Every tool you rely on has a clause you didn't read. Sometimes it's a paywall. Sometimes it's a security hole that runs arbitrary commands the moment you open a file. Sometimes it's a vendor betting that your switching costs are too high for you to leave. The clause is always there. You're just paying it on a schedule you didn't negotiate.
Look at what happened with Marimo, the notebook software. A high-severity flaw let a malicious actor execute commands as a local subprocess before a single user-written cell had run, just by getting someone to open a crafted notebook in edit mode. That's the hidden clause in trusting a third-party tool with privileged local access. You get the convenience. They get a surface area attached to your machine. At any given moment, the thing making your work easier is also the thing one bad actor needs to run code with your credentials.
Now look at the opposite move. A master's student needed a LaTeX editor. He used Overleaf until the git sync he wanted required a paid tier. His response was not to pay. He compiled a full TeX engine to WebAssembly and ran it entirely in the browser, with no backend, no account, and no subscription. Files live on his disk. He uses git however he wants. Nobody owns his workflow but him. That's not stubbornness. That's clarity about where control actually lives.
These two stories are the same story told from opposite ends. One person trusted the platform and paid with attack surface. One person refused the platform and paid with a weekend of engineering. The second person made the better deal, by a wide margin.
We have watched this play out in client after client. The pattern is always the same. The tool starts free or cheap and feels neutral. Then the tool becomes necessary, the price goes up, a feature gets locked, or a breach happens. By then the dependency is so deep that switching costs more than staying. The tool has become a landlord, and you've become a tenant who forgot to read the lease.
LinkedIn built a four-layer cognitive memory system to personalize their AI hiring assistant and keep a persistent, contextualized state about each user across every session. Think about what that means from the other side of the table. Every interaction you have with their platform is being remembered, categorized, and used to shape what you see next. The platform is building a model of you so accurate that leaving gets harder every month. That's not a conspiracy. That's just good product design. But it's also a trap with very comfortable padding.
Even zoning law is teaching this lesson right now. Lexington, Kentucky is pushing to let agrivoltaic solar projects onto agricultural land, combining energy production with farming on the same acre. The pitch is control: stop buying power from a utility that can raise rates whenever it wants, generate it yourself, keep the land in productive use. Every independent operator who has ever dealt with a utility bill going up 30% in a year understands why this matters. The clause in the utility contract is called "rate adjustments," and you agreed to it by not having an alternative.
And then there's the frontend world, where a developer built a syntax highlighter that does the job without any bloated JavaScript dependencies. No complicated markup, no spans-on-spans, no node_modules folder full of packages maintained by strangers. Just the output. That's the same impulse as the LaTeX student and the agrivoltaic farmers. Remove the intermediary. Own the outcome directly.
Here's the thread we keep seeing across all of it: every convenience has a counterparty. Someone is always on the other side of the abstraction, collecting something. Sometimes it's your money. Sometimes it's your data. Sometimes it's your attack surface. Sometimes it's your ability to leave without pain. The business case for simplifying down to what you actually control is not just philosophical. It's financial. It shows up in your vendor spend, your security posture, your ability to move fast when something breaks, and your negotiating position when a contract comes up for renewal.
This is the question we ask every client when we start a new engagement: of everything you're paying for or depending on, what would you lose in 48 hours if the vendor changed terms, got acquired, or went dark? Most founders have never made that list. When they do, it's usually uncomfortable. There's a CRM that holds their entire contact history and can't export cleanly. An analytics platform that's the only place conversion data lives. A notification service that would take two months to replace if it raised prices tomorrow.
The answer is not to self-host everything or write everything from scratch. The Marimo vulnerability was eventually patched. Overleaf is a fine tool for people who don't need git. Platforms have value. But there's a difference between using a tool and being owned by one. That difference lives in whether you understand exactly what you've traded and whether you made that trade consciously.
Map your dependencies this week. Not the obvious ones. The ones where you'd have no good answer if the terms changed by Friday. That's where your hidden subscriptions are, and some of them are costing you a lot more than a monthly fee.
The clause is always there. The only question is whether you found it first.