DHAHAB Ventures · Investor One-Pager
DIRA · درع
A zero-dependency security scanner that answers the question every pre-seed founder gets asked: "is this codebase safe enough to sell to an enterprise?" One command, one readiness score, MIT licensed.
The Problem
No security hire, no clean answer.
Enterprise buyers now gate contracts on a security questionnaire before signature. A pre-seed or seed team has no security hire and two bad options: a platform priced for a team they don't have, or five uncoordinated point tools (gitleaks, trufflehog, semgrep, npm audit) nobody wires into one answer.
The Product
Seven scanners, one command.
Secrets (24 patterns + entropy) · dependency CVEs via OSV.dev (5 ecosystems) · 38 config/IaC rules (Docker, K8s, Terraform, GitHub Actions, cloud, frontend, LLM apps) · git-history leaks · live TLS & security headers · license risk + SBOM (CycloneDX/SPDX) · an 18-check, 80-point startup security-readiness score.
pipx install git+https://github.com/Yusuf-Gadelrab/dira@v1.5.0— installs and runs today- 208 passing tests, zero runtime dependencies, MIT licensed
- Two optional paid tiers (Readiness Report $149, Deep Audit $499) — built, zero sales to date
Why Now
Procurement gates every enterprise deal.
SOC 2-shaped questionnaires now show up before a startup's first enterprise contract, not after. Gitleaks, trufflehog, and semgrep each do one slice of that well — none produce the readiness score a buyer's security team actually asks for. DIRA is the one-command version of "can we pass this," priced at zero so a solo founder can run it before anyone else looks.
Roadmap
dira-scan) and npm — packaged, not yet listedFounder
Yusuf Gadelrab
Valedictorian, Lynbrook High School, Class of 2024. BS Computer Science, San José State University, expected May 2028. Co-author, an ACM SIGCSE TS 2026 poster abstract on CS education with Dr. Ethel Tshukudu's CS Education Research Lab at SJSU. Solo builder and maintainer of every product on this page.