I'll start with the uncomfortable numbers .
That's the surface story. Here's the rest.
What I'm building
Bordair is a prompt injection detection API. When developers ship AI features, users can type instructions that hijack the model: leak system prompts, exfiltrate data, bypass safety. I scan the input first, in under 50ms, across text, image, document, and audio. Three lines of code.
The market just validated itself. Late 2025:
$810M of M&A in three months. All three are now being absorbed into £100K+ enterprise security bundles with 9-month procurement cycles, which leaves the developer-first segment wide open.
That's where I'm building.
Why I'm pre-revenue on purpose
Here's the part most founders won't admit: I haven't turned on the paywall yet, and that's deliberate.
Bordair has a paid tier live, but only on Kingdom 5 of Castle, my CTF-style red-teaming game. Everywhere else, including the production API, is free.
Why?
Because for a security product, trust compounds before revenue does. Every free user generating attack prompts is improving my detector. Every dataset star is social proof. Every novel jailbreak from Castle is training data my paid competitors don't have.
I could turn on Stripe across the board tomorrow and probably get five paying customers. Or I can spend three more months hardening the detector with 6,000+ adversarial prompts from real players, then charge with confidence and conviction.
I'm choosing the second.
This only works because my burn is $300/month. If I had VC pressure I'd have to flip the switch early. The fact that I don't is, ironically, my biggest advantage.
The data flywheel
The unfair advantage is Castle (castle.bordair.io). 5 kingdoms, 35 levels of prompt injection challenges. Players try to break AI personas across text, image, document, and audio. Free to play. Real points. Real bragging rights.
Every successful jailbreak gets captured with full media provenance and feeds my training pipeline. Players see a fun puzzle game. I see an attack-generation engine that pays itself.
So far:
I find the named stars more meaningful than user count right now, because those are the people who recognise what they're looking at.
Recent traction
Past week was the first time I felt actual momentum.
£6,500 isn't life-changing money. But it's the first external validation that someone other than me thinks this is worth building, and the accelerator gives me structure I've been lacking as a solo founder doing this nights and weekends.
What I'd tell my past self
The honest reason indie hackers fail in technical categories isn't tech, it's patience.
I've been building this for a while whilst working full-time in cybersecurity.
Every weekend, every evening, no consistent revenue, no team.
What kept me going wasn't conviction that I'd succeed. It was three specific beliefs:
If you're building in a category where data is the moat, your job isn't to collect data. It's to build a system that makes other people want to give you data.
What's next
Incubator runs into summer. Plan:
I'm not going to pretend this is going perfectly. I'm one person, pre-revenue, with a $300 AWS bill and a day job. But the unit economics are clean, the moat compounds, and I'm in a category where $810M of recent M&A says I'm not crazy.
Try it
castle.bordair.io. Free tier works.
If you break Ghost in a way I haven't seen before, I'll personally email you, patch it, and thank you for the training sample.
Happy to AMA in the comments. Architecture, dataset construction, the data flywheel mechanics, the decision to stay pre-revenue, the day-job-and-startup grind, anything.