Live data from Hacker News

Viewing profile — gmontard

gmontard

HN member
Joined
Thu, Oct 24, 2013, 1:24 PM UTC
HN karma
104
Public activity
97 items

About gmontard

Founder at Bearer.com

Recent public activity

  1. story
    Show HN: Bearer Code Security Scanner Add Support for Java, PHP, Go, and Python

    Hello there, I’m Guillaume, the cofounder and CEO of Bearer, a code security startup trying to rethink security products for a developer-first World. 7 months ago we introduced on …

  2. story
  3. story
    Detecting sensitive data shared with OpenAI

    Hi HN, I'm Guillaume, the founder of Bearer, an Open Source code security scanning tool. Despite the buzz around generative AI (which, as a reader of HN, you've likely encountered)…

  4. comment
    Comment #35578411

    I’ve been on a call with a few security folks where their organization work with OpenAI and they are all clearly afraid of leaking sensitive data. No one yet really know how to han…

  5. story
    Show HN: TypeScript Security Scanner

    Hi HN, I’m Guillaume, the cofounder of Bearer, an Open Source SAST solution. After launching a few weeks ago here on Hacker News with support for Ruby and JavaScript stacks, I’m ha…

  6. comment
    Comment #35527842

    I like your counter approach to everything we read lately on the topic! I think to your point, besides the quality of the output (that we can challenge with every tool, AI or not),…

  7. comment
    Comment #35527150

    Here is an interesting article from Contrast CTO, especially in an industry that is quite opaque. Comparing one tool with another remains a big challenge, but at least this gives a…

  8. story
  9. story
  10. comment
    Comment #35066621

    Oh, I’m really sorry about that, I didn’t know (my fault) mentioning we were on HN was against the rules. Calling that « vote manipulation » is quite exaggerated imho but I get it.…

  11. comment
    Comment #35061721

    Btw if you have some exemple please share or even better write an issue, we’d be super happy to look at it and fine tune the rules. It’s just a 1.0, we can do much better for sure …

  12. comment
    Comment #35061699

    I agree, in theory :) But I’m happy you say that and gives me hope our future automated remediation suggestion can be easily adopted.

  13. comment
    Comment #35061675

    In an ideal world security tools like this one should be useless… but unfortunately we don’t all live in this world where security requirements are all captured, understood and imp…

  14. comment
    Comment #35061642

    We need to open for configuration the filtering and prioritization logic that essentially does that today, but so you can apply your own logic. I advise to start today by looking f…

  15. comment
    Comment #35059612

    You're pushing it ^^

  16. comment
    Comment #35059200

    Once we're a bit more ready on the Cloud version, we'll release the pricing. Honestly I also hate when pricing is not available, so I'd like us to avoid this going further! Thanks …

  17. comment
    Comment #35058608

    Also, super expensive, you need the $99 plan :) https://about.gitlab.com/pricing/ Integration with SCM is clearly a top priority for us, especially directly in PR. GitHub SARIF is …

  18. comment
    Comment #35058573

    SARIF output is on our Roadmap btw! Github code scanning is not so great from what we've heard so far, but also it's very expensive, you need to be on the Enterprise plan...

  19. comment
    Comment #35058553

    Well, we're getting there, at least into proposing some fixes. Automatically fixing is tricky, it means changing your code that can get automatically deployed in production without…

  20. comment
    Comment #35058501

    Not taken, just wanted to give the context of why this license.

  21. comment
    Comment #35058177

    I wouldn't say dominating tbh, but clearly one of the good solution out there for sure. Probably the biggest differentiator is our ability to detect sensitive data flows and map th…

  22. comment
    Comment #35057682

    Workflow is coming with our Cloud offering, with all the cool integration you can think of as Jira or Slack. On the "marking" part, we have two options that will be available super…

  23. comment
    Comment #35057477

    We hear you

  24. comment
    Comment #35057469

    That's right, we don't want to have someone doing managed service on top of us without a getting a license (or just an agreement). Basically, it's the AWS vs Elastic case, that res…

  25. comment
    Comment #35057356

    Absolutely! We wanted to find a good balance with a license to allow any team to use it for their own usage no strings attached and at the same time protect us against a big vendor…