TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Show HN: Assertly – scriptable monitoring for infosec, IT, compliance, DevOps

53 pointsby JakaJancar9 months ago
Hey HN!<p>Jaka here, solo founder of Assertly (<a href="https:&#x2F;&#x2F;www.assertly.com" rel="nofollow">https:&#x2F;&#x2F;www.assertly.com</a>). Assertly is a monitoring tool for continuous infosec, IT, compliance and DevOps regression testing. It enables teams to automate periodic checks using JavaScript.<p>Before Assertly, I was the CTO of Celtra (<a href="https:&#x2F;&#x2F;celtra.com" rel="nofollow">https:&#x2F;&#x2F;celtra.com</a>), a B2B SaaS company, for over 10 years, from “git init” to 250 people and the company’s sale to private equity. I was primarily responsible for product strategy, engineering, QA, DevOps, but also for IT and InfoSec.<p>I found that ensuring security, integrity, privacy, and compliance in peripheral and internal IT systems was often harder than for our core product. While for the latter we would write tests and rely on our CI&#x2F;CD pipeline, for other systems, things would be written up in policies where adherence is hoped for but rarely verified. If it is verified, it is done so manually and infrequently (e.g. quarterly). More laborious, while giving less assurance.<p>Today, If you want to automate, you can use scheduled GitHub Actions, but the trial-and-error process is slow and the alerting system is inflexible—it’s just not designed for this purpose. Synthetic monitoring tools are better, but limited when you need to go beyond frontend. So I created Assertly.<p>Assertly lets you automate checks with minimal overhead. It’s like Google Docs—click “New” and you’re writing a script. You get real-time alerts and a simple dashboard to see current and historical compliance. Common use cases include user access control, GDPR compliance, and network security checks. See some example code here: <a href="https:&#x2F;&#x2F;www.assertly.com&#x2F;examples" rel="nofollow">https:&#x2F;&#x2F;www.assertly.com&#x2F;examples</a>.<p>Companies using Assertly experience a 46% reduction in costs related to misconfiguration, incidents, bugs, and non-compliance. 73.6% of all statistics are made up.<p>For the technically curious: The scripts each run in its own VM (on ECS Fargate) so they’re securely isolated for when you need to touch sensitive data. You can install any tool, e.g. a CLI client or a port scanner. We keep a pool of VMs ready for sub-second run latencies. Assertly itself is written in Rust and React.<p>Here is the link to sign up &amp; try for free: <a href="https:&#x2F;&#x2F;www.assertly.com&#x2F;pricing" rel="nofollow">https:&#x2F;&#x2F;www.assertly.com&#x2F;pricing</a>. If you’d like to get past the credit card barrier, mail me at jaka@assertly.com and I will manually provision an account for you.<p>I’m excited to launch Assertly and would love to hear your feedback. How do you get peace of mind if not through automation? Is there something you’d automate if the overhead were zero? Are there use cases have missed? Let me know your thoughts!

8 comments

Terretta9 months ago
Amazing, and, demonstrating security mindedness doesn&#x27;t have to be only for enterprises:<p><i>“SSO on Any Plan: Single Sign-On using your identity provider is available in all plans and never costs extra. We support all major identity providers such as Okta, OneLogin, Azure AD, and Google.”</i><p>Three guys and a dog can start with M365 or Google Workspace and be SSO (or at least OIDC) from day one, thanks to the IdP baked in and firms like Assertly &quot;taking your security very seriously&quot; even when you&#x27;re a startup.<p>ADD:<p>This is great. One of the example checks makes the point better than I can:<p><i>“User Deprovisioning: A SaaS tool used by a company does not support SSO&#x2F;SCIM, or it requires an expensive &quot;Enterprise&quot; plan, so accounts of former employees need to be deleted manually. Unfortunately, this task is sometimes forgotten.”</i>
评论 #41469805 未加载
chatmasta9 months ago
Nice landing page. If you raise funding for this, don&#x27;t let the inevitable &quot;redesign&quot; lose the clarity of messaging you&#x27;ve got there. I love the hero text asking me the questions that keep me up at night. I&#x27;m not even a CISO and I was anxious just reading those.
gregor_p8 months ago
Congrats on the launch! Based on the demo you showed in SF it looks very promising. I wish you could have had this tool back at Celtra :)
spuzvabob9 months ago
Congrats on the launch! The usage examples make a lot of sense, I&#x27;m wondering if you plan to provide preconfigured implementations for the most common checks or is custom coding the only option?
评论 #41459896 未加载
mihak09 months ago
This looks promising and could save compliance teams a lot of time (and headaches). Great stuff!
Klaa9 months ago
Congratulations on the launch. So it seems your break is over :)
gregorfartek9 months ago
Great stuff! Congrats on the launch!
jess-zhang9 months ago
curious how&#x27;s this different from pingdom, datadog etc?
评论 #41458767 未加载