I’m building ARIA, an AI security analyst that investigates threats and can take action within controls set by the customer. Today, companies either overwhelm analysts with alerts or ask them to trust automation. ARIA starts by requesting approval, verifies every outcome, and earns narrowly scoped autonomy over time - it cannot promote itself. I taught myself software development this year and built the working desktop and web platform, backend, security connectors, and governance system myself.
No reviews yetBe the first to leave a review for Aria-Sec
Maker
📌
Hey Product Hunt 👋 I’m Sary, the solo founder behind ARIA.
I built ARIA because security teams already have enough dashboards and alerts. What they need is an AI analyst that can investigate threats, explain the evidence and blast radius, recommend a response, and eventually act - within clear human-defined boundaries.
ARIA’s core idea is governed autonomy. It starts by asking permission, earns trust through verified outcomes, cannot promote itself, and immediately loses autonomy after a failure.
I only started coding this year and built the platform from scratch, including its security connectors, AI-SPM engine, identity monitoring, voice interface, and trust architecture.
ARIA is also open source, so builders and security teams can inspect how its governance model works and help shape it.
I’d particularly value feedback on:
Which security workflow you would trust AI to handle first
What evidence you would need before allowing autonomous action
Which integrations ARIA should support next
Thanks for checking it out. I’ll be here answering every question.
Report
Congrats on shipping this solo. The scoped autonomy approach sounds thoughtful. One thing that would help build trust: a clear audit log export that shows every action ARIA took, the approval chain, and what data it accessed. SOC 2 reviewers will ask for it anyway, and having it visible in-app would make the "verify every outcome" promise tangible instead of just a claim.
Report
Maker
@navflow Thank you - you’re right about the trust value here. ARIA already maintains an in-app, tenant-scoped audit ledger covering actions, actors, approvals, outcomes, and governance changes.
The gap is packaging that evidence into a clear, exportable chain - including the specific systems and data each operation accessed - for operators and SOC 2 reviewers. That’s a useful distinction, and I’m adding the unified export experience to the roadmap.
Report
Really cool approach with the trust-building autonomy model. One thing that would help teams adopt this faster: a sandbox mode where ARIA investigates a copy of recent alerts in parallel with human analysts, then compares findings side by side. That way you can show measurable accuracy and false positive rates before anyone grants it any action permissions.
Report
Maker
@sian_tate That’s a great point. ARIA already supports a version of this in AI SPM: users can investigate findings in a sandboxed environment, with human approval required before any action is taken.
Right now, though, that capability is limited to the AI SPM panel. A universal sandbox mode—allowing ARIA to work alongside analysts across all functions and compare results side by side—is definitely something I need to build.
Such a promising launch—congrats on Aria-Sec! AI security that earns your trust before it acts is a clever idea. Wishing you a strong Product Hunt day! 🚀
Report
Maker
@zvonimir_sabljic1 Thank you, appreciate the comment. I applied to Y combinator with the idea so lets see what happens
Congrats on shipping this solo. The scoped autonomy approach sounds thoughtful. One thing that would help build trust: a clear audit log export that shows every action ARIA took, the approval chain, and what data it accessed. SOC 2 reviewers will ask for it anyway, and having it visible in-app would make the "verify every outcome" promise tangible instead of just a claim.
@navflow Thank you - you’re right about the trust value here. ARIA already maintains an in-app, tenant-scoped audit ledger covering actions, actors, approvals, outcomes, and governance changes.
The gap is packaging that evidence into a clear, exportable chain - including the specific systems and data each operation accessed - for operators and SOC 2 reviewers. That’s a useful distinction, and I’m adding the unified export experience to the roadmap.
Really cool approach with the trust-building autonomy model. One thing that would help teams adopt this faster: a sandbox mode where ARIA investigates a copy of recent alerts in parallel with human analysts, then compares findings side by side. That way you can show measurable accuracy and false positive rates before anyone grants it any action permissions.
@sian_tate That’s a great point. ARIA already supports a version of this in AI SPM: users can investigate findings in a sandboxed environment, with human approval required before any action is taken.
Right now, though, that capability is limited to the AI SPM panel. A universal sandbox mode—allowing ARIA to work alongside analysts across all functions and compare results side by side—is definitely something I need to build.
Pazi
Such a promising launch—congrats on Aria-Sec! AI security that earns your trust before it acts is a clever idea. Wishing you a strong Product Hunt day! 🚀
@zvonimir_sabljic1 Thank you, appreciate the comment. I applied to Y combinator with the idea so lets see what happens