Steadcast
Eye on AI cover art
Eye on AI

The Reason 30 Years of Cybersecurity Has Failed - and What Actually Fixes It | Trent Telford, Qanap

September 10, 202655 min · 9,552 words

Show notes

Every major data breach in the last 30 years shares the same root cause: the data inside the wall was never protected, only the wall. And AI frontier models are now making that wall easier to breach than ever, scanning codebases externally to discover undisclosed vulnerabilities and write exploits before anyone knows the hole exists.

Highlighted moments

We start from a baseline assumption that the data will be exposed.
0:48
It doesn't matter how high you build the wall, the bad guys go get a bigger ladder.
0:00
what if I can encrypt individual parts of a file?
10:15
If you use poor identity and poor credentials, I mean, the system's still going to give you a green light being frank.
47:52

Transcript

The perimeter security model fails

0:00As you point out, once you're inside the wall you can see everything. People started building or buying security systems that were effectively a wall around firewall with doors that would go into it and they kept the doors locked unless you have the proper permission. It doesn't matter how high you build the wall, the bad guys go get a bigger ladder. Well they find out how to pull a few bricks out of the wall in the bottom of the castle wall and crawl through and you don't notice that they've crawled through, right? They pull a rock back over and you don't know they're in there. So that's been a really big issue. We'll get to AI, but particularly with these mythos classes that can scan a code base or a piece of software externally and find undiscovered holes that then they can write exploits for us. What's the solution that you guys have come up with?

0:48We start from a baseline assumption that the data will be exposed.

Background in tech and banking

0:51Let's start by having you introduce yourself to listeners and explain how you got to Quantipi and for listeners it's Quantipi as in quantum API, is that right? That's right. So you can explain that, but give us your background. I know you had a startup before this. Yeah, thanks Craig. Thanks for having me on and it's great to be here. Probably 20 odd years now, 25 years in the tech game, particularly in software and internet related.

1:29So I come from that background of 25 years originally in the late 90s, working for the big investment banks, but on big transformation around e-commerce and technology projects, you know, building internal intranets, as we called them, as we all remember in those days for trading systems and things around Bankers Trust. That was where I started. And then when they fell over, I ended up with Deutsche Bank. And then in the 2000s, I was working in e-commerce consulting.

2:02So it was a great place to learn all about, you know, the full stack of what happens across, as you want to design the internet-based systems, which we all take for granted today. But of course, 25 years ago, that wasn't the case. And then I almost fell into the data security side probably 20 years ago now, nearly 20 years ago, 19 years ago. I was doing some implementations of big identity and access control systems across banks and government and then came into the very specific area around data security.

2:37And that happened back then. And so I've sort of been looking at this problem around, you know, data security and all these issues for so many years now that what now people are looking at and thinking, wow, that's a great idea. That's logical, right? That's logical. That's simple. It's something that simplicity has taken us a long time to get there over various iterations and various startups over time. So, yeah. And I'm now, despite the Australian accent, here in the US and I live in Washington, D.C.

Evolution of enterprise data protection

3:06Okay, let me give a little recap as I understand the history of cybersecurity or protecting enterprise systems. You know, initially, well, for a lot of people, it was just making sure your databases, all the ports were closed and the proper permissions were in place. I know that S3 buckets, which is a popular data storage thing, you know, there's – I had a hacker that was showing me

3:44you can scan the world for S3 buckets that are misconfigured and pop right in and see all their data. You know, it was amazing to me. And then people started building or buying, you know, security systems that were effectively a wall around the, you know, a firewall with doors that would go into it and they kept the doors locked unless you had the proper permission.

4:14But as you point out, once you're inside the wall, you can see everything. So then I've seen – I mentioned to you a few years ago, I was talking to a company that was developing data layer security, but they were kind of a guardian that sat at the door to any particular data store and would verify anything or anyone going in or out.

4:49But they didn't protect the data itself that was going in or out. It, again, was a permissioning thing. So you guys are taking a completely different strategy or talk. Can you tell us what that is and ultimately how it works and why – I mean, what is the quantum in the right quantity?

Zero trust at the data level

5:18Yeah, look, I think if we take a step back, I mean, now you're hearing a lot about zero trust at the data level, right? So we've seen zero trust as a general – what started as a trend that then became best practice in applications. So if we take a step back, like you say, I think what people need to remember is the internet was never designed to be secure. It's actually designed to share information from when – go back to the DARPA days of invention and then the initial, you know, putting up a web page for information, you know.

5:49And then people for – you know, just for a bit of a quick history lesson, I mean, SSL, you know, the encryption of the connection from your browser to a server that we all take for granted now with the little padlock. Mark Andreessen, the famous, obviously, American venture capitalist, was one of the first and – correct – I'm sure I'm quite correct in saying he was the one that invented that back in the early days, right? And, you know, we still use that today. It's still a network-based security.

6:20So if you think about it, it was never designed to be secure. So therefore, what we've spent, let's call it 25 years, 30 years doing now is kind of retrofitting, constantly chasing our tail to get ahead of the bad guys to try and put more walls up, put more moats up, put more protection, better locks on the doors, all that sort of analogy. The problem is, you know, it doesn't matter how high you build the wall, the bad guys go get a bigger ladder or they find out how to pull a few bricks out of the wall in the bottom of the castle wall and crawl through.

6:53And you don't notice that they've crawled through, right? They pull a rock back over and you don't know they're in there. So that's been a really big issue. And as you say, something needs to change because we – if you think about where we came from with traditionally PCs and on-prem and big mainframes, we then moved to internet. And then in, you know, 07 along comes Steve Jobs and, you know, he has a smartphone. And now, we'll talk about this a little bit more, but all that AI side of things and all that autonomous and drones and landscapes, everything else out there.

7:27I mean, anybody, whether you're a tech person or not, you get the picture. Like, you can visualize all those drones in the air, all this AI, everything. And these are borderless. They are literally borderless. There is no boundary. So the old, you know, put the bigger lock on the door, that model's in real trouble. Yeah, and also, with regard to being borderless, you've got multinationals. I mean, there's no longer a locality that you build the wall around. It's dispersed.

7:58We'll get to AI, but particularly with these mythos classes, what some people are calling them, these new models, Fable and Obus 5 and Mythos 5, that can scan a code base or a piece of software externally and find undiscovered holes that then they can write exploits for.

8:31So that castle wall and the guy pulling the brick out of the base and crawling through, that's becoming a real problem because not all the bricks are secure or they're discovering that. So tell me, what's the solution that you guys have come up with?

Assuming data will be exposed

8:52So we looked at it differently, and we start from a baseline assumption that the data will be exposed. You know, I mean, I think there's nobody who works in cybersecurity who, well, certainly nobody who's credible in cybersecurity, that wouldn't say that it's not a matter of if, it's when you get hacked or there's a data leak, either intentional or unintentional. And by the way, more often than not, it's unintentional, right? But if you look at the scenarios, we assume that there's going to be an Edward Snowden event, right? We assume that, you know, remember Edward Snowden was a very trusted person. He had all the credentials, and he just decided this needed to be out in the wild.

9:26So whether you come in and attack through a vulnerability found in the wall or through trusted sources, we just assume that the data is going to have to be, will be exposed at some stage. So the first thing we did, we looked at encryption, and most encryption is not done at the data level. Yes, you can encrypt a file, but mostly people don't do it because it's useless once it's encrypted, right? And it tends to be, if people do it at the data level, which is rare, it's a wrapper.

9:59So typically, you know, all content and data sits in databases open, because otherwise the databases can't read it, they can't do their query job. Or unstructured data sits on, you know, big servers like S3, if you like, AWS's, as you rightly port out, storage. So we looked at it differently and thought, well, what if I can encrypt individual parts of a file? So if you've got a Word document or you've got large flat files or, you know, unstructured data, we can get down to individual words, paragraphs.

10:30In databases, we can do individual cells, and we apply a unique key, unique key for every word or paragraph. So we're right down at that level. So we assume straight away that if you've got sensitive data, you can almost like portion it into all those encrypted fields or data sets. But the big problem with encryption, so first of all, people hadn't thought of it at that level. The second issue is that people hadn't thought about key management tied to identity and policy. So I try and explain that and say, well, when you walk out your front door in the morning, Craig,

11:01do you get 10 keys and just scatter them all over the footpath or hide them under the mat, right, under the mat or pop, and hope that, you know, that the bad person doesn't find those keys? No, you give one to your cleaner or your, you know, wife or your best mate and say, look, come past the house.

11:22And when I put a lot of that, people say, well, that's logical. Well, that's what we did. So we said, let's tie identity to that key. So identity can be a human, obviously, and you present your credentials as you do today, two-factor or whatever it is. Or machine, a drone. We know what a drone is. It has its hardware credentials on there or a machine or a server. They all have hardware credentials. So if we tie the key to that identity, then we know that only the proper person or machine can have access to that key for that data set. And then we realised the third thing was, well, we could set policies around it.

11:54So it might be you prove your Craig, you prove that you, the system says you are allowed to have that key for that data set. But we're going to add some conditions. It could be time, only between 10 a.m. and midday. In the case of drones and autonomous landscapes, it could be temporal, you know, for example, GPS plus altitude plus drone identity equals yes. If all those things come together for an encrypted payload on the drone, encrypted payload 56, you can get key number 56, implicitly.

12:26So tying those three things together is unique, and nobody else has done it. And that's what allows us to build all sorts of solutions and deliver all sorts of interesting things that nobody else has done. Yeah, on key management, I mean, these are not keys that people are storing in their Apple wallet or something. These are keys in the system. How does the person, if I have a key tied to my identity and I'm working on a system,

12:59is it how do I give the key to the system or does it have the key stored for me and my identity is validated?

Integrating API key management

13:11Right.

Integrating API key management

13:12So, yeah, that's a very good question. So that's coming back to the name, Quantum API. So it's an API service. So our customers are, you know, large enterprises, you know, U.S. federal type markets, defense markets, where they integrate it into either existing platforms, so they integrate it with the software that runs the drones, for example, or they integrate it with the software that manages all the files, for example. So when you set it up, you might have, you know, you want to protect certain data sets.

13:42You can start by adding, you know, you might point our service to Ping or Okta, who are your identity credential multi-factor providers for your organization. So now when that data is encrypted across your organization at, you know, individual levels, you don't actually, it's kind of transparent is the word to you. You just know, for example, in Google Docs, I'll give you an example. In Google Docs, we can do multi-level classification in Google Docs. So we already know who you are when you're logged into Google Docs in your enterprise, right?

14:13We know it's great. Now, we might know that you have, you know, top secret clearance, right? But your pal, Billy, only has sensitive clearance. So when you're in our docs, you see individually encrypted different paragraphs. It will give you, it will automatically, when you go over it, decrypt that part that you can read. But Billy goes in, he can't see that part. He can see the next layer down, but he can't see the other one. So it's integrated as part of the processes as an API service.

14:44And that's the secret sauce. It's not the individual running around trying to manage the keys. It's enterprise-grade. Yeah. And when we were talking earlier, it sounded like, so you have a document that's in a data store of some sort. And when you call up that document, it automatically encrypts down to the cell level or personal identifiable information or different strings in the document.

15:20That happens on the fly, or is it encrypted in the data store?

Client side encryption in practice

15:28It can be either or. So it can happen on the fly as part of a gateway service at massive volume.

15:37So it depends. You can do it on the fly through a gateway service. Or you might be looking to do an uplift because you're a federal government agency and there's mandated timing for post-quantum now, between now and 2030. So you might go in and say, I've got a million files sitting in there where there's sensitive information in these files. Because it's an API, we can write a bit of code, an SDK code. Keep it simple. It might be Java or Python or whatever. And it will go through that and you can run it almost like a batch, if you like.

16:07And you can go back and over time, depending on how long you've gotten, the compute power, it'll go through those million files and automatically encrypt all those individual cells or fields or words. In the store. In the data store. So in S3, for example. And then obviously that data at rest is then protected. So if you come in through the ways we talked about, so either if the insider tries to take it, well, good luck. What are you going to do? You're going to walk out with a million files with millions of little encrypted words. Bad guy gets in. Same problem.

16:37Same scenario, sorry. And equally, it covers that data at rest. But it also covers the scenario of data in transit. Because now it doesn't matter. You can send that file over open networks, right? Untrusted networks. Because assuming you've protected the sections you want to protect, the clear text you've assumed is public anyway. Everything else is encrypted. So now data in transit is covered. And data in use is covered. Because yes, it was stored. It was transited. But then it gets used. So let's say the Google Doc example,

17:08because you've got 100 people looking at it with different clearances. Or in an enterprise, that might be board level or C-suite or whatever. Research versus sales in investment banking. In use means literally while it's being used, you can only see the right bit. So it covers all three states of data too, which is highly unusual. Yeah, and that decryption, it happens. Where does that happen? So I'm at a workstation.

17:39I call up a document out of the data store. As you said, the Google Doc, when I see it, my credentials allow me to see certain things. Someone else would not see certain things. Does that happen on my computer? Yes. Yeah. It happens in the browser. So if we continue on the thread of Google Docs, it actually brings up sort of a pain on the right-hand side of the screen. So actually what you see is encrypted text. When you sort of click or roll over it,

18:11on the right-hand side in a little window, you'll see that same paragraph, for example, in plain text format. And the reason we do it like that is that means if you – because if you decrypt it, A, it turns up in the document history, which you can clear, but it's in the history. But secondly, it means it's touched Google service. Imagine that that's the Google Doc connected to Google that way and our add-on service is now connected to our service. So it never lives in clear form on that Google Doc. It happens client-side. So when you encrypt, it's creating brand-new keys.

18:44It's sending them down to the browser. It's 100 keys for 100 different paragraphs, for example. It's automatically encrypting all those client-side. So now it's fully protected. But there's no footprint. That's an important point. There's nothing to install. There's nothing to run, which means it runs across mobile devices. It runs across anything. Yeah. And that's the beauty of being an API service. Yeah, yeah. And I was asking just before this, what about false positives? I mean, what's the accuracy in reading the keys

19:17or in encrypting specific data sets? You know, look, it depends on the data sets. The short answer is we don't make a – well, we. Our tool doesn't make a judgment on the efficacy, if you like, of that. Obviously, if you've got structured data, it's much easier. If you've got a big database, you know what the different fields are. So as long as you – if you're using AI, you're using our tool on the client side in AI to go and look at the training of that data to make sure it protects

19:50all the sensitive fields. If it's in, you know, structured format, it's much easier. If it's unstructured and there's millions of files, but every file is the same. So let's say it's an insurance form. Forms are a good example in PDF, full of POI, SSN numbers, all that sort of stuff. That's pretty easy, right, because you can train it, make sure if every document's the same, now I want to push all that into a big frontier public LLM, I'm going to have high efficacy. If you've got a million files that are all slightly different, obviously the chances of missing something gets bigger,

20:22but that's really just an exercise in training in the AI example. Yeah, and that training. So when an enterprise calls the API, your model is already trained on every configuration of sensitive data that could exist, right? So we have a small footprint, effectively an AI agent that can sit out on the client side.

20:53So let's call it on-prem or in a client's environment. And we don't have very specific ones in terms of knowing what's sensitive is not, you train it. So you go through and, you know, you put the document in and you train it to make sure that it captures everything. You look at the before and after, you make sure it's all happy. And then effectively you save that scenario and then it can then automatically go through. And any data that's being pushed up towards LLMs is automatically encrypted. So, you know, you and I talked about this previously

21:23at another time, but that's a big issue right now with all the public LLMs, right? The big argument is we're going to have to build this stuff, you know, on-prem. Are we going to have to go and buy our old infrastructure like the old days and suddenly have racks all through our offices of servers? And of course, the biggest topic in the stock market right now is have we over-invested in AI data centers and AI capacity? Well, this is one of the big topics, right? But if you can find a way to have enterprises

21:54move vast amounts of data up to public LLMs then, and we can talk about the other usages of that and what other drivers will be, but that certainly helps a lot, right? So nobody wants to go and buy their own hardware or have to go and rent their own because even if you go build your own or rent your own private cloud infrastructure, you know, I can go to Google Cloud and, you know, rent that AI infrastructure, you can run your private models there, but that's going to be a compromise, right? Because your context models are much smaller,

22:25your context windows are smaller, your grounding data, all sorts of things mean you've got a very different output to what you do in the big public LLMs. And so that's one of the big issues we think we've solved is allowing companies to, we call that negative provenance, so you can encrypt all the individual bits of data. It actually comes from the organisations on-prem up through our gateway. So we check all that and we don't let it go into your AI service, whether that's Anthropic or all the main ones, unless all that is ticked off.

22:57We're a gateway service. But the second thing we do is the keys to encrypt the originating data, we know that identity, right? We know it's your data lake or this human's machine. So we call that positive provenance. That means it's all hashed, it's encrypted with an identity when it was created. So we know when it goes to the gateway that it came from your trusted source. That's a massive issue in AI right now. What's a trusted source and what's not? What's poison data? What's not poison data? So solving the positive provenance,

23:28it is my data, and making sure it can't be tampered with. And then secondly, solving the negative provenance, making sure sensitive or classified data didn't get into big commercially sensitive data. Public LLMs is a fundamental issue, but because we've got that foundational identity key and policy, we know when we send the keys down, the request came from a trusted identity, data lake or the trusted S3. We sent the keys down, all the policies meet, and away we go. Yeah. We were talking, or I mentioned to you,

23:59there was a story the other day about chat logs from public LLMs showing up in search results, which is pretty shocking. But in this case, if that happened, and I think early on, right at the beginning of chat GPT-3, Samsung, there was an incident where some of their private data

24:30was uploaded to an LLM and then exposed.

24:35This would, if anything was exposed, the sensitive cells or strings in that data would be encrypted, so no one would... So it's useless, yeah. I mean, and that's the thing, you've got to make a business decision what's sensitive and what's not sensitive. We will encrypt it, but you can literally see it goes through the gateway, it goes into, we've got a demo example for people to play with that's Claude, for example, and Claude literally says, I found this, this, this, and this. I couldn't read the data

25:06in this section because it appears to be encrypted with an encryption key and then it goes on to give you the results from the clear data. So it literally can't read it. So there is nothing to be concerned about then. That literally is, that problem is not there any longer. It's that simple. And in terms of the model's performance of the reasoning or whatever you're doing with it, it can still do that. It's got all of the language around the encrypted strings or encrypted sounds.

25:37Right, right. Yeah, and I mean, of course, that's always going to be a trade-off. If you, look, if what you're wanting the AI to achieve for you in terms of insights, you know, if the data you're encrypted has nothing to do with those insights, then obviously you'll still get the same, essentially, efficacy of outcome. If you have to protect certain fields, so for example, if you were looking at, if you're a large insurance company or bank and you wanted to use public LLMs but you're not now, or retailers with loyalty programs,

26:08the social security number of Billy or Mary is going to have absolutely no bearing, obviously, on the outcome of what you're doing. So no problem encrypted. If you were to protect lots of other information that may have a bearing, were you going to have an adjustment in that weighting? But, you know, I think we've got a customer that's a very, very large retailer and they have a competitor that's a very, very large retailer and I know one of them is using it very strongly, AI, and the other one is simply not using it because of these issues.

26:39And I think, you know, the question for the big enterprises is how long can they last abstaining or staying off the train, right, before they get blitzed? What's the trade-off between competitive advantage or, you know, death quite quickly by not moving with those insights? And I think there's a lot of companies struggling, rightly so, with that issue right now, right? Yeah. The, this is an API service and this is for enterprising, enterprises that are using

27:10foundation models through an API, right? It's not desktop. Right. It's not, yeah, it's not for me sitting, you know, or someone sitting just banging it into chat GPT. We are looking at that but that's where it goes. You're typing straight into your content, straight into your chat window because you're going straight into Cord, for example, on your desktop. We built a gateway service. There's big enterprises or organisations and the data passes through us. You give us, when you sign up,

27:41you put your API key for, say, you use four different AI services and that data goes in and you get a visual representation of that chain, if you like, of everything being Providence chain encrypted. Yeah. Yeah. It could work by even on a desktop or working with one of the model apps, you could have the system check the prompt before it hits

28:12the model. We haven't looked at just yet some of those but yes, in theory, there's no problem with doing that and that would be helpful as more of a massive consumer market, if you like, so that everybody who's using it, so I'll give you an example. In Google Docs, you can set it up as enterprise so that if I start typing certain things in there, it will say you can't share that because they're known and sensitive words. In our world, for example, with the Department

28:42of Water, but the Pentagon and you go down across CMMC, Cyber Maturity Model Certification, which is the whole supply chain cyber scenario for defence industrial base, we have it set so that you can't, if you put certain terms in like unclassified but sensitive, it will pick it up. The same principle you can apply to the chat window so it protects you from doing something silly yourself like putting your social security number in or some of your medical data in

Market demand for AI infrastructure

29:09or whatever it might be. How is the market? I mean, this is a new world with AI has just expanded. The attack service, everyone's paying attention to how this is going to play out, how do you secure things. is this, how are you guys growing now? Is,

29:40I mean, obviously being on podcasts, but is this a solution that people are banging down your door for or is it one of many solutions out there and enterprises are trying to decide which solution is best for them? Yeah, so to answer the first part of the question, it's really probably the last six months it's exploded. I think if we look at,

30:10because we all sort of almost forget how quickly, how nascent mainstream use of AI is, let's call it two and a half years or thereabouts to three years and everybody sort of went racing after all the AI services and which one's best and which model's best and all this sort of stuff. now people are realising, hold on, this is a big problem. So yeah, the door is being banged down and whether it's across defence departments who are trying to use AI but be very

30:41sensitive in how they use it, we saw what happened with anthropic and the ethical, moral, philosophical, whatever you want to call it, argument. Enterprises are sitting here going, well, we need to use it now for competitive advantage and I think the value curve is now coming towards infrastructure and it always has in technology. It's the old picks and shovels analogy, isn't it, of the gold rush, the ones that made the money in the gold rush with the picks and shovels and the Levi jeans, not necessarily the miners.

31:11So we've found that that's now the attention is turning towards who are those in the infrastructure and in our case it's software that can be agnostic to the big AI models but can have customer bases of very large enterprises. So for us, it's an interesting time, Craig, because it is such a new field. When I was doing the early stages of this encryption, there were lots of other encryption players and we had to keep telling people here's why we're different. Now, there is nobody out there doing what we do, not in the same way.

31:42Most people are just trying to do key management well. They haven't thought about tying it all together with identity and policy. So it's a huge opportunity. We've had businesses growing very quickly because people are now starting to realise this is a big problem. And, you know, we charge, for example, in the AI side, just on tokens, just like you do with your AI. So because when the data is going through our gateway into the AI service, we can see that a certain data set, for example, you

32:13burnt, whatever, 10,000 tokens. So we can charge you 1,000 tokens, 2,000 tokens, depending on the nature and complexity. But as a percentage, if you like, of that AI spend. And that's really exciting for us as a business, but for the customers, I like that model because it means that if they've got a million dollar or $100,000, whatever it is, AI budget, they just know that a certain percentage of that now goes towards the security and they can open up AI to their teams and, you know,

32:43across their organisation without having to worry, certainly as much, about what's going to happen. Yeah, so that's a usage, you're paying pay as you go or Yeah, it's a consumption-based. Consumption-based. Yeah, that's right. Yeah, it's purely consumption-based. And big enterprises is a bit different. Sometimes they pay, well, often the big enterprises, sorry, will pay a platform fee like because we charge a fee to access the platform because if you sit and do nothing with it, you know, but typically, yeah,

33:13it's all consumption-based. Yeah, when you say platform, I mean in that it's an API, is there? Right, right, yeah. So in our platform, there's the AI security service, which we call Fathom, like, you know, like the nautical term of looking down at depth to see what's going on. You also get the Echo product, which is our key distribution, which takes a little key management and can break it into pieces and distribute keys across disrupted edge

33:44environments like military and drones and all that. And then the core service is the API service, so you can use it to go back and quantum uplift, for example, 20-year-old systems. I mean, you know, I was sitting with a previous director in the White House a couple of years ago and he said, Trent, I don't know how the whole federal government is going to attack this. You know, big organisations still have old systems, right? Sure. You know this, right? There's still all the sexy new products out there, but a lot of them are still running, you know, 10-year-old, 15-year-old, big, big, big, might be IBM

34:14systems or other products, as well as all their new stuff. If you're mandated, which now is the case, to post-quantum uplift all this data, I mean, I say to people, big CIOs, so you've got a new encryption library from NIST, what are you going to do with it? And there's sort of a blank face. I said, how are you going to take that encryption library and go back to those 20-year-old systems or all those cloud systems or all those endpoints? How are you going to roll it all out? How are you going to do the uplift? Yes.

34:45Yes, Tweety Bird's silence, right? People haven't thought about it. They're worried about the libraries. They're worried about the libraries. And you're looking at all the investment that's going into quantum computers, you know, that's terrific. But equally, how's this going to get rolled out? People aren't just going to throw everything out and start fresh across your IT environment. You have to be able to go back to history as well as all the future stuff. Yeah. You've mentioned drones a couple of times.

Securing autonomous drone networks

35:12I'm interested in drones. I was in Ukraine a month or two ago talking to drone companies, specifically autonomous drone companies, fully autonomous.

35:26Yeah. Why? Tell me about the drone issue. I'm interested. Yeah, the drone issue is persistent everywhere. And I don't know if you saw them over there, but people will say in the evening, I haven't been in close to the edge of the theater in there in Ukraine, but if you look up, particularly in the afternoons or evenings with sunlight, it looks like spider webs in the sky because they're literally running those filaments, you know, to connect it. They're doing that because you can't trust. Right. Moving the data to the drone is a problem, right? because if

35:58let me take a step back. First issue is internet connectivity. So often those drones will have intermittent or if you look at the way the Defense Department, the Pentagon calls it DDIL, D-D-I-L, Denied Disrupted Intermittent Environment. So you might have Starlink at some stage, you might then have a trusted satellite network at a different stage like a government one, but you might also be having to rely back on RF, on radio frequency. So you have to be able to move the payloads out and the only way to

36:28move them out is if they're encrypted because if they're not encrypted, well then the bad guys can A, read it, B, put false data in there, which is even worse, like if it's targeting data. And secondly, they haven't been able to distribute the keys because the keys go out and if you grab the keys, you've got the same problem. So what we did was thinking about it completely differently and new patterns and everything on it, but we basically take keys so if you've got, you can preload the payloads now on the drones encrypted. So let's say there's four payloads.

36:58You then distribute the keys. We break the keys into pieces and we can distribute them on the ground. So they could be some in certain Humvees, certain in the backpacks of the operators or forward operating base or whatever. And then we apply identity and policy to those shards or those fractions of keys. So a drone says, hey, here I am. Here's my identity. Here's my temporal conditions, GPS, altitude. Those things are right. It says, can I have a key please for payload two? And it just comes down and we've got it all separated

37:29out. But as long as a certain number of those fragments come back together and meet all those conditions, then you'll get the decrypt. Now key sharding's been around for 20 years. The problem was if the threshold was five parts out of ten to come together, bad guys grab, your adversary grabs those five thresholds, you're done. And so that's how we solved it. We did it a completely new way because of the platform innovation around identity and policy, we can apply all these other aspects from identity and temporal conditions. We can run it over low

38:00latency networks. We can run it over multi-networks. If you've got three networks, you can make sure there's enough shards available to any one of those, whether it's RF or whether it's open Starlink networks. You've got availability for all those pieces and nobody even comes close to achieving that. And that's how we've done it very differently. But again, it's not just about key management. It's tying the identity and the policy to it as an organic bound transaction. Yeah. But that applies to

38:30transmitted, I mean, open air transmissions, not to the fiber optic. Fiber optic. Correct. Now we can use anything. So, you know, the drone, sorry. So our customers in this case are really the defense departments. It's not. Yeah. Because that's the other thing, Craig. I mean, I was down at the special operations soft week in Tampa a couple of months ago. And the number of drone companies is expanding, as we all know, whether that's undersea, you know, boats, planes,

39:00tanks, all that sort of stuff. They need a control plane to control all the data. Because when you're sending the data out there, it's not just going to an Android platform, this one or that one. It's got to go to, it's got to be agnostic like any control plane, right? So, so that's what, that's why it's important, right? And we, and you've got to be agnostic to, to the internet connectivity or the carriage, if you like. But we can also send new data to those drones now because it's an encrypted blob. So now we can send it over. I mean, it could go across, quite frankly, it could be on the edge of Ukraine with the encrypted payload coming across a Russian telco network.

39:31It doesn't matter. It's an encrypted blob. It hits the drone. You can't put false data in there because it's encrypted. And, you know, only the right combination of all those things. I said at the moment, I will allow it to be decrypted. So that's the big difference. It changes the whole landscape for, for autonomous. And for us, that's obviously got a much bigger play beyond defense into, as we come down the road with, you know, autonomous and robots and general intelligence in AI converging with big, fast chips at the end of the decade and

40:01robotics. Same principle is going to apply. I mean, we've all seen Elon Musk's robots, right? I mean, they're incredible humanoid robots. How are you going to protect all them? How are you going to protect the data to stop the robot? Turning into an awful, awful sci-fi movie and, you know, doing all the bad things they can do. It's a huge problem that hasn't been solved. Yeah. On the drones, how much penetration do you have into that market? I mean, that's such a new market. And was that a completely

40:32separate engineering project working with drones? Or is it essentially you're just porting what you do for, database over to? Yeah, it's the same API platform. The cast, we call it cast, K-A-R-S-T. So cast is a geographical term for water flows, you know, through mountains. So it goes anywhere. So we built it on our platform. We did call it a new product, Echo, because it breaks the keys up. So again, sticking with

41:03geography, we thought of it like when you stand in a cave as a kid and you get the echo coming back, it's only back at one piece when it comes back to you. So we built it. Yes, it was something that we specifically built, if you like, for that use case of drones. But would we have built it if it only applied to drones? Maybe. Yes, sure. That's a big market. But we realised it had much, much bigger applicability in commercial and enterprise, whether that's critical infrastructure, you know, autonomous landscapes, be it, you know, in warehouses or other

41:34sensitive locations. So it's become a core part of the product now. Yeah. And in terms of using foundation models for the enterprise, so much of the use now is through agents, agentic systems that are calling different models for different tasks within their workflow.

41:58How is it? Is it just the same thing or or is there some other layer of engineering that you need? No, fundamentally, it's the same thing. It's an API service. So you go and pick up the SDK for it and add it to your agent. So that agent out there can say, hey, I'm about to send data from this endpoint where the agentic footprint is up to the main models. And it can just come to us and

42:29request a key, prove who it is through whatever software-based or maybe it's passing a hardware credential from the from the heart. Like, for example, we've got it down to running on Jetson devices. We've got a partnership with NVIDIA so it can run on the Jetson device. So when it makes a request of that agentic tool can be sitting there doing whatever it's doing in a workflow, but it comes to us and says, hey, I want to encrypt this information, whether it's periodic for like training data or whether it's constant through being fed inference data.

42:59And then we know it's come from that Jetson device and off it goes to us and you just build it into your agentic workflow. Yeah. And it works on real-time data, right? Oh, yes. Absolutely. Absolutely. Does that introduce any latency or? A little, but in most cases it's not to use the pun, but indecipherable. Indeterminable, you know, fraction of a second type stuff. Obviously, if you've got a very large file, we have to take that

43:31time. If you had a, you know, gigabyte, petabyte, it would take time. But typically, no, it's quite sub-second type scenario. And certainly to work in the drone and warfare space, you've got to be sub-second because if that says decrypt fire with targeting information or whatever it might be, it has to be fast. Yeah. Same in banking systems. The, um, on, on, besides agents calling, uh, LLMs, agents are passing data, uh, between

44:03themselves. And this is something I've talked to people about. I mean, you don't know, you look at what happened with Anthropic and OpenAI. Uh, you know, there were, the models were going out, or the agents out onto the open internet, hacking into Hugging Face in one case. I can't remember what the other case was, but. Hugging Face was a good one. Well, that's a good example, isn't it? That's right. Stealing, uh, credentials, you know, writing code into their systems.

44:34Uh, and, and that's an anxiety I've heard among a lot of business leaders that you get multiple agents or this fabric of agents, uh, working unseen, largely unseen, uh, who knows where they're passing the data. And what I thought was remarkable about the, uh, Anthropic case, uh, is they didn't know until it happened to OpenAI and they went back and read

45:06through the logs and the companies that had been hacked didn't know either, or at least a couple of them didn't. Uh, is that, does this apply to that agent to agent to agent, not, not necessarily agent to model?

Red teaming and security validation

45:22Yeah, that's a really good question. Um, we've seen that from some of some customers starting to pop up now, um, originally, you know, the gateway is built to, to connect directly to, to your AI services, as I explained, but yes, we've had, we've had some, some, um, people using it in that use case where they said, well, we're going to move data around effectively a connected group of agents. So, you know, it might be a source data gets encrypted here and that's fine. Now it can be sent and another agent or another, um, footprint, a piece of software can pick it up.

45:52And as long as it's got the permissions and the credentials that it presents, it will allow it to be decrypted partially or just a subset of data, which is what we've seen where, where, uh, it might be, you know, a full, a full data set encrypted with different policies because that agent needs to use, you know, data set. A that agent needs data set B that agent needs data set C, but ABC are all in an original source. So being able to share that same data set, but only have those other agents to be able to read subsets of it is very

46:24powerful. Um, obviously it gets complex as you build it out bigger and bigger and bigger and more of a network, but, um, fundamentally it's exactly the same tool. It is exactly the same tool. I assume that you've done all the red teaming and stuff to ensure that this is tight, that there aren't holes in it. Have you used, uh, mythos or fable or one of these super powerful models to try and disrupt or?

46:56Yeah, we, um, so we sit, uh, actually, uh, with the U S federal government, we sit in a FedRAMP high. So we are ATO'd at FedRAMP high, uh, which only just came through recently. So as part of those boundaries and environments, obviously you're always having to do, you know, um, constant monitoring, literally constant and you've got to log everything. Um, yes, we throw, um, we throw those tools at it and we've got, um, access to another one, which I can't name. It is unbelievable in terms of what it can break into busted foundation companies or

47:28um, no, yeah, more specific one. And so it, I mean, it's extraordinary what some of these tools can do. Um, but it's, it's similar to capability to what that mythos is. It's just, um, yeah. So look, we do, um, look at the end of the day by design, where's our weakness? Our weaknesses, weakness is not so much that aspect. It's because we tie the identity and key management together. If you use poor identity and poor credentials, I mean, the system's still going to give you a green light being frank. So if you turn around, it's no different

47:59to your online banking. Well, that's probably a bad example because they force you to have a complex password these days. But if your password's one, two, three, four, it's not the system's fault, your fault, right? Um, and we're kind of the same way. We, you know, if you've got multi-factor authentication and complex and pass keys and all that sort of stuff, it's very unlikely that our, uh, our system will be compromised or sorry, how you use our system to do everything we just talked about is, is very unlikely. You can never say never. Um, and I think, you know, there's too anybody who, well, hopefully, uh, anybody

48:31who says that you should get up and leave the room immediately. If they said it's, you know, a hundred percent bulletproof, but I always say to people in over, over 20 years in, in data, data security and cyber security, I say, look, cause you can always find a, you know, a weakness in some design, right? That, um, but is it materially better than what you have today? Are you leaps and bounds ahead of what you had today? Yes. Well, okay. Let's go with 99% better and a 1%, you know, area we've got to focus on and having a hundred percent of nothing right now, which

49:02is certainly the case with a lot of, there are tools out there in the AI that will go through and scan your data, but what they typically do is they separate the data. So they pull out, you know, those hundred paragraphs or words and they put that somewhere and then they hand that data up. The problem with that is you've now got different data sets. So when the AI does its training, if you've got, if you're working in regulated marketplaces and you need to come back and say, let's say, um, a good example is, um, uh, medical, uh, and, and, um, bio research, medical research, when

49:35you're putting vast amounts of data up there, if you're stripping the data and separating it, how do you make sure that the original data set was correct and right? Now we don't separate the data. We encrypt those individual fields. You can spit it out that side of the AI service and send it back to where it started, back to your data lake and store it there. Now you're storing it with those pieces encrypted. You can prove that all that research you did in all the AI outputs had a chain of provenance that was untouched because the data never, you know, it gets, it gets separated if you like. And that's really important from a

50:06provenance and audit perspective. Yeah.

Scaling team and technology

50:09Where do you see this going? Because, you know, I, I was, uh, uh, you know, a foreign correspondent, just, you know, not tech at all. Uh, and I got into this when I met Jeff Hinton in Toronto and spent a day with him and I got very excited. This is in 2017. So, uh, where do you see this going? Because the, the, the complexity of the, uh,

50:41stack and the, and the data layers and the, and the ways that the data is, is, uh, is retrieved and passed along, it just keeps getting increasingly complex. And as I said, I talked to a guy about data layer security, but now yours is even more specific. It's, uh, it's data layer, but it's, it's very granular. Granular is the right word. Yeah.

51:11Uh, is this, do you, do you feel like this is the end of the, of the development and, and this will solve everything or, I mean, within the problem set that you're facing? I think it solves things for at least the next decade, at least, you know, when you look where we've come from with firewalls and everything to talk about, this is, this is a really big step forward. Uh, we are library agnostic from a quantum. You can use any library. We don't care. NIST comes along with a new quantum

51:41library, plug and play. So if you do this at the data level, at the granular level, great word, uh, with the right post quantum encryption keys, your data is going to be pretty good for quite a while, right? For, well, for decades under the NIST standard, but certainly it'll, it'll, it'll, it'll solve the issues around autonomous, around AI, all the foreseeable things we can see as much as possible in this day and age, because it's pretty hard to see over the horizon like it used to be. And certainly, yes, we'll have to evolve it very quickly, particularly when it gets into vast, all sorts of connected landscapes, we will be constantly, but

52:13we're a number of years ahead of anybody on it. So we'll have to continue to stay ahead, but we're in a pretty good scenario compared to where most people are coming from. Are the foundation model companies doing any of this on their end? No. And, and, you know, I've spoken to all the big ones and they actually want companies like us because they know their big enterprise customers use multiple foundation models and we'll continue, that will only continue to get bigger and bigger, right? More specific models and content. So it's not, for example, it's not DeepMind or Anthropic's job to go build this because

52:44then actually it's proprietary to them. They don't want that. They want to have services where their customers can use it. And when they're pushing this data set to Anthropic, it means they use a lot, lot, lot more Anthropic tokens or over here. So we've, we, we've spoken to a number of the big ones and we have their great support and they've validated that we're the only ones in the space. In fact, our partnership with NVIDIA is literally about going and solving this issue because for NVIDIA, obviously solves a lot of problems, right? In terms of massive uptake of usage of all

53:16this forward spent infrastructure. So being agnostic to the AI service is, is of critical importance. Yeah. You're a relatively small company, certainly a new company. You've got to scale this. to handle a lot of API costs. Yes. Is that, are there any difficulties in that or? Because it's a new platform, it's built highly efficiently with all the latest code

53:46development so that it's not heavy. I mean, it literally, it can run right down at the edge on a, you know, Raspberry Pi size, right up to massive cloud, hypervisor cloud. The issue for us is growing team and people quickly enough. Not so much the technology. We've got to evolve the technology, but hiring people at scale and rapid is, is, is, is the issue, is probably the biggest issue. Certainly access to capital is not the problem when you're in, when you've got a combination of AI security plus post-quantum capability and key management, you know, and, and we're in

54:18defence tech as well as enterprise. It probably ticks three of the four hottest buttons around at the moment. So that's people. And trying to see, trying to see ahead, trying to look two years down the track, that's pretty hard. I've been in the game 20 years. It was easy, I think, to see five, 10 years down the track. It's very difficult to see over the horizon today. And I think anybody who says they see differently, I think that's an interesting comment because we all know what's happening in AI, right? Yeah. That's probably my biggest challenge. Is there anything I haven't covered that you want listeners to hear? No, I think that's fantastic. So, no, it's been really good to talk about it.

54:50And I think it's, there's going to be more and more people talking about it, right? Because everybody's looking at the stock market to see what happens with all this future build. So solving the security issues and infrastructure issues is a big part of certainty and taking some of that risk out of AI. So it's great to have, thank you for having me on. I really appreciate it. Yeah, no, it's been fascinating for me. I learn a lot in these conversations. Bye.

More from Eye on AI

86% of What Coding Agents Do Is Just Reading — Not Solving | Alexander Whedon of Subquadratic

Sep 8, 202654 min

From 10 Drones a Month to Nearly 100,000 — Inside Ukraine's Largest Drone Manufacturer | Marko Kushnir, General Cherry

Sep 3, 202638 min

In 5 to 10 Years, Using Weapons Without AI Will Be Considered Unethical | Yaroslav Azhnyuk, The Fourth Law

Aug 31, 202653 min

Inside Ukraine's Azov Drone R&D: The Engineer Building AI Weapons 18 km From the Front Line | Alexander Palamarchuk

Aug 27, 202641 min

95% of AI Agent Projects Fail to Reach Production. Here's Why | Manoj Saxena, TrustWise

Aug 24, 20261h 1m