HNHacker News
TopNewBestAskShowJobs

lukejkwarren

2 karma · joined January 28, 2025

Founder of [PenZen](https://penzen.app), an AI-power security scanning and uptime monitoring tool.
submissionscomments
lukejkwarren··on Ask HN: What do you look for in compliance reporting tools?
Sorry to squeeze you for even more feedback, but my application has a pricing structure of:

9 USD - Hobby 19 USD - Grow 49 USD - Pro 149 USD - Agency

Each plan unlocks more features and targets but pro includes branded compliance reports + active scanning and a few other features, including high limits.

Does this align with what you think is fair? What is the biggest factor/feature that made you willing to pay more and/or pay at all for such a tool?

https://penzen.app for reference

lukejkwarren··on Ask HN: What do you look for in compliance reporting tools?
Thank you so very much for the detailed breakdown. The prohibitively high pricing of cybersecurity tooling is a big problem. PenZen comes in way on the low end, but this erodes trust in the brand. Tough one to navigate as I look to find my footing in the market. I wish I had a customer like you as I'd literally just build all of your feedback directly in.

Many of the points I've actually specifically catered for in my compliance report are reassuring. For example, linking CVEs, sensible layouts etc.

The application itself caters for helping actual devs triage, fix, etc., with the report catering to audit and compliance needs. I've tried to avoid baking this into the report as the tool itself allows devs to get AI remediation guidance. Dev's don't read these reports IMO but they would jump into the application and click a button to see what the fix is - I hope.

Thanks again. I appreciate the time taken to respond with such detail.

lukejkwarren··on Ask HN: What do you look for in compliance reporting tools?
Added context: I've been working on a security scanning tool called PenZen (https://penzen.app) ad interested in how others have solved it.
lukejkwarren··on Ask HN: What do you use to monitor website security (vulns, uptime, etc.)?
That’s the one! Apologies.

Using any other security scanning tools?

lukejkwarren··on Ask HN: Why are LLM UIs so slow?
It's the big bummer with reasoning models, although they are improving a lot. I experimented with various reasoning models for my AI security scanner product but found the performance to just be far too slow.
lukejkwarren··on Show HN: I built a tool that finds real web vulns and tells you how to fix them
Happy to answer any questions about how this works under the hood—like how I’m orchestrating OWASP ZAP in headless mode, how the AI layer generates fixes based on your stack, or how alerting and issue resolution are handled.

Also very open to feedback on what’s missing or what feels unnecessary. I’m trying to build something that’s genuinely useful for devs—not just another dashboard that gets ignored.