Live in production · still shipping
B2B SaaS development case study: CyberFind, a cybersecurity vendor review platform.
Five hundred CISOs will not trust a star rating. CyberFind is a B2B SaaS peer-review and comparison platform where verified security leaders evaluate awareness-training vendors: replacing analyst PDFs and vendor calls with evidence a buyer can defend to their board.
The hard part was never the platform. It was making a review believable enough to shortlist from.

- Industry
- Cybersecurity · vendor intelligence
- Platform
- Next.js · Node.js · PostgreSQL
- Engagement
- Discovery → MVP → continuous delivery
- Community
- 500+ verified CISOs and directors
Vendor comparison & verified peer reviewLive in production
500+
Verified CISOs
1,000+
Peer reviews
4
Years in production
0
Rewrites since launch
About the client
About the client
CyberFind set out to fix one deeply expensive problem in enterprise security: choosing the right security-awareness training vendor without a call to a peer or an analyst report already out of date.
The founding team understood the buying side and the credibility problem. What they needed was a product partner who could design and build the platform: make verification workflows, vendor profiles, comparison and a community layer feel like one product rather than a collection of features. We took the brief the way we run our own SaaS products, with the verification model settled before the first screen.
- Cybersecurity SaaS
- Vendor intelligence
- Community platform
Client at a glance
- Business type
- B2B SaaS · cybersecurity vendor intelligence
- Primary users
- CISOs and security leaders
- Community
- 500+ verified security professionals
- Our role
- Product design, engineering, ongoing delivery
The challenge
Before CyberFind
The challenge
Vendor selection in security ran on trust that did not scale: a call to a peer, a thread on a forum, an analyst report already out of date.
Reviews and ratings existed, but the signal was thin: marketing language, no outcome data, and no way to tell a practitioner from a reseller.
The team needed structured, verifiable peer evidence, with the moderation and identity checks to keep it credible as volume grew.
Key challenges we had to solve
- Vendor credibility: telling a practitioner from a reseller before a review counts.
- Structured comparability across vendors that describe themselves differently.
- Outcome data, not star ratings: capturing what changed after deployment.
- Search visibility: category and vendor pages that rank without thin content.
- A platform that could grow past the MVP without a rebuild.
These challenges shaped the model, the product goals, and the delivery order: everything downstream on this page follows from them.
Goals & success criteria
Project goals & success criteria.
Clear goals up front let us make intentional trade-offs during UX and engineering, and define what "successful launch" actually meant for the client team.
Business goals
- Become the trusted, peer-driven starting point for security buyers evaluating vendors.
- Grow a verified community of security leaders contributing reviews and outcome data.
- Outgrow spreadsheet and analyst-report buying with practitioner evidence.
- Build a revenue asset, not a one-off marketing site, with content compounding in value.
Product & technical goals
- Analyse reviews in one place with outcome metrics, not vendor claims.
- Model verdicts, scoring and outcome metrics so comparisons stay meaningful over time.
- Build fast, SEO-friendly vendor and category pages indexable for organic discovery.
- Separate access to already-live features so the product could evolve without re-platforming.
Product hypothesis
If security leaders trust the evidence, they will shortlist from it, and vendors will come to the platform because that is where the buyers already are.
Our solution
Our solution
We started with discovery around the two personas, the CISO researching vendors and the security leader contributing reviews, and designed flows that make both fast and credible.
Vendor profiles combine curated intelligence with structured peer feedback and an outcome metric. The comparison engine reduces a shortlist to a like-for-like view by industry, company size, and deployment model.
Verification pipelines keep the review pool trustworthy: identity checks, moderation and outcome-based flags rather than star ratings alone.
See how it works →Key solution pillars
Verified peer reviews
Identity checks and moderation before a review counts.
Structured comparison
Like-for-like shortlisting across industry, size and deployment.
Outcome metrics
What changed after deployment, captured in structured fields.
SEO-first architecture
Server-rendered vendor and category pages built to be found.
Product features & UX
Key product features & UX highlights.
Everything a security leader needs to move from long vendor lists to a confident, evidence-based shortlist.
Verified CISO reviews
Every review is tied to a verified security-leader identity, with moderation before it goes live.
Outcome metrics
Structured fields capture what actually changed after deployment, not just sentiment.
Side-by-side comparison
Filter by industry, company size and deployment model, then compare candidates on the same axes.
Structured filtering
Category, region, integration and compliance filters that narrow a long list in a few clicks.
CISO community layer
A growing network of 500+ verified security leaders whose contributions compound in value.
Fast, SEO-friendly frontend
Server-rendered category and vendor pages, indexable and fast: organic search is a core acquisition channel.
Architecture & stack
Architecture & technology stack.
The technology stack is deliberately simple, maintainable and aligned with the team's long-term roadmap: powerful enough for today's needs without locking the product into unnecessary complexity.
Backend & data services
- Node.js API layer covering reviews, vendor profiles, comparisons and peer accounts.
- PostgreSQL relational schema for reviews, verdicts, outcomes and users.
- Role-based access control separating members, contributors and administrators.
- Clear service boundaries so reviews and profile-building evolve independently.
Frontend & UI
- Next.js and React frontend with server-side rendering for speed and SEO.
- A UI kit that a small engineering team can extend without redesigning every page.
- Reusable comparison filtering and review components.
- Responsive layouts, since most vendor checks happen across both desktop and phone.
- Next.js
- React
- Node.js
- PostgreSQL
- REST API
- AWS
We chose a stack that runs for years, not one that scores well in a launch post, with a small, senior team able to hold the whole system in their heads.
Delivery process & collaboration
Delivery process & collaboration.
We ran a transparent, iterative engagement with enough structure to keep momentum and enough flexibility to adjust as we learnt from real usage.
- 01
Discovery & data modelling
We spent a focused sprint on the buying journey, comparison behaviour and review platform, and modelling of verdicts, outcomes and reviews before writing code.
- 02
UX flows & interface design
Design of the review and comparison flows: first for CISO researching vendors, contributor, and administrator moderation.
- 03
MVP development
The first version of the platform shipped with vendor profiles, reviews and comparison in place, released in fortnightly sprints.
- 04
Iteration on real usage
Search, filters and verification tightened against real behaviour rather than assumptions, with new sections added as the community grew.
Engagement model & team
A dedicated QalbIT engineering pod worked as the client's product team: designers and engineers in the same standups, with direct access to the founders.
- Fortnightly sprint demosWorking software, not status decks
- Shared backlogOne board, visible to both sides
- Ongoing partnershipStill shipping today
Results & impact
Results & impact.
From an idea about trustworthy vendor selection to a growing decision engine for the security community.
- 500+Verified CISOs
- 1,000+Peer reviews
- LiveAnd still evolving
Story behind the numbers
CyberFind now gives security leaders what other portals were missing: a trusted, evidence-first way to shortlist vendors. What began as a product idea is a working platform with a growing base of verified contributors and outcome data that compounds in value with every review.
Start here
Building a platform where credibility is the product?
Tell us what you are building and who has to trust it. You get a written scope, an architecture recommendation and a price range within 48 hours.
- A written scope with the exclusions listed
- An architecture recommendation, not a sales deck
- The name of the engineer who would lead it
- Free, and yours to keep either way
Get your free estimate
Three quick questions: scope, approach and a price range back within 48 hours. No sales call required first.
Next step
Let's design a SaaS product worth trusting.
Send us two lines about the platform you are building. You get a written scope, timeline and price range within 48 hours, free, and yours either way.
