Hey everyone, it’s time for a transparent update on what I've been building. I've officially pivoted.
Previously, I was heads-down working on ScrubZero, a local, browser-based PII redacting tool. I still believe in the importance of that mission, but while building, I tripped over a much larger, more urgent problem in the modern development workflow that I simply couldn't ignore.
The AI-Coding Blind Spot
We are in an incredible era where AI-assisted development allows citizen developers to build and ship at lightspeed. But as I was building, I realized a massive gap in this new workflow: just how secure is this "vibe-coded" output?
The reality is that most citizen developers have a severe lack of understanding regarding the vulnerabilities hiding in their generated code. When I looked to the market for a solution, I hit a brick wall. The existing AppSec products are built for enterprise—they come with incredibly steep learning curves, complex integrations, and enterprise-level pricing that immediately locks out indie hackers and lean teams.
Enter Tuora
That friction is why I pivoted to build Tuora.
Tuora is an in-flight code security interceptor designed specifically for citizen developers and vibe-coders. It bridges the gap between rapid AI-assisted creation and necessary security. It ensures that the product you are building is secure enough for your own immediate use, and robust enough to actually scale without collapsing under technical or security debt.
Where we are today
The core is built, completely open-source, and ready to experiment with. Our current MVP is already powerful enough to catch critical vulnerabilities by covering:
Industry Standards: Full mapping against OWASP (Open Web Application Security Project), CWE (Common Weakness Enumeration), and MITRE ATLAS (AI-specific threat framework) frameworks.
Custom Protection: Powered by our own proprietary threat signatures designed specifically for AI-generated code patterns.
This is just the baseline—Tuora is built to expand far beyond these initial frameworks as we scale.
CLI Compatibility & Availability: To make adoption frictionless, the Tuora CLI is built to run where you already code. It currently natively supports:
Linux (Native & via WSL2)
macOS (Both Intel and Apple Silicon architectures)
What's Next: Tuora is currently free to use while we refine the core engine with the community. Moving forward, we are actively developing a paid tier for serious users and teams that will provide deeper, actionable intelligence analysis on your codebase.
If you are building with AI and want to ensure your code isn't a ticking time bomb, the tool is open for you to try at https://runtuora.com. I'd love to get your feedback on the setup!
I find pivots interesting when they look like a change of direction but feel more like a change of scale.
Reading this, I wasn't sure whether you abandoned the original problem.
Or whether you discovered a larger version of it.
It is a complete pivoting where my previous idea opened up the lead to the current direction. It was through feedback that drove the decision.
It took one feedback that goes like this "PII could be a good niche until every LLM providers come out with their inline redacting tool. How are you going to move on from there"
Seeing the bigger picture is important during pivoting phase. That gave me the courage to make the decision and move on.
That's the part I'd be most curious about.
Not the pivot itself.
The amount of influence that particular piece of feedback ended up having on the decision.
Sometimes a comment is valuable because it's correct.
Sometimes it's valuable because it changes which questions a founder starts asking next.
Those aren't always the same thing.
I've got a few thoughts on that, but it's probably more than I'd try to unpack properly in a thread.
What's the best email to reach you on?
You can reach out to be at me at byleonardlim dot com and I did happy to connect with you how the decision is made.
Hope to hear from you,Aryan!
Just sent a note to me@byleonardlim.com.
Looking forward to the discussion.