Brand and trust
Passport
- Rock
- Minds
- Depth
- 4 · Mine
- Time to dig
- 10+ years
- Capital
- ◐ · medium
- Solo
- ~ partly
- AI
- ↑ AI-resistant
- Rent
- ~ partly
Sample
- Share of apps
- 7.8%
- No-rate
- 79%
- Median price
- $14.84
Figures from the canivibecodeit sample. No-rate is the share of apps carrying this tag that cannot be vibe-coded — a proxy for structural strength. Only the first thirteen mechanics were measured.
Essence
People pay because it is this vendor and no other: security guarantees, a reputation in front of counterparties, "nobody ever got fired for this". The most durable tag in the sample — because it lives in people's heads rather than in the product, and code cannot reproduce it at all.
How it is built
1Password — reputation as an accumulated asset
In a category where the cost of a mistake is at its maximum — all of a user's passwords — trust accrues over years without incidents: public security white papers, regular external audits, transparent write-ups of the architecture. Every year without a breach is a deposit into the moat, and the deposit cannot be made early.
Bitwarden and Signal — open source as an accelerator of trust
Instead of "trust us, we have not fallen over in ten years", the offer is "do not trust, verify": open code, reproducible builds, public audits. Verifiability substitutes for years of reputation — the one way a small team can build trust quickly. In the sample Bitwarden sits right next to 1Password.
"Nobody got fired for buying IBM" — trust as the buyer's insurance
In enterprise, a brand removes career risk from the person signing off: choosing a known vendor needs no justification, choosing an unknown one does. It is built over decades of presence, case studies, customer logos and an army of salespeople. NordVPN showed the consumer variant — use marketing budget to make the brand a synonym for the category.
How it is bypassed
LastPass — an incumbent's trust collapses in a single incident
After the 2022 breach and the poor communication around it, LastPass lost users in waves, and 1Password and Bitwarden collected them with ready-made migration pages and importers. A moat of trust is asymmetric: years to build, weeks to destroy. The attacker cannot schedule someone else's failure but has to be ready for it — one-click import, comparison pages, a public position on security.
Borrowed trust
Certifications (SOC 2, now cheap through Vanta), public audits, a bug bounty, the logos of the first recognisable customers, distribution through trusted channels — the App Store, AWS Marketplace, plugin stores — and open code. Each of them is a way to borrow trust from an institution people already believe, instead of spending a decade accumulating your own.
Zoom against Cisco — redefine whose trust matters
WebEx owned the trust of the buyers. Zoom went around it by winning the trust of the users: "it just works" spread from below, through employees who dragged Zoom into companies against the corporate standard. When a category is redefined — video calling means "no friction", not "an enterprise vendor" — the old brand is answering a question nobody asks any more.
Verdict
The most durable moat, and the most unfair to an attacker: it cannot be coded. The bypasses are verifiability instead of reputation, borrowed trust, readiness for someone else's failure, and changing whose trust decides.