The Ship of Theseus Problem: When Does Your Startup Become a Different Company to Your Auditor?

A puzzle that has nagged philosophers for two thousand years turns out to have a surprisingly practical answer for any founder whose company no longer resembles the one they started, which is most of them.

The ancient Greeks told a story about a ship. Theseus, the hero who slew the Minotaur, sailed home to Athens, and the Athenians preserved his vessel as a monument. Over the years its timbers rotted, as timbers do, and one by one the rotten planks were replaced with fresh ones. Eventually not a single original plank remained.

Plutarch records the question the philosophers fell to arguing about: was it still the ship of Theseus, or something else wearing its name?

Centuries later, another philosopher, Thomas Hobbes, added a mischievous twist. Suppose someone gathered up all the discarded planks and reassembled them. Now you have two ships. Which one is the original?

It is the sort of question that sounds like undergraduate provocation, until you realize you are running the company it describes.

Your company has already replaced most of its planks

The founding engineer's original code has been reworked beyond recognition, or possibly even deleted outright. The infrastructure migrated. The early hires moved on. The product may have pivoted so thoroughly that an early customer would not recognise it. This is not failure. It is growth. But it creates a question your auditor, your enterprise buyer, and your investor are already asking: is this company still a coherent, continuous entity, or merely a name stretched over a constantly shifting pile of parts?

When an auditor, an enterprise buyer, or a prospective investor examines your company, they are asking a version of exactly this question, dressed up as a questionnaire or a due diligence request but fundamentally the same. The answer is not obvious. Most founders assume it goes without saying. It does not.

But the auditor does not care about the planks

The identity of the ship was never in the timber. It was in the practice of upkeep. A SOC 2 Type II report works on exactly this principle: it does not certify that your servers, your staff, or your code are the same as last year. It examines whether the system of upkeep held. Continuity of practice, not continuity of parts, is what earns trust.

Here is where the puzzle resolves itself in a way the philosophers never quite managed. What made it the ship of Theseus across the centuries was not any particular plank but the unbroken commitment to replacing each one before the vessel sank, by people who understood what they were maintaining and why.

A SOC 2 Type II report is designed around exactly this logic, which is why it observes your controls over a period of months rather than freezing them in a single snapshot. What is being examined is whether the system of upkeep held: whether access was reviewed as people came and went, whether changes were controlled as the code was rewritten, whether the logs kept running as the infrastructure moved underneath them. Enterprise buyers understand this even when they cannot articulate it. That is why they keep asking for reports, not promises.

Compliance debt is just rotten planks you decided not to replace

A company accrues risk not by changing, since change is unavoidable, but by changing without maintaining the practices that hold its identity together. Every deferred access review, every undocumented change, every control that quietly stopped running is a plank left to rot on the assumption that the ship will keep floating anyway. For a while it does. Then a buyer asks to see below the waterline, and the deal stalls, not because your product is not good, but because you cannot demonstrate that you are still the company you claim to be.

The startups that stall in enterprise due diligence are rarely the ones that evolved too much. They are the ones that lost their own diligence somewhere along the way, not through malice but through momentum. The work may have been getting done. Nobody was watching it get done. That distinction costs deals.

Trust lives in the habits, not the hull

An entity can change almost everything about itself and remain unmistakably itself, provided the practice that defines it never lapses. A company is not its current servers or its current org chart any more than the ship was its current planks. It is the discipline with which it tends to them, and that discipline is visible to anyone who knows where to look.

This is why, at Aetos, we treat trust as operational infrastructure rather than a certificate to be earned once and filed away. A trust program is not a monument you build and preserve. It is the ongoing practice of replacing planks before they rot, so that however much your company changes (and it will change considerably) the thing your buyers and investors are deciding to rely on remains recognisably, demonstrably itself. That is not a compliance story. It is a growth story.

Theseus kept his ship for centuries. Not by refusing to change a single plank, but by never once neglecting the ones that needed changing. There is no better definition of a durable company.

Where to go from here

If your company has been replacing planks faster than it has been maintaining the practices around them, a readiness assessment is the fastest way to see what is rotting below the waterline before a buyer finds it first. Read our guides on what SOC 2 is and how it works and choosing between SOC 2 and ISO 27001, or use our compliance cost calculator to model what a trust program looks like at your stage.

Shayne Adler

Shayne Adler is the co-founder and Chief Executive Officer (CEO) of Aetos Data Consulting, specializing in cybersecurity due diligence and operationalizing regulatory and compliance frameworks for startups and small and midsize businesses (SMBs). With over 25 years of experience across nonprofit operations and strategic management, Shayne holds a Juris Doctor (JD) and a Master of Business Administration (MBA) and studied at Columbia University, the University of Michigan, and the University of California. Her work focuses on building scalable compliance and security governance programs that protect market value and satisfy investor and partner scrutiny.

Connect with Shayne on LinkedIn

https://www.aetos-data.com
Next
Next

What Do US Startup Founders Need to Understand about GDPR?