What shipped today:
— Renamed from CloudSecurityBot to VrothSec. A positioning specialist in the comments pushed me to tighten the frame before launch. Same product. Different trust level. Security infrastructure, not a GitHub bot.
— Free/paid model is working in code. Public repos get full security scanning automatically. Private repos get a subscription prompt with a payment link. No manual intervention. The bot handles it.
— Landing page live with privacy policy, terms, and refund policy. Paddle product created at $15/month with a 7-day free trial.
— Subscribers stored in a private GitHub repo as a JSON file. No database, no server, no infrastructure cost. When someone pays, their installation ID gets written to the file automatically. When they open a PR, the bot checks the file.
Here's what the bot posts on a private repo PR from a non-subscriber:
"🔒 VrothSec — Subscription Required. VrothSec is free for public repositories. Private repository scanning requires a subscription. Get VrothSec Pro — $15/month"
And here's what it posts on a public repo with real issues:
"🔴 Critical — config.py, Line 3: Hardcoded OpenAI API key. Fix: Move to environment variables."
Both flows tested and working.
What's left:
10 founding member spots at $15/month, locked in forever.
If you build AI products on private repos and want early access: https://jeffrin-dev.github.io/VrothSec-site/
Congrats on the launch! How did you get your first early users? Any specific channel that worked best
Hey — since you asked about early users, would you be open to trying VrothSec on a private repo? Happy to activate you manually for the first month at no cost in exchange for honest feedback.
Honestly just IH and Dev.to so far. Posted on Day 1 before writing a single line of code — the build-in-public thread has driven all the visibility. No paid ads, no cold outreach. No paying users yet but the engagement has been real and the product launched 2 days ago. Still early.
Strong update.
This is exactly why the rename mattered before launch.
CloudSecurityBot made it feel like a utility.
VrothSec makes it feel like something that belongs inside the repo workflow.
The product now reads much closer to security infrastructure, which is the right frame if you want teams to trust it on private repos.
Also smart to keep the launch simple:
public repos free
private repos paid
clear PR-level value
That makes the product easy to understand fast.
That's exactly the shift I felt after the rename. CloudSecurityBot was a tool. VrothSec is something you trust with your codebase. The frame change happened before launch which is the best time for it.
The three-line model — public free, private paid, PR-level value — came from trying to explain it to non-technical people. If they don't get it in one sentence, the positioning is wrong.
Exactly.
That line is the whole reason the broader brand matters now.
VrothSec works well for the security product.
But if this keeps expanding, Vroth.com is the stronger company layer behind it.
Vroth as the infrastructure brand.
VrothSec as the AI repo security product.
That gives you room to grow beyond the first GitHub App without renaming again later.
Since you already made the shift before launch, this is probably the cleanest time to lock the structure properly.
The structure is right. Vroth as the company layer makes sense if this expands past the first product.
Already replied on the other thread — same answer. Not the right time to lock that in. First paying customer first, then brand infrastructure.