TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Show HN: Automated code security assistant for developers

64 点作者 eslamsalem大约 5 年前

9 条评论

eslamsalem大约 5 年前
Hello HN, It&#x27;s my pleasure to introduce to you Shieldfy, a code security assistant.<p>It started back 10 years ago in 2010, I was a team leader in a small software house, we were building websites and applications for customers. One day I wake up in a phone call from my manager that one of our websites has been hacked. I jumped out of my bed and opened my laptop … yes, its hacked. It was a nightmare, I didn’t know where to start and almost lost my job back then.<p>The short story is that a hacker exploited a vulnerability in the website to log into the admin panel and take control of the website.<p>I was devastated but I decided that I need to learn more about security .. being a developer without know how to secure your code is not enough. Two years later I was in good shape and started to work as a security consultant for development companies especially to work for developers to strengthen their codes.<p>Here we come, in 2016 I decided to quit my job and start a cybersecurity company, my dream was and still to enable developers to write secure code, to not face a disaster as I faced before. Are you crazy? That what I heard from everyone at my friends, colleagues, starting a security company .. in the MENA region .. in Egypt! and not a security service, it’s a Product, a technical product.<p>I admit it was scary for me too, the economic situation and currency devaluation pushed a lot of talents to leave the country and work abroad. and the remaining is afraid to work for a startup. Luckily, I found 2 co-founders who were my colleagues from my last company. and we incorporated the company in Delaware, US. to implement credit card processing via Stripe. (Thank you Stripe Atlas.)<p>After days and days of a sleepless night, we have now a minimum product we can sell, we launched but no one came. Ok, Let us discover channels to market the product. We listed the product in the beta testing website like beta list also submitted in Reddit, FB groups, Twitter .. everywhere After a lot of hassle to get the words out, we got some users, and one day I opened my email to find confirmation about the first paid user<p>From getting the first traction to first paid user, to be accepted in Cylon accelerator in London, yay (after a lot of rejections from local accelerators). But, we couldn’t get a UK visa (rejected two times) and the Cylon opportunity disappeared And if that wasn’t enough, my two co-founders decided to leave. There was not much money in the company back then, and churn was very high. There weren’t any lights at the end of the tunnel.<p>But I felt the spark again inside me, I must not ever give up. I need to push it further.<p>We changed the core product to focus more on finding vulnerabilities inside the developer code. That’s the original goal, help developers to write more secure code.<p>We also decided to focus on companies that have it’s own dev team in-house. But i need money to continue ….<p>I pitched the company to 50+ VCs and angels and believe me that is a big number here in Egypt, especially if you know that the total number of active VCs in Egypt was lower than 20 VCs, and nearly no active angels. And the answer was No, We need some traction, We need a lot of traction, You are a solo founder now, Do you think you can build this technology?!!<p>My last pitch was to Arzan Capital, and I was very lucky because the venture partner is an entrepreneur, he co-founded Jeeran, one of the first internet portals in the MENA region. And guess what he is a developer by heart and he still writes code till now.<p>He was very interested in our product and after a couple of tough meetings they decided to invest. That was it, I expanded my team to include some crazy developers and security engineers like me, who believe we can build that thing.<p>After a couple of months, we got more traction and we got into 500 startups accelerator program, the first in the MENA region. It was a life-changing experience interacting with well-experienced mentors coming from Silicon Valley. We refined our Idea, our technology.<p>And now I’m happy to announce our product, Shieldfy — Your virtual security assistant.<p>That’s our story, I&#x27;m happy to answer any question regarding the product or our journey.
TACIXAT大约 5 年前
Which languages are supported? I went through a few pages on the site but could not find the information.
评论 #22487133 未加载
jiveturkey大约 5 年前
&gt; both static &amp; dynamic analysis<p>I very, very much doubt you are doing DAST. You should remove that claim or provide more details.
评论 #22490757 未加载
branon大约 5 年前
&gt; Connect Shieldfy with your presonal or organization github account.<p>presonal -&gt; personal<p><a href="https:&#x2F;&#x2F;shieldfy.io&#x2F;how-it-works&#x2F;" rel="nofollow">https:&#x2F;&#x2F;shieldfy.io&#x2F;how-it-works&#x2F;</a><p>The page title is also not properly capitalized.<p>Good luck!
评论 #22487470 未加载
评论 #22487241 未加载
Wolfmother大约 5 年前
Really nice website. Good job! One thing which I noticed is that on my phone (One plus 6t) main text and cta on the top of the page is not centered :&#x2F; probably it&#x27;s easy fix :) Anyway, maybe you would like to introduce your tool on my side project&#x27;s website <a href="https:&#x2F;&#x2F;owwly.com" rel="nofollow">https:&#x2F;&#x2F;owwly.com</a>
评论 #22490657 未加载
hashamali大约 5 年前
Very cool. How does this compare to Snyk? <a href="https:&#x2F;&#x2F;snyk.io" rel="nofollow">https:&#x2F;&#x2F;snyk.io</a>
评论 #22490643 未加载
notlukesky大约 5 年前
Good luck. Will you add other login methods?
评论 #22490734 未加载
jiveturkey大约 5 年前
what is an SQI injection?<p><a href="https:&#x2F;&#x2F;shieldfy.io&#x2F;product&#x2F;code-vulnerabilities&#x2F;" rel="nofollow">https:&#x2F;&#x2F;shieldfy.io&#x2F;product&#x2F;code-vulnerabilities&#x2F;</a><p>looks like a typical SQL injection to me. how could someone typo that for SQI. security product needs attention to detail ...
评论 #22490722 未加载
评论 #22510905 未加载
jayfk大约 5 年前
Where does package vulnerability data come from? Are you using your own database?
评论 #22490668 未加载