Exploit Prevention as a Service for Rails
hakiri.io
hakiri.io
My two cents for you: you're far enough along that you can start seeding your market as fast as possible.
* How about going to meetups at app dev companies such as Pivotal, Carbon 5, ThoughtWorks, etc.?
* How about a free version for open source projects, or students, or nonprofits?
Try to make the signup faster and easier.
* How about an item on the homepage saying "Upload a Gemfile.lock to see if it's secure"? I would personally do this first because it's fast, easy, and needs no setup.
* How about an item on the homepage asking "What's your GitHub username?" then skim for vulnerabilities? I would personally do this because I write many open source gems.
A lot of these things are on the roadmap, including the free option for OSS, pitching at larger dev shops, and Gemfile.lock scanning without signing up.
Thank you.
This is not quite true. Brakeman (and Hakiri for that matter) runs static code analysis and finds vulnerabilities that were introduced by the developer. E.g., XSS, SQL injection, etc.
I'd be comfortable saying "this can give you a false sense of security"; useless is far too strong.