Been working on Monarc for a few months now, first real post about it here.
The problem I kept running into: small businesses genuinely don't know if they're secure. Not because they don't care, but because every decent security tool out there is priced and built for companies with a dedicated security team. If you're running a small startup or a small shop, you're basically locked out of knowing whether your own website is exposed.
Monarc scans for real vulnerabilities, tracks security posture over time, and maps everything against the compliance frameworks businesses are increasingly expected to meet, things like ISO 27001, SOC 2, NIST, HIPAA, GDPR. The part I've spent the most time on isn't the scanning itself, it's the output. Most tools generate reports written for security analysts. I wanted something a non-technical founder could actually read and act on without googling every third term.
Currently finishing an MSc in Cyber Security alongside this, aiming to launch commercially in Q1 2027. Still early, mostly putting this out there to hear from anyone who's built or sold into the security/compliance space, what worked, what didn't, what I'm probably underestimating.
Site's at usemonarc.com if you want to poke around. Would genuinely appreciate feedback, especially the harsh kind.