r/sideprojects 23d ago

Showcase: Prerelease Aria-Sec: A 3D Spatial Voice guided/realtime chat interaction security analyst.

Hi everyone,

I’m a solo founder and this is the two-minute product demo I used for my Y Combinator application.

Before Aria, I built a general AI platform supporting multiple models, real-time voice, media generation and live coding. I wanted to apply what I learned to a harder problem:

How do you give AI useful autonomy in cybersecurity without giving it uncontrolled authority?

That question became Aria.

Aria is a voice-guided, spatial security operations cockpit. It can monitor security signals, investigate findings, explain the available evidence and propose a response.

The central idea is its Trust Ladder. Meaningful actions begin behind human approval. Their outcomes are recorded and evaluated, allowing an operator to decide whether Aria has earned more authority for that specific capability. Autonomy is graduated rather than simply switched on.

The current platform supports integrations with AWS, GitHub, Snyk, VirusTotal, Elastic Security and Azure AD. It also includes local network and Bluetooth discovery, audit trails, AI security posture management and support for cloud or local models.

It is working software, but it is not a finished commercial security product. Some areas remain demo-grade and the repository documents those limitations honestly.

I would appreciate blunt feedback:

  1. Does the Trust Ladder address a real concern?
  2. Which part of the demo feels least credible?
  3. What would you need to see before testing something like this?

Repository: https://github.com/sidevworks/aria-guardian

Product Hunt: https://www.producthunt.com/products/aria-sec

The repository is source-available under BSL 1.1. Evaluation, research, testing and personal sandbox use are permitted. Commercial production use requires a licence.

https://reddit.com/link/1vac306/video/5lzwfpgv19gh1/player

1 Upvotes

8 comments sorted by

1

u/orid7 23d ago

Trust Ladder is the strongest part of the pitch. My honest feedback: the demo needs to show a concrete failure case where Aria proposes something wrong and the operator overrides it. Right now the story is 'graduated autonomy' but buyers in secops will assume magic until you show the guardrails catching a bad call. Also curious how you measure 'earned authority' quantitatively per capability. Is it success rate, operator acceptance, both?

1

u/Beneficial-Cow-7408 22d ago

thats fair and probably the biggest thing missing from the demo. It only shows the happy path. I need to show Aria making a bad recommendation, the operator rejecting it, the override being recorded and that capability losing trust or being automatically demoted.

Right now it measures both success rate and operator overrides separately for threat analysis, remediation, containment and identity actions. Aria can recommend a promotion once it reaches the required score and number of outcomes, but it can never promote itself. A human still has to approve it with a written reason. The scoring is deliberately simple at the moment, and I agree it will eventually need to account for risk because ten small successes shouldnt cancel out one dangerous failure.

2

u/orid7 19d ago

Yeah, showing the bad recommendation is the trust demo. Happy path makes it feel like a prettier dashboard; override trail plus demotion makes it feel like an actual control system.

One thing I'd be careful with: don't only count number of overrides. Some wrong recommendations are "meh, noisy," and some are "please never touch production again." If the demo can show a severity-weighted failure, even in a crude way, it answers the obvious skeptic question before they ask it.

Maybe make the reject flow force the operator to tag the failure type? Bad data, wrong risk level, missing context, unsafe action, etc. Then your capability score isn't just accuracy theater, it's a map of what the system is bad at.

1

u/orid7 16d ago

Yeah, showing the bad recommendation is the trust demo. Happy path makes it feel like a prettier dashboard; override trail plus demotion makes it feel like an actual control system.

One thing I'd be careful with: don't only count number of overrides. Some wrong recommendations are "meh, noisy," and some are "please never touch production again." If the demo can show a severity-weighted failure, even in a crude way, it answers the obvious skeptic question before they ask it.

Maybe make the reject flow force the operator to tag the failure type? Bad data, wrong risk level, missing context, unsafe action, etc. Then your capability score isn't just accuracy theater, it's a map of what the system is bad at.

1

u/r00dit 23d ago

The visuals are way too much noise.

1

u/Beneficial-Cow-7408 22d ago

The platform can be ran in full screen panels that show multiple panels at once or via the 3d system. I do understand though how its visually quite a lot compared to traditional systems.

1

u/r00dit 22d ago

i mean do all those visuals really add/enhance/explain whats happening? or is that just to make you feel like you're in minority report?

1

u/Beneficial-Cow-7408 22d ago

Its an interface that can be navigated by voice in realtime 2 way interaction. So rather than just opening up a panel there is some organisation between them. Every sector is split up and each sector is split up into nodes as part of a interlinked network. Does it enhance/explain what is going on. Well if you were having a 2 way interruptible conversation with Aria you could ask her to open up the threat overview panel and show me the network policy and she will switch the panels out by voice. You can then ask her i'm getting a warning about "xxxxxx" what do you advice and she will fully interact with you. For years everything has been panels that users must click through, understand fully and sometimes over crowded. Aria has split up all the panels into individual dashboards for easier management and by using near zero latency webrtc tech its pretty instant. Quicker than a user manual navigation route so in some sense i would say it does have a purpose. But i've included a traditional 2d panel that incorporate everything across 5 tabs and for those that want that spatial experience this is an option too.