I built a free tool so you can vibe-code freely and not worry about what your AI actually shipped. Feedback very welcome, and I'll happily give you feedback on your product as well

I build with AI a lot. And the thing that got me wasn't bugs it was that I'd ship something I liked and have no idea whether I'd left a door open somewhere. I wouldn't have known what to look for.

This is when I built VulX. VulX lives integrates into your workflow (for example in Claude and Cursor). You connect it once and it's just there, part of the workflow, not another tab, not something you go to. "Is this safe to ship?" becomes a question you ask mid-flow, and the answer comes back from something that isn't the thing that wrote your code. Asking your AI to check its own work is marking your own homework. This is the second reader.

And when you're deep in it and don't think to ask, it checks anyway and emails you.

That's the whole idea. You keep building whatever you want. The worrying is somebody else's job now.

vulx.ai

Feedback very welcome, especially where it's confusing or where a finding doesn't land. And happy to return the favour with your product drop it down and I will give you feedback within an hour

reddit.com
u/TX_2_WildExpert — 6 days ago

we're live tomorrow and if you could show your support

If you're here and have a Product Hunt account, we'd love your support. A quick upvote or comment goes a long way for a team on launch day ❤️ As it is pre-launch if you could send a review and on launch day send a upvote we would greatly appreciate it

🔗 https://www.producthunt.com/products/vulx-watch-launch?launch=vulx-watch

Thanks for stopping by and supporting us! 🙌 if you are also launching I would be happy to upvote on your product too

reddit.com
u/TX_2_WildExpert — 22 days ago

My product is launching tomorrow(second launch) and wanted to ask what should I do the day before so that it is successful

Tomorrows my second PH launch and I want to actually do it right this time.

First launch I kind of just posted and hoped got some traffic, not much that stuck. This time I've got the page, tagline, and first comment ready, and a small audience to notify.

For those who've launched before: what's the highest-leverage thing to do the day before?

Not looking for upvotes here, genuinely trying to not fumble it twice. Appreciate any hard won lessons

reddit.com
u/TX_2_WildExpert — 22 days ago

Launching on PH for the first time any tips?

Not first time founder but first launch on ProductHunt and first time creating a product for consumers, and I'm realising I have no idea what im doing.

What I have built: think of it as a health tracker for your codebase: it rereads your github repo a few times a week, keeping score of what's broken, what you've fixed, and what quietly crept back. It's also continuously monitored against our threat intelligence database, so you're alerted the moment a new vulnerability affects you.

now things I'm unsure about:

How much does it hurt to launch without a big following? I don't have one.

What do you wish you'd prepared before launch day rather than scrambling on the day?

happy to hear the blunt version rather find out sooner than later

the launch thing: https://www.producthunt.com/products/vulx-watch-launch?utm_source=other&utm_medium=social

u/TX_2_WildExpert — 24 days ago

Send me your app and I'll test and give you feedback!

I liked what the other user did so I'll also offer the same and check back occasionally to help test your apps and give you some feedback. I like this community and it's nice to give back!

I'll give you some feedback about bugs I find, UI design and suggestions, and user experience issues or compliments. I could also offer suggestions as I think of them.

A little about me:

  • Solo founder building a cybersecurity startup (VulX Ltd, UK-registered) while still finishing school, so I split time between coursework and shipping product.
  • Like you, I love productivity tools, and I'm willing to pay for stuff when I find it genuinely useful.
  • Currently building VulX Watch, a proof-based vulnerability scanner that connects to your GitHub repo and continuously reviews AI-generated code for security issues (SAST/DAST pipeline running on FastAPI, Temporal Cloud, and E2B sandboxes). It's aimed at people shipping apps built with AI coding tools who want a safety net without hiring a security team.
  • Outside of that I've done freelance work in web development, 3D animation, and motion graphics, and I've got a side interest in AI/ML research (published a paper on stock embedding methods, another on aging/longevity).

PS: this is quite a lot of stuff I have to test so might take me a couple days if anyone wants to help feel free too

reddit.com
u/TX_2_WildExpert — 25 days ago

We walked away from a GRC partnership to bet on our own product. It went live today, please be as critical as you can

Hey, I'm Tomek, founder of VulX. Launched today, I'd rather have criticism than compliments.

That's a real scan. Nine findings on one repo, sorted by how much we actually believe them.

The bottom box is the part I care about. Those are pattern matches, maybes. We label them as maybes and never dress them up as more. Most scanners hand you all nine at the same confidence and let you work out which ones are real.

Connect a GitHub repo and VulX Watch keeps checking it, re-scanning as new advisories land, telling you in plain English what's broken and how to fix it. The model that wrote your code can't audit itself.

We scanned 21 AI-built SaaS apps to test whether this was a real problem. Zero came back clean. 309 findings, of which 54 were corroborated across two independent vendors, I publish that split because a scanner you can't calibrate is a scanner you ignore.

We've been staring at this for months and have lost the ability to see it clearly. If you point it at a repo and it's wrong, or useless, that's the comment I want.

u/TX_2_WildExpert — 25 days ago

We walked away from a GRC partnership to bet on our own product. It went live today, please be as critical as you can. Free access for anyone who is able to give good feedback(not advertisement I dont want your money)

Hey, Im Tomek, founder of VulX. I would really appreciate any feedback or criticism.(Not advertisement I dont want your money)

quick backstory: Initially our company had a partnership with a GRC company. We have moved away from it to build something of our own and as of today, its live.

what it is:

The goal is bigger than a scan: every codebase keeping itself current, on its own. Not a report you read once and file away a repo that stays patched, keeps its dependencies honest, and tells you the moment something you shipped last month turned dangerous this morning. the vision of a codebase always being up to date with the latest vulnerabilities

Connect a GitHub repo and our autonomous pentesters go at it: reading your code the way an attacker would, arguing with each other about whats actually exploitable, and surfacing a finding only once one of them has tried to prove it wrong and failed.

Every dependency is checked against public vulnerability databases as new advisories land. A cross-network intelligence layer, so a threat found in one codebase strengthens detection across all of them. Plus our own in-house model for filtering false positives.

We've been staring at this for months and have lost the ability to see it clearly. We'd rather have criticism than compliments, so to make it worth your time, anyone who leaves useful feedback gets free access. No card, no catch.

reddit.com
u/TX_2_WildExpert — 25 days ago

We walked away from a GRC partnership to bet on our own product. It went live today, please be as critical as you can. Free access for anyone who is able to give good feedback(not advertisement I dont want your money)

Hey, Im Tomek, founder of VulX. I would really appreciate any feedback or criticism.(Not advertisement I dont want your money)

quick backstory: Initially our company had a partnership with a GRC company. We have moved away from it to build something of our own and as of today, its live.

what it is:

The goal is bigger than a scan: every codebase keeping itself current, on its own. Not a report you read once and file away a repo that stays patched, keeps its dependencies honest, and tells you the moment something you shipped last month turned dangerous this morning. the vision of a codebase always being up to date with the latest vulnerabilities

Connect a GitHub repo and our autonomous pentesters go at it: reading your code the way an attacker would, arguing with each other about whats actually exploitable, and surfacing a finding only once one of them has tried to prove it wrong and failed.

Every dependency is checked against public vulnerability databases as new advisories land. A cross-network intelligence layer, so a threat found in one codebase strengthens detection across all of them. Plus our own in-house model for filtering false positives.

We've been staring at this for months and have lost the ability to see it clearly. We'd rather have criticism than compliments, so to make it worth your time, anyone who leaves useful feedback gets free access. No card, no catch.

reddit.com
u/TX_2_WildExpert — 25 days ago

We walked away from a GRC partnership to bet on our own product. It went live today, please be as critical as you can. Free access for anyone who is able to give good feedback(not advertisement I dont want your money)

Hey, Im Tomek, founder of VulX. I would really appreciate any feedback or criticism.(Not advertisement I dont want your money)

quick backstory: Initially our company had a partnership with a GRC company. We have moved away from it to build something of our own and as of today, its live.

what it is:

The goal is bigger than a scan: every codebase keeping itself current, on its own. Not a report you read once and file away a repo that stays patched, keeps its dependencies honest, and tells you the moment something you shipped last month turned dangerous this morning. the vision of a codebase always being up to date with the latest vulnerabilities

Connect a GitHub repo and our autonomous pentesters go at it: reading your code the way an attacker would, arguing with each other about whats actually exploitable, and surfacing a finding only once one of them has tried to prove it wrong and failed.

Every dependency is checked against public vulnerability databases as new advisories land. A cross-network intelligence layer, so a threat found in one codebase strengthens detection across all of them. Plus our own in-house model for filtering false positives.

We've been staring at this for months and have lost the ability to see it clearly. We'd rather have criticism than compliments, so to make it worth your time, anyone who leaves useful feedback gets free access. No card, no catch.

reddit.com
u/TX_2_WildExpert — 25 days ago