Carta CEO's response to the unsolicited outreach to their customers' investors
twitter.com
twitter.com
Carta CEO's first response saying it was a one time employee mistake that happened on Friday: https://x.com/henrysward/status/1743713154721554849?s=20
Evidence by Karri that it happened well before Friday, and happened to multiple other companies too, questioning if it was indeed a one time incident: https://x.com/karrisaarinen/status/1743741496921383250?s=20
The linked tweet is Carta's CEO Henry Ward's comment ranting about how Karri should have reached out to them instead of publicly questioning the company, accusing him of using this incident to increase his twitter/linkedin exposure.
This particular detail stands out as to how the solicitation actually happened: "He (Carta's CEO) explains commonly Carta Marketplace looks for sellers and buyers in their platform who have opted in to it. But in this case the employee in question, again not employed by Carta but a separate business, Carta Marketplace, was able to access our cap table data by their “break the glass” system which requires approval to see customer data. He didn’t know how it was done, he offered that potentially the employee self approved the request. The employee in question was put on administrative leave."
Lol, the employee (of technically a different business entity?) might have accessed the info through self approved request, but Carta's CEO is sure that this only happened this Friday to one company and is a one time incident. Yeah, I don't believe it.
That begs the question, when is that system supposed to be used? In what sorts of situations would it be beneficial to Carta'a clients for another company (Carta Marketplace) to access their confidential information?
Perfectly justified reason, and a reasonable feature. But I would bet that essentially everyone at “both” cartas who interact with founders or investors have access, and while theoretically every break glass is logged with a justification, and those justifications are audited, every single one says “helping company (company being accessed)”. That’s assuming anyone even looks at the audit trail (Narrator: they do not).
The trick is you need to actually audit the use. We reviewed every access, audited as part of our soc 2 commitments, at a +2 reporting level the next business day.
How does Karri know this? Did someone in the email group tell him? Why would a VC leak information damaging to the company?
And if this is true, isn't this an implication that Henry is lying to investors about the problem? Karri has already proven he hasn't opted in to CartaX.
Apologising and saying you will put processes into place to prevent it happening again is corporate comms and emotional 101, and it would have blown over in a week.
This buy order was for $2.5M, they take 2% transaction fee
from the buyer and seller.
We pay them about $10k a year for the cap table management
but this transaction alone would net them $100k.
So I can see the temptation.There are competitors that have (1) better product (2) cheaper and (3) better customer success. Nobody has to stay with Carta. Just move away, and you can get better service at an affordable price. I used Cake Equity, but I am sure there are other options available.
> It took me multiple calls with customer representative to cancel my account because Carta did not want to automatically add an option for people to cancel their plan.
This is not how most people would describe "care about [...] customers."
paulg is talking about Carta apparently used to email investors to advertise the existence of their new CartaX (Liquidity) platform. I don't know the contents of these emails, but I assume it was something like, "if you ever want to sell, ask your founder to opt-in to CartaX." I don't agree with this practice, and Henry apparently also said "sending marketing emails to investors is at best poor taste if not just wrong"[1].
In my opinion this case is a bit different, because not only are they apparently advertising Liquidity to investors, but Karri is saying they are trying to broker deals and close sales through back channels without the founders knowing or opting in to Liquidity.
Either way, in my opinion this history adds a bit of evidence to support this is a wider problem in how Carta employees treat data privacy.
1: https://nitter.net/MarwanRefaat/status/1357820073918910464#m
I was expecting more of a statement: Carta does not spam or solicit our customers’ investors. In this case, there was a salesperson who broke our rules, and they have been terminated. We apologize for the mistake. Please contact your account rep if you have any concerns.
https://sfstandard.com/2023/10/25/carta-san-francisco-lawsui...
Should have left to “it has come to my attention that X has happened. It was a one time incident and we did Y to rectify it. I am sorry this happened and we are doing Z so it doesn’t happen again. We deeply value our customers privacy and trust. Our mission is X and I will ensure we will do right by our customers.
- Yours truly, CEO “
Deflecting and talking about values and abstract things to avoid directly addressing the issue is however and is what should be condemned on HN.
Your point still stands though as the emotional petulant rant in this case was even worse than a spineless corp speak response.
At minimum, this is confidential information. At worst, they may be leveraging privileged information that only they and your Board have.
Either way, it's ugly. Even with a good explanation and tight controls in place, it needs to be opt in for shareholders.
Could have just ended it there and it would have been over, acknowledge the issues, apologize and promise to do better. Then for some unknown reason he just said Forget it and set the company of fire.
Who is ever going to want to talk with that CEO, if he posts a Tweet like this as a followup? Or do business with him at all?
If you're a prospective customer or partner, and this is what you've seen, are you going to bother researching, to find out whether this was a fluke or typical behavior?
So, if it was a fluke, I'd think the best move is to make the very next messaging be an all-out effort to un-fudge it all up.
We all have bad moments, and I'd like to think there's an imminent un-fudging.
I'm utterly ignorant about this, I think every tech company I've worked at that offered options has used it, and I've often wondered how things worked before it existed.
Sorry but I just don't buy it. When you communicate this way it becomes apparent that the truth isn't on your side, or if it is then it's not what is most important to you.
Stick to the facts guys. Either information was used inappropriately or not, it was either systemic (i.e happening all the time) or occured because of a lapse of controls or specific employee trying to get around said controls (in which case you should probably fire them). Identify and disclose which it is along with what you are doing to fix it.
There is no need to muddy the conversation with the why/ethics/whatever of getting called out.
The accusation was clear, as should have been the response.
https://henrysward.medium.com/what-i-tell-employees-about-ne...
Some of the information about this incident highlights a breach of information ethics, and the rest is all accusation from people who don't know the internal company data access protocols.
Founders need investors, and investors want access to shares, pricing, and valuation info. The problem getting completely left out of all discussion about this, is that the usage of this data (which should be ethical and signed off on certainly) to enable private market liquidity MOST benefits the employees. Carta killing this business is a huge setback to financial improvement for startup employees. But you know, as long as founders feel cozy it's all good.
Sure is starting to look like they cooked their own goose. How can the CEO state with a straight face that "it's a separate company" but they can "self-approve" (he doesn't even know?? Why would you even agree to hop on a call with a customer without knowing. Come on.) to breakglass access everyone's cap table?
They're fucked.
Not looking forward to all the email threads I'm going to see on Monday. Didn't have this one inked on the Q1 plan.
Now we're all wondering what other shenanigans they're likely pulling.
If it’s legal and only if it’s legal and the whole company has to be broken apart will they suffer for this. But I’m not sure how they’re breaking any legal laws?
But I also doubt that it is legal. I am not a lawyer but I'm sure over the next week plenty of lawyers will be reviewing the same documents that I have read, and it doesn't seem like this is above board.
I'm sure their legal team is scrambling to contain this before any discovery arrives.
Carta depends, critically, on it's reputation as a secure and trustworthy platform. By any measure they appear to have violated that trust.
Are you saying Carta doesn't give a fuck about their customers? Wow, lol. You (ironically?) hit the nail on the head.
Anyway, they're not pissing off just the ones you see directly affected here, each one of those will likely advocate against them in his/her own circle, and any business they might be involved with in the future. Also, these discussions and this incident, will live on the internet forever. Carta's brand, and their CEO's reputation will remain tainted, no matter how trivial you might view this, and it will be a golden edge for their competitors.
They'll experience the power of the almighty Word-of-mouth marketing but going downhill.
1. Apology (great, I hope they end it here) 2. Shift the blame slightly (uh oh) 3. Attempt to make him feel bad (yikes) 4. Question the initial incentive (big yikes) 5. Full conspiracy (big big yikes)
Extremely manipulative and weak feeling.
Product: https://www.angellist.com/startups/equity
Comparison to Carta: http://angellist.com/startups/angellist-vs-carta
[1] https://nitter.net/henrysward/status/1743794996732735679u
Barring something within the shareholder agreement (between the startup employee and the startup) that bars the employee from selling those shares on Carta's platform, what's the issue?
You’re a startup who keeps a payroll spreadsheet in Google Sheets and the Google recruiting team accesses that data to recruit your employees and decide how much to offer them.
There’s nothing wrong with Google trying to hire your employees, but it’s wrong for them to use your confidential data from another business unit to do so.
Maybe I'm misunderstanding? But that doesn't seem like they're sharing cap table data with anyone. They've found a buyer for the employee's shares at some price. Is it implied that they shared the cap table info with that buyer (i.e. the third party investor)?
But I hope people wake up to what they are agreeing to when they sign up as a user for Carta. Carta makes you agree that they owe you NO duty of confidentiality with respect to any information you submit into the service.
Some, like Elon, may seem to be untouchable in the end, but I can’t imagine this is good at all for Carta’s – checks notes – cap table?
What exactly is special about series B shares that should prevent Carta from making a market for trading such shares? Does anyone have an actual argument that would actually be sensible in a capitalist framework?
If I had a contract with you to keep something of yours safe, and you found out I sold it, would your response be something like “behold the power of the free market”?
Seriously though, your comment and questions are not genuine, you're trying to setup a "capitalism is bad" narrative using this story as an example.
I'm not buying it.
And as a customer, I expect my vendor not to take my data and use it against me.
And then when I simply ask for clarification why this is happening not be gaslighted and made to feel a victim.