TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Automated code security assistant for developers

64 pointsby eslamsalemabout 5 years ago

9 comments

eslamsalemabout 5 years ago
Hello HN, It&#x27;s my pleasure to introduce to you Shieldfy, a code security assistant.<p>It started back 10 years ago in 2010, I was a team leader in a small software house, we were building websites and applications for customers. One day I wake up in a phone call from my manager that one of our websites has been hacked. I jumped out of my bed and opened my laptop … yes, its hacked. It was a nightmare, I didn’t know where to start and almost lost my job back then.<p>The short story is that a hacker exploited a vulnerability in the website to log into the admin panel and take control of the website.<p>I was devastated but I decided that I need to learn more about security .. being a developer without know how to secure your code is not enough. Two years later I was in good shape and started to work as a security consultant for development companies especially to work for developers to strengthen their codes.<p>Here we come, in 2016 I decided to quit my job and start a cybersecurity company, my dream was and still to enable developers to write secure code, to not face a disaster as I faced before. Are you crazy? That what I heard from everyone at my friends, colleagues, starting a security company .. in the MENA region .. in Egypt! and not a security service, it’s a Product, a technical product.<p>I admit it was scary for me too, the economic situation and currency devaluation pushed a lot of talents to leave the country and work abroad. and the remaining is afraid to work for a startup. Luckily, I found 2 co-founders who were my colleagues from my last company. and we incorporated the company in Delaware, US. to implement credit card processing via Stripe. (Thank you Stripe Atlas.)<p>After days and days of a sleepless night, we have now a minimum product we can sell, we launched but no one came. Ok, Let us discover channels to market the product. We listed the product in the beta testing website like beta list also submitted in Reddit, FB groups, Twitter .. everywhere After a lot of hassle to get the words out, we got some users, and one day I opened my email to find confirmation about the first paid user<p>From getting the first traction to first paid user, to be accepted in Cylon accelerator in London, yay (after a lot of rejections from local accelerators). But, we couldn’t get a UK visa (rejected two times) and the Cylon opportunity disappeared And if that wasn’t enough, my two co-founders decided to leave. There was not much money in the company back then, and churn was very high. There weren’t any lights at the end of the tunnel.<p>But I felt the spark again inside me, I must not ever give up. I need to push it further.<p>We changed the core product to focus more on finding vulnerabilities inside the developer code. That’s the original goal, help developers to write more secure code.<p>We also decided to focus on companies that have it’s own dev team in-house. But i need money to continue ….<p>I pitched the company to 50+ VCs and angels and believe me that is a big number here in Egypt, especially if you know that the total number of active VCs in Egypt was lower than 20 VCs, and nearly no active angels. And the answer was No, We need some traction, We need a lot of traction, You are a solo founder now, Do you think you can build this technology?!!<p>My last pitch was to Arzan Capital, and I was very lucky because the venture partner is an entrepreneur, he co-founded Jeeran, one of the first internet portals in the MENA region. And guess what he is a developer by heart and he still writes code till now.<p>He was very interested in our product and after a couple of tough meetings they decided to invest. That was it, I expanded my team to include some crazy developers and security engineers like me, who believe we can build that thing.<p>After a couple of months, we got more traction and we got into 500 startups accelerator program, the first in the MENA region. It was a life-changing experience interacting with well-experienced mentors coming from Silicon Valley. We refined our Idea, our technology.<p>And now I’m happy to announce our product, Shieldfy — Your virtual security assistant.<p>That’s our story, I&#x27;m happy to answer any question regarding the product or our journey.
TACIXATabout 5 years ago
Which languages are supported? I went through a few pages on the site but could not find the information.
评论 #22487133 未加载
jiveturkeyabout 5 years ago
&gt; both static &amp; dynamic analysis<p>I very, very much doubt you are doing DAST. You should remove that claim or provide more details.
评论 #22490757 未加载
branonabout 5 years ago
&gt; Connect Shieldfy with your presonal or organization github account.<p>presonal -&gt; personal<p><a href="https:&#x2F;&#x2F;shieldfy.io&#x2F;how-it-works&#x2F;" rel="nofollow">https:&#x2F;&#x2F;shieldfy.io&#x2F;how-it-works&#x2F;</a><p>The page title is also not properly capitalized.<p>Good luck!
评论 #22487470 未加载
评论 #22487241 未加载
Wolfmotherabout 5 years ago
Really nice website. Good job! One thing which I noticed is that on my phone (One plus 6t) main text and cta on the top of the page is not centered :&#x2F; probably it&#x27;s easy fix :) Anyway, maybe you would like to introduce your tool on my side project&#x27;s website <a href="https:&#x2F;&#x2F;owwly.com" rel="nofollow">https:&#x2F;&#x2F;owwly.com</a>
评论 #22490657 未加载
hashamaliabout 5 years ago
Very cool. How does this compare to Snyk? <a href="https:&#x2F;&#x2F;snyk.io" rel="nofollow">https:&#x2F;&#x2F;snyk.io</a>
评论 #22490643 未加载
notlukeskyabout 5 years ago
Good luck. Will you add other login methods?
评论 #22490734 未加载
jiveturkeyabout 5 years ago
what is an SQI injection?<p><a href="https:&#x2F;&#x2F;shieldfy.io&#x2F;product&#x2F;code-vulnerabilities&#x2F;" rel="nofollow">https:&#x2F;&#x2F;shieldfy.io&#x2F;product&#x2F;code-vulnerabilities&#x2F;</a><p>looks like a typical SQL injection to me. how could someone typo that for SQI. security product needs attention to detail ...
评论 #22490722 未加载
评论 #22510905 未加载
jayfkabout 5 years ago
Where does package vulnerability data come from? Are you using your own database?
评论 #22490668 未加载