Qubit Security presented an 18-slide deck in early 2017 to secure a $3M Series A investment. The company positions its 'Plura' platform as a modern, SaaS-based alternative to traditional security infrastructure like Firewalls, WAFs, and SIEMs, which it critiques as expensive and inefficient. At the time of the deck, Qubit claimed 170 customers and 500 servers under management, processing 800 million logs. The deck relies heavily on architectural diagrams and market growth statistics from IDC to justify its expansion. While it provides a clear breakdown of how the $3M would be spent—prioritizi…
Key takeaways
- The company sought a $3M Series A investment in Q1 2017 following a $1.6M Seed round in 2015 (Slide 16).
- Qubit Security reported a traction base of 170 customers and 500 servers, processing 800 million logs (Slide 11).
- The product architecture requires installing a 'Plura Agent' on the customer's server to facilitate real-time log transfer to the Qubit Cloud (Slide 7).
- The business model features three tiers: a Free 'Starter' plan, a $200/month/host 'Premium' plan, and a 'Direct Contact' Enterprise tier (Slide 14).
- Market data cites a $78B global information security market with a 15.3% CAGR for the $2B SIEM segment (Slide 9).
- The core team claims a long history of collaboration, stating they have been 'More than 10 years together' (Slide 15).
- Revenue growth targets are segmented by channel, aiming for $1M from direct enterprise access and $400K from cloud IaaS channels (Slide 13).
- The $3M investment is earmarked for Infrastructure ($1M), Overseas expansion ($1M), New Hires ($600K), and Marketing/Sales ($300K) (Slide 16).
Executive Summary and Value Proposition
Slides 1-2: The Hook
Qubit Security opens with a clean, product-focused title slide featuring the 'Plura' dashboard on a laptop. The CEO, Seungmin Shin, is identified immediately. The second slide serves as the high-level pitch: 'Qubit Security SaaS Cloud REAL-TIME ANTI-HACKING.' The core mission is stated simply: to analyze logs in real time to detect and block hacking. This is a standard, effective opening that identifies the product category (SaaS Security) and the primary function (Log Analysis) without technical jargon.
The Problem and Market Context
Slides 3-5: The Failure of Legacy Systems
Slide 3 visualizes the 'Current Security System' using generic icons for Firewalls, WAFs, IDS/IPS, and SIEM. Slide 4 provides the 'Why Now' justification, citing FireEye and W3C data. It claims it takes 146 days to detect a breach and that 99% of systems are vulnerable. Slide 5 summarizes the 'Problem' with existing systems, labeling them as expensive, unreliable, and 'unattractive.' While 'unattractive' is a subjective and perhaps weak critique for enterprise security, the other points focus on the lack of integration and scalability in traditional hardware-heavy setups.
Slide 9: Market Size
The company targets the Information Security Market, which it values at $78B globally. It drills down into the SIEM (Security Information and Event Management) sub-sector, valued at $2B with a 15.3% CAGR. The bar chart shows steady growth in SIEM spending from 2009 to 2015, sourced by IDC. This slide establishes that they are playing in a large, growing market, though it doesn't specify their projected share of that market.
Product and Technology Deep Dive
Slides 6-8: Architecture and Compatibility
Slide 6 lists the Web and OS logs the platform can analyze. It covers the major players: Apache, NGINX, Windows Server (2008 through 2016), and Linux (CentOS, Redhat, Ubuntu). This demonstrates broad market applicability. Slide 7 explains the 'Qubit SaaS Architecture.' The process is a simple three-step visualization: Install Agent -> Customer's Server -> Real-Time Log Transfer to Qubit Cloud. Slide 8 showcases the user interface on both desktop and mobile (Samsung/Android), noting support for Korean, English, Japanese, and Chinese languages, signaling global ambitions.
Traction and Business Model
Slides 10-11: Proof of Concept
Slide 10 lists 'Reseller Partners.' Completed contracts include iNet, Sejong Telecom, and Whatap. The 'in progress' list is more ambitious, featuring Naver Business Platform (NBP), NHN Entertainment, and SoftBank Group (SB CK). Slide 11 provides the hard data: 170 customers, 500 servers, and 800 million logs. For a Series A pitch, these numbers provide a baseline of activity, though the '500 servers' figure suggests the average customer is quite small (approximately 3 servers per customer).
Slides 12-14: Competition and Revenue
Slide 12 is a simplified competitive landscape. It places Qubit Security against giants like IBM QRadar, Splunk, HP ArcSight, and LogRhythm. The claim is that Qubit is 'Easier, Better, Cheaper.' However, there is no feature-by-feature comparison to back this up. Slide 13, 'How to make money,' shows a path to $2M in revenue through various channels, including e-learning, game publishers, and IaaS channels. Slide 14 details the pricing tiers: a Free Starter pack, a $200/month/host Premium pack, and a custom Enterprise tier. The Premium tier includes system hacking prevention and 60-day log search, which are absent in the free version.
Team and Investment Ask
Slide 15: The Team
The team slide features seven individuals, with a note that there are '+8 More.' A significant portion of the team, including the CEO, CCO, and several developers, comes from WindySoft Inc. The slide highlights a 'More than 10 years together' history, which is a strong signal for investor confidence in team stability. The inclusion of a 'Hacker' (Juho Park) with CTF finalist credentials adds technical credibility to a security firm.
Slides 16-18: The Ask
Slide 16 is the most critical for the fundraise. It shows a $1.6M Seed investment in 2015 and a request for a $3M Series A in Q1 2017. The allocation of funds is clear: $1M for Infrastructure, $1M for Overseas expansion, $600K for New Hires, $300K for Marketing & Sales, and $120K for Operations. The deck concludes with a 'Looking for Partners and Investors!' call to action and a 'Thank you!' slide.
What Works / What is Missing
What Works: The deck is visually consistent and avoids over-cluttering slides with text. The architectural explanation (Slide 7) is exceptionally clear, making a complex technical process easy for a non-technical investor to understand. The team's long history of working together is a major asset that is highlighted well. The clear breakdown of the $3M ask shows that the founders have a specific plan for the capital, particularly regarding infrastructure and international growth.
What is Missing: The most glaring omission is the lack of specific revenue figures. While Slide 13 shows 'How to make money' with various dollar amounts, it isn't clear if these are historical figures or future projections. Furthermore, the unit economics (Customer Acquisition Cost vs. Lifetime Value) are entirely absent. The competitive analysis is also very thin; simply claiming to be 'Cheaper' and 'Better' than Splunk or IBM without data points is unlikely to satisfy a sophisticated Series A investor. Finally, there is no mention of the 'moat' or proprietary IP—what prevents a larger competitor from simply lowering their price or launching a similar SaaS agent?
Founder Takeaways
Focus on the 'Agent' Model: If your startup uses a distributed architecture (like an installed agent), use Qubit's Slide 7 as a template. It perfectly balances the 'where it lives' (Customer Server) with 'where the value happens' (Cloud). Quantify the Team Bond: If your core team has a long history, don't just list their resumes. Use a phrase like '10 years together' to signal that the team is 'divorce-proof,' which is a common concern for early-stage investors. Be Specific with the Ask: Don't just ask for a lump sum. The bar chart on Slide 16 that breaks down the $3M into specific buckets (Hires, Marketing, Infrastructure) shows a level of operational maturity that investors appreciate.
Frequently asked questions
- What is the primary problem Qubit Security aims to solve?
- According to Slide 5, Qubit Security identifies existing security systems as expensive, unreliable, and poorly integrated. They specifically target the inefficiency of traditional Firewalls, WAFs, and IDS/IPS setups, which they claim suffer from poor accuracy and lack of scalability. The deck highlights that it takes an average of 146 days to detect a hack, suggesting current tools are too slow.
- How does the Plura platform actually work technically?
- The technical approach is detailed on Slide 7. It involves a 'Plura Agent' installed directly on the customer's server. This agent performs real-time log transfers to the Qubit Cloud. Slide 6 specifies that the system analyzes logs from various environments, including Apache, NGINX, Windows Server (2008-2016), and Linux distributions like CentOS, Redhat, and Ubuntu.
- What is the company's current market traction?
- As of the deck's publication in early 2017, Slide 11 reports 170 customers and 500 servers managed. They also claim to have processed 800 million logs. Slide 10 lists completed reseller contracts with Sejong Telecom and Whatap, with 'in progress' contracts involving larger entities like Naver Business Platform and SoftBank Group (SB CK).
- What is the specific financial ask and valuation?
- The deck asks for a $3M Series A investment in Q1 2017 (Slide 16). It mentions a previous $1.6M Seed investment from 2015. However, the deck does not explicitly state the pre-money or post-money valuation for the Series A round, nor does it provide current revenue figures beyond a 'How to make money' growth chart.
- Who are the key members of the leadership team?
- The team is led by CEO Seungmin Shin, a cryptographer and former CTO of WindySoft Inc. Other key members include CCO Kyeongsoo Yeom, CTO Sayoun Kim (formerly of Alticast), and a dedicated 'Hacker' named Juho Park who was an ISEC CTF 2011 finalist. The slide emphasizes that the core team has worked together for over a decade.
