Our first real enterprise deal didn't stall on the product. The team that would actually use AIVA loved it after the first demo — booking flows, language coverage, the analytics dashboard, all of it landed exactly the way we'd hoped. It stalled for eleven weeks in procurement, a process we hadn't budgeted for, run by people we never spoke to directly, asking questions nobody on our team had ever been asked before, about parts of the business we'd genuinely never had reason to formalize.
The gap nobody warns you about
Selling to a small business is a conversation. Selling to an enterprise is a conversation followed by a review process that has nothing to do with whether they liked the product. Our prospect's team wanted AIVA. Their procurement function wanted a security questionnaire running to several hundred line items, a data processing agreement, answers about sub-processors, a documented incident response process, evidence of employee access controls, and a vendor risk score we didn't know existed as a concept until we were being scored on it and asked to explain a number we hadn't produced ourselves.
We were a bootstrapped team who'd spent two years obsessed with latency and language coverage — the things a customer actually experiences on a call. Nobody had spent meaningful time on the document that turned out to gate the entire deal, because until that point, nobody had ever asked us for one. Our existing customers signed up, added a card, and started taking calls the same afternoon. This prospect's legal and security teams had never heard of us, would never sit in on a demo, and didn't care that the voice latency was under 200 milliseconds. They cared whether we could produce a data flow diagram and name every third party that ever touched a customer's data.
What we actually had, and didn't
We didn't walk in with a shelf of compliance certifications. We're honest about that — we didn't have them, and pretending otherwise in a security questionnaire is the fastest way to lose an enterprise deal permanently rather than slowly, because a reviewer who catches one overstated answer stops trusting every other answer on the page, including the true ones. What we had was a real answer to every question, even when the real answer was "we don't have that yet, and here's what we do instead."
Where we didn't have a formal certification, we offered a call with the actual engineer who owned that part of the system, willing to walk their security team through exactly how it worked. That's not a substitute for certification in general — a reviewer scoring vendor risk against a checklist can't tick a box because someone sounded credible on a call. For this deal specifically, it turned out to matter more than we expected. Their reviewer told us afterward that most vendors send a compliance team member reading from a script, and getting the person who actually built the thing was unusual enough to be reassuring rather than alarming — it read as a company with nothing to hide behind the answer, not a company too small to have a proper process.
Being small and honest beat being polished and vague. We couldn't fake a certification. We could answer, in detail, every single time, without a script.
There was a point, around week five, where a consultant reached out offering to help us "get compliance-ready fast" — the pitch was closer to packaging what we already had into more impressive-sounding language than doing any of the underlying work. We passed. Dressing up an honest "not yet" as something further along than it was felt like exactly the move that would cost us the deal the moment anyone checked, and worse, it would have meant lying to a team that was actually paying close attention. Slower and real beat fast and cosmetic, even under deadline pressure — the same trade-off we keep making in how we market AIVA generally, just with a lot more money riding on it in this particular instance.
The moment we almost let it go
Somewhere around week seven, with no clear signal on timeline and a second round of follow-up questions that felt like it was starting the review over, we seriously discussed whether to keep investing founder time in a deal that might not close. Eleven weeks is a long sales cycle for a company our size to carry without certainty, and every week spent answering a new procurement question was a week not spent on product or on the pipeline of smaller customers who'd sign up and start paying the same day. We didn't walk away, mostly because the team that would actually use AIVA kept telling us, unprompted, that they were still pushing internally on their side. That signal — that the delay was procurement doing its job carefully, not the deal quietly dying — is what kept us in it. Without it, I'm not sure we would have stayed the course.
What we changed because of it
We didn't pass procurement and move on. We used the questionnaire as a punch list. Every question we couldn't answer well became a task: formalize an incident response process, document our sub-processors properly, write down data handling practices that had lived only in our heads until someone outside the company forced them onto paper. None of it was theater for the deal — all of it was work we should have done anyway, and having a real prospect ask forced a prioritization that "we should get around to this eventually" never had.
That punch list is where our current DPA and public sub-processors list came from — both public documents now, not assembled from scratch under deadline pressure the next time someone asks. It's also where our SOC 2 and ISO 27001 work started. Neither is a finished certification today, and we say so plainly on our security page rather than let the acronyms imply more than they mean: SOC 2 Type II is in progress, with a Type I report available now under NDA, and our ISO 27001-aligned controls are self-attested rather than independently certified. None of that existed when this deal began. We'd rather show the real, current state of that work than round it up to sound more finished than it is.
What I'd tell another small founder
Budget procurement as its own sales stage, with its own timeline, separate from the product conversation, and separate from your pipeline forecasting — treat it more like structuring custom pricing for a large account than like closing a self-serve signup. It will take longer than you think, involve people who never see your demo, and ask questions that have nothing to do with whether your product is good. Don't try to look bigger than you are — a small company pretending to have enterprise-grade compliance theater is more suspicious to a trained reviewer than a small company being precise about exactly what it has and doesn't. It's the same instinct behind why we hired for customer success before sales: the relationship after the signature matters as much as the one before it, and a reviewer can usually tell which kind of company they're evaluating.
Eleven weeks after that first questionnaire landed in our inbox, we signed the deal. The product didn't change in that time. Our ability to answer honestly, in detail, every time we were asked something hard — that's what closed it. If your own procurement team is asking similar questions about us right now, our security page is the place to start, and we'd rather get the hard question directly than have it stall quietly in someone's inbox for a week before it reaches us.