Episode 713 ·

Why Developers are the New Guardians of Data with Ariel Shiftan, CTO at Piiano

Today we’re talking to Ariel Shiftan, CTO at Piiano. We discuss how Piiano's platform works to encrypt sensitive data and centralize privacy controls, how Israel cultivates strong technology talent through direct communication norms, and Ariel’s award-winning AI project that combats malaria in Africa.

All of this right here, right now, on the Modern CTO Podcast! 

For more about Piiano, check out their website: https://www.piiano.com/

Have feedback about the show? Let us know here

Produced by ProSeries Media.

About Ariel Shiftan:

Ariel is the co-founder and CTO of Piiano, a data protection company. He is a software engineer and a security expert with more than 20 years of hands-on and executive leadership experience. Ariel holds a PhD degree in computer science from Bar-Ilan university. Prior to funding Piiano, Ariel led the deep learning breakthrough of a small team that won XPRIZE's AI for Impact competition for fighting malaria in Africa. Back in 2012, Ariel founded NorthBit, a turnkey software firm specializing in hardcore cybersecurity and low-level engineering solutions. NorthBit was later acquired by Magic Leap in 2016, becoming its product security division, where Ariel led the security life cycle globally, overseeing 700 engineers.

About Piiano:

Piiano offers infrastructure to safeguard data and ensure privacy compliance effortlessly. Gain immediate visibility into sensitive data (SSN, payment info, PII etc.) usage and privacy concerns within your source code using the Piiano Scanner. Store and use sensitive data securely, including SSN, BAN, ACH, PII, PCI, PHI, KYC, and more, in the Piiano Vault. With Piiano, organizations can achieve application-level security and compliance in a matter of days. Experience the power of Piiano and take control of your data protection journey.

Transcript

(Intro Narrator at 00:00:00) Today, we're talking to Ariel from Piiano about how developers are the new guardians of sensitive data. You're listening to Joel Beasley, Modern CTO.

(Joel Beasley at 00:00:14) So you founded a company, they got acquired by Magic Leap, or you went and worked with Magic Leap. You then were managing like 700 plus engineers, right? And then it looks like, then what did you do after that? Like I'm trying to create this mental map to better understand you.

(Ariel at 00:00:33) Yeah, sure. So first, yeah, that's the second company of me and my partner. The previous one was less like a startup kind of or product kind of company, but more like a services kind of company. So we helped many, many companies, including Fortune 500, just solving very complex engineering problems and even including cyber and security problems, but not only. And eventually we got acquired by Magic Leap to lead the whole product security operation. So we managed indirectly, like we oversaw 700, even 800 engineers doing software, hardware, and cloud, different methodologies. But what we needed to do back then is to make sure everything they build is built securely. So you need to make sure your processes are embedded into all these organizations to make sure you are overseeing everything. So we had our own team of 30 people, but we also like 700, 800. And then we were there like for three years or something like that. My partner left a bit earlier. I stayed a bit longer, but then we took time off. So he took the time off to do his stuff.

(Ariel at 00:01:38) What he likes to do is finding security vulnerabilities. So he found many of them in Windows kernel, and he got like a lot of money from that from Microsoft. And what I wanted to do, I wanted to do something good for humanity, just use the time for something that I will learn from, but also contribute something to the world. And this is where I helped another friend of mine to use AI, to leverage AI. Like what today everybody knows already, but back then it was a bit less well known, to leverage AI in order to help people in Africa to get away or reduce at least the damage being done by malaria. So I can talk a bit about that, but that's what I did back in the time being.

(Ariel at 00:02:20) And then we had COVID. And then during that time we say, "Hey, let's take what we learned in Magic Leap." And what we learned is that engineering, engineers or engineering teams, they lack the infrastructure to properly secure sensitive data. And we say, "Hey, let's build that infrastructure and let's make the life of the next people building new systems." So we have an existing system. So instead of them having to build it from scratch, let's give it to them off the shelf and they will easily integrate it and just be able to focus on their own stuff instead of protecting data. So that's maybe in a few sentences the story of how we got to today.

(Joel Beasley at 00:03:05) When Josh was telling me about the conversation and talking about how developers are the new guardians of data, right, that really caused me to think. And so I was digging deeper into what you guys were doing, because you're right. Because the developers are always using it and working with it and having to build with it, we have all sorts of strategies for anonymizing it or making it safe to work with in development environments and all of that. But there's never, at least in my experience, a point in time where the developers first become an expert on the privacy of data. It's almost, it's an afterthought.

(Joel Beasley at 00:03:45) And so when I saw that you were doing this, I said, "Well, that reminds me a lot of when I used to be really frustrated about payment processors and Stripe came along." And I was like, "Oh, finally I can just extract it. I don't have to really deal with it." And then there were some other subscription type management abstractions for billing, and I could just learn the language of interacting with those abstractions and go back to putting the systems together. I really enjoyed like business logic and solving specific problems. And so I didn't necessarily want to become an expert on data privacy. Then you have the other side of things where you get people, when the companies are big enough, where they have data privacy experts, and then it becomes this battle between engineering and the data privacy teams and all of that. So when I saw that you guys had an approach to solve this, like I want to know how are you doing it? Can you help me understand? I'm a software engineer for 17 years, and then I did the podcast. So I have a really good solid foundation historically of building those types of systems. But help me understand exactly what you guys do.

(Ariel at 00:04:51) Yeah. So what you mentioned, like Stripe, I think it's a very good example. They took the complexity of dealing with credit cards, okay, or dealing with billing, and they translated it into a simple set of APIs. So we basically did the very same thing, but for data protection. So data protection is, as you said, engineers, that's not what they are thinking about when they are building systems. That's maybe part of the problem. I'm not expecting them to be experts, but up until a couple of years ago, there was no reason for them to think about it, right? It wasn't in the news. It wasn't prioritized. There's many reasons for that. We will talk about it later. But the point is that today we are all seeing what's happening when they are not building it with privacy and security in mind, when systems are just built and then security and privacy are being integrated as afterthought, as you said. So we are all seeing it in the news every day, right? And the solution for that eventually is that it has to be done by design, because again, we are seeing what's happening when it's not the case.

(Ariel at 00:05:57) So what we did, we analyzed all the GDPR requirements, all the CCPA, all these many other regulations that developers, as you said, they don't care about. But we also brought our expertise in security. And actually we were, we are coming from both sides of defense and offense. So we took everything we knew, everything we learned in the last 20 years from the time we started our first steps in the cyber domain, even before it was called cyber, it was IT security back then. So we took all that background plus the new stuff, the new threats and techniques from security side, but again, also the new requirements and regulations.

(Ariel at 00:06:39) And we just built, we built an infrastructure that provides all of it with simple APIs. So it wasn't only our idea. I mean, we came up with that, but we also saw that very good and large companies like Netflix, like Google, JPMorgan Chase, and a few others, they build something like that internally. But the problem is that most companies, they don't have the resources to build that infrastructure for them like the very big companies are doing. And eventually they have to, at some point in time, just waste a lot of resources, a lot of engineers to develop a lot of it.

(Ariel at 00:07:17) So, and then as you said, it's not their expertise. So they don't really like to do it. Maybe they don't do it the best possible because they don't like to do it or because they are not experienced or because they don't have the knowledge. And they are wasting again, a lot, a lot of time and resources instead of focusing on building their own stuff, which is exactly what used to happen with billing, right, that you mentioned with Stripe. So eventually for you as an engineer, let's say that you are just collecting data. You're building some backend application. You collect data. So instead of thinking too much, you just get, you use our infrastructure, you get like two APIs: store data, get data. That's all.

(Ariel at 00:07:57) So instead of storing the sensitive data, the very sensitive data, wherever you store it today normally, like in many databases—

(Joel Beasley at 00:08:06) Yeah. Let's just say I would put it in Postgres, right? I got a table. There's 10 columns. One or two of them are sensitive. I'm somehow going to send those sensitive columns to you and have some sort of reference ID, right, in its place. And then when I need that information, I can use it right inside of the site.

(Ariel at 00:08:25) Yeah, exactly. That's one option. But normally, there is, what you described is a great example. Like maybe you use Postgres. Normally we see today so many types of database being used in the same system because it's very easy today and people prefer to use like microservices and each team prefers its own database. So the problem is even much more complex. There's so many copies of the data and that's part of the problem. And I can talk about it as well, but eventually, right, instead of just storing it as is in Postgres, so you use our API to encrypt it before you store it or to store it in our infrastructure. And in both cases, what you get out of it, so as a developer, you just need to call a single API before you store the data and call another single API when you fetch it back. But what you get from the other side of the system, from the side that controls everything, you get single place that can control all accesses to all sensitive data. And that system also solves all the security and privacy compliance requirements that, again, otherwise you need to build yourself. Does it make sense to you?

(Joel Beasley at 00:09:29) Yeah. Yeah. So rather than me having, let's say, let's give an example. Let's say we have three different application teams. Each team runs a different application at the company, and they all need some sort of PII, rather than that personal information being in three different databases, it's just going to be in one database. And then it's going to have a reference to those. So it's going to reduce your attack vector significantly.

(Ariel at 00:09:55) Right. Either it's really stored in the database or the other option is that it's encrypted and stored. It's still stored in the three databases, but encrypted with the key that is only available in that centralized location. But in both options, in both cases, eventually you get like centralized control over the data. And that centralized control allows you to really nail down or lock down the access of the data, but also comply with the needed privacy regulations.

(Joel Beasley at 00:10:21) That's kind of brilliant. How do you handle it with these newer types of technologies, like the ChatGPTs and the AIs? Are you even playing over there? Because I know they have different ways that the learnings happen and they store information and retrieve information.

(Ariel at 00:10:37) Mhmm. That's a very good question. Actually, we are seeing from our customers the challenge today when they try to adapt GPT or other types of AI APIs. And there's two points where the problem happens. One is if they want to use sensitive data they collected from their customers and they want to train the model to be better adapted to their own data and they want to benefit more from the data and to be able to provide more value to their customers. But if they use the APIs as is, they don't have the guarantees they need to make sure it's not utilized for training by those APIs or maybe just it's not protected enough there. So what we are providing them is some proxy that sits in between the caller, like in between their own applications to OpenAI, and that proxy knows to identify the critical pieces like the PII we mentioned earlier, the identifiers. So maybe other types of sensitive information, like think about social security number or email addresses or phone numbers or even names, and also to translate it into something non-sensitive. So that data is the one being eventually sent to the APIs. And then when the result comes back, we translate it back. So for you as a developer, it is transparent. The only thing you need to put is the proxy in between, but you just use the data normally and we make sure that it doesn't leak to those APIs.

(Joel Beasley at 00:12:01) That's pretty interesting. I'm just going to ask for some clarification there just because I'm kind of nerdy about it. So let's say that I'm running a GPT type service and the person, I don't prompt them for any sort of sensitive information, but they tell me sensitive information. They just put it right in the input. That input then hits your systems before it hits the model at my company and redacts everything? Or it just passes along metadata saying, "Hey, you're about to receive this input and these tokens amongst this input are sensitive"?

(Ariel at 00:12:38) No, it basically sits in between your backend to OpenAI API, for example, or any other LLM you're using, any other API, and it sits in between and just redacts the sensitive data. It replaces it with some non-sensitive data or synthetic data, and it translates it back on the way back from the API. So for you, it is transparent, but we make sure it doesn't leak to the APIs.

(Joel Beasley at 00:13:02) Okay. And it's early days. Like that sounds great as something to have today. Obviously, the use cases are going to get crazy more complicated. Big issues will happen in life, and then we'll come up with standards, and people will write books, and we'll figure out how to segment our systems. So because, you know, the dream of it is just to throw every piece of data I have at this artificially intelligent system for it to hold all of it in context in real time and be able to conversationally dispense valuable business insight to me. That's a beautiful dream. But being able to do that in a way, well, obviously, that system would not be client facing to any degree. But yeah, to be able to do that in a way that respects all the different, you know, like the GDPR and all the different requirements that you have, that's an important thing to consider.

(Ariel at 00:13:55) Right. Yeah. And what we are seeing and not only about GPT and AI, but also about many other use cases that maybe we'll talk later, like for example, data lake, okay, or data warehouse where companies, they use this infrastructure to collect everything they have and then try to get more value out of it, similar to what they're trying to do with AI today. So what we are seeing, and I have been talking the last two years with over 300 companies like people like either security or engineering leads. And what we are seeing eventually that people either they compromise on security and privacy of the data by just allowing everybody to access it, by sharing it with OpenAI, by sharing it with third parties. So that's maybe if they choose kind of that approach, "Hey, the value is more important. Let's do as much as we can to get more value." And that's life, right? Maybe privacy, security is second priority. So you want to provide better product, better value. You want to be more competitive. So either you do that. And the other option is that you compromise on innovation, you compromise on the value. If you prioritize security, if you prioritize privacy, if you avoid sharing the data, if you avoid allowing all your BI analysts to access the data warehouse, so you are losing something. So in both cases you are losing.

(Ariel at 00:15:07) And what we are saying is that if you work the right way, if you make sure that you are doing everything that you mentioned earlier, like if you're making sure that you are centralizing control over sensitive pieces and you're making sure that those are not leaking, that those are protected. And if you keep most of the data without it, without those identifiers, so by default, everything is much less sensitive. If you do that, then actually you can, it's a win-win. You can both win the security and privacy and the trust of your customer and reduce the potential damage in case of a breach and make sure you are not getting the fines and many other benefits of getting strong data protection architecture or infrastructure. And the other side, you can still benefit and provide the best value for your customers.

(Ariel at 00:15:55) So it's not that or that. There is a way to do it right. It's not as complex as it used to be because there are companies that build infrastructure, as I mentioned earlier, that solves it. And then there are companies like us and others that are providing that kind of infrastructure off the shelf. So only what you need to do as a developer is to make sure you are using the right tool.

(Ariel at 00:16:17) And if you use the right tool, you can make security team happy. So you don't need to have the fight with them that you mentioned earlier, like the tension between the security, the privacy teams with the engineers. They will be happy that you use such an infrastructure and you will be happy that you can get more value out of the data and you don't need to waste time in building a lot of the stuff that the security and privacy team is telling you to do.

(Joel Beasley at 00:16:39) Yeah. You're in a brilliant position because you completely nailed the spectrum of there are people out there that'll just say, ah, who cares? We need to be competitive, and we need to get to market fast, and we'll pay the fine or we'll deal with the publicity issue if it arises, but we can't just sit around and wait for all the nerds to tell us it's okay to flinch. Right? You've got that's one end of the spectrum.

(Joel Beasley at 00:17:01) I'm a nerd, so I'm one of those people. On the other end of the spectrum, you have the people that are just extremely cautious, are gonna wait for standards, aren't gonna do anything potentially. And then you've got what I would consider the 80% of the people who they know that they're going into a situation. They're gonna take their vitamins. Right?

(Joel Beasley at 00:17:19) They're like, hey, we know this isn't a cure-all, but we have to do something. We need some prudence. We need something to point to, some process that's not nothing. And I think that's a really good position to be in. Right?

(Joel Beasley at 00:17:34) Because you're able to serve the market that's saying, hey, you can serve the entire spectrum of the market, right, from where you're sitting. And that's actually a really good position. You can serve the most conservative individuals with their privacy policies and data protections, but you can also serve the people in the middle because they can just pick up your infrastructure and start using it right away.

(Ariel at 00:17:58) Exactly. It's like our solution, if we talk about that specifically, it's really self-serve and you don't need to take all of what it allows you to take from day one. You can start by just making sure, again, you just use the single API we mentioned earlier. Before you store sensitive data, make sure to call a single API and you already get 80 percentages of what you need to get in terms of making it much, much, much harder for the penetrators to try to get your data. And then over time, when you need more, when you are obligated to more and more regulations and requirements and you have a stronger maybe privacy team because the company is growing and you understand that you need to invest more on this. And we see in many cases companies going toward IPO.

(Ariel at 00:18:41) Hey, now we have to fix everything, right? But then if you start that the right way, it is much, much, much easier for you just to grow up, right, to consume more of what those infrastructure allows you. So you can do it granularly. That's what I'm trying to say. And that's exactly the way we see it.

(Ariel at 00:19:00) Yeah.

(Joel Beasley at 00:19:01) How do I sell this to my team? So let's say I run a team or two teams or three teams of engineers, and I have to sell this idea that, hey, we're gonna take a cycle. And instead of building the next feature the customer wants, we're gonna go protect some of our data to reduce our attack vector. How do you sell that to your team or is that not your customers? Do your customers look different?

(Ariel at 00:19:25) Yeah. It's a good question. Most of our customers eventually today are coming from healthcare, FinTech, and other areas where there is a lot of sensitive data, and there it is a bit either more regulated or there is a lot more trust, like interest. Fintech companies, they have to gain the trust of their customers. So they understand they need to protect the data.

(Ariel at 00:19:49) But we are starting to see the shifts of the adoption to more and more companies because the world today is not where it was five years ago. Today, the demand is coming from the customers. Today, the threats landscape is much more complex. Today, the systems are much more complex. Today, the regulations are much stricter.

(Ariel at 00:20:08) So many things change in the last couple of years. So more and more companies understand they need to invest in that. Once there is understanding in the team that you have to do something, this is where you actually prefer to take something off the shelf because instead of building and spending many, many cycles of development that you mentioned of fixing it yourself. What we are allowing you is exactly like you mentioned Stripe in the beginning of the talk, we are just giving you a simple API. So once you understand you need to do something about it,

(Ariel at 00:20:39) that's where it's very easy to convince your team, right? Once the security team, for example, or the privacy team give you the list of requirements, or maybe you as VP R&D or lead architect, you understand that you have to do something about it. So exactly in this point, we come and tell you, hey. You understand that you need to do something about it, but of course you don't want to build it, right? Nobody want to build security and privacy infrastructure, maybe except us, right?

(Ariel at 00:21:04) That's what we like to do, but nobody else really want to do it. So we are, again, just giving you simple APIs, and you can use it, make everybody happy, and move forward with what you really need or want to build.

(Joel Beasley at 00:21:16) And when you've got these, let's focus on the industries that are already comfortable with the sensitive data that they know that they need to solve this problem. They know that they need to be working to improve, like healthcare and fintech, as you mentioned. For them, there's obviously several different options that they have. Right? They could do the stupid thing of building it themselves.

(Joel Beasley at 00:21:39) I'm just kidding. It might not be stupid. But they could build it themselves. They could use other tools. They could use your tool.

(Joel Beasley at 00:21:46) What is it about your tool that is competitive advantage?

(Ariel at 00:21:52) Yeah. So building yourself indeed is an option. And, actually, maybe the main competitor that we see today is companies that build it themselves. The reason, I guess, is that there was no such an infra until recently. Okay.

(Ariel at 00:22:04) We are young and even the few competitors we have are pretty much young. So the main competitor today really is do it yourself. I believe today, it's not something companies should really do. Right? Especially where there is already solutions out there like ourselves.

(Ariel at 00:22:19) What's unique about us, I think, is that we built it with the developers in mind. We built it to be the simplest we could for the developers to adopt. And we, for example, allow them to get with the single command line, Docker run command on their own desktop. They can get the whole solution running on their own desktop locally. They can test with it.

(Ariel at 00:22:41) They can play with it. They can use it for CI/CD for free. We are not charging for that. Our solution is eventually provided as a very simple container that can be deployed anywhere. So even in production, if you want, you can deploy it within your own architecture.

(Ariel at 00:22:54) You can deploy it on-prem. You can deploy it on any cloud provider. We provide all kind of types of integration like Kubernetes and ECS and Cloud Run and serverless, not serverless. And so that's, I think, what's unique about us. We also provide the fully hosted solution like maybe our competitors do, but we are much more flexible in that.

(Ariel at 00:23:18) So we're just allowing you to consume it the way you want and play with it as much as you want, and we built it for the developers. That's, I think, what's unique about our solution.

(Joel Beasley at 00:23:29) When you're on these presales calls working with people that might become customers and they're discussing how they already have an existing system. Right? And so in their mind, they're gonna be thinking, do I move over to Piiano or do I continue to build out our system? First of all, does that even ever happen? And if so, what do you say to them?

(Ariel at 00:23:52) Yeah. Of course. It happens a lot because most companies we are talking with are not new. Okay. That's reality.

(Ariel at 00:23:58) There are also many new companies. And if they're smart enough, they're just doing it from day one, of course. Right? But most companies are not new. So for those companies, there is different ways to look on that. First,

(Ariel at 00:24:10) anything new being built, of course, they want to build it the right way. So we are giving them the tools to do it the right way. But for existing systems, we have also invested a lot of efforts to provide a very simple, annotation kind of solution. Like you just take the code, you annotate the fields in the ORM definition, the model definition in the ORM you use, like whether it's Django, Hibernate, TypeORM or other ORMs that we support, you just annotate the fields that you want to protect. And we do all the heavy lifting for you behind the scenes.

(Ariel at 00:24:43) We make sure that that field is protected, is encrypted. It stays within the same database that you are already using, but before being stored, it's automatically behind the scenes being encrypted for you. And that encryption, as I said in the beginning, now allows you to get centralized control because to access to that, you have to decrypt it. And at that point in time, the code behind the scenes reads out the decryption request to the API to the centralized place that makes sure it's only done if allowed.

(Joel Beasley at 00:25:15) And can it run locally?

(Ariel at 00:25:17) Yeah. Yeah. It can run locally. It can run on-prem. It can run anywhere.

(Ariel at 00:25:21) Or we host it for you when you just get an endpoint and you talk with our APIs.

(Joel Beasley at 00:25:25) Okay. So have you had people that were building it themselves and said, uh, I'm not gonna do that. I'm instead gonna switch over to Piiano?

(Ariel at 00:25:35) Yeah. Yeah. We had those. They started themselves. Some of them say, hey.

(Ariel at 00:25:40) It's very easy. Let's build it ourselves. They started to really dive into it and understand what the full feature set that they really need to build. And then they realized, hey. It's too much.

(Ariel at 00:25:49) Let's look for some vendor doing it. And they came to us. Some of them even tried and started to build and they realized it's too complex because nobody wants to think too much about how do they manage the keys for the encryption, right? Encryption sounds simple. I just need to call a single API, write a single function, library function.

(Ariel at 00:26:06) Right? Let's do AES. Right? It's very simple. But then where does the key come from?

(Ariel at 00:26:10) Okay. And then you need different keys for different types of data and you have many, many services accessing the data. So you need to control who can access what key, and then how do you rotate the keys? So even just talking about encryption, which is one very specific feature from our solution, there are so many challenges to tackle it, especially when you scale, when you have many systems, when you want to make sure it runs in the needed latency that you have and that you get eventually, you get the control over the data. So nobody really want to do it.

(Ariel at 00:26:41) So we are seeing companies starting to do it, starting to really analyze what they need to do, and this is when they sometimes come to us.

(Joel Beasley at 00:26:49) For companies that were making it themselves and then they transitioned to Piiano, how did that transition actually unfold from a human perspective at their organization? Did you have insight into that?

(Ariel at 00:27:03) Yeah. It depends. Sometimes we just start with a company again with something new they are building. So then it's very easy. We are working with the team that builds the new stuff and we grow from there.

(Ariel at 00:27:13) Okay. So over time, maybe an additional team or two teams adopt it. So that's maybe the more organic way, right, to do it, team over team and everybody are happy. Sometimes there are legacy systems that are very connected, right? Like microservices that are very heavily connected and rely on each other.

(Ariel at 00:27:34) And then it needs to be more together in a way, right? So we still start with one thing, but very quickly, we are starting to see that instead of sharing personal data directly between services, instead of two services talking to each other over APIs like REST API or any other type of communication like event driven architecture. So instead of talking directly with, sending email or social security number to each other, they're actually sending encrypted social security number via our solution or tokenized or something that is not sensitive by itself, but is referencing the data stored within our vault, within Piiano Vault. So that's what we are seeing. And then it means that you have to integrate both services somehow together.

(Ariel at 00:28:18) Okay. Not really together. There are ways to kind of define new version of the API and support both of them for a while. But my point is that if services communicate to each other and owned by different teams and they start to talk secure information instead of, as today, nonsecure APIs, so there is a need for a bit more thought, but we have been going through that with a few companies already and there is just the playbook for doing it. And, again, the motivation to do it is that once you're doing it, you are really solving a big problem and that's becoming a business enabler for you to innovate more.

(Joel Beasley at 00:28:56) And are you headquartered in Tel Aviv?

(Ariel at 00:28:59) Yeah. We're headquartered in Tel Aviv. We also have some US presence, our CEO, but successfully most of the team today is still in Tel Aviv.

(Joel Beasley at 00:29:08) Yeah. Yeah. And I personally, I have many friends from Tel Aviv, and one of the things that I, well, I first noticed when I went to whatever the big security conference is every year in San Diego maybe.

(Ariel at 00:29:19) RSA.

(Joel Beasley at 00:29:24) Yeah. RSA. There it is. And I went in the year I went, the different sections were almost different countries. Right?

(Joel Beasley at 00:29:32) And I had some friends, and they took me over to the Israel country area where I saw a bunch of different Israeli cybersecurity type startups, and I got to be, have some conversations and hang out with them. And one of the things that I picked up on was that they all had an unusually high level of discipline and directness. And for me, that is what I enjoy. Right? I'm an entrepreneur.

(Joel Beasley at 00:29:57) I'm a business owner. I like discipline. I like directness. And so whenever I find somebody who's having a startup from Israel area, I'm always curious to how they expand, what other cultures, what would it be like if a third of your company was from another country and what culture. But it seems like right now, you're just mostly Tel Aviv. You've got one or a couple handful of people from the outside.

(Joel Beasley at 00:30:24) And as far as clients go, are you guys discussing publicly if you're venture funded, if you're bootstrapped, if you're cash flow positive? Do you have those conversations publicly?

(Ariel at 00:30:36) Yeah. We are venture backed by YL Ventures. It's one of, I think, the best cybersecurity investor in Israel.

(Joel Beasley at 00:30:43) Of course.

(Ariel at 00:30:44) They're only investing in Israel. They're only investing in cyber. Actually they have offices in San Francisco as well and in New York, but the companies they're investing in are mostly, only from Israel or Israeli founders and only in the cyber domain. And so we are backed by them. We secured $9,000,000 two years ago.

(Ariel at 00:31:03) It's all public. And it took us a while to build the infrastructure. We build the infrastructure I talked about because we wanted to make sure it's food resilient. It took us some time to really analyze all the requirements of security and privacy and the regulations and nail down how to make it very, very simple to be consumed by developers.

(Ariel at 00:31:24) So it took us about a year to build the product. And since then, we started to really work with customers in production, and that's where we are today, growing a bit and going to the next set of customers.

(Joel Beasley at 00:31:38) Well, I think what Israel is doing as a country is brilliant because when you have the general population doing service, right, and they're going through and you're getting these people that go through the service, they come out, they understand, they could be twenty, twenty-three and understand what cybersecurity at scale looks like. And when you do that to your whole population, it's just brilliant. Because I was trying to figure out selfishly, I was thinking to myself, why are there so many good startups coming out of Tel Aviv? I was trying to figure it out.

(Joel Beasley at 00:32:12) And then what my ultimate conclusion was, two things. One, I think is largely due to how they do their service, public service. And the second thing, I think it's largely due to the culture. The fact that you communicate and people are direct, I think that allows things to get done faster.

(Ariel at 00:32:29) Yeah, I think you're totally correct. There are a few people in the army, in the Israeli army that are heavily technologists, heavily focused on innovation. And basically what you learn is that everything is possible technology-wise, and you can solve other problems. Nothing is an issue.

(Ariel at 00:32:45) You really, you know, again, in many, many places, not everywhere, but in many, many places, you really understand how things work in the details of it, right? Like, behind the scenes, not just as a normal developer, but you really understand the mechanics behind the development being done. And then you understand that really you can solve everything. And I think that mental understanding is what eventually allows those people to look at problems and say, "Hey, we can solve it. No problem." But nobody solved it yet. Okay, but we can solve it. That's not a problem.

(Ariel at 00:33:17) Okay, we just dive into it. We just do some research, and in a couple of weeks, we'll give you a POC of something. Okay. So that's what a lot of Israeli companies are very good at. As you said, they have the best technology. They are not afraid of asking questions even, you know, just the newest or the latest developer that just joined, he can ask any question. He's not afraid of asking anything.

(Ariel at 00:33:41) In many, many cases, he really finds something that nobody thought about. So that's part of the culture as well, as you mentioned. And I think that's what Israelis are very good at, right? What maybe Israelis are less good at is how to take that great technology, right, that maybe even solves real pain of many, many people, but how then to scale it or even before that, how to sell it, how to market it and how to do the marketing bluff, right? How to even extend a bit of what you have in order to bring the next customer. That's what in many cases, Israelis are less as good at maybe other originally created countries.

(Joel Beasley at 00:34:19) We can work together.

(Ariel at 00:34:20) Yeah, let's do it.

(Joel Beasley at 00:34:22) America can make stuff up all day. I want to make sure that we talk about the software that you won an XPRIZE for, or was that one of Google's prizes back in the earlier 2000s? Tell me about that.

(Ariel at 00:34:39) Yeah, yeah. That's what I did in between Magiclip to founding Piiano. So actually, I helped a friend of mine with doing that. He started that effort a couple of years before that. What they are doing, they are trying to solve malaria in Africa. So they have a mobile application and many people on the ground walking and using the mobile application to map all the area, just mark where there are water bodies that are the place where the mosquitoes live. And if these mosquitoes live close enough to houses, to people, so in the night, during the night, they can fly and just spread around the disease. So what they are doing is that operation that makes sure that you spray all the water bodies around everybody, all houses. But doing that effort manually, it's very time consuming, but also very expensive, okay? And then one of the main problems in Africa is the lack of money. So with the lack of money and the need to spray everything and to invest a lot of money in that operation, that's the reason that it's very hard to solve the problem. So what I was helping that team is to leverage AI, to leverage deep learning networks over images, over many layers of data that is actually freely accessible in the public internet, like many layers of just the colors of everything and then historical information about how much rain, how much water is there on the ground in many places and historical information about the temperature of many, many, everything around the globe. So we used all these layers to train a special model that could predict where should be the next water body in a specific area in Africa.

(Ariel at 00:36:25) And that algorithm, that model that we have developed actually won the XPRIZE AI for Impact. XPRIZE is a competition that is backed by the largest companies. The specific competition that we won, that he won $3 million from, if I'm not wrong, is backed by IBM specifically. But yeah, they won the first position. Actually, they won it when COVID just started and because of COVID, everything was delayed for a couple of months and eventually a year after, they really made it and got the final approval and got the money.

(Ariel at 00:37:02) And they're using that money today to solve the real problem in Africa. They're working with government to define areas and then use the AI in order to predict where the water bodies are going to be. And then eventually send real people to spray the real water bodies and make sure they eliminate the mosquitoes there.

(Joel Beasley at 00:37:19) Well, yeah, I originally was born in Florida, so I know mosquitoes. There's a lot of mosquitoes in Florida.

(Ariel at 00:37:25) Mhmm.

(Joel Beasley at 00:37:26) Yeah. I remember the one of the first times I picked up on the vehicles that just drive around and spray all the water bodies for mosquitoes. Obviously, it's an expensive thing. And when you have a poor country or more resource constrained country, right, then if you have a hundred water bodies, it's like, which ones do I spray? So a tool where I could say, okay, my budget this year is $1 million, and it tells you which water bodies could be sprayed to have the greatest amount of impact for that million dollars because you can't get to all of them. That's a brilliant tool. That's an awesome thing.

(Ariel at 00:38:05) Yeah. And you can imagine that Africa is not like Florida. I mean, it's not as clean as Florida in terms of you know where the houses are, you know where the water bodies are. In Africa, everything is much less organized, let's say. And then it's even very hard to know where people live, okay? You don't even know that, right? And then you don't know where the water bodies are. So a lot of the effort is also in the mapping part, not only on the spraying part, but you need to do both.

(Ariel at 00:38:33) And again, being restricted in money, that's still the reason why malaria is still out there.

(Joel Beasley at 00:38:40) Yeah. When Josh told me that you guys won an award, I was like, did they get rid of it?

(Ariel at 00:38:45) Unfortunately not. Unfortunately not. And the team is still working on that, and they are working also with the Bill Gates Foundation to try to, everybody tries to help each other there eventually. But yeah, unfortunately, it's not prioritized enough, I guess, for most of the world. That's why it's still there.

(Joel Beasley at 00:39:04) Well, in regards, I'm watching the time, I want to be respectful of your time. In regards to Piiano, the PII software that you guys are building and working with, what's the best way for someone to get started? Do they have to call and talk to a sales team? Can they just download something from your site or GitHub? And how do they get started?

(Ariel at 00:39:23) Yeah. Just go to our website, piiano.com, and there is a Get Started button. You just press it. You do five minutes, you know, getting started kind of walkthrough, and you understand the essence of it. And then we are happy to jump on any call. There is a way to talk to us. And once you understand what you want to do, normally, we start to collaborate. We open a Slack channel, engineers to engineers. So we help our customers eventually with the adoption. We make sure they're doing it the best way, the most cost effective way. And they're also getting the most out of the platform. So to begin with, jump to our website, click a single button, and five minutes, you get it. To extend it, feel free to talk to us, and we are just assisting you all the way until it's fully functional in production.

(Joel Beasley at 00:40:11) Perfect. And can you just spell the website for me again?

(Ariel at 00:40:14) Yes, sure. Like piano, P-I-I-A-N-O, .com. That's it.

(Joel Beasley at 00:40:19) Brilliant. That's so easy. Oh, wait. There's a logo right here. Well, thank you so much for doing this, man. I look forward to talking with you again next year about how you're a billionaire and you sold to Microsoft or something.

(Ariel at 00:40:36) I also believe so. It's really the good time. You know, it's not exploding yet, but it's the time to build it and be fully mature for the large companies that will come in a couple of months, in a couple of years, because as I mentioned briefly, but the world of data protection is just getting more needed or more, people are looking for solutions because their customers eventually are expecting much more than what they expected 10 years ago, even two years ago. Two years ago, they were less suspicious about data being collected, okay. And Mark Zuckerberg wasn't invited to the Senate to talk about privacy issues. So today it's in the headlines, right, of what everybody cares about. It's not the only thing everybody cares about, of course, but it's becoming much, much more important for everybody. And that's why companies start to understand it. Again, they start to understand the need to build for it. And so we are exactly here to catch these companies and help them with that journey.

(Joel Beasley at 00:41:36) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.