GreatHorn’s Demo Day deck is a lean, visual-heavy presentation designed for the fast-paced environment of an accelerator graduation. The company positions itself as a proactive layer in the cloud communication security stack, targeting a $36 billion market. The narrative moves quickly from the problem—spear phishing and unauthorized access across platforms like Slack and AWS—to a technical solution involving ML-based emergent detection. The standout feature of this deck is its traction curve, showing a steep climb from near-zero to 16 million emails protected between September and December 20…
Key takeaways
- The company defines its value proposition as 'Know Before The Breach' on the title slide.
- GreatHorn targets a $36 billion cloud communication market as of 2019 (Slide 4).
- The solution addresses security gaps across diverse platforms including AWS, Slack, Yammer, and QuickBooks (Slide 3).
- A product demonstration slide highlights the specific threat of spear phishing within a standard inbox (Slide 5).
- The technical architecture utilizes a 'Data Lake' and 'ML SVM' for emergent detection (Slide 6).
- Traction grew exponentially from September 2015 to 16 million emails protected by December 2015 (Slide 7).
- The deck leverages a 'Strategic Partnership' with Microsoft to build institutional trust (Slide 8).
- The presentation omits a specific dollar amount for the 'Ask' or a detailed breakdown of the founding team's history.
The Demo Day Format: Visual Impact Over Text Density
The GreatHorn deck is a quintessential example of a Demo Day presentation. Unlike a 'send-ahead' deck that an investor might read in silence, this deck is designed to support a live speaker. It features minimal text, large-scale graphics, and a focus on high-level momentum. The goal of this specific deck was not to close a round on the spot, but to generate enough intrigue to secure follow-up meetings with the venture capitalists in the audience at Techstars NYC.
Slide 1: Brand Identity and Mission
The title slide introduces the GreatHorn logo—an owl—and the tagline "Know Before The Breach." This immediately positions the company in the proactive cybersecurity space. The use of the owl symbol suggests wisdom and vigilance, which are standard tropes in security branding, but the clean, modern illustration keeps it feeling like a contemporary SaaS product rather than a legacy enterprise tool.
Slide 2 & 5: The Product in Context
Slide 2 shows a clean laptop mockup with a blurred inbox. This is a setup for Slide 5, which provides the 'reveal.' On Slide 5, we see a specific spear phishing email: "Can you authorize this? ... I'm expecting a package at the office today - can you track it for me here?" A red arrow points to the GreatHorn alert label. This is an effective way to demonstrate the UI/UX without getting bogged down in a feature list. It shows the investor exactly what the end-user sees: a clear warning in a familiar environment (Gmail).
Slide 3: The Expanding Attack Surface
Slide 3 is a critical 'Problem/Scope' slide. It places a group of people at the center, connected to various cloud services: Amazon Web Services, Yammer, Slack, Intuit QuickBooks, and Concur. This slide communicates that GreatHorn is not just an email filter; it is a security layer for the entire modern 'cloud-first' workforce. By including logos like QuickBooks and Concur, they signal that they are protecting financial data and employee travel/expense records, which are high-value targets for hackers.
Slide 4: Market Validation
GreatHorn keeps its market slide incredibly simple. It quotes a "$36 billion cloud communication market, 2019." By using a future-dated projection (relative to the 2015 presentation date), they are telling investors that they are riding a massive, growing wave. The lack of a 'TAM/SAM/SOM' breakdown is typical for a Demo Day pitch where brevity is prioritized over granular financial modeling.
Slide 6: Technical Architecture
To satisfy the technical due diligence requirements of a seed-stage investor, Slide 6 provides a high-level architecture diagram. It highlights "GreatHorn Preprocessors + Sensors" feeding into a "Detection and Classification Rule Engine" and an "ML SVM (Emergent Detection)." The mention of 'ML SVM' (Machine Learning Support Vector Machine) was a significant buzzword in 2015, signaling that the company was using advanced data science rather than just simple blacklists to identify threats. The "Data Lake (Aggregated Learning Set)" at the bottom suggests a network effect: the more customers they have, the better their detection becomes for everyone.
Slide 7: The 'Hockey Stick' Traction
This is the 'money slide' of the deck. It shows a cumulative growth chart of "16 Million Emails Protected." The timeline is short—only four months (Sept 15 to Dec 15)—but the slope is steep. Going from near-zero to 16 million in such a short window is a powerful indicator of product-market fit and the scalability of their automated onboarding process. It proves that their 'sensors' are easy to deploy across large organizations.
Slide 8: Strategic Validation
Slide 8 features the Microsoft logo prominently with the text "Strategic Partnership." For a startup in the crowded cybersecurity field, validation from a platform giant like Microsoft is invaluable. It serves as a proxy for technical quality and enterprise readiness, reducing the perceived risk for potential investors.
Slide 9: The Call to Action
The deck concludes with the owl logo and a generic contact email: founders@greathorn.com . In a live Demo Day setting, this is usually when the founder gives their final 'ask' verbally, even if it isn't written on the slide.
What Works in this Deck
Visual Clarity: The deck uses a consistent dark theme with high-contrast orange and white text. It is highly readable from the back of a large auditorium. · Focus on Scale: By focusing on the number of 'emails protected' rather than just 'number of customers,' GreatHorn emphasizes the sheer volume of data they are processing, which reinforces their machine learning narrative. · Concrete Examples: Showing a real spear phishing email makes the abstract concept of 'cloud security' tangible for the audience.
What is Missing
The Team: In the provided slides, there is no mention of the founders' backgrounds. In cybersecurity, founder pedigree (e.g., ex-NSA, former CISO, or previous successful exits) is usually a major selling point. · Business Model: The deck does not explain how they charge. Is it per user, per month, or based on data volume? While not always necessary for a Demo Day pitch, it is a gap for a full teardown. · Competitive Landscape: There is no mention of how GreatHorn differs from incumbents like Proofpoint or Mimecast. They rely on the 'cloud-native' imagery to imply this difference, but they don't state it explicitly. · The Ask: There is no slide detailing how much capital they are raising or what the milestones for the next 18 months will be.
Founder Takeaways
If you are preparing for an accelerator demo day, the GreatHorn deck is a strong template to follow. Prioritize one major metric (like their 16 million emails) and make it the centerpiece of your presentation. Use high-signal logos to build credibility quickly, and don't be afraid to use simple diagrams to explain complex technical stacks. However, ensure that your 'read-only' version of the deck includes the team and financial slides that this live-presentation version omitted.
Frequently asked questions
- What specific problem does GreatHorn solve?
- GreatHorn focuses on identifying and preventing breaches before they occur, specifically targeting vulnerabilities in cloud communication. Slide 5 illustrates this by showing a spear phishing attempt disguised as a routine internal request. The deck suggests that as companies move to cloud tools like Slack and AWS (Slide 3), traditional perimeter security is insufficient, necessitating their automated analysis engine.
- How does GreatHorn's technology work according to the deck?
- Slide 6 outlines a multi-layered technical stack. It begins with 'Preprocessors + Sensors' that feed into two parallel engines: a 'Detection and Classification Rule Engine' for known threats and an 'ML SVM' (Support Vector Machine) for 'Emergent Detection' of new threats. These feed into a central Analysis Engine and a Data Lake, which aggregates learning sets to improve protection across all client endpoints.
- What is the scale of GreatHorn's market opportunity?
- The deck identifies a $36 billion cloud communication market by the year 2019 (Slide 4). By framing the problem around communication tools rather than just 'email security,' GreatHorn expands its potential reach to include any platform where employees interact, such as Yammer, Slack, and even financial tools like QuickBooks (Slide 3).
- What traction did the company demonstrate during its time at Techstars?
- The traction slide (Slide 7) is the most compelling piece of evidence in the deck. It shows a sharp upward trajectory in the number of 'Emails Protected.' Starting at a negligible amount in September 2015, the volume increased to approximately 2 million in October, 7 million in November, and peaked at 16 million by December 2015.
- Who are the key partners mentioned in the deck?
- The primary partner highlighted is Microsoft, noted as a 'Strategic Partnership' on Slide 8. Additionally, the deck implies compatibility or integration with a wide ecosystem of enterprise tools, showing logos for Amazon Web Services, Yammer, Slack, Intuit QuickBooks, and Concur (Slide 3).
