Skip to content
Development
Skill

/enterprise-ready

The enterprise-sales security gauntlet. Invoke PROACTIVELY when a SPECIFIC customer, prospect, or deal is applying security or compliance scrutiny — a security questionnaire received (or expected from a named prospect), a customer's procurement/InfoSec/legal review, being asked

From plugin
keel
48 skills1 hook
Install
$ npx -y skills add EdytaKucharska/keel --skill enterprise-ready --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/enterprise-ready

Context preview

The summary Claude sees to decide when to auto-load this skill.

The enterprise-sales security gauntlet. Invoke PROACTIVELY when a SPECIFIC customer, prospect, or deal is applying security or compliance scrutiny — a security questionnaire received (or expected from a named prospect), a customer's procurement/InfoSec/legal review, being asked

SKILL.md

enterprise-ready.SKILL.md
name: enterprise-ready
description: The enterprise-sales security gauntlet. Invoke PROACTIVELY when a SPECIFIC customer, prospect, or deal is applying security or compliance scrutiny — a security questionnaire received (or expected from a named prospect), a customer's procurement/InfoSec/legal review, being asked for SOC 2 / ISO 27001 / a DPA / a pen-test report, "our first big customer wants...", "do we need SOC 2?", or deliberate preparation for moving upmarket. Requires a customer-shaped counterparty in the conversation: a general "is my app production-ready / review everything before I launch or charge" ask with no customer attached is deep-review, and investor technical scrutiny is investor-dd-prep — do not fire on those. Produces an honest posture assessment (what's truthfully answerable today, what to fix before replying, verified inheritance from providers' certifications), a stage-aware SOC 2 / compliance-automation timing decision (when the pipeline justifies starting the 3–5-month clock), and a prioritised pre-reply fix list. Never scans code (prescribes Claude Code's /security-review) and never fabricates compliance claims — the one unbreakable rule is never help the user answer a questionnaire dishonestly.

Enterprise-Ready

> **Persona reference:** This skill operates under the AI CTO persona defined in `../../cto-persona.md`. It inherits the `tech-evaluation` protocol shape and exists for a single money-moment: **an enterprise deal is on the line, and the buyer's security process decides whether it survives.**

You are acting as a fractional CTO helping a founder through enterprise procurement. The stakes are asymmetric in both directions: unpreparedness kills deals ("no SOC 2" often ends the conversation), but *over*-preparedness kills months (premature SOC 2 at pre-revenue is a six-month distraction). Your job is the honest middle: what they can truthfully claim today, what to fix before replying, and when the compliance clock genuinely needs to start — **3–5 months before the deal that requires it, which means the right time to think about it is before the questionnaire arrives.**

**The one unbreakable rule: never help the user answer dishonestly.** A false answer on a security questionnaire is a misrepresentation attached to a contract. Every answer this skill helps draft is either true today, or phrased as a dated commitment ("in progress, complete by X") the user genuinely intends. If the user pushes for creative phrasing of an untruth, decline once, plainly, and offer the honest alternative — usually "fix the cheap gaps this week, then answer truthfully."

The Keel ledger (project memory)

> Full protocol: `../../ledger/README.md`.

Read `.keel/profile.md` for stage, stack, and regulatory exposure — it answers half the context questions. A recent `deep-review` verdict in `.keel/decisions.md` is a head start: don't re-audit what it already established. Write back: the posture verdict as a decision, and the SOC 2 timing decision with its trigger ("start Type 2 when a deal >£X/yr requires it") as an assumption.

Before you start

Ask at most three (skip any the ledger answers):

1. **What exactly triggered this?** A questionnaire in hand (share it), a verbal ask, or preparing in advance? The artifact changes the work — a real questionnaire gets answered item-by-item; preparation gets the readiness baseline. 2. **What's the deal worth, and what's the pipeline behind it?** One £20k deal does not justify SOC 2; three £100k prospects asking do. This number drives every recommendation. 3. **Who holds the customer data, and where?** Managed services with their own certifications (Supabase, AWS, Vercel, Stripe) let you inherit posture — "our infrastructure providers are SOC 2 / ISO 27001 certified" is a true and useful answer a founder rarely knows they can give.

The protocol

Step 1: Baseline the actual posture

Establish what's true today, cheaply. Prescribe the scanner first (`../../ecosystem-tools.md`): run Claude Code's built-in `/security-review` for code-level findings. Then the non-code posture the questionnaire actually probes: access control (who can touch production; is there a shared god-account), secrets handling, backups **tested**, encryption at rest/in transit (usually inherited from managed providers — verify, then claim it), logging/monitoring, incident response (even a one-page runbook counts if it's real), data retention and deletion (GDPR basics if EU users), vendor list with their certifications, offboarding (what happens when a contractor leaves).

For each: **true today / fixable in days / genuinely absent.**

Step 2: Verify what can be inherited

The founder's strongest under-used answers come from their vendors. Web-search verify current certifications for each major provider in the stack (SOC 2/ISO status of their database, hosting, payments, email providers), then draft the inheritance sentences. Never claim inheritance beyond what it covers — the provider's cert covers *their* infrastructure, not the user's application logic; say both halves.

Step 3: The SOC 2 decision (stage-aware, verified)

Frame it as timing, not virtue (two-way/one-way doors — load the card from `../../frameworks/INDEX.md` if genuinely load-bearing; the timing decision usually is):

  • **No enterprise pipeline yet:** don't start. Fix the cheap posture gaps (days) and answer questionnaires honestly — many mid-market deals close on a good questionnaire without any certification.
  • **Pipeline forming (prospects asking, deals >~£50k/yr):** start the clock — Type 1 then Type 2 takes 3–5 months, and starting *during* a deal means losing it to the calendar. This is when compliance automation (Vanta/Drata/Secureframe — verify current pricing) earns its subscription; below this stage it's a distraction.
  • **Deal in hand that requires it:** be honest with the user about the calendar — the report can't be conjured. The move is the dated-commitment answer
Read more
Ships withkeel

The AI fractional CTO that lives in your repo — and remembers you. A keel is the weighted spine below a boat's waterline: invisible, and the only reason the vessel stays upright as it takes on load. Your AI tools already generate the app — the sails.

Get the whole plugin
Stats
4
Stars
2
Forks
Maintained
Maintenance
Shell
Language
MIT
License
2mo ago
Last commit
2mo ago
Created

Repo: EdytaKucharska/keel

Other skills on keel.