics. Find a way to say "yes", which satisfies their need to hear you say "yes", but your "yes" conditions mean they need to spend money (which they won't want to do), and further conditions, even if they do, as other commenters have suggested, make the process dysfunctional. Watch our politicians in government handle any issue. They are masters of saying "yes" and delivering "no", which makes people…

Slightly off topic, but.... > Find a way to say "yes", which satisfies their need to hear you say "yes" This is the best skill to train if you're going to be working with enterprise clients.

Winning government work (which is probably similar to large enterprise) is all about ensuring all of the government tender requirements get a "yes" tick when considering your product, but then ensuring that your fine print gets you out of all the unsavory things you had to agree to for those "yes" ticks. You can afford at this stage of the process to underprice and beat your competition. Note that the thing you underprice is the fixed price commitments that the government will change anyway, invalidating your fix price commitment instead switching over to the overpriced fine print pricing (see below).

You might wonder how to do that without them noticing that you are backing out of all your commitments. You in effect force them to agree that the fixed price commitments that you make are only valid if the government does their bit of the project, and you lock down exactly what their bit is. Anything outside this clearly defined scope is a "variation" or "change".

You do it by identifying the grey areas and putting a condition on each grey area.

For example there might be a requirement in the tender that you'll deliver some report in a week, or build some software function in 3 months at a fixed price. You would have some fine print to say "if all client staff are available to contribute, if all systems are fully available for review and if all approvals are gained. 1 week project $2,000 additional hours $220 per hour". You know its going to take far more than one week, now you are going to get paid for it, but you charged only $2,000 for the initial week which was likely cheaper than the other tender submitting companies who you are competing with. You just got them to agree to pay you $220/hour, and they didn't realize that most of the project will actually be carried out under this bit of fine print because they didn't meet their commitment to their side of the project - bingo!

Your client can't disagree with the grey area conditions because its only reasonable that if they require the report in a week that they do their side of the project work and if they don't then you need to be paid for the extra time it is taking.

Your client will be optimistic about what they can do when it comes to what they need to contribute to the project. Take advantage of that optimism and get them to be paying you when it takes them longer than they expected to do their bit.

The real money is made in these additional terms because in many cases all the initial conditions of the contract become irrelevant for various reasons and thus the terms are dictated by the fine print that you defined, that the client is not paying close attention to during the tender assessment process because all they care about is ticking off their predefined requirements, which you already made sure you get a big "yes" tick on. This is how big companies make scads of money from government consulting contracts. They know to make their initial tender extremely appealing to the client and their fine print extremely lucrative.

Make sure you have a good project manager whose job is mainly to track actual against contract commitments and get signoff when moving to hourly instead of the fixed price commitments.

Re: Ask HN: Huge enterprise customer wants to see our source code

#75

Well, having worked for a small software startup that did just that, I can tell you what we did. We agreed to letting them audit the code with conditions. 1. The audit happened on our computers with someone from our team in control (me). I locked the computer when I wasn't physically there to watch what they did. 2. We removed the most sensitive part of the code and told them what it did. We kept the method signature…

I've done this too. The question is usually a matter of compliance more than anything else. They want to check the licenses of any included packages, makes sure there's no encryption stuff that can't leave the USA, etc.

Doing what OP described is great: it lets their folks do the audit with no risk of you loosing "ownership". It shows you are both a good partner and value what you do.

Re: Ask HN: Huge enterprise customer wants to see our source code

#76

If my memory serves me right, This is exactly how Microsoft stole Apple's code in the early days

I'm not sure it does.

Apple borrowed ideas from Xerox. Microsoft were given source code for Mac in order to keep producing Office for it. Both Apple and Microsoft have copied UX elements off of each other.

But I don't recall Microsoft stealing Apple's code. Maybe copying some GUI elements at most...

Re: Ask HN: Huge enterprise customer wants to see our source code

#77
Hi i'm founder of https://bitbank.nz a trading prediction and stats platform that uses machine learning to predict cryptocurrency price, seems very similar to problems we have been facing.

After a quick call with a massive customer and walking them through our forecasting strategy and code we saw an abrupt end of communication after that!

Brain rape like something straight out of a silicon valley TV show https://www.youtube.com/watch?v=JlwwVuSUUfc

After giving away our secret sauce they simply cut all communication and one can only assume they are implementing their own version of what we have now...

If they are such a huge customer they should be prepared to pay like everyone else should be if you can prove from your predictions/charts that your algorithms performance is solid.

Give them a short free trial but be careful not to give them too much for free.

We now only offer a 1 day free trial and the value should be obvious after that, start with a crazy price and slowly drip feed discounts, product features and trial extensions like you would market to a normal customer, if they are going to do invest time doing any custom integration with your apis ect then why cant they invest money upfront too?

Its easy as a scientist to not make a strong sales standpoint but your worth more than you think!

Re: Ask HN: Huge enterprise customer wants to see our source code

#78
I used to work for a company that did model risk management consulting for large banks and source code reviews were a standard part of what we did. What sounds different from the OPs situation is that it is the customer who would be conducting the review and not a third party. Take everything you read here with a grain of salt but it would be best to consult a lawyer. Even if you hold the patents for what your software is doing under the hood it may difficult and expensive to sue in the event that your customer does simply copy your secret sauce

Re: Ask HN: Huge enterprise customer wants to see our source code

#79
In a past life I was at a SaaS company that was asked this from every single customer (and they were BIG customers). We always said no. No, no, no.

You know why? It was not secret sauce at all and boolean logic. Amazing how the wool was pulled over a pile of rubbish ;)

Re: Ask HN: Huge enterprise customer wants to see our source code

#80

I'll offer a different pov from many other comments. I work for a fortune 50 basically doing web server stuff. Right now our security team would like to run some startups code synchronously as a module in our web server. Their code could easily cost us millions off dollars (if the outage was small). I need to make sure their sdk is free of race conditions, and has proper timeouts and throttling and has proper metrics…

Are you going to audit all of their code changes from now into perpetuity as well? It seems like you kinda alluded to the thing that would actually be effective, which is not synchronously calling external services in high-uptime-requirement applications...
Post reply on HN