<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
    <channel>
        <title>Aaron Edwards</title>
        <link>https://uglyrobot.dev</link>
        <description>Aaron Edwards personal site</description>
        <lastBuildDate>Sat, 19 Sep 2026 00:07:14 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <image>
            <title>Aaron Edwards</title>
            <url>https://uglyrobot.dev/favicon.ico</url>
            <link>https://uglyrobot.dev</link>
        </image>
        <copyright>All rights reserved 2026</copyright>
        <item>
            <title><![CDATA[We finally hit $1M ARR in February]]></title>
            <link>https://uglyrobot.dev/articles/1m-arr</link>
            <guid>https://uglyrobot.dev/articles/1m-arr</guid>
            <pubDate>Mon, 02 Mar 2026 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img alt="DocsBot reached $1M ARR in February 2026" loading="lazy" width="1376" height="768" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ffeatured-1m-arr.b3adb84e.jpg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ffeatured-1m-arr.b3adb84e.jpg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ffeatured-1m-arr.b3adb84e.jpg&amp;w=3840&amp;q=75">
<p>We finally crossed $1M ARR in February.</p>
<p>I wish I could say we crushed the original plan. We didn't.</p>
<p>We expected to get here about four months earlier, but growth went flat through most of Q3 and Q4 in 2025. Not dead. Not dramatic. Just... flat. That stretch forced us to get more honest about what was working, what wasn't, and where we were still operating like an earlier-stage company.</p>
<h2>Why it took longer</h2>
<p>The biggest lever was pricing, but it took way longer than I expected.</p>
<p>We spent close to a year planning it, testing options, talking to customers, and trying not to break trust in the process. This wasn't a quick "raise prices and hope" move. We wanted pricing that actually matched the value customers were getting.</p>
<p>When we finally rolled it out, it worked. That change pushed us over the line.</p>
<h2>We grew up a bit</h2>
<p>The pricing shift mattered, but it only worked because other pieces improved at the same time.</p>
<p>We put real effort into onboarding. Setup is clearer now, time-to-value is faster, and people are getting to useful outcomes earlier. That has helped both activation and expansion.</p>
<p>We're also maturing as a team and as a business. Bringing in growth leadership changed a lot for us, and I wrote more about that in <a href="/articles/no-longer-a-solopreneur">No Longer a Solopreneur</a>.</p>
<h2>Moving upmarket on purpose</h2>
<p>We removed our consumer-level plan and focused more on qualified businesses.</p>
<p>At the same time, we added more value to Standard and Business so those plans are stronger for the customers we want to serve long term.</p>
<p>We also tightened our sales process for qualified accounts. Better qualification, better discovery, cleaner handoffs. Less noise, more focus.</p>
<h2>Agency partner program (early, but real)</h2>
<p>We're still early here, but the agency/implementer partner motion is starting to come together.</p>
<p>A big part of this is giving partners better controls. Per-bot RBAC is one of those features that sounds small until you're managing multiple clients and teams. Then it becomes table stakes.</p>
<p>There is still a lot to build, but this channel is already showing promise.</p>
<h2>2026 priorities</h2>
<p>$1M ARR is a milestone. It isn't the finish line.</p>
<p>This year we're trying to push harder and build more leverage across the company, including a fuller team of AI agents supporting internal operations.</p>
<p>Our first AI "employee" already changed how we run parts of marketing and documentation. That alone has saved time and removed a bunch of repetitive work.</p>
<p>Current focus areas:</p>
<ul>
<li>Sales systems for larger, better-fit accounts</li>
<li>Partnerships and agency growth</li>
<li>Hyper-personalization for key customer segments</li>
<li>Paid acquisition with tighter ICP targeting</li>
<li>Building authority in specific, high-intent niches</li>
</ul>
<p>Thanks to everyone who helped us get here. Customers, partners, team, friends, all of it.</p>
<p>We're just getting started.</p>
<p>-Aaron</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[My 1-Year SEO Journey: Lessons Learning Non-Technical SEO]]></title>
            <link>https://uglyrobot.dev/articles/1yr-seo-report</link>
            <guid>https://uglyrobot.dev/articles/1yr-seo-report</guid>
            <pubDate>Sat, 14 Sep 2024 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img alt="Overall SEO growth" loading="lazy" width="1280" height="527" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Foverall.3e3fae95.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Foverall.3e3fae95.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Foverall.3e3fae95.jpeg&amp;w=3840&amp;q=75">
<p>As a founder, non-technical SEO was a new challenge for me. This post is my honest buildinpublic 1-year summary since getting serious about it. I'll share what worked, what didn't, and what you should focus on for your sites.</p>
<h2>Content Marketing: A Mixed Bag</h2>
<img alt="Blog posts statistics" loading="lazy" width="1280" height="574" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fblog-posts.721d5ecd.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fblog-posts.721d5ecd.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fblog-posts.721d5ecd.jpeg&amp;w=3840&amp;q=75">
<p>My first step was integrating headless WordPress into my NextJS site and jumping into regular blogging. We published 90 posts this year, a mix of:</p>
<ul>
<li>New product updates</li>
<li>Relevant articles</li>
<li>Case studies</li>
<li>Tutorials</li>
</ul>
<p>Most posts were AI-written with varying levels of human editing. Quality varies in my opinion. The results? Mixed at best.</p>
<h3>What We Learned</h3>
<ul>
<li>We get some traffic to the blog, with occasional spikes for timely articles (e.g., OpenAI announcements).</li>
<li>Growth is stagnant despite our efforts.</li>
<li>Most traffic goes to a small subset of posts on highly technical/niche AI topics.</li>
<li>These visitors likely aren't our ideal customers.</li>
</ul>
<p><strong>My Take:</strong> Content marketing feels like a waste of time unless your product is super niche with low-competition keywords. The effort-to-reward ratio just isn't there for most businesses.</p>
<h2>Documentation: The Hidden SEO Goldmine</h2>
<img alt="Documentation SEO impact" loading="lazy" width="1280" height="571" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fdocumentation.0eb303d9.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fdocumentation.0eb303d9.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fdocumentation.0eb303d9.jpeg&amp;w=3840&amp;q=75">
<p>Documentation turned out to be one of our easiest SEO wins. Here's why:</p>
<ol>
<li>You have to write them anyway for your customers.</li>
<li>They're great for SEO.</li>
<li>Our DocsBot support chatbot crawls them daily, training itself to respond to customer questions.</li>
</ol>
<h3>Our Strategy</h3>
<ul>
<li>We regularly analyze which docs are ranking well.</li>
<li>We then optimize them further for keywords and add CTAs.</li>
<li>We use a dual approach for titles:<!-- -->
<ul>
<li>H1 headers are customer-focused</li>
<li>Meta titles are optimized for search clicks for potential customers</li>
</ul>
</li>
</ul>
<p><strong>Pro Tip:</strong> Don't neglect your documentation. It's a multi-purpose asset that can drive traffic, improve user experience, and even be a <a href="https://docsbot.ai">source to train an AI support bot</a>.</p>
<h2>Alternative Pages: Comparing Yourself to Competitors</h2>
<img alt="Alternative pages comparison" loading="lazy" width="1280" height="573" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Falternatives.6980fb9b.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Falternatives.6980fb9b.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Falternatives.6980fb9b.jpeg&amp;w=3840&amp;q=75">
<p>Creating "alternative" pages comparing your product to competitors is table stakes for any SaaS company. Here's our approach:</p>
<ol>
<li>We keep adding more competitor comparisons.</li>
<li>We use a consistent template but customize all content sections with the help of AI.</li>
<li>Each page features a comprehensive comparison table. This takes a lot of manual work to research, but it's worth it. And if you forget to keep it updated, it's not technically lying, right?</li>
</ol>
<h3>Benefits</h3>
<ul>
<li>While they can be hard to rank organically, they're excellent landing pages for Google PPC ads.</li>
<li>They train our AI retention agent to respond when someone is considering canceling to switch to a competitor.</li>
</ul>
<p><strong>Hack:</strong> Create an alternative page for your own product to capture users looking to switch away from you. Try to outrank your competitors' comparison pages, or even target it with PPC!</p>
<h2>Programmatic SEO: Scaling Content Creation</h2>
<img alt="Programmatic SEO results" loading="lazy" width="1280" height="572" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fprogrammatic.82f512ed.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fprogrammatic.82f512ed.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fprogrammatic.82f512ed.jpeg&amp;w=3840&amp;q=75">
<p>We experimented with programmatic SEO using:</p>
<ul>
<li>A custom script</li>
<li>Content template</li>
<li>Unsplash API for images</li>
<li>GPT-4 for writing with structured output json</li>
</ul>
<p>The result? 300 landing pages for various industries. The hardest part was reviewing the output from the AI and making sure it was not hallucinating features or functionality that we don't have. Took a lot of context, prompt tuning, and reviewing to get good outputs.</p>
<h3>Outcomes</h3>
<ul>
<li>Indexing took time (tip: launch gradually)</li>
<li>Most traffic goes to low-intent pages (e.g., "astrology chatbots")</li>
<li>1.7k clicks isn't bad for the effort involved</li>
</ul>
<p><strong>Next Steps:</strong> We plan to identify top-performing pages and add demo chatbots to enhance user engagement.</p>
<h2>Free Tools: The Tip I'm Scared to Share</h2>
<img alt="Free tools SEO impact" loading="lazy" width="1280" height="574" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ffree-tools.980d2298.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ffree-tools.980d2298.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ffree-tools.980d2298.jpeg&amp;w=3840&amp;q=75">
<p>Intent is everything in modern SEO. Our biggest win came from <a href="https://docsbot.ai/tools">creating free tools</a> for searchers that:</p>
<ol>
<li>Can't be instantly answered by AI (e.g., advanced calculators, checkers, converters)</li>
<li>Give users exactly what they want with no friction (e.g., no signup required)</li>
</ol>
<p>This approach has been a game-changer for our SEO strategy. Here's why it works so well:</p>
<ul>
<li><strong>High-Intent Traffic:</strong> We hit on several high-traffic, high-intent keywords, causing our traffic to explode.</li>
<li><strong>Developer-Friendly:</strong> As a developer, I can create multiple mini-products in a day, especially with AI coding tools like Cursor and GitHub Copilot.</li>
<li><strong>Quick Indexing:</strong> These tools are typically indexed within a week or two.</li>
<li><strong>Backlink Magnet:</strong> Useful tools naturally attract backlinks, more so than content. This potentially increases our Domain Authority (DA), helping other pages rank higher.</li>
<li><strong>Listing Sites:</strong> Launching these tools on Product Hunt, Hacker News, Reddit, etc. can generate additional backlinks from listing sites.</li>
</ul>
<p>However, there's always room for improvement:</p>
<ul>
<li>Some tools have low search volumes or need keyword optimization.</li>
<li>I should focus more on keyword research before building the tools, whoops.</li>
<li>We need to test new strategies to better convert these leads beyond a custom CTA. Example: Add to email series in exchange for more usage credits.</li>
</ul>
<h2>Looking Ahead</h2>
<p>SEO is an ever-evolving field, and what works today might not work tomorrow. However, focusing on user intent, providing genuine value, and leveraging your unique strengths (like development skills for free tools) can set you apart. That's what a year of hard SEO work at DocsBot has taught me anyway!</p>
<p>Remember, SEO is a marathon, not a sprint. Stay consistent, keep experimenting, and always prioritize providing value to your users.</p>
<p>P.S. If you're interested in training an AI chatbot for your business to handle customer support, team knowledge access, customer retention, RFP completion, custom copywriting, research, and more, check out <a href="https://docsbot.ai">DocsBot AI</a>.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[My Journey to $500K ARR: Lessons from Launching 8 Products in 6 Months]]></title>
            <link>https://uglyrobot.dev/articles/500k-mrr</link>
            <guid>https://uglyrobot.dev/articles/500k-mrr</guid>
            <pubDate>Tue, 02 Apr 2024 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img alt="A celebration of $500k arr" loading="lazy" width="1792" height="1024" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2F500k-mrr-wide.0633aed7.jpg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2F500k-mrr-wide.0633aed7.jpg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2F500k-mrr-wide.0633aed7.jpg&amp;w=3840&amp;q=75">
<p>It took many trials, errors, and relentless perseverance, but I just reached $500k Annual Recurring Revenue (ARR) from all my projects combined! This journey shows the power of resilience, strategic positioning, and the magic of being at the right place at the right time. This post aims to share insights and lessons learned from launching eight products in six months, highlighting the importance of not giving up, putting oneself out there, and positioning yourself to ride the big technology wave when it comes.</p>
<h2>The Struggle and the Breakthrough</h2>
<p>The road to success was anything but smooth. I first launched Infinite Uploads back in 2021 after a year of work with a cofounder. Growth has been slow to flat for multiple years, and I didn't have the time or desire to put what was needed into it. But when the latest AI excitement started and the technology became available to build with, I began building new products furiously. I did not want to miss out on this wave. I launched eight different products in a span of just six months, but most were unprofitable or barely broke even. This period was marked by uncertainty, experimentation, and a relentless search for that one product that would resonate with the market. The struggle wasn't just about creating something valuable; it was about finding a fit in a market that's constantly shifting, especially in the world artificial intelligence.</p>
<h3>Products That Didn't Quite Make It</h3>
<ol>
<li><strong><a href="https://infiniteuploads.com">Infinite Uploads</a></strong>: The first product I launched, a WP cloud storage SaaS, was a good learning experience but never gained significant traction. I <a href="https://uglyrobot.dev/articles/infinite-uploads-aquired">sold it in 2024</a> for about 3x ARR.</li>
<li><strong><a href="https://wordpress.org/plugins/imajinn-ai/">Imajinn AI WP Plugin</a></strong>: The first AI image generator for WordPress that went viral on Twitter but almost no-one paid for.</li>
<li><strong><a href="https://imajinn.ai/">Imajinn AI SaaS</a></strong>: The intent was to build a SaaS using newly available DreamBooth AI model custom training targeted at B2B. It was a good idea, but the tech was not ready, and the market was not there yet.</li>
<li><strong><a href="https://imajinn.ai/photobooth">Imajinn AI Photoboot</a></strong>: I slighly pivoted marketing to target the B2C market with AI avatars and one-time payments, and made about $9k from it but consumer excitement was short-lived.</li>
<li><strong><a href="https://imajinn.ai/sneakers">AI Sneaker Generator</a></strong>: A fun project that generated AI-designed sneakers. This was meant to be a lead magnet for Imajinn AI SaaS, and still brings in a lot of SEO traffic, but few conversions.</li>
<li><strong><a href="https://imajinn.ai/storybook">AI Children's Book</a></strong>: A fun project made with my wife and built on top of Imajinn AI SaaS, and my first try at ecommerce. Unfortunately, despite a lot of interest it's mostly only sold to friends and family. We did get featured in our local Dallas magazine and morning news TV show, which was fun.</li>
<li><strong><a href="https://imajinn.ai/product-visualizer">AI Product Photo Generator</a></strong>: A free project that makes product photos look amazing with AI backgrounds. This was meant to be a lead magnet for Imajinn AI SaaS, and still brings in a lot of SEO traffic, but few conversions.</li>
<li><strong><a href="https://imajinn.ai/portrait">AI Couples Portraits</a></strong>: A fun project that generates printed AI portraits of couples. I built this to try to go viral for Valentine's Day, but despite spending a month on TikTok marketing and ads, it didn't take off. I sold like 3 ever.</li>
<li><strong><a href="https://docsbot.ai">DocsBot AI</a></strong>: The breakthrough came with DocsBot in February 2023, an AI-powered chatbot creator with many use cases like customer support and internal knowledge access. DocsBot was the product that resonated with the B2B market, and it quickly gained traction. The product-market fit was strong, and the demand was evident. DocsBot became the cornerstone of UglyRobot, driving significant revenue growth and propelling me towards this $500K ARR milestone.</li>
</ol>
<h2>Making My Own Luck</h2>
<p>Success is often attributed to luck, but there's much more to it. It's about making sure you are in the right place at the right time. It's about creating opportunities and being prepared to seize them. For me, making my own luck meant not giving up despite the setbacks. It involved putting myself out there, connecting with potential users, gathering feedback, and iterating quickly. I have learned a little bit more each time launching a new product.</p>
<h3>Some Key Lessons Learned</h3>
<ul>
<li>Put yourself out there: Launching products is not just about building something great; it's about getting it in front of people. I learned the importance of marketing, community building, and networking to create buzz around my products. This was especially true for DocsBot, where I leveraged my network and connections to get the word out, and that eventually led to a viral tweet that brought in a lot of early customers.</li>
<li>Power of the MVP: The minimum viable product (MVP) approach was crucial in my journey. With each successive launch I became less and less of a perfectionist. I was also often able to addon to or resuse code from the previous one speeding up development. It allowed me to quickly test ideas, gather feedback, and iterate based on user responses. This iterative process helped me refine my products and find the right product-market fit. Still, even with DocsBot my MVP was too feature-rich. I could have been first to market with a simpler product. Instead I lost millions in marketshare to a competitor who launched a simpler product a few days before me.</li>
</ul>
<h2>Riding the AI Excitement Wave</h2>
<p>The timing couldn't have been better. The release of groundbreaking image and language models captured the world's attention, creating an unprecedented excitement around AI. By positioning DocsBot and my other projects within this wave, I was able to tap into a growing interest and demand for AI-powered solutions. Unfortunately most of the B2C products simply brought in waves of "AI tourists" who were not interested in paying for anything, just trying the shiny new toys. DocsBot's success was being able to capture the B2B market by providing actual ongoing value.</p>
<h2>Building a Solid Foundation</h2>
<p>Achieving this milestone is just the beginning. My next goal is to reach $1 million ARR. With a solid foundation now in place to build on, including systems, employees, and marketing flywheels, scaling up seems much more attainable. I still have a long way to go, but the journey so far has taught me valuable lessons that will compound and guide me in the next phase of growth.</p>
<img alt="A robot celebration of $500k arr" loading="lazy" width="1024" height="1024" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2F500k-mrr.daec15a8.webp&amp;w=1080&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2F500k-mrr.daec15a8.webp&amp;w=2048&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2F500k-mrr.daec15a8.webp&amp;w=2048&amp;q=75">
<h2>Looking Ahead</h2>
<p>As I look towards the future with an eye on the $1 million ARR goal, It's good to remember the lessons learned from those initial six months of product launches. As I continue on this journey, I remain committed to innovating, delivering value, and making my own luck every step of the way.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[I Used Codex for Our Annual SOC 2 Pentest]]></title>
            <link>https://uglyrobot.dev/articles/ai-soc2-pentest</link>
            <guid>https://uglyrobot.dev/articles/ai-soc2-pentest</guid>
            <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img alt="DocsBot SOC 2 Type II badge" loading="lazy" width="1200" height="675" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fsoc-2.e43553f9.jpeg&amp;w=1200&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fsoc-2.e43553f9.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fsoc-2.e43553f9.jpeg&amp;w=3840&amp;q=75">
<p>Our annual penetration test was due for <a href="https://docsbot.ai">DocsBot</a>. I <a href="https://x.com/uglyrobot/status/2070133703536197649">shared the first results on X</a>, but the full workflow deserves more than a post.</p>
<p>I <a href="/articles/soc2-certified-solo-founder">wrote about getting SOC 2 Type II certified</a> last year. Certification was the milestone. This is the less glamorous part that comes after it: doing the work again, improving it, and collecting evidence that the controls are still real.</p>
<p>The traditional path is to hire a vendor, give them a target, and wait for a black-box scan. That can be useful, especially when you need independent validation. It can also be expensive, shallow, and disconnected from the people who have to fix what it finds.</p>
<p>This year I tried a different starting point.</p>
<p>I used Codex to test the system from both sides:</p>
<ol>
<li>Source code first</li>
<li>Runtime behavior second</li>
<li>Auditor report last</li>
</ol>
<p>That order matters.</p>
<p>The entire scan used around 6–7 million tokens, ran for 6–7 hours, found 37 issues ranked by severity, and produced a 50-page vulnerability assessment and penetration testing report mapped to our SOC 2 controls.</p>
<p>Then I used agents to help fix and independently verify all 37 findings.</p>
<p>When I was CTO at WPMU DEV, a project like this could have taken one or two months. This took hours of machine time plus my review.</p>
<h2>Why start with the source code?</h2>
<p>A black-box tester sees what an outsider can see. That is valuable, but it also means the tester has to discover the shape of the application from the outside.</p>
<p>Codex could begin with the map.</p>
<p>I used its deep security scan workflow to inspect the full application surface across our repositories. Different agents could take different slices:</p>
<ul>
<li>API routes</li>
<li>Authentication boundaries</li>
<li>File uploads and downloads</li>
<li>Webhooks</li>
<li>Billing flows</li>
<li>Widget endpoints</li>
<li>Server-side request forgery surfaces</li>
<li>CORS and cookies</li>
<li>Secrets and permissions</li>
<li>Dependency risk</li>
<li>Tenant isolation</li>
</ul>
<p>This was not just grepping the codebase for scary strings and dumping everything into a report. The agents could trace a route, see how it was called, inspect the authorization checks, follow the data into storage, and compare the implementation with the intended security model.</p>
<p>The main agent then validated findings one by one.</p>
<p>That context makes a big difference. A suspicious pattern is not automatically exploitable. A route that looks protected in one file may be exposed by middleware somewhere else. A scanner can flag the pattern. An agent with repository context can investigate the path.</p>
<h2>Then test the real application</h2>
<p>Source review still leaves an important question: does production behave the way the code says it should?</p>
<p>After the repository scans, I had Codex test staging and production non-destructively. It checked the actual endpoints using the code analysis to decide what to probe.</p>
<p>The questions were practical:</p>
<ul>
<li>Can this route be reached without authentication?</li>
<li>Can one tenant access another tenant's object?</li>
<li>Do the live cookies and headers match the intended security model?</li>
<li>Do upload and download flows expose anything they should not?</li>
<li>Does runtime behavior match the assumptions we made while reading the source?</li>
</ul>
<p>That last question is where shallow audits often fall apart.</p>
<p>Code review can miss deployment configuration. Runtime scanning can miss the path that would make a strange behavior exploitable. Connecting the two gives you a much more useful answer:</p>
<p><strong>code → runtime behavior → exploitability → remediation → evidence</strong></p>
<h2>The economics were strange</h2>
<p>The scan consumed enough tokens to sound ridiculous: roughly 6–7 million.</p>
<p>If I had paid directly for all of them, I estimated the model cost at around $200–$500. In practice, it used a large part of my weekly Codex allowance plus one of the limit resets I had banked.</p>
<p>That is still dramatically cheaper than a typical external pentest.</p>
<p>Cost is only part of the story, though. The bigger advantage was continuity. The same system that found an issue could explain the code path, propose a fix, retest the exploit, check for regressions, and turn the result into evidence for the audit.</p>
<p>The output was not a scanner export somebody would ignore in a spreadsheet. It was an engineering queue.</p>
<h2>We fixed all 37 findings</h2>
<p>Finding issues is the easy part. The value comes from closing them without creating new ones.</p>
<p>For each issue, or related group of issues, Codex helped run the same pipeline:</p>
<ol>
<li>Create a separate worktree</li>
<li>Assign the fix to an agent in the correct repository</li>
<li>Keep the patch scoped to the finding</li>
<li>Hand it to a separate verifier agent</li>
<li>Have that verifier review the patch and test the exploit path</li>
<li>Iterate until it passed</li>
<li>Run our normal regression tests before merge</li>
<li>Finish with human review</li>
</ol>
<p>The important rule was simple: the agent that wrote the fix should not be the only agent that approved it.</p>
<p>Many fixes went through three or four layers of review: implementation agent, verifier agent, security reasoning pass, regression tests, then my merge review.</p>
<p>Find the issue. Prove it. Patch it. Verify it independently. Test for regressions. Merge.</p>
<p>That loop is much more interesting to me than "AI found 37 vulnerabilities." Finding a pile of possible problems is easy. Turning them into verified fixes is the work.</p>
<h2>What this does not prove</h2>
<p>I would not tell every company to cancel its independent pentest vendor tomorrow.</p>
<p>An external tester brings independence, specialized experience, and credibility that your own agent run does not automatically provide. Your auditor, customer contracts, cyber-insurance policy, or compliance scope may specifically require a qualified third party. AI can also share the same blind spots across scanning, fixing, and reporting if you do not deliberately separate those roles.</p>
<p>For us, this was an affordable, repeatable security review and a strong evidence package for our annual SOC 2 work. It let us go much deeper before deciding where outside validation adds the most value.</p>
<p>The safest use of this workflow is not "the AI says we're secure."</p>
<p>It is:</p>
<ul>
<li>Give the agent broad visibility into the authorized system</li>
<li>Keep runtime tests non-destructive and in scope</li>
<li>Separate implementation from verification</li>
<li>Require evidence for every finding</li>
<li>Keep a human responsible for the final decision</li>
<li>Bring in independent expertise where the risk or requirement calls for it</li>
</ul>
<h2>Coding agents are becoming security infrastructure</h2>
<p>I used to think of coding agents mainly as a way to write features faster.</p>
<p>This project changed that.</p>
<p>A capable agent can become part of a repeatable security review system: map every surface, test each assumption, verify the findings, fix the code, retest the exploit, and produce an auditor-ready record of what happened.</p>
<p>It does not remove responsibility. If anything, it makes the responsibility more explicit because the human has to define authorization, scope, evidence, and the standard for "fixed."</p>
<p>But it changes what a small team can afford to examine.</p>
<p>Our first SOC 2 effort proved that a lean company could build a serious compliance program. This year's pentest made me realize the ongoing security work can become much more continuous too.</p>
<p>Not a point-in-time scan that goes stale in a folder. A loop we can run again.</p>
<p>That might be the biggest security benefit of coding agents: not one magical audit, but making careful review cheap enough to repeat.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[I Asked Codex to Help Me Build a Robot for WordCamp US]]></title>
            <link>https://uglyrobot.dev/articles/building-a-shoulder-robot-with-codex</link>
            <guid>https://uglyrobot.dev/articles/building-a-shoulder-robot-with-codex</guid>
            <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img src="https://pbs.twimg.com/media/HO0GcJkXMAI1qa7.jpg?name=large" alt="Blender preview of the small robot I am building to wear on my shoulder" class="rounded-2xl">
<p>I'm building a little robot to wear on my shoulder at conferences. I <a href="https://x.com/uglyrobot/status/2084331165914112194">shared the first build thread on X</a>, but there is a lot more to the story.</p>
<p>The first public test will be WordCamp US in Phoenix. I plan to mount it with magnets, walk around the conference with it, and let people talk to a physical DocsBot AI voice agent.</p>
<p>It listens through a microphone, answers through a speaker, changes its animated expression while it talks, and moves its head to feel a little more alive.</p>
<p>I have no idea how to build a robot.</p>
<p>But AI does.</p>
<p>That is what made this project irresistible.</p>
<h2>From a description to a parts list</h2>
<p>I started by describing how I wanted the character to look and behave. Small enough to sit on a shoulder. Retro, friendly, and obviously a robot. A square screen for a face. A head that could turn. A voice people could hear in a noisy room. Expressive enough to feel like a character instead of a phone strapped to a costume.</p>
<p>Then I bought roughly $50 of parts from Amazon and asked Codex to build it with me.</p>
<p>The core is an ESP32-S3 board with a 1.54-inch, 240×240 color display. It already has useful robot parts packed onto it: Wi-Fi, Bluetooth, microphones, touch, and motion sensors. I added a small external speaker, motors for movement, a controller board, wiring, and the other pieces needed to make the head and body work.</p>
<p>Normally, every one of those choices would send me into a week of datasheets, electronics forums, and half-working tutorials. Instead, I could show Codex the exact parts and ask it to reason across the whole system.</p>
<p>Which pins can safely be used? How should power be split? Where does the capacitor go? How do I keep a motor from pulling the voltage down and resetting the screen? What dimensions need to be reserved in the printed body?</p>
<p>The agent did not make physics disappear. It made the unknowns navigable.</p>
<h2>Giving a square screen a personality</h2>
<p>The face came first because that is the part people will actually connect with.</p>
<p>We built 15 expressions and behaviors for the tiny screen: idle, blink, speaking, waiting, smile, confused, surprised, love, wink, angry, crazy, sleep, and looks to the left and right.</p>
<p>I got absurdly specific about the face.</p>
<p>The eyes needed to be slightly bigger. The mouth needed to move lower. Then there was too much space between them. The surprised eyes were too large. The wink needed a slight rotation. The mouth bars were too thin at the sides. Blinks needed to happen less often and finish faster.</p>
<p>These are not normal engineering requirements. They are taste.</p>
<p>Codex could keep translating that taste into coordinates, transitions, timing, and drawing code until the character felt right.</p>
<img src="https://pbs.twimg.com/media/HO0IITLXgAAYFxc.jpg?name=large" alt="The robot electronics, screen, printed body pieces, and wiring on my workbench" class="rounded-2xl">
<p>The expressions now run on the real electronics. Codex combined my early face and voice experiments into one program that can join Wi-Fi, listen to someone speak, call the DocsBot Voice API, answer through the speaker, animate its face, and control the moving parts.</p>
<p>Watching all 15 expressions come alive on the actual screen was a bit of a Frankenstein moment.</p>
<h2>Designing a body around parts I already bought</h2>
<p>The physical body had to wrap around reality.</p>
<p>The screen determined the head dimensions. Buttons and the charging cable needed openings. The speaker and motors needed mounts. Wires had to pass through the neck. The head needed enough clearance to move without colliding with the body.</p>
<p>OpenSCAD turned those measurements into printable parts. Because the design was code, Codex could change dimensions, regenerate the model, and reason about whether the electronics would fit.</p>
<p>It could also check the movement in simulation before I committed to a long print.</p>
<img src="https://pbs.twimg.com/media/HO0HFJGXYAAq-9M.jpg?name=large" alt="OpenSCAD views of the robot head designed around the screen and electronics" class="rounded-2xl">
<p>Then Blender MCP gave me polished previews of the model before printing.</p>
<p>That brought taste into the physical build loop too. I could see when the face border felt too heavy, when the proportions drifted, or when the feet looked like clown shoes.</p>
<p>At one point my entire design feedback to Codex was, "Your arms and legs suck."</p>
<p>It was accurate feedback.</p>
<p>The render made weak choices obvious before they became plastic. Codex updated the OpenSCAD model, Blender rendered the next version, and I judged it again.</p>
<h2>Then reality attacked</h2>
<p>Software people get spoiled by undo.</p>
<p>A bad code change can be reverted. A bad 3D print sits on the desk for hours, consuming filament while teaching you about tolerances.</p>
<p>My first prints quickly reminded me that a simulation is not a workbench. Supports fuse to parts. Holes shrink. Wires take up more space than their diagrams. Cheap motors have opinions. A USB-C cable that looks flexible online becomes a structural component when you try to bend it inside a tiny body.</p>
<img src="https://pbs.twimg.com/media/HO0H_mWWEAAkaeh.jpg?name=large" alt="An early robot part printing with failed supports and stringing" class="rounded-2xl">
<p>The body is ready to print, but it still needs its first complete assembly. Plastic tolerances and my assembly skills are the next boss battle.</p>
<p>Conveniently, the 3D printer doing this work is one I won at a previous WordCamp US. Now it is printing a robot to take back to WordCamp US. That feels appropriate.</p>
<h2>AI coding agents have reached my workbench</h2>
<p>The interesting part of this project is not that an AI wrote some embedded code.</p>
<p>It is that one agent could help across disciplines that used to be separate rabbit holes:</p>
<ul>
<li>Electronics and power</li>
<li>Embedded software</li>
<li>Wi-Fi and voice APIs</li>
<li>Character animation</li>
<li>Motor control</li>
<li>Parametric CAD</li>
<li>Physics and clearance checks</li>
<li>Blender renders</li>
<li>3D-print preparation</li>
<li>Debugging the assembled hardware</li>
</ul>
<p>I still make the decisions. I decide whether the face feels friendly, whether a part is ugly, whether the movement is worth the complexity, and whether I trust the wiring enough to plug it in.</p>
<p>But I no longer need years of experience in every tool before I can attempt the project.</p>
<p>That changes who gets to make physical things.</p>
<p>AI coding agents started by helping us move pixels around a browser. Now mine is helping move a robot's head on my desk.</p>
<h2>The deadline is a conference crowd</h2>
<p>The first job for this robot is simple: start conversations.</p>
<p>At WordCamp US, someone should be able to walk up, speak to it, and hear a DocsBot voice agent answer through a physical character sitting on my shoulder.</p>
<p>Codex got the face, voice, and movement working on the actual electronics. OpenSCAD produced the printable body. Blender helped me reject ugly choices before printing them.</p>
<p>Now the design has to become plastic, survive assembly, attach securely with magnets, and spend a conference day moving through a crowd.</p>
<p>I fully expect to leave Phoenix with a new bug list.</p>
<p>But even if an arm falls off, this project already proved something to me. The gap between "I have an idea for a robot" and "there is a talking face on my workbench" is much smaller than it used to be.</p>
<p>AI didn't just help me code faster.</p>
<p>It helped me build something I did not know how to build.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[The tiny DocsBot robot that started conversations for me]]></title>
            <link>https://uglyrobot.dev/articles/docsbot-robot</link>
            <guid>https://uglyrobot.dev/articles/docsbot-robot</guid>
            <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img alt="Aaron and a conference attendee wearing DocsBot Robot prototypes" loading="lazy" width="1024" height="768" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fhero.0b68b44c.jpeg&amp;w=1080&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fhero.0b68b44c.jpeg&amp;w=2048&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fhero.0b68b44c.jpeg&amp;w=2048&amp;q=75">
<p>I built a tiny robot for DocsBot and carried it around the conference floor.</p>
<p>It was a small, 3D-printed thing with a screen for a face, moving head and
arms, and a speaker inside its body. I expected people to notice it for a
second and then go back to whatever they were doing.</p>
<p>That wasn't what happened.</p>
<p>It felt like everyone loved it. Everyone wanted one. At one point I started
wondering if we should sell these instead of AI agents.</p>
<h2>It gave people an easy first question</h2>
<p>People would stop and ask what it was, whether it could talk, how the head
worked, and if they could build one. Those questions gave me a natural way to
explain DocsBot without opening with a pitch.</p>
<p>The robot did some of the social work for me. A physical object is easier to
approach than a person who looks like they are waiting for a sales
conversation. Once someone asked about the robot, we had something specific to
talk about.</p>
<img alt="Three assembled DocsBot Robots in different finishes" loading="lazy" width="1024" height="768" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Frobot-collection.bf8cafbf.jpeg&amp;w=1080&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Frobot-collection.bf8cafbf.jpeg&amp;w=2048&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Frobot-collection.bf8cafbf.jpeg&amp;w=2048&amp;q=75">
<h2>It was a conference guide with a face</h2>
<p>The robot was powered by DocsBot's voice AI agents. I trained it on the
conference information so people could talk to it and ask about upcoming
sessions, nearby restaurants, and the weather.</p>
<p>Those answers came from the same DocsBot building blocks we use elsewhere:
training sources, Skills, and Actions. The robot could listen through its
microphone, answer through the speaker, and animate its face while it talked.</p>
<p>That made the demo more useful than a prerecorded script. Someone could ask a
question about the place we were standing in and get an answer from a physical
DocsBot character.</p>
<h2>The build became part of the product story</h2>
<p>The robot is not a separate marketing prop. It runs DocsBot voice software on
an ESP32-S3, uses a small iPhone and Apple Watch remote, and has a body built
from printable parts. The face, voice, movement, wireless setup, and physical
assembly all had to work together.</p>
<p>That made the conversations more interesting. People could ask about the
software, then the hardware, then the process of putting the whole thing
together. I could show them the actual object instead of describing a future
prototype.</p>
<h2>We got more value without a booth</h2>
<p>We weren't sponsors and didn't have a booth. We still got more value out of
most of the booths because people already knew who we were. Everyone who had
any interest in DocsBot came over to talk.</p>
<p>I keep thinking about what that says about conference marketing. Doing a good
job and creating something high-quality still matter, but they don't guarantee
that anyone notices. The robot was cute, specific, and different from
everything else on the floor. It gave people a reason to come over.</p>
<p>At a conference, being memorable can matter more than having the most polished
thing in the room.</p>
<h2>I open-sourced the build</h2>
<p>The full project is now in the
<a href="https://github.com/uglyrobot/docsbot-robot"><code>uglyrobot/docsbot-robot</code></a> GitHub
repository.</p>
<p>It includes:</p>
<ul>
<li>ESP32-S3 firmware with credential-free Wi-Fi setup</li>
<li>The SwiftUI iPhone and Apple Watch remote</li>
<li>Current STL files and editable OpenSCAD sources</li>
<li>Assembly diagrams, print guidance, a parts list, and Amazon search links</li>
</ul>
<p>I removed private Wi-Fi and service configuration from the public code. The
repository also calls out the attribution requirements for the original
articulated limb toolkit.</p>
<h2>What I learned</h2>
<p>The best conference demos give people a reason to walk over before they know
what the product does. This robot made that happen over and over as I walked
around the floor.</p>
<p>If you want to build one, start with the
<a href="https://github.com/uglyrobot/docsbot-robot/blob/main/docs/parts-list.md">parts list</a>
and the <a href="https://github.com/uglyrobot/docsbot-robot/blob/main/docs/assembly.md">assembly guide</a>.
The project is open source, so you can print your own version, change the
colors, and make the robot your own.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[DocsBot Week: Founder Mode, No Sleep, and 20+ Features Later]]></title>
            <link>https://uglyrobot.dev/articles/docsbot-week</link>
            <guid>https://uglyrobot.dev/articles/docsbot-week</guid>
            <pubDate>Thu, 01 May 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>"Remind me to never do a DocsBot Week marketing campaign again."</p>
<p>That's how I feel sitting here, one day away from wrapping up what has been the most intense product sprint of my life. Twenty-plus new features launched. Fourteen detailed announcement posts. Nine emails. A live stream kickoff that got cut short by a thunderstorm and power outage. Daily bug fixes. Countless UX tweaks. And not much sleep.</p>
<h2>The Hardest Step</h2>
<p>Developers often think shipping means merging code. But the real step-the one that turns half-finished PRs into an actual product-is polishing. It's the part where you take raw functionality, add UX, define purpose, and wrap it all with clear messaging. You have to turn a feature into a useful product.</p>
<p>That step is slow and painful, and right now it's mine alone. As founder and product manager, I'm the bottleneck. Some of these features were started by our devs over a year ago. DocsBot Week forced me to finally finish them, test them, and ship them in a form that makes sense to real users.</p>
<img alt="DocsBot Week announcement" loading="lazy" width="1200" height="630" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fimage-5.119650c5.png&amp;w=1200&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fimage-5.119650c5.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fimage-5.119650c5.png&amp;w=3840&amp;q=75">
<h2>Founder Mode</h2>
<p>Every day was the same grind:</p>
<ul>
<li>Review old PRs, finish edge cases, fix bugs</li>
<li>Decide the user-facing purpose and messaging for each release</li>
<li>Work with our marketing team to build docs, posts, graphics, and emails</li>
<li>Push live updates while mopping up problems from the previous day's launch</li>
<li>Watch usage, collect feedback, tweak the UX, repeat</li>
</ul>
<p>It was a forcing function-one that finally turned dusty branches into polished features.</p>
<h2>The Marketing Machine</h2>
<p>Product alone doesn't move the needle. So in parallel, I had to direct the marketing engine: coordinating schedules, approving copy, lining up social posts, and making sure the story of DocsBot Week held together.</p>
<p>Fourteen announcement posts and nine emails later, we had a full narrative arc. Each feature release built into the next. The content team worked fast and hard, but the weight of aligning product and messaging still sat on me.</p>
<h2>Live Stream Chaos</h2>
<p>We kicked off DocsBot Week with a live stream. It was going well… until Texas weather decided otherwise. Thunderstorm. Power out. Stream dead. Founder lesson: live streams suck.</p>
<p>We still got the launches out, but it reminded me why async content is safer than betting on live events.</p>
<h2>Panic, Bugs, and Progress</h2>
<p>Every daily launch came with last-minute bugs and unexpected UX friction. Feedback rolled in immediately, and I scrambled to adjust. Some nights I'd patch and re-deploy three times before the new features felt usable.</p>
<p>It was messy. It was stressful. But by the end of each day, we had taken another step toward making DocsBot a better product.</p>
<h2>Looking Back</h2>
<p>DocsBot Week more than flashy announcements. It was a forcing function. It took a year's worth of half-finished work and compressed it into seven days of actual shipping.</p>
<p>The result:</p>
<ul>
<li>20+ new features live</li>
<li>14 announcements written</li>
<li>9 emails shipped</li>
<li>Hundreds of bug fixes and UX improvements</li>
<li>A team stretched, but stronger</li>
</ul>
<p>I don't want to run another week like this anytime soon. But it showed me what's possible when the deadline is immovable and the scope is brutal.</p>
<img alt="DocsBot Week feature summary" loading="lazy" width="1536" height="864" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fimage-13.ad6623e9.png&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fimage-13.ad6623e9.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fimage-13.ad6623e9.png&amp;w=3840&amp;q=75">
<h2>DocsBot Week is done.</h2>
<p>If you haven't yet, go <a href="https://docsbot.ai/article/docsbot-week-recap-the-ai-agent-era-has-officially-begun">check out the full list of what we shipped</a>. Better yet, subscribe and see how DocsBot can transform your customer support, team knowledge, and daily workflows.</p>
<p>I'll be sleeping for the next three days.</p>
<p>-Aaron</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[I sold Infinite Uploads!]]></title>
            <link>https://uglyrobot.dev/articles/infinite-uploads-aquired</link>
            <guid>https://uglyrobot.dev/articles/infinite-uploads-aquired</guid>
            <pubDate>Mon, 09 Dec 2024 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>I’m thrilled to share how I just sold <a href="https://infiniteuploads.com">Infinite Uploads</a>, the first SaaS product I built with my co-founder Joshua Dailey. This wasn’t an easy decision, but it was the right one to focus on my main business, <a href="https://docsbot.ai">DocsBot AI</a>. Here’s the full story.</p>
<img alt="Infinite Uploads Dashboard" loading="lazy" width="1280" height="850" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fiup-dashboard.10e64df5.png&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fiup-dashboard.10e64df5.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fiup-dashboard.10e64df5.png&amp;w=3840&amp;q=75">
<h3>Finding the Right Fit</h3>
<p>Infinite Uploads was born during the COVID lockdowns, built to provide WordPress users with an easy, unlimited cloud storage and CDN solution. While the product has great potential, my time has been consumed by other more successful products like <a href="https://docsbot.ai">DocsBot</a>, leaving little room to grow Infinite Uploads as it deserves.</p>
<p>So beginning of last year I started looking for a buyer. I wrote a detailed <a href="https://uglyrobot.dev/articles/selling-infinite-uploads">post</a> announcing my intentions, and made it brutally honest, sharing all the numbers and challenges. I wasn’t super aggressive about trying to get the best value possible out of it. Instead, I wanted to find the right fit and someone who would appreciate and grow Infinite Uploads. I really wanted it to be in the hands of someone who I knew would take care of it and help it come to fruition in an amazing way because I think the product has so much potential. It just wasn’t something I had the time to focus on.</p>
<p>I shared on Post Status Slack and Twitter/X with all the big WP players and got a few leads but nothing came of it. It was either too small for them or too expensive for the single developer buyers. Ultimately it was via my X followers that I found a buyer. I began discussions with Blake Whittle of ClikIT. I had some wavering on if I should sell, and he was very patient with me, but ultimately I decided to go for it. The main sticking point was he did not have the cash up front for my asking price.</p>
<p>At WordCamp US, I connected with Blake. After doing an escape room and hanging out, I walked him through everything, he made an offer, and shortly after, we signed a Letter of Intent (LOI). Now the first thing anyone always asks is, Oh, how much did you sell for? How much money did you make? And I always hate when they don't provide those numbers. So I will say that I did post my asking price on my <a href="https://uglyrobot.dev/articles/selling-infinite-uploads">original post</a>. And the offer was pretty close to my asking price (3x current flat ARR/net profit) but involved about a 40% down payment and a seller financing portion that would be paid out monthly over 3 years with no contingencies. After discussing with my wife, I signed the LOI, and Blake’s team began drafting the asset purchase agreement.</p>
<h3>Structuring the Deal</h3>
<p>Since Infinite Uploads is part of my holding company, UglyRobot LLC, we opted for an <strong>asset purchase</strong> rather than a full business sale. This included the code, IP, domains, customer base, social accounts, and other assets. The initial contract needed adjustments, including clear terms for payment delays or defaults on the financing. Tools like ChatGPT o1 helped flag potential issues and ensure clarity.</p>
<p>We also worked through IRS reporting requirements, which included preparing <strong>IRS Form 8594</strong> (Asset Acquisition Statement Under Section 1060). This form is required for both buyer and seller in an asset sale to allocate the purchase price among the sold assets. Allocating assets properly is critical, as it can significantly affect tax outcomes for both parties. For example:</p>
<ul>
<li>The <strong>buyer</strong> may need to capitalize certain parts of the purchase over years (e.g., goodwill or IP), which aren’t immediately deductible.</li>
<li>The <strong>seller</strong> may have parts of the sale taxed as ordinary income (e.g., software support contracts) versus capital gains (e.g., goodwill or IP).</li>
</ul>
<p>This often-overlooked step is a key part of the negotiation and can have long-term financial implications.</p>
<h3>Due Diligence and Documentation</h3>
<p>After finalizing the agreement, we set a closing date of <strong>November 25th</strong>. I created a shared Google Drive for a "data room" to upload all necessary due diligence files, including:</p>
<ul>
<li><strong>P&amp;Ls and financials</strong></li>
<li><strong>Recent invoices for costs</strong></li>
<li><strong>Stripe reports</strong></li>
<li><strong>Proof of ownership</strong></li>
<li><strong>Documentation on Big File Uploads acquisition</strong></li>
<li><strong>SOPs and updated code documentation</strong></li>
</ul>
<h3>Closing Day</h3>
<p>On November 25th, it all came together. Blake wired the down payment, and we skipped escrow to avoid hassle and costs, given our trust. We scheduled a live meeting with his team to transfer everything, including:</p>
<ul>
<li>Domains and DNS</li>
<li>Cloud accounts</li>
<li>Stripe account</li>
<li>Other key assets</li>
</ul>
<p>We encountered one minor DNS outage due to incomplete records in Cloudflare but resolved it quickly. A tip for future sellers: <strong>use separate accounts for your products</strong> to make ownership transfers smoother.</p>
<h3>Announcements and the Future</h3>
<p>The acquisition was announced by <a href="https://clikitnow.com/clikit-acquires-infinite-uploads-big-file-uploads/">ClikIT</a> and covered by <a href="https://wptavern.com/clikit-acquires-uglyrobots-infinite-uploads-and-big-file-uploads-plugins">WP Tavern</a>. It’s exciting to see the product getting attention and heading into its next phase of growth.</p>
<h3>Reflection</h3>
<p>Now that I’ve sold my first business, does this officially make me an entrepreneur? While it wasn’t life-changing money, I’m thrilled with the outcome. Blake and his team are passionate about Infinite Uploads, and I’m excited to see the product grow under their care. Customers will benefit from better support and updates, and I’ll get to focus more on my main projects.</p>
<p>Infinite Uploads is entering its next chapter, and I couldn’t be more optimistic about its future. 🚀</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[No Longer a Solopreneur]]></title>
            <link>https://uglyrobot.dev/articles/no-longer-a-solopreneur</link>
            <guid>https://uglyrobot.dev/articles/no-longer-a-solopreneur</guid>
            <pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<h2>No longer a solopreneur</h2>
<p>Being a solo founder sounds freeing. You imagine full control, clear vision, and the ability to move fast without slowing down to align with anyone else. The reality is much heavier. Vacations never felt like vacations—I was still checking in on campaigns, assigning tasks from hotel rooms, and holding everything together even while trying to unplug. When big decisions came up, there was no one who truly understood the weight or the context to bounce ideas off. I could lean on friends or advisors, but it was still my call, my responsibility, and my sleepless night if things went sideways.</p>
<p>At DocsBot, our "team" until now has been my son, who I've been mentoring in marketing and entrepreneurship, plus a trusted bench of long-term contract developers and admins. They are all invaluable, but I remained at the center of every decision. Every project eventually funneled through me for approval, prioritization, or execution. If something stalled, it was because I hadn't nudged it forward yet. That kind of bottleneck is brutal when you're trying to build a category-defining product.</p>
<p>That changes now. I'm excited to share that <a href="https://twitter.com/joshdailey">@joshdailey</a> is joining DocsBot as Chief Growth Officer, leaving WP Engine to join the future of customer support. Josh isn't just another hire; he's the person who can share the load, drive results, and own outcomes alongside me.</p>
<p>If you want to read more about the story behind this partnership, check out <a href="https://www.therepository.email/from-treehouses-to-tech-the-lifelong-friendship-behind-docsbot">"From Treehouses to Tech: The Lifelong Friendship Behind DocsBot"</a>, a feature in The Repository highlighting how Josh and I went from building treehouses as kids to scaling DocsBot together. The piece dives into our long-running collaboration, the early experiments that paved the way for DocsBot, and why now is the right moment for us to team up again.</p>
<h2>Why Josh?</h2>
<p>Josh and I have history. We co-founded Infinite Uploads together during COVID (now acquired), where we learned how each other operates under pressure and uncertainty. We shipped product, handled support fires, and navigated growth during the strangest business climate imaginable. We were in the trenches together, and I know I can trust him when things get messy.</p>
<p>This summer he worked part-time with DocsBot, digging deep into the product, the workflows, and the customer journey so we could both be sure this was the right next chapter. He talked with customers, watched onboarding calls, and immersed himself in our roadmap. By the time we started talking seriously about a full-time move, we both already knew he was the right person—it was just a question of timing.</p>
<p>A few weeks ago he and his wife came to visit. We sat on the swing in my backyard and mapped out the details that would make him a true partner in the business: profit share, phantom equity, clear goals, and mutual expectations. We talked through how we'd make decisions, what success looks like at each stage, and how we can keep each other accountable. By the time the sun went down we knew it was time to make it official.</p>
<h2>What changes for me</h2>
<p>For me, this is both a relief and a turning point. I finally have a trusted partner to lead growth—someone to challenge and run with ideas, carry real weight, and care about the outcome as much as I do. It means I can take a real vacation without packing my laptop out of fear. It means the backlog of marketing experiments, strategic partnerships, and customer education initiatives no longer lives solely in my head.</p>
<p>It also gives me space to return to what I love most: building, strategy, and product. I get to spend more time working closely with our engineers, sweating the details of our AI stack, and shaping the experience that our customers rave about. Having Josh own growth means I can go deeper on the craft of DocsBot without sacrificing the company's momentum.</p>
<h2>What changes for DocsBot</h2>
<p>For DocsBot, it's the start of a new chapter. Josh is already laying the groundwork for a growth engine that is systematic and scalable: better analytics, sharper positioning, tighter feedback loops between sales, success, and product. He has a knack for telling the story of why DocsBot matters in a way that connects with founders, support leaders, and operations teams alike.</p>
<p>The market for DocsBot is massive. We and our competitors have barely touched it. Today we already have customers ranging from banks in Venezuela and law firms in Saudi Arabia to massive Japanese tech firms and car washes in Texas. Every business needs an AI agent that brings instant, 24/7, multilingual knowledge access for their customers or their team. Our job is to introduce them to what DocsBot can do, and now we have the leadership in place to do it at scale.</p>
<p>I'm energized for this next season. With Josh leading growth, DocsBot is better positioned than ever to serve customers who want reliable AI support that actually understands their business. And on a personal level, I'm grateful to no longer be doing this alone.</p>
<p>Here's to building the future—with a partner.</p>
<p>-Aaron</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[Raising Prices: A Scary Decision That Paid Off]]></title>
            <link>https://uglyrobot.dev/articles/raising-prices</link>
            <guid>https://uglyrobot.dev/articles/raising-prices</guid>
            <pubDate>Wed, 10 Sep 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Three months ago, I pulled the trigger on something that had been sitting in the back of my mind for months: I raised prices for DocsBot.</p>
<img alt="DocsBot pricing plans" loading="lazy" width="2047" height="1565" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fpricing.69733f2b.png&amp;w=2048&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fpricing.69733f2b.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fpricing.69733f2b.png&amp;w=3840&amp;q=75">
<p>Not just a token increase either. I cut our lowest plan completely and bumped the price of our primary ICP plan by 50%. For a founder, it’s one of the scariest moves you can make. Your mind instantly goes to the worst‑case scenarios:</p>
<ul>
<li>What if customers leave in droves?</li>
<li>What if growth stalls?</li>
<li>What if we miscalculated the value our customers actually see?</li>
</ul>
<p>But I also knew that the lowest plan wasn’t serving our business or our customers well. It attracted the wrong profiles—ones that cost more in support than they delivered in value. Meanwhile, our ICP consistently told us that the tool was saving them thousands through AI‑powered customer service. So I decided it was time to test whether the pricing was truly aligned with the value we provide.</p>
<h2>The Results</h2>
<img alt="DocsBot metrics after the price change" loading="lazy" width="2048" height="1123" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fmetrics.a9dc368f.png&amp;w=2048&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fmetrics.a9dc368f.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fmetrics.a9dc368f.png&amp;w=3840&amp;q=75">
<p>Three months later, the numbers speak louder than any fear I had going in:</p>
<ul>
<li><strong>Active subscribers:</strong> –2.6%</li>
<li><strong>MRR:</strong> +12.5%</li>
<li><strong>Churn rate:</strong> –14.7%</li>
<li><strong>ARPU:</strong> +15.5%</li>
<li><strong>Customer lifetime value (cLTV):</strong> +35.4%</li>
</ul>
<p>Yes, subscriber count dipped. But MRR rose. Churn improved. ARPU jumped. And lifetime value surged — which changes the entire growth equation.</p>
<h2>The Grandfathering Strategy</h2>
<p>We chose not to force existing customers to the new pricing immediately. That shift will come next year. But something surprising happened: about 15% upgraded on their own.</p>
<p>Why? Feature gating. We started rolling out new features only to customers on the new plans. It wasn’t about punishing old users, but about rewarding the ones aligning with where the product is headed. The result: natural, voluntary upgrades without pressure.</p>
<p>Soon, we’ll launch an early upgrade campaign alongside more gated features that add real value, making the decision to switch even easier.</p>
<h2>Why It Worked</h2>
<p>The biggest lesson here: the right customers don’t balk at higher prices if the value equation is obvious.</p>
<p>Our ICP isn’t buying “software” — they’re buying outcomes. If a product saves them thousands, a 50% price bump barely registers. And by shedding misaligned customers, we can serve our best customers better.</p>
<p>The higher cLTV also opens a new lever: CAC. With stronger unit economics, we can confidently spend more to acquire even better customers, knowing they’ll stick around longer and return more value.</p>
<h2>My Takeaway</h2>
<p>Making the decision was far harder than living with the outcome.</p>
<p>Pricing is emotional for founders. It feels like you’re putting a price tag on your worth. But ultimately, it’s about alignment. When you line up pricing with the true value you deliver, everyone wins: customers get results, the business gets healthier, and you as a founder can grow without the constant fear of fragility.</p>
<p>This was one of the scariest steps I’ve taken with the business. And it turned out to be one of the most clarifying.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[Selling Infinite Uploads?]]></title>
            <link>https://uglyrobot.dev/articles/selling-infinite-uploads</link>
            <guid>https://uglyrobot.dev/articles/selling-infinite-uploads</guid>
            <pubDate>Thu, 22 Feb 2024 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p><strong>UPDATE: I <a href="https://uglyrobot.dev/articles/infinite-uploads-aquired">sold Infinite Uploads in November 2024!</a></strong></p>
<p>I believe the time has come. I've decided to consider the sale of <a href="https://infiniteuploads.com">Infinite Uploads</a>, a unique cloud storage &amp; CDN SaaS/WP plugin that integrates seamlessly with WordPress.</p>
<img alt="Infinite Uploads Dashboard" loading="lazy" width="1280" height="850" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fiup-dashboard.10e64df5.png&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fiup-dashboard.10e64df5.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fiup-dashboard.10e64df5.png&amp;w=3840&amp;q=75">
<p>Launched by me and my co-founder Joshua Dailey (now at WP Engine) in January 2021 after almost a year of building during the COVID-19 lockdown, Infinite Uploads was born out of a vision to enhance WordPress users' experience by providing a simple unlimited cloud storage and CDN solution. Despite its potential for high growth and the unique features it offers, including a robust video encoding and hosting service, the time commitment to my most successful product, <a href="https://docsbot.ai">DocsBot AI</a>, has led me to consider selling this venture.</p>
<h3>Builder not a Marketer</h3>
<p>It's been a remarkable journey since the inception of Infinite Uploads. I'm a builder and marketing is not my strength. Since the departure of my CMO co-founder over a year ago Infinite Uploads has just been on autopilot. This product has shown the potential to revolutionize how WordPress users manage their media content, and it pains me to see its potential wasted.</p>
<p>It could be a huge strategic opportunity for the right buyer to compliment their existing plugin suite or WordPress hosting service. The opportunity for significant expansion is undeniably there. I'm confident a simple dedicated marketing campaign or cross-promotion could rejuvenate its trajectory, pushing MRR far beyond $2,000.</p>
<img alt="Infinite Uploads SaaS Dashboard" loading="lazy" width="800" height="1002" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fstats.e7c1a50c.png&amp;w=828&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fstats.e7c1a50c.png&amp;w=1920&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fstats.e7c1a50c.png&amp;w=1920&amp;q=75">
<h3>A Unique Opportunity</h3>
<p>Infinite Uploads stands as a unique opportunity in the WordPress ecosystem. It's not just a plugin but a fully SaaS product with recurring revenue, a sizable opted-in email list of 6-7k, and a suite of features that set it apart, including:</p>
<h4><strong>Cloud Storage and CDN</strong></h4>
<ul>
<li>A seamless integration with WordPress, allowing users to upload and manage files directly from the WordPress dashboard.</li>
<li>Unlimited cloud storage and CDN solutions, with no file size limitations.</li>
</ul>
<h4><strong>Video Encoding/Hosting</strong></h4>
<ul>
<li>GDPR-compliant, cookieless video hosting with no ads, tracking, or banners.</li>
<li>A highly customizable player for branding, with no filesize limitations for uploads or storage right from the WP dashboard.</li>
<li>Advanced encoding for compatibility across devices, with variable bit rate HLS streaming for optimized bandwidth usage and faster video delivery, all served from a CDN.</li>
</ul>
<img alt="Video Upload block" loading="lazy" width="800" height="594" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fvideo-block.be00e91a.gif&amp;w=828&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fvideo-block.be00e91a.gif&amp;w=1920&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fvideo-block.be00e91a.gif&amp;w=1920&amp;q=75">
<h4><strong>Big File Uploads Plugin</strong></h4>
<p>The sale also will include the <a href="https://wordpress.org/plugins/tuxedo-big-file-uploads/">Big File Uploads</a> plugin with its outstanding 256+ five-star ratings and over 90,000 installs. We aquired this plugin in 2021 and it has been a great addition to the Infinite Uploads suite as a free lead generator and our main source of referrals and email subscriptions.</p>
<h4><strong>Assets</strong></h4>
<ul>
<li><a href="https://infiniteuploads.com">https://infiniteuploads.com</a> - site, code</li>
<li><a href="https://wordpress.org/plugins/infinite-uploads/">https://wordpress.org/plugins/infinite-uploads/</a> - Plugin and code</li>
<li><a href="https://wordpress.org/plugins/tuxedo-big-file-uploads/">https://wordpress.org/plugins/tuxedo-big-file-uploads/</a> - Plugin and code</li>
<li>Associated domains, certs, branding, Github repos, social media accounts, Stripe account, etc.</li>
<li>Email list of 6-7k</li>
</ul>
<h4><strong>Tech Stack</strong></h4>
<ul>
<li>WordPress plugins - PHP, JS (partially jQuery, partially React), Bootstrap</li>
<li>Website - WordPress website with custom plugin, Divi theme, SaaS API uses WP REST API</li>
<li>We provision and interface with an S3-compatible object storage service</li>
<li>Our CDN partner provides CDN services for storage, as well as the Video encoding and hosting and player</li>
<li>AWS Batch on demand for long running jobs and crons like collecting usage stats, deleting files from cloud storage, etc. Jobs are written in PHP, packaged/deployed into Docker image via script ($2/mo AWS bill)</li>
</ul>
<h4><strong>User Base and Revenue</strong></h4>
<img alt="Infinite Uploads MRR" loading="lazy" width="1688" height="918" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fmrr.792a45ac.png&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fmrr.792a45ac.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fmrr.792a45ac.png&amp;w=3840&amp;q=75">
<p>Here are some key stats, as of February 2024. Once we open discussions and I know you're serious, I can provide more detailed financials and access to the Stripe account.</p>
<ul>
<li><strong>$2k MRR</strong></li>
<li><strong>$22k TTM</strong></li>
<li><strong>94% Gross Margin</strong></li>
<li><strong>17% YoY MRR growth</strong></li>
<li><strong>8.1% Churn rate</strong></li>
<li><strong>45.5% Trial to paid conversion rate</strong></li>
</ul>
<p>All of these numbers are with me putting in about <strong>1-3 hours a month of support and no marketing.</strong></p>
<h3>Competitive Landscape</h3>
<p>Our main competitor is <a href="https://deliciousbrains.com/wp-offload-media/">WP Offload Media</a>, which is a great product with 50k installs of their free version, giving some insight into the potential market. But WP Offload has seen a period of neglect, especially after its acquisition by WP Engine, which was primarily interested in Advanced Custom Fields (ACF) rather than enhancing WP Offload itself. This situation presents a significant opportunity for Infinite Uploads to capitalize on the gaps left by our competitors.</p>
<p>Additionally WP Offload is a freemium plugin, not a SaaS. It requires creating and properly configuring separate cloud and CDN accounts, where Infinite Uploads is a one-click solution. It also doesn't offer video hosting or encoding. There are a few other cloud storage plugins but none that offer the video hosting and encoding features that Infinite Uploads does. This positions Infinite Uploads additionally against products like VideoPress (Automattic), PrestoPlayer, Vimeo, and Wistia.</p>
<h3>Valuation and Acquisition</h3>
<p>Given these strengths and the plugin's quick growth potential, I'm seeking a valuation of around $75k as an asset purchase, hoping for an acquisition that appreciates the unique position Infinite Uploads occupies and its potential for rapid scale. I'm open to discussing the terms and structure of the sale, including a short transition period to ensure a smooth handover and continued growth. I'm also very open to creative deal structures and strategic partnerships that allow me to maintain a stake in the product and participate in its future success.</p>
<h3>The Path Forward</h3>
<p>For those interested in a SaaS product with strong foundations, immediate revenue, and significant growth potential within the WordPress ecosystem, Infinite Uploads represents an unparalleled opportunity. It's a chance to own a product that not only enhances WordPress functionality but also opens new avenues for revenue and user engagement through its advanced video features and large user base.</p>
<p>As I shift my focus towards nurturing DocsBot, I am excited to see where Infinite Uploads can go in the hands of someone ready to unlock its full potential. It's a bittersweet decision, but one that aligns with my vision for the future and the strategic focus required to achieve it.</p>
<p>For inquiries or to express interest in this opportunity, feel free to reach out. Let's discuss how Infinite Uploads can embark on its next chapter under your guidance, continuing to serve and expand its loyal user base.</p>
<pre class="language-c"><code class="language-c"><span class="token keyword">if</span> <span class="token punctuation">(</span>interested_in_infinite_uploads<span class="token punctuation">)</span> <span class="token punctuation">{</span>
    <span class="token function">reach_out_for_a_discussion</span><span class="token punctuation">(</span><span class="token char">'<a href="/cdn-cgi/l/email-protection" class="__cf_email__" data-cfemail="325353405d5c7247555e4b405d505d461c515d5f">[email&nbsp;protected]</a>'</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
    <span class="token function">explore_the_potential_together</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span>
<span class="token punctuation">}</span>
</code></pre>
<p>I'm excited to see where this journey takes us. 🚀</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[Finally SOC 2 Certified as a Solo Founder]]></title>
            <link>https://uglyrobot.dev/articles/soc2-certified-solo-founder</link>
            <guid>https://uglyrobot.dev/articles/soc2-certified-solo-founder</guid>
            <pubDate>Fri, 03 Oct 2025 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<h2>Finally SOC 2 Certified as a Solo Founder</h2>
<p>I still remember where I was when I first thought: maybe SOC 2 isn’t just for big companies. I’d spent years pushing it aside — too costly, too vague, too “enterprise checkbox.” But this October, DocsBot is now SOC 2 Type II certified. You can see the announcement here: <a href="https://docsbot.ai/blog/docsbot-is-now-soc-2-type-ii-certified">DocsBot is Now SOC 2 Type II Certified</a>.</p>
<p>Here’s how we got there — the mistakes, the hacks, the surprises — from my POV.</p>
<img alt="SOC 2 badge" loading="lazy" width="1200" height="675" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fsoc-2.e43553f9.jpeg&amp;w=1200&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fsoc-2.e43553f9.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fsoc-2.e43553f9.jpeg&amp;w=3840&amp;q=75">
<hr>
<h2>The shadow of SOC 2</h2>
<p>For a long time, SOC 2 was something whispered about in venture circles or huge SaaS orgs. It sounded like a standard for the security-obsessed, not for a scrappy solo founder or indie hacker.</p>
<p>I understood it should be about security. But it came from CPAs, not builders. In practice, it reads like a laundry list of “controls” — suggested security best practices — and the audit is about showing you did those things over time. Some controls feel outdated. Others are pure theater: checkboxes that don’t meaningfully improve security. You can even “modify” or weaken them if your context justifies it.</p>
<p>So I postponed. For years.</p>
<p>When I pitched to bigger clients, some didn’t care about security frameworks. They just asked me to fill out a Vendor Security Assessment / Questionnaire (VSA / VQA). Others wanted SOC 2 or walked away. I lost deals over “no SOC 2” more than once. But the cost of doing it often seemed bigger than the value.</p>
<p>Then our sales pipeline started growing. We got interest from enterprise-grade prospects. It was time to stop treating SOC 2 as an “optional extra.”</p>
<hr>
<h2>Choosing a path: Sprinto vs OneLeet</h2>
<p>In my past life at WPMU DEV, I’d worked with Vanta. It’s polished but expensive and infamous for steep renewals. I didn’t want to get locked into that kind of surprise pricing.</p>
<p>I evaluated OneLeet (YC-founded, used by many early-stage startups) and Sprinto. OneLeet’s quote (after discounts) was around $6–8K/year. They said they’d hold prices flat for a few years. Reasonable, but still heavy on a lean budget.</p>
<p>Sprinto was cheaper ($4–6K). Less slick in UI and automations, sometimes quirky, likely managed from India. But their support approach is what sold me: whenever I hit a bump, they’d do a screenshare and walk me through the fix. That hands-on help is gold in compliance.</p>
<p>So I went with Sprinto.</p>
<hr>
<h2>Building from inside: roles, hacks, shortcuts</h2>
<p>I wanted to avoid reinventing the wheel doing stuff by myself. So I enlisted my college-age son (studying business) to own policy writing, vendor agreements, training, subprocessor docs. He’s detail-oriented; I handled the tech, architecture, monitoring, tooling.</p>
<p>Because our team is small (a few employees plus contractors), adoption was manageable:</p>
<ul>
<li>Everyone signed policies, did annual training, installed device monitoring.</li>
<li>Background checks: we had one new hire mid-process so I paid $29 for their check. For overseas or contractor roles, we set exclusions in policy where checks were unworkable.</li>
<li>Many controls default to “manual pen test.” That’s expensive. Rather than skip, I used Astra’s Pentest-as-a-Service (a few hundred dollars). Not perfect, but it gave me a report I could show in sales conversations and satisfy part of the requirement.</li>
</ul>
<p>Infra side:</p>
<ul>
<li>We rely heavily on IaaS (Vercel, Firebase). That means a lot of infrastructure security is outsourced.</li>
<li>I use GCP’s built-in security and monitoring tools, GitHub Dependabot, cloud logging, etc.</li>
<li>I’m the technical gatekeeper (I approve all code). That control is odd for SOC 2, which expects peer reviews. Instead of hacking out the control, I set up AI-based code review (OpenAI Codex + Cursor). I documented screenshots, the logic, the process. Auditor accepted it. Yes — AI reviewed my own code.</li>
</ul>
<img alt="DocsBot Trust center" loading="lazy" width="1200" height="675" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ftrust-center.29deb5b1.png&amp;w=1200&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ftrust-center.29deb5b1.png&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Ftrust-center.29deb5b1.png&amp;w=3840&amp;q=75">
<hr>
<h2>The timeline, audit, and surprises</h2>
<ul>
<li>March 2025: I started planning and asking around.</li>
<li>June: signed with Sprinto and kicked off.</li>
<li>By end-August: controls mostly in place.</li>
<li>To get Type II, you need at least a 90-day monitoring window.</li>
<li>I solicited two auditor quotes. One was a better communicator, simpler process, far cheaper. We ended up paying $1,200.</li>
<li>Audit began. Auditor got access to Sprinto, asked ~6 clarifying questions or asked for more screenshots, and within weeks finished the review. Because we had some controls in place earlier, they even backdated them.</li>
</ul>
<p>What I thought would drag to end of year finished early.</p>
<hr>
<h2>The moment of triumph</h2>
<p>When they told me “you’re certified,” I felt weirdly relieved. It wasn’t just validation. It was removing a barrier I’d loathed for years.</p>
<p>Now we’re live: DocsBot has a trust center (hosted by Sprinto), where clients can sign NDAs and access audit reports and security artifacts. You can read the official announcement here: <a href="https://docsbot.ai/blog/docsbot-is-now-soc-2-type-ii-certified">DocsBot is Now SOC 2 Type II Certified</a>.</p>
<p>Ongoing cost will probably settle around $5–6K/year (Sprinto + auditor renewal). That’s a price I’m comfortable paying for sales confidence.</p>
<hr>
<h2>Reflections (what worked, what I’d do differently)</h2>
<h3>What worked</h3>
<ul>
<li>Choosing a compliance partner who helps you instead of leaving you lost in checkboxes.</li>
<li>Delegating policy and paperwork to someone else (in my case, my son).</li>
<li>Using mid-tier hacks (Astra pentest, AI code review) to satisfy controls without going full “enterprise budget.”</li>
<li>Automating monitoring through platform tools (GCP, Dependabot, etc.) so less manual overhead.</li>
</ul>
<h3>What’s weird / still murky</h3>
<ul>
<li>Some controls feel like theater (you’ll do them because they’re on the list, not because they’re threat-driven).</li>
<li>You can argue or modify control severity in your context. The control framework isn’t absolute.</li>
<li>Auditors vary hugely in style and price. The right auditor can drastically reduce friction.</li>
<li>Renewal pricing is a gamble. That’s where many compliance platforms squeeze you.</li>
</ul>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[WordCamp US 2024: Connections, Insights, and a Dash of Fun]]></title>
            <link>https://uglyrobot.dev/articles/wcus-2024</link>
            <guid>https://uglyrobot.dev/articles/wcus-2024</guid>
            <pubDate>Mon, 23 Sep 2024 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img alt="Aaron at WCUS" loading="lazy" width="1216" height="832" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fwp-aaron.e2f02570.webp&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fwp-aaron.e2f02570.webp&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fwp-aaron.e2f02570.webp&amp;w=3840&amp;q=75">
<p>Just got back from <strong>WordCamp US (WCUS)</strong> last week, and wow, what an experience! My wife and I decided to make the trip together this year, and it turned out to be an incredible journey both personally and professionally. Overall, we spent about <strong>$1,450</strong> for the two of us to attend. We opted for a cheaper hotel a few blocks away from the main venue, which worked out great. Plus, we enjoyed free meals from all the after-parties and socials—can't beat that! We also snagged plane tickets on sale back in March, so planning ahead definitely paid off.</p>
<h2>Pre-Event Preparations</h2>
<p>Before the event, I wanted to make the most out of my time there. I booked around <strong>20 meetings</strong> ahead of time. How? I used an X post with a calendar link—<strong>TidyCal</strong> is a cheap lifetime deal from AppSumo that's been super handy. I also DMed many X connections and even ran a sub-$20 X ad targeting WordCamp keywords. This strategy helped me line up meetings with WordPress business owners, <strong>@docsbotai</strong> customers, YouTubers, podcasters—you name it.</p>
<h2>The Marathon of Meetings</h2>
<p>The first day was intense—back-to-back meetings that were pretty exhausting for an introvert like me. But it was worth it. I also had about <strong>10 impromptu meetings</strong> just by bumping into acquaintances from previous WordCamps, X followers, and floor introductions. The WordPress community is tight-knit, and it's amazing how many connections you can make in such a short time.</p>
<h3>Valuable (and Sometimes Painful) Feedback</h3>
<p>One of the highlights was getting valuable feedback on <strong>DocsBot</strong> from customers. Some of it was hard to hear but essential for improvement. I walked them through how to enhance AI support responses and expand usage across more products and use cases like pre-sales, retention, and copywriting. I also gathered a number of reviews and case studies that I can use for marketing. This face-to-face interaction is something you just can't replicate online.</p>
<h3>Networking and Potential Partnerships</h3>
<p>I had some exciting conversations about potential partnerships, including one with a big WordPress host that shall remain nameless ;-). Learned some influencer marketing tips from YouTube's <strong>craylormade</strong>, which was enlightening. I also asked many pointed questions about what marketing channels are working for fellow entrepreneurs and B2B sales. Probably will be able to book <strong>two or more podcast appearances</strong> from the connections this week.</p>
<h3>A Significant Milestone: LOI for Infinite Uploads</h3>
<p>I've been in talks for much of the year with someone interested in acquiring <strong>Infinite Uploads</strong>, my first WordPress SaaS. We even did an escape room together, which was a fun way to get to know each other better. Came away from the trip with a <strong>Letter of Intent (LOI)</strong>—we'll see how that works out, but it's a significant step forward.</p>
<h3>Personalized Gifts with a Twist</h3>
<p>I wanted to bring gifts but didn't want to do the usual swag. So, I trained a <strong>Flux AI model</strong> on their online images to generate fun pics of them in various styles, including their products and the WordPress logo. Printed them out to hand out—it was a great laugh and even got some shares on social media!</p>
<img alt="Katie Keith" loading="lazy" width="1280" height="1280" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fkatiekeith.a4a79720.jpeg&amp;w=1920&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fkatiekeith.a4a79720.jpeg&amp;w=3840&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fkatiekeith.a4a79720.jpeg&amp;w=3840&amp;q=75">
<h2>Fun Moments and Personal Connections</h2>
<p>Picked up my annual favorite shirts at the Gravity booth and chatted about my trademark struggles with Carl Hancock. it's amazing how just following each other on X opens doors—you feel like you know the person already. Got to wow <strong>Mark</strong>, the founder of WordFence, with a demo and talked AI. Love geeking out and building these relationships you could never achieve via cold outreach.</p>
<h2>Attending Sessions</h2>
<p>Believe it or not, I only went to <strong>three sessions</strong>:</p>
<ol>
<li><strong>WPAI</strong> to see what my fellow AI fanatic <strong>@jameslapage</strong> has been working on.</li>
<li><strong>Gravatar</strong> to support <strong>@ronnieburt</strong> with some well-planted questions.</li>
<li>The <strong>Brand</strong> session to get some unofficial legal advice on my trademark issues.</li>
</ol>
<p>Each was valuable in its own way, and I'm glad I chose quality over quantity when it came to sessions this year.</p>
<h2>Quality Time with Old Friends</h2>
<p>Hung out all week with some of my favorite old <strong>@wpmudev</strong> coworkers. Bought way too many shoes at the Nike store with my best bud <strong>Joshua Dailey</strong>. Also, I never want to see another <strong>Voodoo donut</strong> until maybe next year. It's these personal moments that make the trip memorable beyond just business.</p>
<img alt="WordCamp US 2024" loading="lazy" width="1024" height="768" decoding="async" data-nimg="1" style="color:transparent" srcset="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fwcus.fb4fb725.jpeg&amp;w=1080&amp;q=75 1x, /_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fwcus.fb4fb725.jpeg&amp;w=2048&amp;q=75 2x" src="/_next/image?url=%2F_next%2Fstatic%2Fmedia%2Fwcus.fb4fb725.jpeg&amp;w=2048&amp;q=75">
<h2>My Wife's Role and Support</h2>
<p>My wife got to learn and practice her <strong>DocsBot elevator pitch</strong> and was a great support throughout the event. She came away with a renewed interest in helping more with the business. I'm determined to turn her into the next great B2B AI influencer!</p>
<h2>The Takeaways</h2>
<p>Overall, WCUS was a <strong>huge success</strong>. I think it's a much better investment than sponsoring a small booth where you're stuck all week. If you can be super strategic with your time to connect as much as possible, the ROI is incredible. In-person connections are more valuable than months of work on social media; combine the two for some amazing synergy!</p>
<h3>For $1,450, I Came Away With:</h3>
<ol>
<li><strong>Probably 2+ big customers</strong> and likely much expansion revenue.</li>
<li><strong>Lots of feedback</strong> on my product to guide its development.</li>
<li>Potential <strong>influencer partnerships/affiliates</strong>.</li>
<li>At least <strong>two podcast bookings</strong>.</li>
<li>An <strong>LOI for the acquisition</strong> of my first SaaS!</li>
<li><strong>New marketing ideas</strong> to implement.</li>
<li>And lots of <strong>friends and ongoing connections</strong>.</li>
</ol>
<h2>Moving Forward</h2>
<p>Now, I just have to do better than last year at <strong>following up</strong>, <strong>closing deals</strong>, and <strong>keeping up the relationships</strong>! The real work begins after the event, and I'm excited to see where these new opportunities lead.</p>
<hr>
<p>Thanks for reading! If you attended WCUS, I'd love to hear about your experience. Feel free to reach out on X <a href="https://x.com/uglyrobot">@uglyrobot</a>.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
        <item>
            <title><![CDATA[After 15 Years in WordPress, I Didn't Use It for My Sister's Site]]></title>
            <link>https://uglyrobot.dev/articles/why-i-didnt-use-wordpress-for-my-sisters-site</link>
            <guid>https://uglyrobot.dev/articles/why-i-didnt-use-wordpress-for-my-sisters-site</guid>
            <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<img src="https://elisajohnston.com/assets/elisa-portrait.jpg" alt="Elisa Johnston, whose author and coaching website I built with Codex" class="rounded-2xl">
<p>My sister needed a website.</p>
<p>She had already bought a domain and WordPress hosting, which sounds like most of the job should have been done. Instead, she logged in and found around 50 plugins preinstalled, upgrade notices everywhere, and a dashboard that assumed she already knew what half of it meant.</p>
<p>She couldn't figure out how to build the site.</p>
<p>I've worked with WordPress for more than 15 years. I built plugins, helped grow WPMU DEV, and made a career out of solving WordPress problems. So naturally, she asked me for help.</p>
<p>I opened the setup and had an uncomfortable thought: I didn't want to build her site with WordPress either.</p>
<p>Ten minutes later, she had a fast static site running on Cloudflare Pages, built with a few prompts in Codex using the ChatGPT subscription she already paid for.</p>
<p><a href="https://elisajohnston.com">Here is the finished site.</a></p>
<h2>The problem was not WordPress itself</h2>
<p>WordPress can still build almost anything. That is both its strength and its problem.</p>
<p>My sister did not need almost anything. She needed an attractive home for her writing, speaking, coaching, books, and contact information. It needed to be fast, secure, inexpensive, and easy to update a few times a year.</p>
<p>The hosting company had given her a toolbox full of choices before she had made a single decision:</p>
<ul>
<li>Which theme?</li>
<li>Which page builder?</li>
<li>Which form plugin?</li>
<li>Which SEO plugin?</li>
<li>Which security plugin?</li>
<li>Which backup plugin?</li>
<li>Which of the 50 preinstalled plugins were useful, paid upgrades, or just clutter?</li>
</ul>
<p>That flexibility was not empowering her. It was transferring every product decision to her.</p>
<p>WordPress used to feel like the shortcut. For this job, it felt like the long way around.</p>
<h2>I gave the agent the whole job</h2>
<p>I didn't start by asking Codex to make a pretty homepage.</p>
<p>First, I gave it my sister's name and existing online presence and asked it to research her work. It collected the themes she writes and speaks about, the audiences she serves, her books and resources, and the way she already describes herself online.</p>
<p>Then it proposed the information architecture and content plan before writing code.</p>
<p>That ordering mattered. A website is not a pile of components. It is an argument about who someone is, what they do, and what a visitor should do next.</p>
<p>Once the plan looked right, Codex built the static site, connected the assets, and deployed it to Cloudflare Pages. No database. No plugin updates. No WordPress admin. Almost no attack surface.</p>
<p>The result was not merely "AI made a landing page." The useful part was that one agent could move from research to positioning to content to implementation to deployment without dropping the context between five different tools.</p>
<h2>The update experience changed too</h2>
<p>The biggest win is not that I built it in ten minutes. The biggest win is how she can maintain it.</p>
<p>When she wants to add a speaking event, change a paragraph, or publish a new resource, she does not have to remember where that setting lives. She can tell ChatGPT what she wants changed in normal language.</p>
<p>The implementation becomes a detail handled by the agent.</p>
<p>That is a completely different interface for owning a website. Instead of learning the tool's mental model, she can describe the outcome.</p>
<p>For a site that changes occasionally and does not need complex dynamic features, that feels much closer to the original promise of a website builder.</p>
<h2>The post hit a nerve</h2>
<p>When I <a href="https://x.com/uglyrobot/status/2041115125315223967">shared this on X</a>, the response was much bigger than I expected.</p>
<p>Some people saw it as evidence that WordPress had become too complicated. Others correctly pointed out that my sister had a hidden advantage: her brother knew how to choose Cloudflare Pages, set up the repository, review the output, connect the domain, and fix anything that broke.</p>
<p>One <a href="https://ronic.ai/blogs/the-duct-tape-era">essay responding to my post</a> called this the "duct-tape era" of AI website building. I think that criticism is fair.</p>
<p>My sister did not suddenly become a developer. She got a technical person to set up an agentic workflow for her. If the deployment breaks in a strange way, she is still probably calling me.</p>
<p>But that does not make the shift unimportant.</p>
<p>The amount of technical help required dropped from "build and maintain this website for me" to "set up a reliable path once, then let me request changes myself." That is a huge reduction in dependency, even if it is not zero.</p>
<h2>Why not WordPress?</h2>
<p>This is not my obituary for WordPress.</p>
<p>If my sister needed memberships, ecommerce, editorial workflows, a large plugin ecosystem, or a nontechnical agency that could take over tomorrow, WordPress might still be the right answer. It remains one of the most capable and transferable platforms on the web.</p>
<p>But capability is not the same thing as fit.</p>
<p>For a simple personal or small-business site, I now ask different questions:</p>
<ol>
<li>Does this need a database at all?</li>
<li>Will the owner actually use a visual admin interface?</li>
<li>Could an agent safely make the few changes they need?</li>
<li>Who owns the system when the agent gets stuck?</li>
<li>Are we choosing a platform for today's job or for every imaginary future job?</li>
</ol>
<p>For Elisa's site, a static build plus an AI coding agent was the simpler product.</p>
<p>That is the part I think the WordPress community should take seriously. The competition is not only Wix, Squarespace, Webflow, or another CMS. The new competition is a conversation that produces and maintains exactly the software someone needs.</p>
<p>The old question was, "Which website builder should I learn?"</p>
<p>The new question might be, "Why should I have to learn the builder at all?"</p>
<p>I spent a big part of my career helping WordPress democratize publishing. I still care deeply about that mission.</p>
<p>But on this project, the most democratic option was not teaching my sister another dashboard. It was letting her describe what she wanted and giving the agent the keys.</p>]]></content:encoded>
            <author>aaron@uglyrobot.com (Aaron Edwards)</author>
        </item>
    </channel>
</rss>