Episode 351 ·
Will Ackerly - Controlling Who Has Access To Your Data & Keeping Bias Out of AI
Today we’re talking to Will Ackerly, the Co-Founder and CTO at Virtru. And we discuss how Virtru allows you to keep control over who has access to your data after you send it away. How Will holds over 25 patents, and how we can keep AI explainable and keep bias out of AI going forward.
All of this, right here, right now, on the Modern CTO Podcast!
To learn more about Virtru, check them out at https://www.virtru.com/

About Will Ackerly:
Will is the Chief Technology Officer and Cofounder of Virtru. Prior to founding Virtru in 2012, Will spent eight years at the National Security Agency (NSA) where he specialized in cloud analytic and security architecture. During his tenure at the NSA, Will led the development of the Trusted Data Format (TDF), an open standard published by the US Office of Director of National Intelligence (ODNI) and used today by agencies and companies for the secure transfer of data and the technical foundation on which Virtru was founded. Will holds 25 patents, and is a frequent speaker and quoted expert on cryptography, data protection, and big data analytics.
About Virtru:
Virtru is a global leader in data protection and privacy, equipping enterprises with flexible, end-to-end data encryption solutions that protect emails, files, databases, video, and more.
Virtru’s tools are easy to use and integrate seamlessly with Gmail, Outlook, Google Workspace, as well as enterprise apps such as Salesforce, SAP, and Zendesk. Additionally, with features that include access controls, key management, DLP rules, and persistent audit, organizations are able to meet privacy and compliance requirements like GDPR, HIPAA, ITAR, and CJIS.
To see how you can take full control of your organization’s data, everywhere it’s shared, contact Virtru to start the conversation today.
Transcript
(Intro Narrator at 00:00:00) Hello, my friends. Today, Joel's talking to Will, the co-founder and CTO at Virtru, and they discuss how Virtru allows you to keep control over who has access to your data after you send it away, how Will holds over 25 patents, and how we can keep AI explainable and keep bias out of AI going forward. All of this right here, right now, on the Modern CTO Podcast.
(Joel Beasley at 00:00:29) Here we go. This is the Modern CTO Podcast. What was your first job in electrical engineering in this category?
(Will Ackerly at 00:00:45) My first job was actually at Advanced Micro Devices in Austin. So AMD, actually, as an intern. So I was an electrical engineering, computer engineering undergrad. We have at Rose-Hulman in Indiana, and there was a co-op program. So you rotate through different co-op, quasi-internships. You can be six months or longer. I ended up actually putting all my co-ops back to back and spending a little over a year at AMD helping design the first two-processor motherboard on the 64-bit architecture. It was actually interesting because AMD was definitely the underdog and Intel was the big beast. And Intel was in the process of moving the world off of x86. AMD saw this opportunity as part of the transition where Intel was saying, you know, as we move from 32-bit to 64-bit, let's kill x86.
(Will Ackerly at 00:01:45) AMD was like, wait, you don't have to move. We'll just 64-bit everything. And so they were really seizing that opportunity. And so I got to see the first Windows two-processor 64-bit system boot up as an intern. That was a lot of fun. So I thought that was actually going to be my career, working at AMD for the rest of my life. And then a recruiter came and said, hey, there are opportunities in the government. I was actually previously Air Force ROTC and really considering a career there. So it was an opportunity to actually get my hands dirty and get back into coding, which I thought, you know, as an Air Force officer, it would actually be harder because a lot of the engineering expertise goes into contracting-type stuff. So it was a really cool opportunity. So he said, hey boss, I've got this shot-in-a-million opportunity to do something special in this regard. And he was like, dude, that's awesome. Go for it.
(Joel Beasley at 00:02:45) It is really, really cool. I went to an event once and it was a professional event, local, downtown. And I got recruited, or somebody was trying to recruit me or engage my interest in doing offensive security for the FBI. And it sounds so cool, but then you realize that they're a large organization, right? They have thousands of employees and they have jobs. And you can just go, because we watch movies, right? So it gets kind of crazy. But they have, you could be an assistant to someone, you can be a paper pusher. There's so many different jobs. It just sounds really cool.
(Will Ackerly at 00:03:22) Yeah, it's a big community, lots of jobs. I actually ended up spending eight years at NSA, and you can have an extremely varied career there just hopping from, like you said, completely different roles, different kinds. You can go offense, you can go defense. I spent most of my time in defense, actually. But yeah, for sure.
(Joel Beasley at 00:03:47) Yeah. And I think some of the offensive stuff for hacking and things of that nature, those are newer movements, right? I mean, they existed before, but they're definitely growing in size now. Especially, they built a new base in Georgia, and one of the towns that's known for the golfing tournament, I forget. But Augusta, Georgia. They built a new cybersecurity command center there. Have you heard about that?
(Will Ackerly at 00:04:14) I haven't really spent a lot of time. Most of my time was actually stuck in either DC area or deploying. There are some other facilities. They've got a joint unit actually in Colorado. The governor actually spent a lot of time talking about, Hickenlooper in particular, talking about the sort of joint integrated success there. But yeah, that community is growing and expanding, and a lot of new discussions about the varied missions that didn't used to be talked about as much. Anne Neuberger is an example of getting out ahead of the cybersecurity issues and engaging with industry, where NSA used to be "never say anything," is now more looking for opportunities to get the message out in terms of the cybersecurity threats and what to do. They just put out a zero trust architecture recommendation, for instance, that has some, you know, if you look closely, that and the new executive order actually has a lot of really powerful recommendations if you look at it.
(Joel Beasley at 00:05:17) Does Virtru do anything with the government or security?
(Will Ackerly at 00:05:20) The preponderance, like 98% of what we do is commercial. From a mission standpoint, you know, when I left government in 2012, the big motivation for me was the gap in usable security for the individual and having choice to say, hey, I want data privacy. I want sovereignty over my data. For the first four or so years, it was just a free product. And we're like, we'll raise some money, we'll worry about the details of the business model as we go, and believe in the, you know, get it into the individual's hands. And that's really the crucible for usability. So we definitely have federal engagements now. We got FedRAMP certified, and that was quite an experience. So we are selling capabilities back into the government. But I think the real focus is on everybody else.
(Joel Beasley at 00:06:23) Yeah, I've heard those contract vehicles, or however you get set up—I threw that term around loosely—but I looked into it a little bit. And the amount of work it takes for a business to be able to interface with the government, it's not a little bit of work. It's a lot of work.
(Will Ackerly at 00:06:38) It is a ton of work. I think it can be very frustrating and intimidating, and a lot of components of the government recognize the issue and are investing in a bunch of programs. Depending on your domain, there are some really cool programs out there, like the small business initiatives and some of these incubators where you can go onto a campus and do a literally five-minute pitch. And they've got this on-ramp process. One example is AFWERX for the Air Force. They can go to Vegas. They've got this big facility. It looks super cool. You go and pitch, and they've got senior people that are taking a lot of time out to give you feedback and engage and just meet you and mingle and try to reduce that barrier. When push comes to shove for most things, exactly what you said, it's totally true. But there are pockets of some really cool innovation happening as well.
(Joel Beasley at 00:07:38) Yeah, relationships are everything, right? Getting to meet and interface with those people, that can change your entire life.
(Will Ackerly at 00:07:44) Yep, yep. Totally.
(Joel Beasley at 00:07:46) So what are you learning right now? You're a founder of this company, co-founder with your brother. Correct?
(Will Ackerly at 00:07:51) Yep. Yeah, John. He was in New York doing private equity when, you know, I was talking about, we had just released on the public internet the spec that I'd been working on for a few years. So there's this thing called the Trusted Data Format, which is really just an open source wrapper for, hey, if I'm wondering if I want to control who has access to my data, it's a standardized way of tagging it and encrypting it and saying, you know, how do you control the key? And I was basically saying, look, the real opportunity is in reducing the friction associated with end-to-end encryption. And now that this is out there for anyone to use, I think there's an opportunity to take this into the apps that everyone uses every day. So yeah, so John left his job in private equity, moved to DC, and we started a company together. And it was really cool. There are a lot of things that I could do with my brother and just have super open and honest and difficult conversations that would be tricky if we weren't tied by genetics, I feel like.
(Joel Beasley at 00:09:11) So it's been a good thing?
(Will Ackerly at 00:09:12) It has been incredible. We actually had a couple of potential investors say, under no uncertain terms should you ever found a company with family. It just introduces unnecessary risk. It can get complicated, and that could be a negative. We talked to some people who had counter opinions. And, frankly, I've learned a lot about my brother. We're separated by six years. I'm the youngest and he's the oldest. And I got to know him more, I feel like, more through running a company than the previous thirty-some-odd years of my life. So there are some rough spots, but we get along super well, and it's been, I wouldn't have done it any other way.
(Joel Beasley at 00:09:56) I love it. I've got an older brother. He's a doctor. We interface at dinner about the problems at the crossroads of technology and medicine. So your data format actually could have some usability there too in the medical space, right?
(Will Ackerly at 00:10:13) Big time. That's actually the, in the medical industry is the largest shared vertical across our customers. So we got 6,000-some-odd organizations that use Virtru. And personal health information, HIPAA, and wanting to do right by patients is the most common use case for it, for sure.
(Joel Beasley at 00:10:31) Have you looked into what Tim Berners-Lee is doing with his pods and his Solid framework?
(Will Ackerly at 00:10:37) Yeah, trying to move a lot more to the edge. I haven't dug into it super deeply.
(Joel Beasley at 00:10:45) I was telling Rob, I was like, you guys should dig into this because the explanation I got from Rob about what you guys are doing sounds identical to the explanation I had from Tim Berners-Lee. And so I, Rob had a surface-level understanding. He had looked into it a while ago, I believe he said, and then, you know, things mature over time. But they've got 50-plus employees, and they're implementing this for governments and large organizations. And it's a framework, like, utility set of tools. They're building the plumbing. And the mission and everything sounds so similar. Probably either partner with the technology or glean some insight as to how they're handling certain problems. But the freedom of data is, you know, I want to own the data. I want it to be mine. And of course, it can have restrictions in place. But yeah, that's where I think the world's going.
(Will Ackerly at 00:11:39) That's super cool. I remember, you know, for a while, the narrative had been everything should be open, right? And then to include the information that's published. And so some of the frameworks of the past didn't have as much of those semantics built in. The semantics were relational to data, but not semantics around policy for access control. And when you're dealing with things like personal health information, right, it's not like you necessarily have something to hide, but you very much, that's a privacy thing. And that's really exciting to hear. I think it's worth digging into. We've actually partnered with a handful of companies that have the same sort of philosophy, and the more the merrier, as far as I'm concerned. Everything that we do is built on an open core. So if there are opportunities to collaborate, or frankly, even if there are things that they're doing that are leading the charge on some fronts, yeah, totally. I think that could be a cool mashup.
(Joel Beasley at 00:12:34) Yeah. With my limited experience of both, and I'm not the brightest person in the world—I had to get Tim Berners-Lee, I was like, explain it to me like I'm a three-year-old, you know, to really help me wrap my mind around it—but from the little bit of knowledge that I have, it seems like your product would almost be like a tool that would, or like an app on their framework, because their mission's more open and robust, I guess, from the little explanation I've had. And it seems like you guys would be a perfect tool for helping permission and share these pods or this data. But I could be completely wrong.
(Will Ackerly at 00:13:12) I mean, I think so far, all the core use cases that we've come across, it's been a nice, easy, lightweight integration. So I wouldn't be surprised if that's totally true.
(Joel Beasley at 00:13:24) So you have 25 patents. Is that right?
(Will Ackerly at 00:13:27) It's about that. Yeah. Some of those don't count from the standpoint of it's the same patent in one country and a second country, kind of a thing. Yeah.
(Joel Beasley at 00:13:37) There have been a handful of exciting innovations just staring at seemingly intractable problems and then kind of busting through those with some hard thought and sweat and late nights.
(Joel Beasley at 00:13:47) Are they mostly Virtru-type patents, or are they just across the board and, all sorts of, you know, anti-gravity machines in there?
(Will Ackerly at 00:13:54) Yeah, they wouldn't accept that one. They're mostly Virtru-oriented. There's one that I have that is not, that has to do with some more hardware failsafe design concepts. But everything else is, you know, it's like searchable encryption is one. So if you, you know, traditionally, if you were to PGP encrypt all of your emails, then that frustrates one of the most exciting features of modern email, which is you can search your inbox in an instant, right? So figuring out a way that a cloud-based email provider can't see your data, but you can still search and they're the ones doing the indexing. And they don't know what you're searching for, but they can retrieve your emails. We have some IP around being able to do that unilaterally. And then some other things are in usability where you don't want to require people to install software in order to receive an encrypted message, right? So there's a lot of IP in some of the differentiated implementations of the open spec that we have. So it's kind of an interesting thing from a business standpoint, right?
(Will Ackerly at 00:15:04) We want to make darn sure that anybody at any point in time can take their keys and go home, and they've got everything that they need to be able to continue to consume their data is open. But we also want to have a business model that's sustainable. So for some of the premium features and usability aspects, we've got some patents around.
(Joel Beasley at 00:15:29) That's pretty neat. Did you imagine you'd be doing this and building all these patents when you were in grade school?
(Will Ackerly at 00:15:35) Oh, gosh. I kind of dreamed of just being able to tinker and build widgets. I'm very much a mechanical bent. I sort of happenstance my way into this space. When I was originally hired by NSA, it was for electrical engineering. And I was told, hey, you're going to build boxes, and unprotected bits are going to go in one end and protected bits are going to go out the other. And then, you know, the world became more software-oriented. And they said, alright, you're going to do that, but in software. And, you know, the rest is history. So I've got the brain wiring, and I had the sort of the desire as a kid to build things, and now I'm much more in the software territory.
(Joel Beasley at 00:16:22) You can build things faster.
(Will Ackerly at 00:16:24) Yeah. You know, it's funny. To build things these days, you almost more often than not—knowing how to code can be really helpful. Right? It's gonna be powered, it's gonna be smart, it's gonna be Internet connected, and you want it to be—to compete, oftentimes that's what people are looking for.
(Joel Beasley at 00:16:45) Well, it has to have a good API.
(Will Ackerly at 00:16:47) Yep. Yep. And in fact, it's interesting going full circle. Right? So for the first eight years of Virtru—gosh, I'm trying to do my math—seven, we were not at the edge. Right? So all these things that are being built, and the space of IoT was not really our focus. There's just so much wood to chop in things like email and protecting files that you put on Google Drive or what have you. But now, increasingly, getting back onto the devices—devices are often one of the biggest risks, right, in terms of threats of compromise and tracking where you are, like video cameras, all these sorts of things. That is one of the main sources of PII pollution. Right? So how can you sort of sequester that? How can you make sure that that's under your control—an asset rather than a liability? So we've been recently kind of circling back on the IoT play.
(Joel Beasley at 00:17:57) That's pretty cool. Yeah. You enjoy what you do every day? You love it?
(Will Ackerly at 00:18:01) I absolutely love it. You know, being able to see hard problems and dig into them with some of the most brilliant people I've ever worked with, and see success and then see expansion in a sustainable way where it's a cool problem—I'd be working on it anyway, but there's a sustainable business model around it. It's pretty special.
(Joel Beasley at 00:18:24) Where do you spend the most of your time, the bulk of your time?
(Will Ackerly at 00:18:27) It's a mix. You know, I'm a member of the board, so I gotta do the audit committee things and stuff like that. But most of my time is split between engaging with customers and the leading edge R&D. So hard problems—the thing that's on the "it might be impossible" kinds of territory—and saying, "Okay, can we make that possible? What threads do we have to pull?" So I get to straddle those two, which is really nice.
(Joel Beasley at 00:18:58) I love that. I get weird because I get to talk to so many people, so I place bets on which profile is he? And the R&D bet paid off in my head. I was like, "Yes!" Because, man, you're brilliant. You got 25 patents. Why would you want to give that up? You know? Let's embrace that and turbocharge that and surround you with an amazing team that will just take you to the next level.
(Will Ackerly at 00:19:21) The thing for me is—and I think it sounds like you've got a lot of similar orientation—which is if you're exposed to a problem, you want to solve it. And for me, right, it's like when your mom was doing things like, "Oh, this is a pain. Can you alleviate my pain?" I don't like building shelfware. I'm not—I don't think I would be a good mathematician. Maybe I might be an applied mathematician, but definitely not a theoretical mathematician. I need to understand how is this going to get used? How is this going to actually improve someone's life? And so getting out there—I've tested as an introvert, but I'm sadder when I don't have someone to be modeling in my head with fidelity to say—and a problem. So getting out there is kind of a necessity for me. But once I've had those engagements, I also like to just shut the door, sink into a problem, pull a couple of really bright other engineers to tackle that with me.
(Joel Beasley at 00:20:22) Yeah. That's what stumped me too, trying to really understand introverts, extroverts, all this stuff. I came after a couple of years of thinking about it and just living life. I'm like, people just have moods. There's seasons too. It's not a daily thing. Throughout the year, there are different moods I go through, different things I want. And, you know, I focus on one for a while and then I want some variety, so I go to another. And then over time, you develop strengths in a couple different areas and then, yeah.
(Will Ackerly at 00:20:50) Yep. I totally relate to that. Generally, particularly recently, some of the times I've been getting out there—I mean, particularly after COVID—it's just been so energizing. That's actually a relatively new feeling for me. Most of the time, I spend a lot of time face to face and I need to recharge, but I think it's one of those seasons for me. Right? I just want to get back out there.
(Joel Beasley at 00:21:14) For everybody. It's like the rain is over. Let's go out and play, you know.
(Will Ackerly at 00:21:19) Yep. Yep.
(Joel Beasley at 00:21:20) You do get to spend a lot of time with your customers. What do they want? What are they talking about right now?
(Will Ackerly at 00:21:26) Yeah. Frankly, feel free to dig into R&D all you want as well. But because a lot of what we're doing is—frankly, if we could recruit other people who are thinking about the same problem...
(Joel Beasley at 00:21:38) Oh, let's give it a shout out. That actually happens a lot on the podcast. Tell me about the problems you're thinking about. It'll attract the right people. Yeah.
(Will Ackerly at 00:21:44) So one of the big things that we're looking at is very low power, low size encryption. So we're thinking about a smartwatch or a tag and those sorts of things. What are the most computationally efficient and fast mechanisms for protecting data? Because traditionally, you know, encryption has been seen as having overhead. We've been able to reduce that really nicely. And then the other is, as you're operating at scale—we've been looking at, okay, if you have a million or 10 million patient records you want to ask a research question over, is there a scalable way that each of the individual patients can have affirmative auditable control over their data? We can do it for hundreds of thousands of records just fine and not really get in the way of an analytic. Can that scale to millions without having to delegate to a central key authority? To what extent can it be true individual sovereignty? And how can you minimize the number of third parties that you have to trust?
(Joel Beasley at 00:23:03) That's a tough problem.
(Will Ackerly at 00:23:04) Yeah. It's also, I think, a phenomenally exciting kind of quantum leap potential. Right? So one of the biggest friction points for health research or a lot of different research domains in almost every industry—we were talking to one of our largest customers. They're one of the larger credit card processors. There are billions of dollars of fraud that could be reduced, prevented, where that ends up translating into increased percentage fees that businesses we interact with have to pay. Right? But at scale, you know, say, "Okay, I'm going to reduce that friction." Can our transaction data power that in a super private way? Make sure that dots can be connected if AmEx is having a problem and Visa is having a problem over here. And so there are threat intelligence sharing systems—they're called ISACs—where there's a financial services ISAC. And the information that's shared is of a much lower fidelity because of the lack of actual control that each party has when they're sharing data into that environment. So if you answer this question—say, "Look, I'm going to protect my data before I share it, and then I can govern how my data is being used as it's being analyzed and people are asking questions of it"—I think that could burgeon a foundational new era of the value of data. Because data is only valuable if it's going to be used, but the potential for misuse prevents some of the sharing. So being able to categorize those two, I think it's worthy of a collaborative effort. And I'm not sure there are a lot of organizations right now that see the opportunity. There's already, with the current technology, so much opportunity to take this sort of self-protecting data—data-centric zero trust is what some people call it. So, yeah, I would love to recruit in that regard.
(Joel Beasley at 00:25:04) Is there ever—we talked earlier about being able to search encrypted data. And so is there a way that these two things could come together where we're sharing data, it's encrypted, we can also search it, so they kind of have the data, but they kind of don't?
(Will Ackerly at 00:25:20) Yeah. You know, there's a domain of mathematics—you were talking about math—particularly applied math with homomorphic encryption. So there's categories of research where they're trying to move from "it is exponentially slower" to "maybe it's not as exponentially slower" in order to compute in the encrypted domain. But it sounds like magic. Right? If you can encrypt pieces of data and actually answer questions without decrypting it. The problem with it right now is in most cases, it's just way too slow. So there's some really cool research happening in other domains, like searchable symmetric encryption, that's closer to what we are doing for the searchability. But doing that will actually frustrate the ability to answer certain questions of that data. So you can do searches like keywords, but you can't as easily do things like AI training or other things. So having this third category of "I'm not going to try to muck with the data. I'm just going to do a standard encryption and then put it somewhere into an environment where later I can give someone the key, and I can require whatever obligations I need before I grant the key." It's like, "Hey, I'm at your house. Can I come in?" "Well, you know, have you taken your shoes off? Are you clean? Are you who you say you are? I'm going to authenticate you first and all these sorts of things." Right? You can control—you can say yes or no even if you're not directly there. So it's a lot more flexible.
(Joel Beasley at 00:27:06) Have you followed—for some reason, I think you'd get inspired by how they're storing data inside of DNA and how they search on that physical data. Have you learned about this at all?
(Will Ackerly at 00:27:15) I'm not.
(Joel Beasley at 00:27:17) Okay. So the company I talked to, Catalog DNA. They were born, I believe, out of an MIT research lab. I'd followed them for several years, and they were encoding data into physical DNA. And the problem originally was the rate at which you could actually encode. So they've amplified that to where it's actually a commercial product now, primarily used in the "write once, read never" type stuff. People that use the big tape backups, you know, they'll write a bunch of it and they'll never actually read it. That's an industry. Right? That's a whole market category. So it has applicable financial gain there today because of the density. The density ratio is roughly a football stadium filled with storage servers condensed down to the size of your hand. That's the density of the data.
(Will Ackerly at 00:28:05) That's incredible.
(Joel Beasley at 00:28:06) And there's thousands of copies because of the way that the DNA molecules work of the data. So it's very redundant. It lasts a long time. And the way they search it is actually through chemistry and chemical chain reactions. So they can run these ridiculously fast searches. Of course, 90% of the stuff is all just in labs right now, not happening at the level of consumerization that we imagine most things happen at. Right? But it's amazing what's going on. And when I was hearing you talk about the way your mind works, I think if you want some playtime, going and watching some of the videos of how they're actually doing this might inspire you for some of the problems you're trying to solve.
(Will Ackerly at 00:28:52) That's super cool. And I can think of a handful of ways I'd love to kind of pull that thread. You know, one is, could—if you're going to be encoding information, is there a way to kind of meta-encode it so that you can control who can decode it? And the other thing is, is there a parlay—are there technologies learned there to help protect at-the-edge DNA decoding? So one of the biggest threats today is the supply chain of—you know, if you go to one of the big "pay a hundred dollars, get your DNA decoded," it's very uncertain who might end up having a copy of your DNA.
(Joel Beasley at 00:29:44) I just assume everyone. That's when I did it. The one time, I realized no matter what the fine print says, I'm doing this, but I'm just assuming that this is public record now.
(Will Ackerly at 00:29:54) Yeah. I mean, it's—I've withheld having to do that unless it's for a very specific medically necessary reason where it's my life or family or whatever. Right? But I've held back. But I wouldn't be surprised if they could take it so you could spit in a vial, mix it with the encryption key, and shake it up. You know what I mean?
(Joel Beasley at 00:30:18) Yeah. Yeah.
(Joel Beasley at 00:30:21) I'm serious. When you start hearing—listen to the episode with David at Catalog DNA. When you start hearing about how they actually will run searches on this data, I mean, this stuff—this is chemistry-based type stuff.
(Will Ackerly at 00:30:32) Yeah. I think if they can figure out how to apply, you know, privacy to anything approaching that, I think that would be mind-bendingly powerful. So I know that it's a national security issue. And for some countries, it's a national imperative and strategic asset to—depending on who you are and what your bent is, either protect my people's DNA or get as much people's DNA as humanly possible. And, you know, having the tools to fight back and not have to make the sort of foundational compromises of "I'm not going to opt in to modern medicine as a result"—that becomes problematic. But yeah.
(Joel Beasley at 00:31:17) Yeah. I figured I might get a letter from my insurance agency. You know, I've been disqualified for coverage because of a preexisting condition from something they did a partnership with 23andMe or something, you know—one of the big name companies. Right? And that's a real legitimate thing. I mean, it's weird too because they do it already in some ways, like with your driving record. You have no control over not letting the insurance company have your driving record. I mean, you know what I'm saying? And so they are able to rate you and they use your credit report. You have no control over them not having access to your credit report. So it's kind of weird because other areas we're like, "What are they going to do with insurance and our DNAs and things like that?" I don't know, man. I'm off topic, but it's a weird world.
(Will Ackerly at 00:32:12) You're not.
(Will Ackerly at 00:32:13) You're not off topic at all, at least not from my standpoint, particularly in terms of the R&D stuff that we're doing. We have pilots today, and if you think about your credit report, that's a good example. And frankly, there could be a lot of value. I'm thinking about the 23andMe DNA and your credit report and all of your other data. This is often information that's being sold.
(Will Ackerly at 00:32:45) But right now, I think it was hundreds of millions of dollars were paid by one of the largest pharmaceutical companies to one of the largest DNA companies for the DNA dataset that they had. And well, where's my check? Or where's your check, right?
(Joel Beasley at 00:33:04) Right.
(Will Ackerly at 00:33:04) You know, for that. And really, all that had to happen is you check the box saying, "Hey, I approve my DNA for being used for research purposes." What they don't tell you is often for commercial drug development purposes. That's research, sure.
(Will Ackerly at 00:33:26) But you're being sold down the river. The same thing is true for your personal health record. If you've ever opted into a drugstore coupon program, usually if you read the fine print, they're usually opting you into additional... or you're opting into having them sell every little piece of information that they're gathering about you commercially. And the protection requirements under the law, at least in the United States, are abysmal. Research has proven that it's reidentifiable.
(Will Ackerly at 00:34:01) So being able to wrap up that data and say... because with new laws coming in, right? Let's get the message out there. You can still answer the analytic questions that you need to answer. Like, are you a high credit risk broadly, or some kind of generalized, non-detail, privacy-invasive kind of a thing.
(Will Ackerly at 00:34:28) Let's reduce the exposure. You can still empower people to answer questions that they must answer without revealing all of the information if you protect the data itself. And genetic data is actually one of the most powerful examples of this, I think, because it doesn't do us any good to have a text document with a bunch of A's, T's, C's, and G's in it. I can't turn that into actual information. I have to give that to a third party, but the technology is there today to wrap that up so that they can turn the crank.
(Will Ackerly at 00:35:11) They never see your raw genetic data, and they can produce the answers in a way where the answers are themselves protected so that only who you authorize to see that information can actually access it, if that makes sense. So you don't have to be disempowered in order for these questions to be answerable. And that applies, I think, to all of the things that we've been talking about, and it's a core aspect of the next generation of what we're doing with TDF.
(Joel Beasley at 00:35:52) Is it because my application would run in your environment and I wouldn't have a stream back to that?
(Will Ackerly at 00:35:58) No. Part of our goal is there's no "our environment," there's no virtual environment. It is core technologies, sort of the DNA of data that's open, that is the language of being able to say, "Hey, if you think about PGP, right?"
(Will Ackerly at 00:36:24) Alice sends an email, and what PGP allows you to do is say, "Alright, I'm sending this to Bob, and here's Bob's key." So that lock can only be opened by Bob. But you could do the same thing for your patient record with an open protocol. But instead of Bob, it could be Alice's patient record as a more abstract attribute.
(Will Ackerly at 00:36:49) And then the re-encryption can happen much more dynamically. And so being able to just write that language and say, "Here are the piece parts. We've got this envelope that says, 'Here's how it's encrypted.' We've got this attribute language. We've got a routing protocol to say, 'Here is where you call back to an authoritative server if there needs to be.'"
(Will Ackerly at 00:37:10) And those servers can be run by anybody. And then the ability to issue identity and federate, right? So one of the magical things that happened is, as we are kicking off Virtru, SSO and federated identity were maturing. So the idea of all these protocols existed to be able to interconnect the legs of the stool, right? Identity, encryption, and these entitlements. And say, "This is the language and anyone can adopt it."
(Joel Beasley at 00:37:41) Now I want to get a little nerdy here because there's something I didn't pick up on. Okay, so help me here. So you've got this encryption. I understand the concept of PGP and the locking. I understand the envelope of the TDF to some degree. But where I'm lost is, as a software engineer, I imagine, okay, I get this data, I unencrypt it, and so now I can perform calculations to gain insights on it, right? But how can I do that without having a copy of it? Because, you know, you can search the encrypted or you can do something. How does that happen?
(Will Ackerly at 00:38:23) Yeah. So there are sort of four or five different trust levels, and you can condition releasing a key conditional on that. One of which is a confidential compute. So all the major vendors now have hardware roots of trust with the ability to spin up a piece of software sitting inside of an isolated piece of memory on a chip, whether it's AMD, Intel, any of the different major providers, or ARM. If you're sitting on a Samsung S20, you can spin up an enclave.
(Will Ackerly at 00:38:59) And there's a remote attestation protocol where I remotely can say, "Am I talking to one of those enclaves?" And if I am, "Let me get a public key associated with it. And oh, by the way, one more question: What software is running inside? Give me the hash."
(Will Ackerly at 00:39:18) And the enclave will actually sign it. So you'll get a manifest. So you can pick and choose. Again, it's a federated thing. You can say, "Okay, I got a manifest proving that it is your software running on an Intel chip." At that point, I might not even care where it is, and I'm going to release the key into that software. So if you have an app designed for one particular purpose and it's been audited and it's published on a Docker container or whatever, you can know before the question is asked what piece of software and what question that piece of software can ask as it's unlocked in the enclave.
(Joel Beasley at 00:40:01) That's complicated stuff, man.
(Will Ackerly at 00:40:03) It's been many years in the making. 2006, I took a swing at it with a team of engineers with this concept of a TPM chip, a Trusted Platform Module, but it was sensitive to way too many things. If the BIOS on your computer changed one bit, all bets are off. And it just wasn't practical. But with the concept of Docker containers and the new generation of these enclaves, it becomes increasingly just like deploying any other Docker container.
(Will Ackerly at 00:40:37) It's just that the identity of that software is now a lot stronger.
(Joel Beasley at 00:40:41) Are you still keeping up pretty close with what AMD is doing now?
(Will Ackerly at 00:40:45) Yeah. We now have a team dedicated to tracking the details of that. It's an interesting sort of technical race on a bunch of fronts.
(Joel Beasley at 00:40:55) I got to talk to Mark Papermaster from there. He was a really smart guy about this stuff.
(Will Ackerly at 00:41:00) Did he get into enclave technologies at all, or is he more focused on other things?
(Joel Beasley at 00:41:05) Nope. I just learned the word "enclave" today in this context.
(Will Ackerly at 00:41:09) Gotcha. Yeah. I mean, a lot of that whole space, I think, bleeds into what some people consider to be DRM, right? So if Netflix wants to be able to pull over a movie, can they be sure that there's not a trivial exploit of, you know, democratizing that control. But it's not about Netflix's movie. It's about me constraining the use of my personal data.
(Joel Beasley at 00:41:43) You think a lot about this personal data, don't you?
(Will Ackerly at 00:41:46) It's a core, core mission objective for us, you know, and for all of the R&D, independent of who might be paying for the initial work. And if you think about most of the regulatory regimes that are out there...
(Joel Beasley at 00:42:00) A lot of times...
(Will Ackerly at 00:42:00) ...it ends up circling back to being about us, right? Whether it's criminal justice information, right? So a lot of local police departments and body cam concerns, right? And the opportunities there... it's a loaded subject, but there are transparency opportunities in deploying those. But, you know, it's burdensome from a cost standpoint. But one core anchor of that is they're out there recording us, even though it's a regulatory thing that might not be on its surface about personal rights.
(Joel Beasley at 00:42:35) Well, the silver lining here is that every time I get into one of these conversations, I'll go hunt down some experts that are in the space, whether it's data privacy or whatever it may be. And every single time I come to the conclusion that there are really, really smart people who care a whole lot, who have great intentions that are working on this night and day with something that has a cash flow positive business model behind it. And then I sort of check that off my list and I can sleep at night. But there's still those big ones, the biggest one being AI, you know, taking over the world. That's like... everyone building it that I have talked to is really, really smart and they all have great intentions. So hopefully that's the amazing AI that comes out of it.
(Will Ackerly at 00:43:22) AI is its own... yeah, I... We actually are spending a lot of time in that space as well. Very different angle. And I think a lot of organizations, because, you know... And again, it is privacy when push comes to shove for a lot of it, insofar as if there's a model... One of the big things I worry about is transparency and explainability and bias—to avoid bias. There are a lot of dangers in not being able to be introspective and be able to attest to, "Okay, how is something trained? What was the training data? Is that trustworthy?" Because people's bails are being recommended by AIs today, right? And that can mean the difference between getting released or being stuck in prison.
(Will Ackerly at 00:44:21) And right now, people are not requiring an audit trail. And, you know, think about TDF, and you can compose it in a really straightforward way. It's like, "This model was trained by this algorithm on an enclave using this training data." And then if someone has a civil rights kind of question, you can provide affirmative evidence. And if there is an issue, you can revoke it, right? So part of TDF is being able to say no.
(Joel Beasley at 00:44:59) So you get that information. You can provide this transparency: the enclave, the algorithm that's going to run, and the training data that was used. That will actually come back to me on the initial handshake. So before I choose to send my data over there... Yes. So I'm essentially just using them for processing power. Everything's been checked. I know exactly what they're doing. They're just going to process this for me.
(Will Ackerly at 00:45:23) Exactly right. Yeah. So in the mature case, compute, where the compute is, is insignificant because you're not having to trust the people who are administering the box, you know, if the hardware is built right.
(Joel Beasley at 00:45:40) Dude, that's going to change it. That's brilliant, man. Are you guys publicly traded? Can I buy some Virtru stock?
(Will Ackerly at 00:45:49) Not yet. Not yet. But it is one of those things that, you know, we'll be opening core aspects of this, right? You should not trust a black box. So being able to say, "Okay, I want to wrap my data," and then a cloud provider has... you can just... it's got commodity hardware and the bits converge. Yeah, totally.
(Will Ackerly at 00:46:16) I think, as I was alluding to earlier, I think people don't aren't wired to think this way yet about and have expectations around the control of their data. But I think over time, as some of these deployed cases are talked about more, I think it'll spawn the imagination a little bit more and get people expecting, "Being able to say that's possible. I want that."
(Joel Beasley at 00:46:44) Yes. Yes. And then to ground myself, I always think two humans ago, two generations ago, we barely had electricity be common in the household, right? So we are... I think it's been a hundred, hundred and ten years or something, but that's nothing, man.
(Will Ackerly at 00:46:59) Yeah. And the pace of acceleration, the exponent is increasing, let alone just the absolute rate. I feel like this is maybe, you know... And my hope is that, you know, it's... you're talking about AI and where's this trajectory going to go, right? Because a lot of people debate about, you know, when the singularity comes, right? But having insight... I don't know. I don't want to dive too deep into that hole, but I think what you said about the accelerating trajectory is dead on.
(Joel Beasley at 00:47:36) Alright. So next time we talk, we're going to go deep into the AI hole, right? We'll bring up the Pentagon and their off-world vehicles, because that still blows my mind that... I don't know. I just think it's cool. And we'll talk about all sorts of weird edge and fringe stuff too.
(Will Ackerly at 00:47:57) Love it.
(Joel Beasley at 00:47:58) You sound like a cool person for that.
(Will Ackerly at 00:48:01) Yeah. Yeah. It's a new accelerating domain. Indeed. And maybe, depending on the timing, we talk a little bit about Mars as well.
(Joel Beasley at 00:48:11) Yes. So we've got Mars, AI, off-world vehicles. And there's off-world vehicles, by the way, right now. We've got rovers on Mars. So those are some off-world vehicles too. But I want to make sure we do some work here too. Call to action. Do we have any specific call to action? We said it earlier, you're looking to recruit some talent. If they're interested in that, they can reach out to your careers page.
(Will Ackerly at 00:48:35) Yeah. I think, you know, Virtru.com. We navigate to jobs. We are looking for people that are smart on confidential compute, encryption, a lot of... as well, designers, right? So one of the big things for us is we see ourselves as a user experience company as well. And so being able to design that interface... in a lot of ways, I see myself actually working in service of that UX team, right? What's the experience that people expect? Let's get there. So yeah. Full stack engineers. We're hiring almost...
(Joel Beasley at 00:49:10) That's amazing.
(Will Ackerly at 00:49:11) ...across the board.
(Joel Beasley at 00:49:12) Okay. And then if people want to use your services, what's the number one reason why people become customers of Virtru?
(Will Ackerly at 00:49:17) Yeah. It's a good question. You know, really, I think it's to be... if you want to be, particularly as you're sharing externally, be perceived as a thought leader in the privacy space and reduce friction as you're communicating, particularly externally, right? So it's one thing to protect information within your environment, but being a good custodian of private information, whether it's your IP as you're collaborating... it's both the right thing to do, and I think there can be a huge business improvement as well, reducing the friction as you're working with other organizations.
(Joel Beasley at 00:49:54) And so it's just Virtru.com?
(Will Ackerly at 00:49:58) Virtru.com.
(Joel Beasley at 00:50:00) Adam, we got a typo in our show notes here.
(Will Ackerly at 00:50:05) Yeah. I didn't do you guys any favors with the naming of the company.
(Joel Beasley at 00:50:12) It sounds cool, though. It sounds like "virtuous," you know, which is a positive word. It's a good intent there.
(Will Ackerly at 00:50:17) It's completely destroyed my ability to say the word virtue. It's not patience as a virtue.
(Joel Beasley at 00:50:27) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected].