One of the challenges I have been facing with growing Currents.dev is building trust without investing $$ into formal certification with SOC / ISO.
I believe it is a common problem for bootstrapped SaaS companies.
Here's what somewhat worked for me:
How do you build trust and satisfy your clients compliance / due diligence concerns?