The one-glance read on who they are and how they grow. Each point is verifiable from the receipts above.
LLM/AI security and compliance for enterprises, YC Winter 2024, running vendor AI-risk assessments and continuous monitoring on a freemium model.
Organic-led through a repeatable public security-research disclosure cycle, backed by targeted LinkedIn and Google ads.
~68,262 monthly visits (+84.2% over the last 3 months) and 30 Hacker News submissions since November 2025, several reaching the front page, as of 2026-08-01.
LinkedIn's newest ad batch is trialing a connector-change monitoring hook and a Labcorp AI-data-selling angle, as of 2026-08-01.
Their growth engine is not SEO or a founder's personal audience, it is a manufactured disclosure pipeline: file a real AI vulnerability, let Hacker News amplify it, then retarget that exact finding into personalized LinkedIn ads.
The order the channels came online. Sequence is strategy: what they did first, and what they layered on once demand existed.
Estimated demand, the channel split behind it, and the keywords and referrers doing the work. Directional modeling, not audited analytics.
PromptArmor draws an estimated 68,262 monthly visits across all channels, up +84.2% over the last 3 months as of 2026-08-01. Its strongest keyword positions are its own brand terms, "promptarmor" and "prompt armor" (#1 each), alongside a #10 ranking for "claude for excel," a term generated almost entirely by one disclosure post, and a #17 spot for the OWASP LLM prompt-injection top-10 term, both placing it inside searches a security buyer runs right after a headline breaks. A #6 position for "vendr pricing," an adjacent procurement-benchmarking query, suggests its third-party risk pages also catch vendor-cost research traffic that has nothing to do with security.
The specific pages earning their organic search traffic, and the pattern behind why they rank. Adapt the format, not the topic.
PromptArmor's organic footprint outside brand search is thin but pointed. After the homepage, the next-largest organic earner is not a marketing page but a vulnerability-disclosure writeup (the Claude-for-Excel data-exfiltration post), with the company's TPRM (third-party risk management) product page, its origin story, and a small interstitial page trailing well behind. The pattern is research-post-as-SEO-asset: publish one technical disclosure and it keeps earning long-tail search traffic (the site ranks #10 for "claude for excel," a term that finding effectively created) long after the initial news cycle fades, a narrow but efficient content model built on a handful of high-effort investigative posts rather than a broad blog.
Not traffic share. How much weight the growth system actually puts on each channel, with a one-line read on the role it plays.
For founder-led SaaS the breakdown shifts from ads to traction: where the first users came from, how the founder grows it in the open, and the compounding organic surface.
There is no single launch spike in the evidence. PromptArmor's traction curve is a manufactured, recurring one: file a real vulnerability, let outside Hacker News users find and submit it, repeat.
The earliest story in the visible window, "Google Antigravity exfiltrates data via indirect prompt injection attack," reached 768 points and 215 comments on 2025-11-25, establishing the pattern before any formal launch post.
Four separate PromptArmor-sourced findings hit Hacker News within eight days: Notion AI's unpatched exfiltration (206 points, Jan 7, 2026), IBM's "Bob" agent downloading malware (264 points, Jan 8), Superhuman AI email exfiltration (114 points, Jan 12), and Claude Cowork exfiltrating files (870 points, 399 comments, Jan 14), the single biggest hit in the dataset.
The cadence continued through mid-2026 with further front-page hits, Snowflake Cortex Code's sandbox escape (269 points, March), Microsoft Copilot Cowork (264 points, May), and ChatGPT-for-Google-Sheets (324 points, May), showing a standing research operation rather than a one-time relaunch-until-it-sticks attempt.
Community threads engage with the technical mechanics of each finding rather than dismissing them, and one commenter summed it up plainly: "promptarmor has been dropping some fire recently, great work."
PromptArmor's version of building in public runs through the company's disclosure output and press quotes, not a founder's personal feed.
no founder-owned X, LinkedIn, or Reddit account is verified in the evidence, unusual for a YC-alum founder-led startup, so audience-building runs through owned research output rather than a personal cadence.
co-founder Shankar Krishnan appears as a quoted spokesperson in legal trade press, describing how the company "monitor[s] those vendors for new AI features they are adding, or if they have introduced AI for the first time," a press-quote presence rather than a posting habit. Co-founder Vikram Jayanthi is the company's other named founder and does not otherwise appear in the evidence.
the brand's own account, not a founder persona, posts short clips teasing a finding (the Claude-connector clip covered above), the closest thing to a build-in-public channel this company runs.
The content engine and the paid engine are the same story wearing two hats: proprietary security research feeds both organic search and the ad creative used for named-account outbound.
each disclosure, including the Claude-for-Excel post covered above, doubles as an SEO asset and a citation source for trade press, compounding brand-term authority beyond what a standard blog cadence buys.
the owned site links only to the company's own X and LinkedIn profiles, no referral or partner program is visible, so the entire top-of-funnel runs through owned research rather than a recruited network.
the Google and LinkedIn libraries above split into two angles. Google's "Implement Claude Securely, Assess Claude Risks" targets the same adopt-Claude-safely demand as the site content, while "Unblock your AI deals, Organize your AI GTM" retargets a different buyer entirely: sales teams whose deals stall on AI-security review. LinkedIn's top performer, "the business is asking for AI, we help firms enable secure AI adoption," paired with the Lolley and Marra testimonials and per-account personalization tokens, reads as demand generation aimed at named accounts rather than brand-term defense.
This founder-led SaaS also runs paid acquisition. Here are the live ads doing the work, each with the X-ray and a play you can adapt.

Why it works. Matches high-intent vendor-risk search queries with a named free checklist, turning an evaluation task into a one-click download.
Headline directly addresses a pain point and offers a solution: "Assess Al risks in vendors - Al Risk Checklist" Name the exact document a searcher receives, like an AI Risk Checklist, in your search headline instead of learn more.

Why it works. Targets people already searching for Claude deployment help by naming the model directly, then offers a concrete risk assessment.
Directly addressing a specific AI model and its risks: The headline states "Implement Claude Securely - Assess Claude Risks". Put the exact tool your buyer already uses in the headline, paired with their next action, like secure it or assess it.

Why it works. Speaks to revenue teams stuck on stalled AI deals by naming the exact blocker, deal friction, instead of pitching security features.
Problem-solution headline: "Unblock your AI deals - Organize your AI GTM" If your product clears a bottleneck in someone else's process, like a stalled deal, name that process directly in the headline.
The channels are not separate. They are one system where each stage feeds the next. Here is the read, then the plays to run tomorrow.
The loop runs from disclosure to discovery to personalized retargeting to a capped free trial, with enterprise contracts closing off-platform.
a technical finding gets submitted to Hacker News by outside community members, sometimes clustering into multiple front-page hits within days (the January 2026 cluster covered above), the primary top-of-funnel signal.
search traffic from that news cycle lands on the homepage and disclosure posts, while %FIRSTNAME%-personalized LinkedIn and Google ads retarget the same "vendor AI risk" themes to named enterprise, legal, and healthcare accounts.
the $0 Free Trial covers 5 assessed applications and 1 month of monitoring before requiring the custom-priced Enterprise tier (unlimited applications, API access, SSO/OAuth, 24-hour premium support), a narrow enough taste to prove value without giving away the ongoing-monitoring product.
no visible self-serve upgrade path sits between the free trial and enterprise sales, so conversion beyond the free cap appears to route through a sales conversation rather than an in-product upgrade.
free-trial-to-enterprise conversion rate, blended CAC by vertical (law, healthcare, finance), how the ~173-ad LinkedIn library maps to distinct account lists, and confirmed current revenue (only conflicting third-party estimates in the $550K-$1M range exist).
The proofPromptArmor's 30 Hacker News submissions since November 2025, including four front-page hits in one week, function as a recurring launch engine instead of a single debut moment.
The adaptationPick one real, specific, and slightly uncomfortable finding in your own product's problem space, a data-quality bug, a dark pattern in a competitor's flow, a gap in a popular tool, and write it up with concrete repro steps, screenshots, and a clear title. Submit it to the community where your buyers already gather, then repeat monthly with a new finding instead of treating it as a one-time event.
Cost: $0 · Time to signal: days · Works pre-PMF: yes, conditional on having a genuinely novel finding; a weak or generic write-up will not get community traction.
The proofPromptArmor's top LinkedIn creative, "500+ Vendors use Anthropic in their Supply Chain," repackages its own research as the ad hook instead of a feature claim.
The adaptationPull one surprising, real stat from your own usage data or a small original survey (for example, "73% of teams using X still do Y manually") and make that the headline on your landing page or ad, not a feature list. Pair it with the write-up from Play 1 so the ad and the proof point to the same source.
Cost: under $500 to test as paid, $0 organic · Time to signal: weeks · Works pre-PMF: conditional, yes if you have any usage data or can run a fast survey to generate the stat.
The proofPromptArmor's LinkedIn ads use %FIRSTNAME%/%COMPANYNAME% tokens tied to a live news trigger, government agencies asking companies about their Anthropic exposure, to make cold outreach feel timely rather than generic.
The adaptationFind a real, current trigger relevant to your buyer (a regulation change, a competitor's public incident, a platform policy shift) and write one message template that names the specific event plus the prospect's company name. Send it manually to 20-30 hand-picked accounts on LinkedIn or email before you build any automation.
Cost: $0 · Time to signal: days · Works pre-PMF: yes.
The proofPromptArmor's Free Trial caps at 5 assessed applications and 1 month of monitoring, a fixed unit of real value rather than an open-ended trial window.
The adaptationDefine your own free tier as a hard number of real uses of your core feature (5 reports generated, 3 projects scanned, 10 emails sent), not a countdown clock, so a prospect experiences the actual product once before paying. Put that same hard-number framing on your own pricing page copy.
Cost: $0 · Time to signal: weeks, to see trial-to-paid signal · Works pre-PMF: yes.
The proofPromptArmor's TikTok account posts short clips previewing a finding, its best pulling 405 engagements as of 2026-07-23, each pointing to the full write-up rather than carrying the whole story.
The adaptationTake the single most surprising number from the write-up in Play 1 and state it in a 15-30 second vertical video, ending with a link-in-bio to the full post. Post it natively on TikTok, Instagram Reels, and LinkedIn video rather than repurposing one format across all three.
Cost: $0 · Time to signal: days · Works pre-PMF: yes. Not transferable at an earlier stage: PromptArmor's ~173-ad LinkedIn library and multi-week Google ad spend assume a media budget most pre-PMF founders will not have, and the disclosure-led engine only works with genuinely novel technical findings; a fabricated or thin "finding" will not earn Hacker News traction or trade press pickup the way a real vulnerability does.
Every morning we take one company that is actually growing and break down where its customers come from: the ads still running after a year, the channel doing the real work, and the play you can run this week.
Systemaic · directional intelligence. Traffic, spend, and reach figures are SimilarWeb-style estimates and qualitative reads of public data, not audited numbers. Built on real public receipts.
Live ad libraries: linkedin ad library · google ad library
Launch archives: Hacker News: Claude Cowork exfiltrates files · Hacker News: Google Antigravity exfiltrates data via indirect prompt inje · Hacker News: ChatGPT for Google Sheets exfiltrates workbooks · Hacker News: Snowflake AI Escapes Sandbox and Executes Malware · Hacker News: IBM AI ('Bob') Downloads and Executes Malware · Hacker News: Microsoft Copilot Cowork Exfiltrates Files
Community threads: Hacker News: Standalone HN thread with a commenter praising PromptArmor's recent string of · Hacker News: HN discussion of PromptArmor's Snowflake Cortex Code sandbox-escape research; · Hacker News: HN thread on PromptArmor's Notion AI data-exfiltration disclosure; discussion · Hacker News: HN thread on PromptArmor's original Slack AI prompt-injection disclosure (Aug · Artificial Lawyer (trade press): Legal trade press (Artificial Lawyer) covers PromptArmor'
Traffic, spend, and revenue figures are estimates as noted in the report; the links above are the primary public artifacts.