business

Verdict

Submitted 5/13/2026, 6:50:20 PM · Completed 5/13/2026, 6:59:02 PM

6.5
pivot
The idea

I built a free cybersecurity skills platform because cert prep felt too shallow

Show original source text →
I’ve been building **SecProve**, a cybersecurity learning and assessment platform, and wanted to share it here because this community seems more open to people actually talking about what they’re building. The idea started from a frustration I’ve had with a lot of cybersecurity training: most platforms either focus on rote memorization, generic multiple-choice quizzes, or “pass the cert” content without really measuring whether someone understands the underlying concepts. So I’ve been building SecProve around a slightly different premise: **Cybersecurity skill should be measurable across domains, not just tested question by question.** Right now, the platform includes: Free Security+ SY0-701 certification practice Adaptive question performance tracking Domain-level scoring Timing and confidence signals A broader cybersecurity domain map Early work toward Elo-style practitioner ranking Explanations designed to teach concepts, not just reveal the right answer The Security+ portion is intentionally free and uncapped. I’m using it as a top-of-funnel entry point, but the longer-term vision is bigger than cert prep. I want SecProve to become a way for people to understand where they are strong, where they are weak, and how different cybersecurity domains connect across real-world roles. The thing I’m trying to avoid is building “another quiz app.” There are already plenty of those. The harder question I’m working through is: **What would make cybersecurity assessment feel more like a real skill signal instead of a memorization game?** Some of the directions I’m exploring: Ranking users by demonstrated proficiency, not just completion Measuring speed, confidence, consistency, and improvement over time Mapping cert objectives to broader cybersecurity domains Helping users understand career-relevant strengths and gaps Eventually supporting scenario-based and adversarial challenges I’d love feedback from other SaaS builders, especially around positioning. Does this feel like a differentiated wedge into cybersecurity learning, or does “cert prep” immediately make it sound like a crowded commodity category? Site is here: https://secprove.com/certifications
TRIZ inventive level: 3/5· Principles: parameter changes, mechanical interaction
Synthesis verdict
**Pivot**: SecProve has a unique approach to cybersecurity learning and assessment, but it needs to address its competitive weaknesses and regulatory risks to succeed. The platform's focus on measurable, domain-aligned skill signaling is a critical unmet need in the market, and its free Security+ certification practice is a smart top-of-funnel entry point. However, the market is saturated with incumbents who have already pivoted from rote memorization to adaptive, scenario-based learning, and SecProve's proposed differentiation may not be enough to defend against competition. Additionally, regulatory risks and dependency on a single certification body pose significant threats to the platform's success.

Strengths

  • Unique approach to cybersecurity learning and assessment
  • Measurable, domain-aligned skill signaling
  • Free Security+ certification practice as a top-of-funnel entry point
  • Clear path to upsell via differentiated assessment
  • Plausible unit economics with high margins

Weaknesses

  • Lack of defensible moat against competition
  • Vulnerability to regulatory or certification body actions
  • Dependency on a single certification body
  • Risk of churn due to misaligned user expectations
  • Need to validate willingness to pay for non-cert content

Best angle

SecProve should pivot to focus on interactive simulation and hands-on labs to provide true skill signaling in cybersecurity, and establish partnerships with industry leaders to validate its ranking system and provide a trusted credentialing layer beyond certs.

Panel verdicts

Viability

meta/llama-4-maverick-17b-128e-instruct

6.0

A solo or 2-person team can build a basic version of SecProve within 4-12 weeks by focusing on core features and simplifying or delaying more complex ones.

Building a basic version of SecProve (v1) within 4-12 weeks is feasible for a solo or 2-person team, but it depends on the scope and complexity of the features included. The existing Security+ SY0-701 certification practice, adaptive question performance tracking, and domain-level scoring are relatively straightforward to develop. However, implementing advanced features like Elo-style practitioner ranking, measuring speed, confidence, consistency, and improvement over time, and scenario-based challenges will be more challenging and may require more time and expertise. The team can likely build a simplified version of the platform within the given timeframe, focusing on the core features and delaying more complex ones. The key will be prioritizing the most essential features and simplifying others to meet the deadline.

Monetization

mistralai/mistral-medium-3.5-128b

8.0

Free cert prep as a funnel works, but monetization hinges on proving the platform’s skill signal is worth paying for beyond certs.

SecProve’s wedge is strong: free Security+ practice as a loss-leader to capture top-of-funnel users, with a clear path to upsell via differentiated assessment (domain-level scoring, Elo-style ranking, confidence/speed metrics). This avoids the commodity trap of generic quiz apps by positioning as a *skill signal* rather than cert prep. Unit economics are plausible: low cost-to-serve for the free tier (automated questions), with premium tiers ($20–$50/month) for advanced analytics, scenario-based challenges, or team dashboards. Margins should be high (80%+) given digital delivery. The risk is conversion—free users may not see immediate value in paid features unless the platform demonstrates tangible career impact (e.g., employer partnerships, skill badges). Channels: organic SEO (cert prep keywords), cybersecurity communities (Reddit, Discord), and B2B partnerships with training providers. Key gap: monetization proof—need to validate willingness to pay for non-cert content.

Risk

nvidia/llama-3.3-nemotron-super-49b-v1

4.0

SecProve's innovative approach is at risk of being stifled by regulatory or certification body actions before it can establish a broad user base.

SecProve's differentiation hinges on its ability to measure skill across domains and provide actionable insights, but this is undermined by several critical risks. **1. Regulation (8/10)**: Cybersecurity certification bodies (e.g., CompTIA for Security+) may view SecProve's adaptive, domain-level scoring as encroaching on their accreditation authority, potentially leading to legal challenges or forced licensing agreements that could be cost-prohibitive within 6 months. **2. Platform Risk - Dependency on Single Certification (9/10)**: Initial focus on Security+ SY0-701 makes the platform highly vulnerable if CompTIA updates the certification in a way that breaks SecProve's content alignment or if they develop a competing, official adaptive platform. **3. Churn due to Misaligned User Expectations (6/10)**: Users expecting traditional cert prep might churn if SecProve's innovative approach doesn't immediately resonate, especially if the platform's broader career development tools are not yet fully fleshed out.

Market

qwen/qwen3-next-80b-a3b-instruct

8.0

Cybersecurity professionals don’t need another quiz — they need a verifiable, dynamic skill profile that employers trust more than a certificate.

SecProve stands out by shifting cybersecurity assessment from memorization-based certification prep to measurable, domain-aligned skill signaling — a critical unmet need. The target audience isn’t just students chasing CompTIA Security+; it’s mid-level security professionals, SOC analysts, and threat hunters who need to prove real competency to employers, peers, or internal teams. These users are frustrated by hollow certs and want to demonstrate nuanced, applied knowledge — especially as organizations increasingly demand proof of skill over paper credentials. The Elo-style ranking, confidence/timing signals, and domain mapping create a credible, LinkedIn-worthy skill profile that competitors like TryHackMe or Cybrary don’t offer. The free Security+ entry point is smart: it’s a high-volume, low-friction gateway to a much larger market of professionals who need ongoing skill assessment. The real opportunity lies in monetizing through enterprise licensing (team dashboards, hiring pipelines, upskilling tracks) and premium individual profiles. The wedge isn’t cert prep — it’s skill transparency. If SecProve can validate its ranking system with real-world hiring data (e.g., correlating scores with job performance or promotion rates), it becomes a trusted credentialing layer beyond certs. The biggest risk is perception: if users still see it as “another quiz app,” adoption stalls. But the architecture already avoids that trap. The differentiation is technical and psychological — not just content, but measurement.

Competition

qwen/qwen3.5-397b-a17b(fallback #2)

4.0

Adding meta-metrics like confidence and timing to multiple-choice questions is an incremental improvement, not a defensible disruption, in a market rapidly moving toward hands-on simulation.

The cybersecurity training market is saturated with incumbents who have already pivoted from rote memorization to adaptive, scenario-based learning. Key competitors include Boson (famous for deep, scenario-heavy SimOS exams that far exceed standard multiple-choice), Kaplan (Adaptive Technology that adjusts difficulty in real-time), and TryHackMe (which validates skills through hands-on browser-based labs rather than theory). SecProve's proposed differentiation—measuring speed, confidence, and using Elo-style ranking on multiple-choice questions—does not constitute a defensible moat. These are feature-level tweaks, not structural advantages. The core weakness is the medium: as long as the assessment relies on selecting text options, it remains vulnerable to the 'memorization game' the founder seeks to avoid. True skill signaling in cybersecurity increasingly demands proof of work via interactive labs or simulation, which requires significant infrastructure investment and content licensing that established players already possess. Furthermore, the 'free cert prep' wedge is a race to the bottom; incumbents can easily replicate free tiers or bundle them with existing subscriptions. Without proprietary data, exclusive industry partnerships for hiring, or a shift to interactive simulation, SecProve risks becoming a niche utility with high churn once the user passes their exam.

Synthesized by meta/llama-3.3-70b-instruct · 6.8s