1
1 Comment

We launched a security scanner for AI-generated code 4 weeks ago. Honest report.

On March 15 we shipped SafeWeave - an MCP server that runs 8 security scanners in parallel directly inside Cursor, Claude Code, and Windsurf.

The problem we're solving:

40–60% of AI-generated code contains vulnerabilities. Snyk and SonarQube catch these in CI/CD - minutes to hours after the code is written. By then you've lost context. Fixing is rework, not craftsmanship.

We run the scanners inside the editor while you're coding. Results in ~12 seconds. Code never leaves your machine.

Where we are after 4 weeks:

  • 120+ developers on Discord
  • Free tier live: npx safeweave-mcp - no signup, no card
  • Built by ex-Snyk + Trail of Bits engineers
  • Launching on Product Hunt this week

What worked:

Zero-friction install. npx safeweave-mcp - 30 seconds and you're scanning. People will try things when there's no barrier.

Targeting vibe coders specifically. "Vibe code fearlessly. We secure the vibes." resonated far better on X than any technical framing we tried.

Discord-first strategy. Building community before revenue forced us to actually talk to users instead of optimizing landing pages.

What didn't work:

Messaging confusion. People kept conflating "in-editor security scanning" with "Copilot's built-in safety features." Very different problems. Took 3 rewrites to get the distinction clear.

SEO. Blog content takes longer to rank than you hope. Obvious in hindsight.

What we're still figuring out:

Conversion from free to paid is lower than we expected. High install numbers, not enough upgrades. We know the problem - people don't feel the pain of the free tier limits until something actually goes wrong.

Enterprise motion. Indie devs love us. Enterprise DevSecOps teams need a completely different conversation and we haven't nailed it yet.

Happy to answer anything - especially hard questions about competing with Snyk.

on April 11, 2026
  1. 1

    I can see how figuring out the enterprise motion would be tough for this. I actually know a couple of Enterprise DevSecOps decision-makers who might be happy to answer your questions about that.