Stop Clutching Pearls: Why Carta's Catastrophe Isn't What You Think
Silicon Valley is up in arms over revelations that employees at Carta's brokerage business improperly accessed sensitive cap table data from Carta's core SaaS business in order to connect buyers and sellers of startup shares. The conventional wisdom is to blame Carta for this "breach of trust" in mishandling sensitive customer data.
But there's another way to view this story that puts responsibility back on the global startup community. Founders freely provided their confidential cap table data to Carta without any data centric policy controls and technical safeguards in place. In the spirit of caveat emptor, if you subscribe to Carta’s service and you agree to give them your sensitive cap table data without any policy controls in place, then perhaps you bear some responsibility for any misuse.
Rather than clutch pearls when things go wrong, founders should have demanded proper data protections upfront. What if founders agreed to share their data with Carta only after it had been protected by a policy control capability like the open Trusted Data Format (TDF)? The data itself could have been policy-wrapped to restrict access to only approved purposes.
With granular data-centric security controls, implemented by Carta, or implemented by the data owners themselves, this entire fiasco could have been avoided. Founders could freely share sensitive data with Carta without sacrificing security, privacy, or control. Properly protecting data from the start would have prevented improper access downstream.
As I have written previously, this is not a technology issue — the technology is ready — it is a willingness issue. My brother, Will Ackerly, and I started Virtru in 2012 to address a global crisis of Trust and lay the foundation for individuals and enterprises to exercise the fundamental human right to privacy and security. Today, we are giving the public and institutions (over 7,000) easy-to-use and practical tools to take action to protect their data wherever it is shared. Our careers in government gave us insight into the foundational failure of the early internet: that you must trust third parties to “do the right thing” with your data, and that these entities were, at best, cavalier with this responsibility. (And, Virtru is indeed not alone – there is an emerging group of companies and groundbreaking new approaches, working to return ownership and control to data owners.)
It's time for the startup world to evolve its understanding of data-centric security. Rather than simply blame third parties after a breach, demand they implement controls like encryption and granular policy enforcement on your data first. Take responsibility for securing your data before it ever leaves your hands.
There’s also strength in numbers: When a critical mass of privacy-minded startup leaders and their organizations take action to demand better protections for data, big things can happen — and we all benefit as a result.
Once again, Carta's catastrophe demonstrates the need for data-centric security standards to allow organizations to share sensitive data without sacrificing control over the data itself.
John Ackerly
As Virtru's CEO and Co-Founder, John is a long-time privacy advocate with experience scaling growth companies and shaping technology policy. He previously served leading economic and strategic roles in the White House and U.S. Department of Commerce. John holds degrees from Williams College, Oxford as a Rhodes Scholar, and an MBA from Harvard Business School.
View more posts by John AckerlySee Virtru In Action
Sign Up for the Virtru Newsletter
Dive Deeper

"This Message Will Self-Destruct": Secure Document Sharing With an Access Kill Switch

Email Encryption for Banks: What CISOs Need to Know in 2026
/blog%20-%20anthropic%20boat/anthropic-boat.webp)
Mythos Is a "Walls Crumbling" Moment — And We're Gonna Need a Smaller Boat
/blog%20-%20mythos%20john/ai-john-mythos.webp)
Anthropic Just Proved What We've Been Saying: Security Has to Start with the Data
/blog%20-%20pubsec%20AI/pubsecAI.webp)
Public-Sector AI Needs Secure, Controlled Collaboration
/blog%20-%20RSA%202026/RSA-BLOG.webp)
RSA 2026: Hope, Hype, and a 20-Year Unsolved Problem

DCS in Action: How Virtru and the Trusted Data Format Power the Mission

Policy Foundations & Strategic Guidance: Data-Centric Security as a Mission Force Multiplier

The Splinternet Problem Has One Solution: Data Interoperability

Beyond Blockchain: Why Operational Data Security Is Crucial in Crypto
/blog%20-%20DCMMC%202026%20Recaps/DCMMC-BLOG-RECAP-2.webp)
Lead CMMC Assessors and C3PAOs: Your Procurement Instincts Could Be Costing You
Book a Demo
Become a Partner
Contact us to learn more about our partnership opportunities.
Become a Compliance Champion
Contact us to learn more about our partnership opportunities.