Solo Founder Building an AI-Powered Web Security Scanner for Developers
Hey Product Hunt! š
I'm Sainadh, founder of MeshaSec.
Like many developers, I found security testing frustrating. Most tools are built for security experts, struggle with authenticated applications, or require uploading sensitive application data to the cloud.
So we built MeshaSecāa local-first AI security scanner that helps developers find real security issues before they ship, without needing to be security experts.
Here's what makes it different:
š Scans authenticated applicationsānot just public pages. MeshaSec automatically logs in using form-based authentication, OAuth, JWTs, session cookies, API headers, and even 2FA (TOTP), so it can test the parts of your application that most scanners never reach.
š„ Automatically tests multiple user roles. Compare high-privilege and low-privilege accounts to uncover IDOR/BOLA, horizontal privilege escalation, and vertical privilege escalation vulnerabilities before they become production incidents.
š¤ AI that works your way. Use a local LLM for complete privacy or connect your own OpenAI or Claude API key. The AI explains every finding in plain English, recommends code fixes, and lets you create Jira tickets directly from the chat with one click.
š» Everything runs on your desktop. Your source code, API keys, credentials, and scan data stay on your machineānothing is uploaded to our servers.
We're currently opening our Windows Beta, and I'd love to connect with fellow makers, developers, founders, and security enthusiasts.
I'm curiousāhow do you currently test the authenticated parts of your application before shipping? Do you rely on automated tools, manual testing, penetration testing, or mostly code reviews?
Looking forward to meeting everyone! š
Replies