# Founders Firewall Secure your startup from day zero. **What this is** A [YouTube Channel](https://www.youtube.com/@foundersfirewall), a [Newsletter](https://buttondown.com/FoundersFirewall) and a [website](https://foundersfirewall.io) that takes a brand-new startup from “just about to buy a domain” to a manageable, pretty secure environment that will be easy to explain to customers and auditors, allowing you to keep building without hiring dedicated security personnel or even a [vCISO](https://www.vanta.com/resources/virtual-ciso) for a few years. Ultimately, everything on this page will have at least one associated video on [Founders Firewall](https://www.youtube.com/@foundersfirewall), and if you implement most of the advice here, you will have a more defensible environment than the vast majority of tech startups, without spending a lot on software, services or staff. **Who it’s for** Founders, first security hires, and staff engineers who need a defensible baseline that won’t slow shipping. 1. For clarity, only one set of tools will be covered at first. The tools shown and used through target the typical "macOS, [[Google Workspace]], [[Slack]], [[Github]]" stack, though all principles apply more generally. For example, if using Windows, you'd want to use [Autopilot](https://learn.microsoft.com/en-us/autopilot/overview) instead of Apple's [Automated Device Enrollment](https://support.apple.com/en-ca/102300). 2. Unless explicitly mentioned, none of the tools suggested are sponsors. They are the tools I believe are the best for the job for a young company, with a bias for open source, free, or commercial but affordable and **easy to buy** solutions. 3. A basic explanation of why each tool is suggested is provided in the `Tools/` directory. 4. **Everything is a draft**, especially until a video is published. Consider written content prior to a video being embedded to be extra-beta :). 5. Automatically created #transcripts of every YouTube video can be found in `Transcripts/` - mostly for indexing purposes, so you can find out if a specific topic is covered in an episode even though not obvious from the title. Videos will be published through 2026, with the expected outline (which is fluid as new ideas come to me, new threats materialize, or requests are received) looking something like: ## Episodes (Season 1) | Video Episode | Article | Tracks | **Posted** | | ------------- | ------------------------------------------- | ------------------------ | ---------- | | S1E00 | Founders Firewall Intro | #general | | | S1E01 | [[Getting and Securing a Domain]] | #infrastructure | X | | S1E02 | [[Basic and Secure Google Workspace Setup]] | #collaboration #identity | X | | S1E03 | [[Mobile Device Security for Google]] | #endpoint #mobile #byod | | | | Apple Business Manager | #endpoint | | | | MDM Deployment | #endpoint | | | | Mac Hardening | #endpoint | | | | Mobile Configuration without MDM | #endpoint | | | | Securing GitHub access | #collaboration #identity | | ## Extra/Bonus episodes | Video Episode | Article | Transcript | | ---------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------- | | [Extra 01](https://youtu.be/inGhEJV-5Hw) | [[Extra Episodes/Extra 01 - Tracebit Community Edition\|Extra 01 - Tracebit Community Edition]] | [[Extra Episodes/Transcripts/Extra 01 - Tracebit Community Edition\|Extra 01 - Tracebit Community Edition]] | ## Draft topics list These are topics that are considered for coverage on Founders Firewall. As the videos and articles get posted, items will be removed from this list. If you see something missing, or you'd like something that's at the bottom of the list prioritized, be sure to comment on the YouTube videos, or reply to the newsletter emails. 1. [[Getting and Securing a Domain]] 2. [[Google Workspace and Gmail]] foundation 3. [[Zero-trust with Context-Aware Access]] 4. Additional spam filtering 5. Strong MFA with YubiKeys 6. Apple Business Manager + Fleet (DEP/ADE) 7. BYOD mobile-only; corp Macs allowed 8. GitHub org hardening (SAML, domains, PAT/SSH caveats) 9. OAuth app governance (Google API Controls) 10. Browser & endpoint controls (Chrome + Santa) 11. CI safety rails (GitHub Actions) 12. AppSec MVP (SAST/SCA/Containers/IaC) 13. AI coding assistants guardrails 14. Secrets & config (SOPS + OIDC) 15. SSO & lifecycle (Google IdP + Cloudflare Access) 16. Data protection (Drive, retention, DLP) 17. Runtime security (containers & serverless) 18. Secure remote access (bastionless) 19. Logging & alerts 20. Governance & trust page (SECURITY.md, VDP, security.txt) 21. Finance controls (money movement) 22. [[External Attack Surface Management]] 23. Honeypots & deception [[Tracebit]]