YC Startup Hiring and Security Intake: We Probed 80 Launches
We probed the 80 newest Launch YC companies: 25% had a careers page at the obvious URL, 11% a security.txt, and 6 of those 9 went to a founder inbox.
Ernest Bursa
Before a Demo Day or a Launch YC post, a startup needs two intake channels that a founder’s inbox cannot be: a public careers page with a real pipeline behind it, and a vulnerability disclosure front door with a security.txt, a scoped policy, and an acknowledgement clock. We probed the 80 newest Launch YC companies on 13 August 2026. Twenty had the first. Nine had the second.
That gap is not negligence. It is what happens when two jobs fall into the space between three co-founders’ roles, and the launch date arrives anyway.
Demo Day is a traffic event, and you only planned for the investors
Every accelerator manufactures a scheduled public moment. You have modelled it as an investor event. It is also an applicant event and a scanner event, and those two streams arrive at the same address.
Here is the shape of the calendar across the programs founders actually join, as published on 13 August 2026:
| Program | The scheduled public moment |
|---|---|
| Y Combinator | Four batches a year. 2026 Demo Days: 24 Mar, 16 Jun, 10 Sep, 2 Dec. Plus Launch YC, continuously. |
| Techstars | Three-month mentorship cohorts; 16 active programs listed in the directory. |
| Antler | 26 locations worldwide, rolling applications, cohorts starting regularly. |
| Entrepreneur First | FORM in London, then a 12-week LAUNCH in SF. Demo Day attended by 200+ VC partners. |
| a16z Speedrun | Two cohorts a year, 60 to 70 teams, acceptance under 0.4%. SR007 Demo Day: 6 Oct 2026. |
| 500 Global | Four-month in-person Silicon Valley program. Batch 36 applications closing 11 Oct. |
| Alchemist | Six months, enterprise and B2B only. Invitation-only virtual Demo Day, in-person SF preview a month before. |
| Sequoia Arc | Two cohorts a year, roughly 10 companies each, built around a four-day Arc Intensive. The current page advertises no Demo Day. |
| HF0 | “The residency for repeat founders.” The site lists batches starting 13 Sep and 4 Jan, Demo Days 4 Dec and 1 Dec, without years. |
Different capital, different cities, same operational fact: on a date you already know, strangers will try to contact you, and the only published address will be yours.
Launch YC is the clearest version of this, because it is a permanent public surface rather than a single afternoon. YC opened it to the world on 29 June 2022, moving an internal Bookface feature onto ycombinator.com. Founders post any day, at any time; visitors sort by industry, batch and launch date and vote companies up a leaderboard. When TechCrunch covered it, YC’s Lindsay Amos described the audience as founders, developers, investors and job-seekers. Job-seeker traffic is an explicit design goal of the page. As of 13 August 2026 it had carried 3,189 launches all-time, with more than 160 from the Summer 2026 batch alone in the month before its 10 September Demo Day.
What actually arrives on launch day, and how fast
Two things arrive: a short, front-loaded burst of human attention, and a steady stream of automated scanning that started before the humans did.
The human half is real but brief. An analysis of 41,301 Show HN posts and roughly 100,000 comment timestamps between June 2025 and June 2026 found a 7.2-hour median attention half-life, with 90% of a post’s lifetime comments arriving by hour 26 and only 4.2% after 48 hours. Same analysis, sobering baseline: the median launch got 2 points and 0 comments, and 61.7% got no comments at all.
For the launches that do land, the numbers get large fast. Robinhood’s December 2013 Hacker News launch, posted by a third party rather than the founders, produced 10,000 signups on day one and more than 50,000 in the first week, per Kat Mañalac’s talk in the YC Startup Library. PostHog, then a three-person YC W20 team, reported “well over 200 sign ups” and 800+ GitHub stars within five days of its own HN launch. And Ashby’s data on roughly 13 million applications found the first week of inbound applications runs 2.5 to 3 times higher than every following week. The spike lands exactly where your process does not exist yet.
The automated half is less discussed. HUMAN Security’s Satori team has documented that threat actors monitor certificate transparency logs such as CertStream, which publicly record every new TLS certificate issued. A fresh certificate is itself the signal that there is something new to scan. In HUMAN’s honeypot work, scanners accounted for 69.5% of bot traffic on average, exceeding 90% on some days, with roughly a third of attempts targeting .env files and another third targeting Git repository data.
Meanwhile Hacker News tells Launch HN founders to make the product easy to poke at: “Remove signup barriers, at least for launch day, you’ll get more and better feedback.” That is good launch advice. It also means you are told to widen your attack surface on the exact day your certificate hits the transparency logs.
We probed the front doors of 80 Launch YC companies
On 13 August 2026 we took the 80 most recent Launch YC companies (launch window 31 July to 13 August 2026, 80 unique domains) and checked two things: whether they had a careers page at an obvious URL, and whether they had a valid vulnerability disclosure contact.
Careers: 20 of 80 (25%) returned HTTP 200 on /careers or /jobs. A re-probe with a browser user agent got 19 of 80; the difference was one timeout. Read the claim precisely: a 404 at /careers is not proof a company has no careers page. Several of the other 60 may list roles on a hosted board or a path we did not guess. The finding is no careers page at the obvious URL, which is still the URL a candidate types.
Disclosure: 9 of 80 (11%) served a valid RFC 9116 security.txt, meaning HTTP 200 with a Contact: line at /.well-known/security.txt or /security.txt. 71 of 80 had none.
Nine is the more interesting number, because 6 of the 9 route to a founder’s inbox rather than a dedicated address. Only three published a real security@ alias. The one file the spec tells a researcher to fetch points, two times out of three, at the person who is also fundraising that week.
The launch posts confirm what the intake actually is. Of the 80 launch bodies, 55 (69%) publish at least one email address, roughly half named founders, half generic aliases. One or two of the eighty carried a hiring signal, and exactly one mentioned security or disclosure; that one was product copy, not a reporting channel. So the picture is exact: on the highest-traffic day the company has ever had, the founder publishes a personal address to the entire internet with no filter behind it.
Decawork carries the thesis better than any aggregate. It launched on 12 August 2026 with 135 votes, selling “the agent control plane for IT teams”: identity, scoped credentials and IT sign-off for AI agents. Its security.txt Contact line is a founders alias. Its YC directory page links the launch and shows a Jobs tab reading zero. A security-adjacent company, founder-inbox intake, no careers surface. That is not negligence. That is the normal state of a four-person team three weeks before Demo Day.
One number cuts against the drama. Across the 1,000 most recent launches (an 11-month window, since the index caps retrieval), the median launch got 19 votes, the mean was 59.7, the maximum was 3,085, and 23.6% got fewer than 10 votes. For most companies Launch YC alone is a low-attention event. You just cannot know in advance which kind of launch you are having, and the intake has to exist before you find out.
Stream one: 298 applications, 15 interviews, and 21 hours you don’t have
The hiring inbound at a tiny company is larger than founders expect and lands on fewer people than at any other company size.
Ashby’s 2026 startup hiring report, built on 1,200+ venture-backed startups, 32,000 hires and 11 million applications, puts inbound applications per hire at 298 for startups under 25 employees. For every hire made, 15 applicants receive an interview, so roughly 95% of inbound is screened out before anyone talks to anyone. A technical hire consumes about 21 interviewer-hours, drawn from the same four calendars that ship the product.
Time is the part founders underestimate. At sub-25-employee startups, hiring takes 42 days with recruiter involvement and 62 days without, and only 38% of jobs at that size have a recruiter involved. A four-person team is structurally in the 62-day column. Tooling follows the same ladder: 43% of startups under 25 employees use AI anywhere in recruiting, rising to 57%, 66% and 77% as headcount climbs to the 100 to 300 band. The help accrues to the companies that need it least.
PostHog published what this feels like from the inside. On one marketing role they logged 300 applicants in the first two days, a single-day record of 900, and 9,000+ applications over 12 months at an average of 460 per role. Their in-house recruiter spent under a minute on each. Of those first 300, 12 got an interview, or 4%. PostHog had around 42 employees then, not four. Now picture the same volume with no recruiter at all.
The default response is a spreadsheet, and the data says it does not scale even at ten times your size. Employ’s 2025 Recruiter Nation Report (Zogby Analytics, September 2025, 1,200+ US recruiters and hiring managers) found 79% of talent teams still rely on spreadsheets for recruiting reporting, and 40% of companies under 50 employees rely on non-dedicated tools, against 18% at 100 to 5,000 employees.
For who you are even hiring first, see the first five hires playbook. For what 298 applications does to a review process, see the triage crisis.
Stream two: the researcher who can’t find you, and the beg bounty who already did
Publishing a security contact invites garbage. That is worth stating plainly, because it is the strongest argument for building a channel rather than exposing an inbox.
Troy Hunt’s “Beg Bounties” post (November 2021) documents template emails arriving at the address published in his own security.txt, reporting DMARC records and missing CSP headers, what Sophos characterised as “easily discoverable configurations that are publicly observable and minor in nature.” Hunt names the barrier directly: “as soon as security contacts are published, organisations have to deal with garbage reports.”
The Hacker News thread on that post carries it better than any statistic. One commenter, danielvf: “We have an up to $250,000 bug bounty for reporting a critical vulnerability in some of our code, as well a whole page on reporting issues. Never had a major report, but we get one or two of these SPF/DKIM/Headers/SSL per week.” Another, tgsovlerkhgsel, put the real cost in one line: “The beg bounty hunters make it a giant PITA to report genuine security issues.” Intigriti reports that SMEs without a formal program are the preferred target, and documents a 2025 variant where the sender manufactures the finding: upload a passport scan to an unauthenticated helpdesk, submit the resulting attachment URL to VirusTotal, then report it back as a data leak and ask for payment.
The cost of having no channel is the mirror image. CISA’s BOD 20-01 states the failure mode in the government’s own words: “If a reporter receives no response from the agency or gets a response deemed unhelpful, they may assume the agency will not fix the vulnerability. This may prompt the reporter to resort to uncoordinated public disclosure to motivate a fix and protect users.”
A real front door is still rare. An analysis of 241 million domains by IoT Defense found valid security.txt files on about 0.238% of them in 2026. In the IoT Security Foundation’s January 2026 survey, of 68 manufacturers newly added in 2025, 52 (76.47%) had no disclosure route at all. New companies are consistently the worst-covered group, which is exactly the group reading this.
Having a security@ address is not having intake
The strongest counter-example is not a company that lacked a channel. It is one that had a good one.
Mindgard reported a remote code execution flaw in Cursor (arbitrary code execution via a malicious git.exe in a repository root, no user interaction required) to [email protected] on 15 December 2025. On 15 January 2026 Cursor’s CISO acknowledged that “an automation failed that was supposed to invite to the HackerOne private bounty program.” Update requests on 16 February, 3 March, 17 March and 1 April went unanswered. Mindgard gave notice of intent to disclose on 1 June and published full details on 14 July 2026, seven months after first contact.
The channel existed and the address was correct. The intake automation and the follow-through failed, and a well-funded company got a public disclosure anyway. If you are four people, “we have a security@ address” is not the answer. An acknowledgement clock with something behind it is.
The smallest setup that actually counts
You can build both front doors in an afternoon. BOD 20-01 binds federal agencies, not your startup, and the EU Cyber Resilience Act governs products with digital elements rather than pure SaaS. Treat them as the best available template, not as an obligation you are currently violating.
- Build the intake before the policy. BOD 20-01 makes receiving capability a precondition: you must be able to receive unsolicited reports before you publish a policy. A page nobody can submit to is worse than no page.
-
Publish
security.txtwithContactandExpires. Those are RFC 9116’s only mandatory fields. Serve it at/.well-known/security.txtover HTTPS, and diary the renewal: 7.3% of thesecurity.txtfiles found in 2026 had already expired. -
Point
Contactat an alias, not a person. Six of the nine companies we found are one departure away from an unreachable channel. - Scope one system, then widen. BOD 20-01’s model adds at least one more internet-accessible system every 90 days. Start with your product domain.
- Separate the acknowledgement clock from the resolution clock. BOD 20-01 targets acknowledgement in 3 business days and a validity assessment in 7, with resolution a separate 90-day target. Acknowledgement is the promise you can keep in launch week.
- Permit anonymous reports and demand no personal data. Both are hard requirements in BOD 20-01’s model policy, and the UK PSTI regulations carry the same no-personal-information rule.
-
Add safe harbor language. disclose.io’s Policymaker generates a policy, safe-harbor terms, a
security.txtand DNS records free under CC0, no account needed. It produces a document, not a triage queue, which is the honest limit of the free option. Our safe harbor guide covers the wording that matters. -
Publish
/careersand put a pipeline behind it. One real URL, roles with a scope, and a form that writes somewhere other than a mailbox. If you would rather copy a process than invent one, start from a hiring process template.
Why this is one system, not two purchases
Put the two streams next to each other and they are the same operational shape. An unauthenticated stranger sends you something unstructured. It has to be acknowledged on a clock, triaged against a rubric, routed to a human, and closed with a decision that carries legal and reputational weight. At four people, you should buy that shape once.
The market does not sell it that way. Greenhouse publishes no prices at all, so a pre-seed founder cannot price it without a sales call. Ashby’s All-In-One Foundations tier starts at $400 a month whether you are 4 people or 90. Workable is $299 a month at the 1 to 20 employee tier, with texting, video interviews and assessments as paid add-ons. Breezy’s free plan allows one active role at a time. YC’s own Recruiting ATS is good and free, but only for YC companies, only while your YC status is active, and it does nothing for the security half. A Techstars, Antler, EF or Speedrun founder has neither half. (More on what per-seat ATS pricing costs a small team.)
The specification already made the argument. RFC 9116 puts an optional Hiring field in the same security.txt as Contact, scoped in section 2.5.6 to “linking to the vendor’s security-related job positions.” The one file a researcher fetches is designed to also carry your job listings.
That is how Kit is built. Its security_txt_body emits Contact, Expires, Policy, Acknowledgments, Hiring, Encryption and Preferred-Languages from one configuration, with a 365-day default expiry and a warning 14 days before it lapses. Behind Contact sits a public VDP reporter portal with a configurable acknowledgement window (72 hours by default), severity-graded resolution targets, rate limiting that defaults to 5 reports per 5-minute window before a temporary block, and AI screening that flags hallucinated functions, fabricated CVEs, template language and vague reproduction steps. Behind Hiring sits a public career portal, magic-link candidate access, process templates across seven role categories, GitHub-integrated code assignments, team review and voting, and interview scheduling. Both sides expose MCP tools, so an AI assistant can work the pipeline or the triage queue directly.
Be clear on what that does not buy. Kit does not distribute roles to job boards and does not benchmark salaries. It does not make you compliant with the CRA, PSTI or SOC 2; it gives you the intake, the policy surface, the acknowledgement clock and the evidence trail those regimes assume you already have. The security module also bills separately from the per-seat hiring plan, so read the pricing page rather than assuming a bundle. The claim is one vendor, one login and one security.txt, not one free extra. And nothing stops beg bounties arriving. Rate limits, screening and templated replies only change what they cost you, which is the part you control.
What to do in the three weeks before Demo Day
Three weeks out: stand up /careers with the two roles you will actually hire, and publish security.txt with Contact and Expires. Two URLs, one afternoon.
Two weeks out: write the disclosure policy (scope, permitted testing, anonymous submission, no personal data required, safe harbor) and the three candidate emails you will send most: acknowledgement, rejection, and interview invitation. Templates beat improvisation at hour 26 of a launch.
One week out: decide who owns each queue by name and what happens if that person is asleep. Set your acknowledgement window somewhere you can honour it, then test both front doors by submitting to them yourself.
The Cursor case is the reason to test. A correct address with broken follow-through produced the same outcome as no address at all, seven months later and in public.
If you want both queues running before your batch’s Demo Day, you can set up a Kit account and have the careers portal and the VDP live the same afternoon. If you would rather build it yourself from security.txt and a spreadsheet, do that instead. The one option that stops working on launch day is the founder’s inbox.
All Launch YC measurements, careers-page probes, security.txt probes and vendor pricing in this article were taken on 13 August 2026 and drift daily.
Related articles
Ready to hire smarter?
Start free for 30 days. Cancel before it ends and you pay nothing. Set up your first hiring pipeline in minutes.
Start hiring free