Exploring Authentic Security with Authentik Security’s Fletcher Heisler
Fletcher Heisler, CEO of Authentik Security, highlights the company’s open-source identity provider, focusing on its enterprise functionality and compliance. The discussion covers the evolution of Identity and Access Management (IAM) and its significance in modern security. Fletcher also emphasizes a careful approach to AI integration, prioritizing human coding.
Transcript
Hey everyone. Welcome back here to Techstrong tv. I want to introduce you to a CEO of authentic, the CEO of authentic Security here.
His name is Fletcher Heisler. I hope I got that right. Fletcher, did we pronounce that right?
Sounds good. All right. Hey, Fletcher, welcome to Text Drug tv.
It's great having you on. Thanks so much for having me. Pleasure.
Um, Fletcher, we're going to, Fletcher we're gonna talk a lot about authentic and authentic security 'cause there's a difference, but before we do that, I wanted to give people a sense of who they're listening to. So if you wouldn't mind, give us, give us kind of your story. Give us the Fletcher story.
Sure. I can give a, a little bit of the authentic story and we can get into that as well as a bit of my background. Sure.
I've been in tech since learning qba in middle school, Uhhuh and, uh, futsing around in the security world, maybe in ways that, uh, I wouldn't do these days. Sure. Have.
Uh, um, but we all, you know, got there. We all been there, right. Things we did we're not really proud of, but it helped make us who we are Learn by doing.
Absolutely. Uh, um, I most recently prior to, uh, authentic, uh, ran a company called Hunter Two. Uh, went through Y Combinator.
It was a, uh, application security training company for, for developers, so helping them Oh, very cool. Create secure code, but they get to actually hack and patch up live applications. Um, so that was a fun adventure, um, acquired by Veracode.
I worked there as the director of developer enablement for a few years. Um, sure. You know, was, uh, a, a little tired of wearing all the hats.
I I had a newborn. So, you know, it was time for a little bit of a break. And someone from, uh, open Core Ventures, which is the original sort of pre-seed funder of, of authentic security of the company, um, reached out to me saying, I know you've been poking around in security and identity, and this guy's been working on a really cool project, um, that, that you might be interested in.
Uh, so Jens, uh, our, our founding CTO, who's in in Germany, um, was an infrastructure engineer at Yelp. Um, and he started building out authentic, really, because he couldn't do what he wanted with Key Cloak, which is our only other sort of open source competitor when it comes to, uh, identity providers. Um, that was seven years ago.
So he's been building this out for a, a very long time. Um, built in, built it in Python, it's a, a Django application under the hood. Um, I'd also, prior to that, uh, started Real Python, which is now a big community for, uh, engineers learning web development and so forth.
So we were tech aligned, uh, in terms of using the, the right kind of technology, um, making it easy for, for developers to use as well. Um, and he was building it all open source. So it's an open core company, um, authentic as an identity provider.
Um, you know, you can just download and use, uh, for free. Um, and it also means it's all built in the open. So even our enterprise features are our source available.
And that just made a lot of sense to me. Um, you know, it's, it's almost like, uh, you know, would you choose a crypto library that's is proprietary and, you know, only hackers can examine it, and you as a customer don't get to, to have any say. No one's really reviewed how this works, uh, behind the scenes, of course not.
But that was kind of the state of the art when it came to, uh, I am. So the fact that Jens had built out a full fledged IDP from the ground up was starting to build a team around this, this really stellar, um, product. Um, you know, I, I realized that companies will also want this too.
Um, on the enterprise side, we were getting a lot of interest from folks saying, we need something that is secure, that is reliable, that we can host. We don't have to rely on you to be up all the time. We don't have to rely on you to make all the right security decisions behind closed doors.
Um, and so we've been at it a few years now, um, with a lot of interest from, you know, we have a million different, uh, home lab installations that we know of. We have very limited telemetry that's all optional. So, um, you know, we, we find out every week, uh, someone running authentic in production that, uh, we, we just get to find out about.
Um, and then on the enterprise side, you know, a lot of big companies and, and agencies and institutions, uh, starting to, to run authentic at tremendous scale. So it's been a fun journey. Absolutely.
Lot to unpack here. I I just wanna try to get this into, you know, how you eat the elephant, right? One bite at a time.
Yeah. I wanna get this into bite-sized chunks for our audience. First of all, when we talk about authentic, the product versus authentic security, the company authentic, the product is the open source project, if you will.
That is just what we say it is. It's open source. Anybody can download, use it, and it has the same positives and negatives that, you know, millions of other open source projects do, right?
Yeah. So the, the vast majority of authentic is MIT licensed. Uh, you can use it however you'd like.
There is a separate, essentially enterprise folder of code in there, uh, which is part of, you know, how the company survives and makes money. Um, sure. But is focused on all of those features that you probably need as a large enterprise, but as a home lab user, uh, you know, wouldn't provide, uh, much value in most of the cases.
So it's kind of an open core model, if you will. Exactly right. With a freemium add on.
Um, let, let, if you don't mind, our audience, as I told you, is technical. First of all, when you say a home lab user, what about the S-M-B-S-M-E market? 10 users, 25 users?
Do they need that enterprise functionality? Some of it, all of it, none of it Sometimes. Um, so if you're talking about kind of a, a mom and pop shop, they're probably fine using Google Workspace or something like that.
As they start scaling up, having more complex needs, uh, they might need something like authentic to tie all those pieces together. Um, but we have had a number of small specialty teams, uh, that, that also want to tie into some, you know, a, a customer's active directory or, uh, they just have, you know, maybe they're at a, a cybersecurity space or a particular country or a particular vertical where they have, um, data concerns about sharing that with anyone. And so running authentic locally, or even air gapped in some cases, um, can be useful even for very small teams if they have those, those kind of specific requirements.
Excellent. Now, Fletcher, what are the, so let me back up. com for 12, 13 years, security Boulevard Cloud native.
Now, I'm, I'm very fam and I've been involved in open source 25 plus years, so I'm really familiar with the models and, and everything else. I, I wanna first dig in technically and ask you, and, and I'm familiar with IAM, right? I, I've always felt that that was the, the killer app of cloud security, right?
That was the biggest difference. Most of my security experience was free pre-cloud, you know, as an entrepreneur. And so was the Moton Castle error cloud changes, all that.
IAM becomes the, you know, focal point of, of your security posture there, I think. Anyway. Um, when you say enterprise class functionality for the authentic, uh, program, what are, what are we talking, you think?
Um, so there are specific integrations, um, you know, a significant, a significantly large enough company. Uh, you might have multiple IDPs in play. And so sort of orchestrating across those, or dynamically migrating off of some legacy provider, um, their compliance requirements.
So if you have government customers, you might have FedRAMP needs, we have a FIPs compliant build. Um, also other auditing pieces we've just introduced, uh, an event map so you can visually see where different, you know, logins or other actions and activities are happening. Um, so those, those sorts of things.
Uh, when it comes to scaling this out at an enterprise and making sure that you do so securely and in a way that you can, can easily manage ongoing, Absolutely. Um, you know, you look at most open source business models, your modern ones, right? And they give away the, I mean, obviously the open source project's free, and there's some open core is a very popular, uh, model.
Probably the most popular model is sort of, well take it from us as a SaaS, right? And then, and so you convert that open source, uh, software, that open source project into a SaaS offering, you know, and people pay for you to maintain it, improve it, secure it, et cetera. I didn't hear you talk about that.
Yeah, I'm not, so it seems like consciously, I'm not saying it won't happen. Uh, we've, we've laid most of the groundwork to help support that. Um, but somewhat to our surprise, we've had just a tremendous amount of interest in self-hosted ia.
So these are folks who are worried about reliability, worried about security. If Okta or Ping or whomever else, uh, entra goes down and none of your employees can access anything right now, the state-of-the-art solution is, well, you should train up and purchase two different IDPs and a third product that orchestrates between them and have a failover that's just too complex and too expensive. Um, so being able to run authentic on-prem or in your own private cloud where the rest of your infrastructure already lies, um, you know, we have cloud formation templates.
You can run that very easily in AWS or other standard providers. Uh, you could do that cross region. Um, but essentially you as the customer now get to choose what kind of reliability are we looking for?
What kind of usage are we expecting, uh, and have a lot more control over that, uh, in a, in a much more cost effective way than saying, I am as a service. I hope it works. Right.
Excellent. Um, you know, the mission of IAM has expanded, right? I, I think for a lot of people, you know, when they hear IAM you mention some of the players in there, right?
Like Okta and, and so forth, you think single sign on, right? And, and sometimes it begins and ends right there, but there's more to IAM today, right? You, you mentioned, uh, uh, active directory integration or, you know, the, an active directory is not the only directory out there anymore, right?
Uh, JumpCloud another company I'm familiar with in, in the IAM space, right? Uh, kind of a cloud-based directory, if you will. Um, when we talk about modern IAM and, and, you know, and what authentic does give us kind of the spectrum of, of what's in there.
Yeah. I think there, um, a couple dimensions there. One is there's a broad set of standards and protocols.
Um, so if you're speaking Skim or OIDC, you know, using Web Auth with ideally hard keys of, of various kinds and, and you know, those levels of security and integration with, with other systems, um, there are just a lot of languages to speak, though, a lot, a lot of protocols to speak. Um, uh, so I think that's, that's kind of the, the broad base of being an IDP today is not just can you do an OAuth handshake, but can you very flexibly support all these different pieces. Um, even to the point of, as you mentioned, starts with SSO, some applications haven't gotten that far.
Can you do a reverse proxy and support some of these legacy apps behind SSO, um, but then still maintain, you know, group ownerships and so forth. Um, so there's all of the r backside of, you know, now how do we manage across different teams, different sub or organizations and so forth. Um, so something you mentioned toward the start, I think it's becoming even more difficult and more important as we get more automation, uh, as we get more service accounts.
If you're thinking of, you know, your, your, uh, bots on your behalf, having access to who knows how many applications, um, so being able with authentic, to use Terraform, to use, you know, short-lived service accounts, things like that, that actually integrate directly, um, with your various applications in a very seamless way, uh, is, is core to every business now. Um, so that's also why, you know, everything you could do in authentic, you're not just clicking through a gui. You can, but it's also an API on the backend.
We want all of our customers to be able to automate as much as possible to use infrastructure as code, uh, to, to be able then to not have that, have that lock in and say, we're going to host it over here now, or we're going to switch this up, but in an assured way, uh, do, you know, a, a seamless migration from another service or whatever that, that next challenge might be. Excellent. You know, Fletcher, I, I don't think we've Reg, we mentioned the websites URLs.
Sure. Uh, so if you just look for authentic with a k, uh, A-U-T-H-E-N-T-I-K, uh, that will turn it up. io.
Um, but, uh, you know, you can find the project that way. Obviously there's, uh, lot at traction on the GitHub page as well. Um, we Were the, I was gonna say, I'm sure it's on GitHub.
Yeah. Yep. Yeah, A few months back, we ended up as the number one trending project on GitHub for a while.
So really got A lot of That's cool. Congratulations. Lot eye evolves From that.
Yeah, Absolutely. Very cool. Um, you know, we haven't really mentioned ai.
How can we do an interview without mentioning ai? What, what's the role, if any, for AI here, Fletcher? I, I alluded to the bots.
Uh, so, you know, if, if you have a lot of service accounts or agents, um, you know, acting on your behalf, uh, obviously you're going to want to secure those in the same and possibly more flexible automated ways. Um, so being able to, to support that with authentic is very important for us. Um, that said, from our side, internally, we're not looking to shove AI into features of our, our IDP, just for the sake of, uh, saying, uh, us too.
Um, you know, we're, we're certainly trying out all the latest and greatest tools in terms of development, but, uh, we also see the value in, um, careful human coding and human ingenuity still. So, uh, you know, we'll, um, we'll be a maybe a little more conservative than other folks to, to start announcing AI powered this and that. Uh, I think a lot of our customers are, are feeling, uh, a little wary from the amount of, of, uh, AI that's being pushed upon them from their own products.
Absolutely. Say that again. Amen.
Anyway, Fletcher, we're about outta time. I want to thank you for coming on Textron tv say, and, and getting us a little smart about what authentic and authentic security keep up the great work. Come back and visit us again soon.
Will do. Thanks so much. Alright.
Fletcher Heisler, CEO, authentic security here, Ontech Strong tv. We're gonna take a break and we'll be back in a moment.