Earlier quoted context omitted.
Well, wait until you are at the receiving end. It can get nasty pretty quickly. What does each one of your systems store exactly? Do they allow configuration of reasonable data retention policies for PII? What do your systems log? How do you make sure that only the minimum amount of PII (including user IP addresses) is logged and that the covered logs are destroyed at the end of a reasonable retention period? How do…
> Nobody who wants to bootstrap a business wants to deal with any of this. It's an enormous time sink. Indeed but it forces you to answer these questions and to think about them during the development process as well, maybe even enough to write decent unit and regression tests for anything authentication/authorization related before some security "researcher" siccs Claude Code or whatever on your API and pwns it.
That's a very narrow perspective. The vast majority of businesses aren't this. Even a plumber who types up offers and invoices on a computer is subject to all of this mess.