Hey IH! đź‘‹
There are thousands of AI demos popping up every day. The problem? You're clicking random links from strangers on Twitter and Reddit, hoping they're not malicious.
So I built DemoVault (https://demovault.org) — a curated gallery of AI demos where every single submitted URL gets scanned by 4 security engines (Google Web Risk, Safe Browsing, URLScan, VirusTotal) before it goes live.
## How it works
1. Developer submits their AI demo URL
2. 4 security engines scan it automatically
3. If it passes, it shows up in the gallery with a safety badge
4. Visitors see the scan results before clicking "Visit Demo"
## What's in it now
- 50+ AI demos across multiple categories
- Safety badges on every card (✓ Safe / ✗ Unsafe / ⏳ Pending)
- Category filtering, search, and sorting
- Review system with feedback reactions
- No signup needed to browse or submit
## Why I think this matters
AI demos are the new portfolio. Developers want to show their work, but there's no central place to do it safely. GitHub repos don't show the live experience. Twitter posts disappear in hours. DemoVault is a permanent, verified gallery.
## Numbers
- Revenue: $0 (it's free)
- Demos listed: 50+
- Built by: just me, solo dev from Seoul
- Stack: Next.js, Supabase, Vercel
Have you built an AI demo? Submit it — I'd love to feature more projects from this community.
What categories should I add next?
The pre-listing scan is the trust layer most directories skip. Anyone can aggregate links, you built the filter that makes clicking them feel safe. That's the difference between a gallery and a liability.
Victor, thank you so much for this insight! 'Gallery vs. Liability' perfectly captures the core mission of DemoVault. I truly believe a directory shouldn't just be a list, but a 'trust layer' that protects the user. The 4-step automated scan was designed specifically for this purpose—to make every click feel safe. I'd love to stay in touch and hear more of your thoughts as we evolve this project. Cheers!
Trust layer is the right framing. When the scan runs before listing instead of after a problem, you've inverted the cost model, from damage control to prevention. That shift changes what a directory owes its users.
Exactly — prevention over damage control. That's the principle we built DemoVault around. If the scan happens after someone clicks a bad link, you've already failed. We wanted the trust to be baked in from the start, not bolted on after an incident. Appreciate you articulating it so clearly, Victor.
You welcome Kris, I'm here to open vision to make a reality so we can go toe to toe and build something if you are interested.