Century Tree Transit Update! Android Availability + Bus Approaching Notifications!

Howdy Aggies!

First off, I want to say thank you. When I first posted about the release of my new bus routes app, I was not expecting anything at all. I was very wrong.

You guys absolutely blew me away. Y'all have shown me so much positivity and given me such great feedback. I just checked and we already have around 300 downloads on iOS alone in just a few days. That may not sound like a ton, but I was expecting to see maybe 50 at most. So truly, thank you, this means a lot to me.

Recent Updates & Features

Thanks to your incredible feedback, here is what we have implemented so far:

  • Bus Approaching Notifications: In the Notifications section under the More tab, you can now add alerts for when a bus is about to reach your stop. (Note that right now it is a little buggy and you may receive duplicate notifications, but it is working!)

  • Easier Inbound/Outbound Switching: Previously, you had to scroll back through the selector to switch directions. Now, when you have a route open, a quick-tap icon pops up below the selector to easily switch between inbound and outbound (requested by u/ExtensionAuthor5483). You can also view both directions at the same time (requested by u/notanindianboi).

  • Route Locking: In the Favorites tab, there is now a lock icon next to each route. Locking a route means it will automatically open every time you launch the app (requested by u/notanindianboi).

  • Notifications Tab UI Redesign: I updated the UI to offer a more user-friendly walkthrough approach (let me know if you prefer this or the old one!). Additionally, you can now choose whether or not to receive official transit news for each route. If you already set up alerts, you are automatically opted in, but you can disable it anytime.

  • Android Support (Kinda!): To be a Play Store developer, I need an Android device (which I currently don't have). However, since so many of you asked, I didn't want to leave you empty-handed. Until official support arrives, I will be releasing APKs for each build directly on my website. You'll need to check the site manually for updates, but I'm also happy to make a group chat or DM y'all!

That’s all for now! I don't want to spam the sub with posts about this app, so I may not post much until I have official Android support ready (or if I need testers).

I remember telling my friends just a few weeks ago that I didn't know if working on this would really be worth it or if anyone would download it. Thanks for proving me wrong. Gig 'em!

Download from the App Store

or

Download the latest APK from my Website

reddit.com
u/Conjeff — 1 day ago
▲ 15 r/aggies

Century Tree Transit Update! Android Availability + Bus Approaching Notifications!

Howdy Aggies!

First off, I want to say thank you. When I first posted about the release of my new bus routes app, I was not expecting anything at all. I was very wrong.

You guys absolutely blew me away. Y'all have shown me so much positivity and given me such great feedback. I just checked and we already have around 300 downloads on iOS alone in just a few days. That may not sound like a ton, but I was expecting to see maybe 50 at most. So truly, thank you, this means a lot to me.

Recent Updates & Features

Thanks to your incredible feedback, here is what we have implemented so far:

  • Bus Approaching Notifications: In the Notifications section under the More tab, you can now add alerts for when a bus is about to reach your stop. (Note that right now it is a little buggy and you may receive duplicate notifications, but it is working!)

  • Easier Inbound/Outbound Switching: Previously, you had to scroll back through the selector to switch directions. Now, when you have a route open, a quick-tap icon pops up below the selector to easily switch between inbound and outbound (requested by u/ExtensionAuthor5483). You can also view both directions at the same time (requested by u/notanindianboi).

  • Route Locking: In the Favorites tab, there is now a lock icon next to each route. Locking a route means it will automatically open every time you launch the app (requested by u/notanindianboi).

  • Notifications Tab UI Redesign: I updated the UI to offer a more user-friendly walkthrough approach (let me know if you prefer this or the old one!). Additionally, you can now choose whether or not to receive official transit news for each route. If you already set up alerts, you are automatically opted in, but you can disable it anytime.

  • Android Support (Kinda!): To be a Play Store developer, I need an Android device (which I currently don't have). However, since so many of you asked, I didn't want to leave you empty-handed. Until official support arrives, I will be releasing APKs for each build directly on my website. You'll need to check the site manually for updates, but I'm also happy to make a group chat or DM y'all!

That’s all for now! I don't want to spam the sub with posts about this app, so I may not post much until I have official Android support ready (or if I need testers).

I remember telling my friends just a few weeks ago that I didn't know if working on this would really be worth it or if anyone would download it. Thanks for proving me wrong. Gig 'em!

Download from the App Store

or

Download the latest APK from my Website

reddit.com
u/Conjeff — 1 day ago
▲ 82 r/aggies+1 crossposts

New Bus App!

Howdy Ags!

As an AggieSpirit driver, I’ve spent countless hours listening to passengers (and fellow drivers) talk about what frustrates them most about getting around campus. After building this idea over the summer, I’m super excited to share that my new app, Century Tree Transit, is officially available on the App Store! Named after our iconic campus landmark, CTT was built to make navigating B/CS faster, smoother, and a whole lot less stressful.

Why should you try it?

Besides the simple features, like the easy to use live map and trip planner, CTT offers some new features specifically to make your life easier.

  • BTD Support! CTT has an alternate section dedicated towards Brazos Transit District. All of the information about how to ride, the routes, and the schedules can be easily found. (note that at this time, BTD does not provide live tracking that I know of).
  • No More Surprise Detours: When a route gets altered, the app traces the normal route with a dashed line so you can see what’s being skipped, with closed or added stops clearly flagged on the map.
  • Custom Delay Notifications: Tired of missing updates? Get notifications for your favorite routes, and customize your schedule so alerts only hit when you actually ride (no more spam on weekends if you don't want it).
  • New to riding the bus? No problem! There is a help guide written out to make you a pro the first time you step on.
  • Service Calendar: Wondering if the busses are running break service on Monday? Just check the calendar!
  • Offline Caching: The first few days is always chaos on the bus. Route data is cached locally so you can still pull up info when servers take a hit.
  • Drivers: You can now view each unit's letter designation (Alpha, Bravo, Charlie, etc.) right on their callout by toggling it in the More tab!

I am also actively working on new features, such as notifications when a bus is approaching your stop!

This is my first app ever! Even if you don't end up sticking with CTT, I would still really appreciate if you could give it a shot and give me feedback!

Check it out on the App Store! Play Store support is coming very soon!

Thanks and gig em!

u/Conjeff — 6 days ago
▲ 3 r/aggies+1 crossposts

Looking for app testers (iOS)

Howdy Ags,

I’m getting ready to release an app for tamu students/BCS residents. I just opened my beta on testflight and I am looking for people to help out with testing before I release it in the upcoming weeks.

Please message me if you’re interested. I’ll give more details in DMs. iOS only for testing (though Android will be supported at release). You will need to have TestFlight.

reddit.com
u/Conjeff — 22 days ago

Feedback on my Cyber Startup

I've been quietly building a security tool, RedPath, for the past month or so and wanted to get some honest feedback before I go further.

The Problem

Most companies get breached not because their firewall had a hole, but because an attacker moved quietly through machines they were already on -hopping from a developer's laptop to a domain controller to a database server over the course of days or weeks. This is called lateral movement, and it's the backbone of almost every serious breach you read about. Think of it like a burglar getting into a building through one office window, then using hallways, keys, and employee badges to reach the server room. The tools that detect and visualize this kind of exposure have historically been built for one type of buyer: large enterprises with dedicated security teams, six-figure budgets, and engineers whose full-time job is operating the tool. BloodHound, Vectra, PlexTrac, these are all powerful products, but they assume a level of infrastructure and expertise that most companies don't have.

Meanwhile, a company with 150 employees and one IT manager has essentially the same attack surface problem, but nobody is solving it for them.

What RedPath Does

RedPath is a continuous attack surface monitoring platform built specifically for mid-size organizations. You install a lightweight Go agent on each workstation, it runs silently in the background, survives reboots, and phones home to a local server. The dashboard then maps out your entire internal environment: which machines trust which users, where credentials are exposed, what service misconfigurations exist, and most importantly, what the actual attack chains look like if someone got a foothold on any given machine.

The core output is an attack path: a step-by-step visualization of how an attacker could move from machine A to machine B to machine C to reach something sensitive. Each path is ranked by severity based on how few hops it takes. A 2-hop path to your domain controller is far more urgent than a 9-hop path to a print server.

Beyond paths, the dashboard surfaces:

  • Credentials exposed in memory or environment variables
  • Services with unquoted executable paths (a classic privilege escalation vector)
  • Registry findings with known exploitation potential
  • Machines running without antivirus, or with firewall profiles disabled
  • RDP sessions, domain group memberships, DNS cache, startup items

All of it is updated continuously as agents check in, so you're not looking at a quarterly pentest snapshot, you're looking at your environment as it exists right now.

Who It's For

The target customer is the IT team at a company with roughly 50–500 employees. They know security matters. They've probably had an uncomfortable conversation with leadership after reading about a breach at a company their size. But they don't have a dedicated security team, and they're not going to stand up a BloodHound Enterprise deployment and hire someone to run it.

They need something that installs in an afternoon, surfaces real findings immediately, and doesn't require a computer science degree to interpret. RedPath is built to be that.

MSPs (managed service providers) are a secondary target - someone managing security for a portfolio of clients could deploy RedPath across all of them from a single interface, with per-client data isolation.

Why It's Self-Hosted

The instinct with any SaaS product is to host it centrally, run it in the cloud, charge a monthly subscription. I thought about that. I decided against it, at least for now, and I think it's the right architectural choice for this specific product.

RedPath agents collect sensitive information: usernames, credential metadata, machine relationships, internal network topology. The kind of data that, if it ended up in the wrong place, would be more damaging than the vulnerabilities it was meant to help fix. An IT manager at a healthcare company or a financial services firm is not going to route that telemetry through a third-party cloud.

Self-hosted means the data never leaves the customer's network. The backend runs on a server they already own. Agents talk to it over their internal network. Nothing touches the internet. From a security posture perspective, that's the correct answer for this type of tool.

There's also a business reality: self-hosted is actually easier to sell into security-conscious organizations because it removes the procurement friction around data residency, compliance, and vendor risk assessments. The sale is simpler, not harder.

I haven't setup backend deployment yet, but the goal is for it to be straightfoward, like a single installer for the backend. Agents also use an individual installer and are very lightweight.

Pricing

Endpoint-based annual licensing. Current thinking is around $10-12 per endpoint per year. I might consider a minimum commitment of roughly $1,500–$2,000 per year to keep the customer relationship worth supporting. For a 100-seat company that's $1,200/year which is less than most IT teams spend on a single SaaS tool they barely use. For an MSP managing 500 endpoints across clients, it's $6,000/year, likely passed through to clients at a markup.

There's no infrastructure cost on our side per customer (self-hosted), so margin is high and scales cleanly.

Where It Stands

The agent is built in Go, runs reliably, and has been tested against a real Windows environment. The dashboard is an Electron desktop application. Very easy to install and run.

Currently the backend runs locally on the customer's server with a SQLite database, with a migration path to PostgreSQL for larger deployments. The API is FastAPI.

What I'm Looking For

Honest reactions. Specifically:

  • Does the pricing make sense, or is it too cheap / too expensive for the target buyer?
  • Is the self-hosted angle a selling point or a friction point in your experience?
  • If you're in IT or security at a small to mid-size company - is this something you'd actually pay for?

Tech stack for the curious: Go (agents), FastAPI + SQLite (backend), React + Electron (dashboard), Cytoscape.js (graph visualization).

reddit.com
u/Conjeff — 3 months ago

Looking for Feedback

I've been quietly building a security tool, RedPath, for the past month or so and wanted to get some honest feedback before I go further.

The Problem

Most companies get breached not because their firewall had a hole, but because an attacker moved quietly through machines they were already on -hopping from a developer's laptop to a domain controller to a database server over the course of days or weeks. This is called lateral movement, and it's the backbone of almost every serious breach you read about. Think of it like a burglar getting into a building through one office window, then using hallways, keys, and employee badges to reach the server room.

The tools that detect and visualize this kind of exposure have historically been built for one type of buyer: large enterprises with dedicated security teams, six-figure budgets, and engineers whose full-time job is operating the tool. BloodHound, Vectra, PlexTrac, these are all powerful products, but they assume a level of infrastructure and expertise that most companies don't have.

Meanwhile, a company with 150 employees and one IT manager has essentially the same attack surface problem, but nobody is solving it for them.

What RedPath Does

RedPath is a continuous attack surface monitoring platform built specifically for mid-size organizations. You install a lightweight Go agent on each workstation, it runs silently in the background, survives reboots, and phones home to a local server. The dashboard then maps out your entire internal environment: which machines trust which users, where credentials are exposed, what service misconfigurations exist, and most importantly, what the actual attack chains look like if someone got a foothold on any given machine.

The core output is an attack path: a step-by-step visualization of how an attacker could move from machine A to machine B to machine C to reach something sensitive. Each path is ranked by severity based on how few hops it takes. A 2-hop path to your domain controller is far more urgent than a 9-hop path to a print server.

Beyond paths, the dashboard surfaces:

  • Credentials exposed in memory or environment variables
  • Services with unquoted executable paths (a classic privilege escalation vector)
  • Registry findings with known exploitation potential
  • Machines running without antivirus, or with firewall profiles disabled
  • RDP sessions, domain group memberships, DNS cache, startup items

All of it is updated continuously as agents check in, so you're not looking at a quarterly pentest snapshot, you're looking at your environment as it exists right now.

Who It's For

The target customer is the IT team at a company with roughly 50–500 employees. They know security matters. They've probably had an uncomfortable conversation with leadership after reading about a breach at a company their size. But they don't have a dedicated security team, and they're not going to stand up a BloodHound Enterprise deployment and hire someone to run it.

They need something that installs in an afternoon, surfaces real findings immediately, and doesn't require a computer science degree to interpret. RedPath is built to be that.

MSPs (managed service providers) are a secondary target - someone managing security for a portfolio of clients could deploy RedPath across all of them from a single interface, with per-client data isolation.

Why It's Self-Hosted

The instinct with any SaaS product is to host it centrally, run it in the cloud, charge a monthly subscription. I thought about that. I decided against it, at least for now, and I think it's the right architectural choice for this specific product.

RedPath agents collect sensitive information: usernames, credential metadata, machine relationships, internal network topology. The kind of data that, if it ended up in the wrong place, would be more damaging than the vulnerabilities it was meant to help fix. An IT manager at a healthcare company or a financial services firm is not going to route that telemetry through a third-party cloud.

Self-hosted means the data never leaves the customer's network. The backend runs on a server they already own. Agents talk to it over their internal network. Nothing touches the internet. From a security posture perspective, that's the correct answer for this type of tool.

There's also a business reality: self-hosted is actually easier to sell into security-conscious organizations because it removes the procurement friction around data residency, compliance, and vendor risk assessments. The sale is simpler, not harder.

I haven't setup backend deployment yet, but the goal is for it to be straightfoward, like a single installer for the backend. Agents also use an individual installer and are very lightweight.

Pricing

Endpoint-based annual licensing. Current thinking is around $10-12 per endpoint per year. I might consider a minimum commitment of roughly $1,500–$2,000 per year to keep the customer relationship worth supporting.

For a 100-seat company that's $1,200/year which is less than most IT teams spend on a single SaaS tool they barely use. For an MSP managing 500 endpoints across clients, it's $6,000/year, likely passed through to clients at a markup.

There's no infrastructure cost on our side per customer (self-hosted), so margin is high and scales cleanly.

Where It Stands

The agent is built in Go, runs reliably, and has been tested against a real Windows environment. The dashboard is an Electron desktop application. Very easy to install and run.

Currently the backend runs locally on the customer's server with a SQLite database, with a migration path to PostgreSQL for larger deployments. The API is FastAPI.

What I'm Looking For

Honest reactions. Specifically:

  • Does the pricing make sense, or is it too cheap / too expensive for the target buyer?
  • Is the self-hosted angle a selling point or a friction point in your experience?
  • If you're in IT or security at a small to mid-size company - is this something you'd actually pay for?

Looking for the version of feedback that makes the product better or saves me from building something nobody wants.

Tech stack for the curious: Go (agents), FastAPI + SQLite (backend), React + Electron (dashboard), Cytoscape.js (graph visualization).

reddit.com
u/Conjeff — 3 months ago