October 2, 2026
We built a simple AI script to save a friend’s app.
It started with a phone call from a founder friend of mine.

By Christian
2 min read
We built a simple AI script to save a friend's app. Now we are launching it to fix cybersecurity for indie founders.
He built a popular AI image generation app. He found product-market fit, his user base was growing, and the unit economics looked great. Then people started taking his app offline.
This was not a basic DDoS attack. Someone found a vulnerability, targeted his server during peak hours, and drained his resources. He panicked and did what most people do in that situation. He bought a license for a heavy enterprise vulnerability scanner.
What he got back was a 300-page PDF report packed with red flags, obscure CVE codes, and false positives. Instead of shipping new features, he was stuck Googling how to decipher enterprise security jargon. He did not need a list of alerts. He needed a solution.
Our Unfair Advantage
That is where we stepped in. My background is in AI development rather than legacy cybersecurity. Not being tied to old corporate standards turned out to be our biggest advantage.
We ignored his massive PDF report. Instead, we put together a quick internal AI script. We pointed it at his external perimeter just to see if the model could spot the anomaly.
The result completely surprised us. In under a minute, the script found an exposed admin panel and a vulnerable endpoint. It did not just throw a random error code at us. The AI gave us plain English instructions. It literally told us what to type, which config file to edit, and which port to close.
Fifteen minutes later, the vulnerability was gone. The bot was stable again. We sat there looking at our script and realized we had stumbled onto something much bigger than a quick bug fix.
Why Security is Broken for Solo Founders
We realized right then that the cybersecurity market is entirely disconnected from reality for small businesses and indie developers.
The industry is stuck in the past. They want you to use complex interfaces, grant root access to third-party agents, and pay thousands of dollars. When you are building a SaaS or running an agency, you want to focus on your product. You do not want to become a part-time DevOps engineer.
That internal script eventually became orb44.
We built it around minimalism and freedom. First, it is agentless. We scan your external perimeter from the outside, meaning we never ask for root access. Second, we keep zero logs. Your infrastructure stays yours. Finally, we speak human. When we find a vulnerability, our AI tells you exactly how to fix it in plain English.
For those who want more control, we also added an optional Watch Satellite to monitor your VPS pulse.
What is Next
We built orb44 to save our own time. Now we are ready to share it.
We are officially launching on Product Hunt on October 21. We set up a generous free tier that lets you scan one domain forever without entering a credit card.
If you are building on the internet, come check it out on the 21st. I would love to answer your questions, talk about how we used to build this platform, and get your honest feedback. Let's make the internet safer without making it complicated.