Hi Rob! Who are you, and what are you currently working on?
Hey there! I’m Rob Picard, 28 years old, and I’m based in Castle Rock, Colorado.
I’m the Security Lead at Vanta, a company that provides security and compliance automation. Prior to this, I was the founder of a security company called Observa.
Observa went through a few iterations but was eventually a self-service SaaS tool to detect accidental database exposure in AWS.

What’s your background, and how did you come up with Observa’s idea?
I’ve been in the security industry for a little over eight years. I started off as a penetration tester at Matasano Security and eventually worked on application security, intrusion detection, and incident response at companies like Addepar and Robinhood.
I’ve been reading Hacker News since I was 14, and I always knew I’d eventually want to start a software company. In late 2020, I read The Launchpad for the first time, and I decided to apply to Y Combinator with an idea I had been considering. I was accepted, and I left Robinhood to start building.
The original idea for Observa was to build a lightweight intrusion detection system targeting earlier-stage companies. We spent a lot of time and effort building this at Robinhood, and I figured there was some 80/20 rule where the low-hanging fruit could be detected by a simpler, less expensive system. This system could provide value to startups that weren’t ready to invest in the more complicated setup.
How did you go from idea to product?
I quickly realized that there were a few obstacles to building something like this that would provide value to smaller startups. Some of the most important log sources that I wanted to monitor were difficult to access or required enterprise-tier subscriptions to the products. In addition, some delayed the data by several days.
I also talked to potential customers and learned that this just wasn’t a priority for them; it wouldn’t be something they’d pay for. This is a classic example of a solution in search of a problem.
I decided to solve a real problem I had experienced. Large consumer companies are constantly fighting account takeover attempts by credential-stuffing botnets. These attackers take advantage of the fact that users often use the same password across many services. They take a list of credentials breached from some database in the past, and they have their botnet try to log in to a list of other services using those same usernames and passwords.
My idea was to work with these service providers and have them share the IP addresses that were performing these attacks in real time. As soon as one company detected the attack, it would trigger a reaction across the industry, and the botnet would be useless against other services.
Long story short, everyone thought this was cool, but after months of trying, I couldn’t get any of these major consumer companies to try a pilot and share some of the IPs they detected. It also turned out that many of them didn’t have sophisticated enough detection capabilities to produce a list of IP addresses in real-time, nor did they have the tooling to block new IPs that I might provide in real-time.
I changed direction again and decided to “do one thing well” with a product that would detect public database exposure in AWS accounts. It’s not difficult for a developer to accidentally make a database publicly accessible on the internet. Even if it has no interesting data, and is only used for testing or development, it can be used by an attacker to pivot into the network.
Many tools will provide you with a list of thousands of potential issues with your cloud posture, so I wanted to focus on the highest signal, and lowest noise signs which indicated an imminent security issue.
I built this tool, launched it on Product Hunt, and a handful of people signed up to use it.





