Hi, I'm Sary. I build from Bahrain.
What I built: Aria, an AI security analyst that investigates threats, explains the evidence, and shows you what an attack actually touched. It's voice-native, and it runs fully on-prem so telemetry never leaves your network.
Who it's for: Security teams that don't have a 24/7 SOC, and organizations in regulated or sovereign markets (GCC, EU, government, banking) where sending security data to a US cloud isn't an option.
Why I started: A few weeks ago I locked myself out of Bitwarden, 1Password, my email, and my domain registrar, all at once. 180+ accounts, gone, recursively. It took two weeks to get back in. I spent that time thinking about how much of security is invisible until it isn't, and how little help there is when you're the only person responsible for it. Aria is the tool I wanted during those two weeks: something that can look, explain, and act, but only as far as you've let it.
That last part matters to me. Aria has a Trust Ladder: it earns autonomy tier by tier from verified outcomes, and it can't promote itself. I don't think AI should be trusted by default in security. It should have to show its work.
I learned to code at the start of this year. Aria is my second project. The first was AskSary, which reached ~3,000 users across 5 platforms. I'm a product and design person before I'm an engineer, so I'd rather be told what's broken than what's clever.
Feedback that would help most: I'm still deciding how hard to lean on sovereignty and on-prem as the wedge versus leading with "AI analyst that explains itself." If you've sold into regulated or government buyers, which one opens the door faster?
Comments (20)
Welcome to the community, Sary 🙋🏻♂️ Your project sounds super interesting. Will go and check its landing page for sure. I hope there is also a little video that demonstrates how it works 🙂.
Thank you very much. This is the first time i've revealed my project to anyone so would love some feedback and yes you can check out the demo given by Aria herself on the website. The actual video is the live working platform.
↳ Replying to Sary Ismail
Sary, starting from today, there is a way to request a feedback for your project and it is available on SaaS Hive here: https://saashive.com/founder-community/request-feedback. If you are interested to receive feedback, have a look at it.
Sary, the trust ladder idea is the right instinct. Most AI security tools ask for blind trust on day one and call it convenience. On your question, I would lead with the analyst that explains itself first, then let sovereignty and on-prem be the proof point once someone is already curious, since regulated buyers tend to trust the reasoning before they trust the location. Hope the two weeks locked out of everything left you with more good ideas than scars.
Thanks, the problem i have is i dont come from a security background so i'm building something based on my AI knowledge more than anything. The biggest hurdle i'm having is entering a market and being taken seriously. I've applied for Y Combinator as i'm hoping that would open up doors and opportunities for me with meeting up and maybe even teaming up with the right people who can guide me along the way. Well the two weeks gave me nothing to do but work on a newer version of my other platform, called AskSary, which is a AI powerhouse studio that does chat, podcast, video, images, presentations, voice over, music creation, game/app development in full and much more. It needed the upgrade as it didnt do half of what it does now
Sary, the AskSary numbers already show you can build something people actually use, so trust that track record more than you are right now. YC is a good swing to take, but being taken seriously in security usually comes from showing the reasoning behind one real investigation, not from a credential. If Aria can walk someone through a full trust ladder decision start to finish, that demo probably does more convincing than the pitch itself. Good luck with the application.
Thank you Stacy, Asksary was was my first ever coding project where I learned everything i know today. Your right in the sense that i need to show a complete path because right now it shows what it protects but doesnt show how it handle threats. Appreciate the advice. What have you been working on?
Sary, working on FounderFlow, an AI Executive Chief of Staff for founders running more than one business at once. It watches your business, identifies what matters, protects your revenue, and tells you exactly what to do next. Same trust question as yours actually, since founders do not want an AI grading their business as fact before it has earned that. Right now we are onboarding the first 30 founding members personally instead of running a self serve launch, one at a time, so the system has to prove itself before anyone signs up. Good luck with the demo path, walking someone through one full investigation start to finish is the right call.
It seems to be the question a lot of people are asking. Can i trust AI and your tackling that problem with a solution. How are you finding your first customers? I practically made mine open sourced recently with the code available on github on a BSL 1.1 license for personal use and still cant get anyone to try it haha.
Sary, honestly it has been one conversation at a time, right here and in a handful of communities like it. I read what someone actually built, ask a real question about their specific business, and stay in the thread instead of moving to the next person. No cold lists, no automation. It is slow, and most days nobody replies, but the few who do turn into real conversations instead of a signup followed by silence. For the first 30 founding members I am doing it one at a time on purpose. Open sourcing Aria on GitHub was a real move. Have you tried putting the repo in front of developers where they already gather, or has it mostly been people finding it here?
I understand the process can be long, i had that issue with Asksary but that project i spent an awful lot of time on reddit, and being very involved.The problem with Aria is that i dont have the expertise or knowledge that i do with Asksary. I dont have a cybersecurity background nor have i worked in the field so i'm finding it much harder to demonstrate.
Sary, thank you for being honest about where things are hard right now. Not having a security background does not cancel out the trust ladder idea, it just means the proof has to come from one full walkthrough instead of a credential, the same point we landed on earlier. Since you asked what I am working on, I want to properly show you instead of just describing it. FounderFlow is the AI Executive Chief of Staff I mentioned, it watches a founder's business, decides what actually matters, and tells them the next move. You have given me real, specific advice through this whole thread, and I would like to return that. Would you be open to a quick look sometime this week?
Yes, absolutely. I’d be happy to take a look at FounderFlow sometime this week. It sounds genuinely interesting, especially the idea of it actively deciding what matters and helping founders prioritise the next move rather than just surfacing information.
Send me over a time that works for you and I’ll do my best to make it work.
I would not force one headline to do both jobs. For broad discovery, “an AI security analyst that explains every decision” communicates the outcome; on a page aimed at regulated buyers, “on-prem” and sovereignty can qualify the right audience immediately. The bigger credibility question may be better answered by one externally reviewed investigation or benchmark than by either phrase. Have you considered inviting a security practitioner to validate a complete case and publishing the review alongside the demo?
That distinction makes sense, and I agree they are two different jobs. The broader positioning should lead with the outcome, while sovereign and on-prem deployment belong prominently on pages intended for regulated organisations where those requirements help qualify the audience.
I also agree that independent validation would carry more credibility than either headline. Rather than seeking a general testimonial, I would want a practitioner to review one complete ARIA investigation, covering the initial alert, collected evidence, decision record, human approval boundary, proposed action, outcome and audit trail.
ARIA already records much of that chain, so the review could evaluate the quality of the evidence, governance and reproducibility rather than simply reacting to a staged demonstration. I would also be comfortable publishing genuine criticism and limitations alongside the findings.
If you know a suitable security practitioner, particularly someone experienced in regulated environments or security operations, I would welcome an introduction.
↳ Replying to Sary Ismail
That sounds like a much more credible validation format than a general testimonial. Reviewing the complete chain—from the initial alert through the evidence, approval boundary, action, outcome, and audit trail—would give a practitioner something concrete to assess.
I don’t have a suitable security practitioner I can confidently introduce right now, so I don’t want to make a loose connection just for the sake of it. I would package this as a very specific review request: one sanitized investigation, the expected time commitment, the materials the reviewer receives, and whether their findings—including criticism—may be published.
That should make it much easier for the right person to decide whether to participate. If I come across someone with relevant SOC or regulated-environment experience, I’ll send them your way.
Sary, I am genuinely happy to see your reply, thank you for saying yes. I am on Pacific time, and Wednesday, Friday, or Saturday are wide open for me. But this should work for you, not me, so just tell me whatever day and time actually suits your schedule and I will make it happen on mine. I am honestly curious what you will think of it, so I will be watching for your reply.
Thats absolutely fine, its only about 10 hours difference haha. But no i'm just trying to work out what time would be best as usually i'm free after 6pm but that would be like after 4am for you which im guessing is not ideal. Probably easier if you can tell me what hours of the day you are available then i can work out whats best for both of us and then go from there.
↳ Replying to Sary Ismail
Sary, let us make this simple. Do not worry about matching my schedule, I will work around whatever suits you best. Can you tell me your timezone and the time of day that is easiest for you? And if you send over an email address, I will get a Calendly link to you so we can lock in a slot without going back and forth here.
sure, i'm not sure what time zone i'm in as i'm from the UK originally and only recently moved to Bahrain, which is next to Dubai/Saudi. Your 10 hours ahead of me. You can drop me an email at sary at sienterpriselabs dot com. Looking forward to hearing from you
Sign in to comment or upvote.
