The economics are simple. Before launch, a design flaw costs a sprint to fix. After launch, the same flaw costs a migration, a customer notification, and possibly a regulator conversation under the DPDP Act. The cheapest security spend a startup makes is the earliest one.
There is also a commercial driver that founders underestimate: the first enterprise customer will ask for a penetration test report, a security questionnaire response and often an attestation letter. Having one already reduces a six-week procurement stall to a document you attach.
A sensible pre-seed to Series A sequence: threat model the architecture before building the sensitive parts, review the authentication and payment code once it exists, and run one full application penetration test in the quarter before you start selling to companies larger than yourself.
In short
- Handling money, health data or PII? Test before launch.
- Pre-product-market-fit and low risk? Model and review first, test later.
- Enterprise sales will require a report eventually — get ahead of it.
- DPDP Act obligations in India apply well before you feel like a big company.