{"id":167,"slug":"managed-platforms-buy-security-team","title":"Counter-argument: a $200/mo managed platform buys you a larger security team than most agencies have","kind":"reference","scope":"business","status":"current","audiences":["kevin","claude-code","candid-team"],"topics":["tech-stack","platform-lock-in"],"reference_body":"**Claim (honest steel-man):** WP Engine, Shopify, and Squarespace each employ security teams larger than most agencies. A self-hosted VM with no patching discipline is *more* vulnerable than a managed platform, not less. A small business paying $200/month to WP Engine is **buying a security team**, not just hosting.\n\n**Source:** Honest gap H1 in brief 4 ([[research-brief-owning-your-stack]]).\n\n**Confidence:** Industry-consensus.\n\n**Implication for Candid positioning:** The argument for \"owned stack\" depends on **operational competence** that the article cannot assume. Don't pretend self-hosting is free — it isn't. The right comparison is **total cost of ownership** (license + dev time + security + on-call + backup ops), not just license fees. This is where the maintenance-retainer line item in Candid pricing earns its keep.","rationale_body":null,"metadata":null,"links":{"outgoing":[{"slug":"rule-server-render-for-ai-crawlers","title":"RULE: Always server-render or statically generate content for AI crawlers. Never ship client-side-only HTML.","kind":"rule","scope":"business","link_type":"relates-to"}],"incoming":[{"slug":"rule-treat-no-export-as-hostage-situation","title":"RULE: A platform that cannot produce a clean export today is a hostage situation. Treat it as such.","kind":"rule","scope":"business","link_type":"relates-to"},{"slug":"research-brief-owning-your-stack","title":"Research brief: Owning your stack — why agency-managed platforms cost more than they save (piece 4 of 15)","kind":"reference","scope":"business","link_type":"relates-to"}]},"created_at":"2026-05-22T19:17:51.370Z","updated_at":"2026-05-22T19:17:51.370Z"}