2
1 Comment

We built a security product - looking for feedback on how to bring this to market

Hi,

I built a security product which I think is different from other (syntactic) security products in the market called Redmirror. Basically it lays semantic rules on top of your code to find bugs that are missed by other tools. This is not novel completely, it's probably going to be a whole category on its own with LLMs getting closer to AGI. However, the way I do it is different and through a combination of rule writing, formal verification and graph search.

Long story short after months of testing "in the wild" we have found multiple bugs that you can check at https://redmirror.devs.mu/ This validated the product but not the business. A few high severity vulnerabilities are not yet disclosed.

However, I am now struggling to bring this to market and looking for your feedback. Right now, we are contacting small to medium companies to offer a security audit on code where you only pay us if we find bugs, but it feels like a scam and we are not getting replies.

Turning this into a managed service or a packaged product came to my mind but I am worried about misuse.

Any ideas? Thanks in advance

on June 9, 2026
  1. 1

    The thing I'd be careful with is that this may not be a trust problem or an outreach problem.

    You already proved the technology can find real vulnerabilities. The harder question is what specific buying event makes someone care enough to evaluate Redmirror in the first place.

    A lot of technically impressive security products struggle because they solve a real problem, but attach themselves to the wrong decision point inside the buyer's workflow.

    I wouldn't make that call casually in-thread because it affects whether this should behave more like a service, a product, or something in between.

    If useful, happy to put the tighter version in writing. This feels like one of those decisions where the actual call matters more than the technology.