Trust & security

CISO call program

Calls 02–04 — agendas + question banks · Last updated: 2026-05-03

CISO call program 02–04

Sequel to CISO call 01 (the original "94% chose safe enablement" reference conversation that anchors the website's SafeEnablement section). Calls 02–04 stress-test specific claims, gather objections, and validate deferred-feature priorities (see future-work.md).

Cohort targets (q2 resolution)

Call 01 vertical was unspecified. Sprint 31 decision: target three different regulated verticals across calls 02-04, with at least one EU-based to validate EU AI Act framing.

CallTarget vertical (preferred)Why
02EU-based fintech or regulated healthtechEU pulls in EU AI Act conversation (validates q4 framework choice); fintech surfaces procurement-side rigor (validates q3 budget gating).
03US federal civilian or defense contractorPressure-tests the air-gapped + signed-evidence story; FedRAMP authorization conversation.
04Regulated retail or regulated payments (PCI-DSS-heavy)Validates the cross-cutting "we don't fight your existing infosec posture" claim; SOC 2 + PCI overlap.

Hard rule: never run two calls with the same vertical. Diversity is the goal; depth comes from call 05+.

Standing block — Block 4 procurement reality (q3 resolution)

Block 4 was not covered in call 01. Going forward it is a standing block — every call (02, 03, 04, 05+) closes with these three questions:

  1. What was the last enterprise-tier security tool budget you signed for? Order of magnitude in dollars per year.
  2. Who was on the buying committee? Specifically: did Legal, Finance, Procurement, IT, or AppSec block or accelerate it?
  3. What closed it? An executive mandate, a peer reference, a regulatory deadline, an audit finding, a champion in your team?

The goal is to triangulate the actual enterprise procurement loop so Tier 1 SSO/SCIM (F1.14) productization priority + the OSS → Team → Business → Enterprise pricing tier gating decisions are calibrated to real budget patterns, not assumptions.

This document is the agenda + question bank + open-question register for the next three CISO conversations. Treat it as a working file — append notes after each call; the format is intentionally pre-populated so we can do A/B comparisons across calls.


Call 02 — "Does the audit chain hold up to a real auditor?"

Goal

Verify that fastpace's audit chain produces evidence a SOC 2 / ISO 27001 auditor would actually accept. This is the single biggest unknown after shipping F0.2 + F2.4 + F2.12.

Pre-call homework

Send the CISO 24h before the call:

  1. A real fastpace audit verify JSON output from a fastpace-installed repo (5–10k entries minimum so the chain has signal).
  2. The assets/docs/audit-schema.md (F2.12) so they can hand it to their audit firm.
  3. A signed AI-BOM (F2.4) showing which models, agents, and prompts shipped in a tagged release.
  4. The assets/docs/framework-mapping.md so they can see the SOC 2 / ISO 27001 / NIST AI RMF / ISO 42001 / EU AI Act mapping in one place.

Agenda (45 min)

TimeTopic
0:00Recap: what changed between call 01 and now (Tier 0 + Tier 1 + 11/12 Tier 2 done)
0:05Walk through one signed audit entry — show prev_hash, entry_hash, signature
0:15The auditor question: "what would your audit firm need to accept this as evidence?"
0:25The pre-merge audit gate (F2.9) — does this fit your CI?
0:35Unknowns for them: what's missing from the audit chain to satisfy SOC 2 CC8.1?
0:40Roadmap input: F2.5 control monitoring, F2.11 policy bundle — relevance?
0:45Wrap

Question bank

Open-ended (use first):

Sharpening (use after the open-ended ones loosen things up):

Skeptical (don't lead with these but probe if they sound interested):

Listening for

Post-call

After the call, append findings under ## Call 02 findings below. Open new items in future-work.md if anything crystallises into roadmap work.


Call 03 — "How do you talk to your developers about this?"

Goal

Test the developer experience claims. F1.9 coach agent says fastpace points the developer at the next action when something blocks; we need to know whether real developers actually use that path, or quietly disable hooks.

Pre-call homework

Agenda (30 min)

TimeTopic
0:00Show the violation flow video (don't narrate, watch their face)
0:05"What was your developer's first reaction to this? Be honest."
0:10Walk their disabled-hooks list with them — why each, and what was the trigger
0:18Coach agent UI integration — does the one-click exception button help?
0:25Trade-offs: does adding more friction reduce mistakes, or just push them around?
0:30Wrap

Question bank

Listening for


Call 04 — "What's the org-scale story?"

Goal

Pressure-test F1.13 (org dashboard) + F1.14 (RBAC/SCIM/SAML) + F2.11 (org-wide policy bundle). These are the three features that move fastpace from "trust harness for one repo" to "trust harness for an org's fleet". We need to know if the org-scale story holds up at 100+ repos.

Pre-call homework

Agenda (45 min)

TimeTopic
0:00Walk through the dashboard at 30+ repos — what jumps out?
0:10Policy bundle: the org-admin pattern. Who in your org would publish?
0:20F2.5 control monitoring: drift between Drata and ground truth — useful or noise?
0:30F2.11 expiry / rotation — how often should bundles refresh?
0:35Audit gate at fleet scale — does it scale to 1000+ PRs/day?
0:40Concerns + asks
0:45Wrap

Question bank

Listening for


Open-ended questions worth asking on every call

These are evergreen, regardless of which call we're on:

  1. "If I told you fastpace shipped feature X tomorrow, what would you stop doing?" — finds the displacement story.
  2. "What does your Q3 (or current quarter) AI governance roadmap look like? Where does fastpace fit?"
  3. "Who's your biggest internal critic of fastpace, and what's their strongest objection?"
  4. "In one year, what does fastpace's footprint in your org look like, and what changed to get there?"

Anti-patterns to avoid


Open question register

Append findings as bullet points after each call. Items that crystallise into roadmap commitments move into future-work.md (not here).

Call 02 findings

Call 03 findings

Call 04 findings