Guarding the “Wild West” of Agent-Driven Code
We’ve spent decades trying to train humans to write secure code and failing, but as Endor Labs Founder and CEO Varun Badhwar joins us today, it’s clear that we finally have an opportunity to get the agents to do it right. With AI coding assistants now producing 61% functionally correct code—but only a staggering 10% of it being secure—Endor Labs is stepping in as the critical “security intelligence layer” to triage backlogs and vet the 2 million models on Hugging Face at wire speed. We’re moving into a watershed era of “vibe coding” where marketing teams are pushing PRs, and if you aren’t using AI to combat AI-driven vulnerabilities, you’re essentially leaving the vault doors wide open for autonomous attackers.
Transcript
Hey everyone. Welcome back to Tech Trunk tv. You know, man, there's just so much going on every day.
I'm really happy to have this next gentleman I'm gonna introduce you to. His name is Varun Badir. Varun is the founder and CEO of Indoor Labs Company you may have heard of, but if you haven't, don't worry.
We're gonna get you up to speed there. But first, let's welcome Varun Varun, welcome to Text Trunk tv. It's great to have you on here.
Great to be back here, Alan. Good to see you. Absolutely.
It's been a while. It's been a while, and I, you know, it must, I'm, I'm thinking it's, it's our RSA time. All my security folks are coming outta the woodwork.
Right. But, uh, it's good to have you here, Varun. We're gonna talk about indoor labs.
I want to talk a little bit about AI generated software and what we can do there. But let's first talk about you a little bit. People not familiar with your story.
As I mentioned, you're the founder and CEO at Indoor Labs. How did you know, how did, where did life take you from two to wind up here? Yeah, great question, Alan.
So, I've been building cybersecurity companies for the last 16 years. Uh, it's always been at this intersection of large shifts in technology. So my first company in 2010 was a company called CipherCloud in securing SaaS applications in the enterprise.
Right? People were freaking out, my data's gonna be with somebody else outside of my network, outside of my VPN. How's that gonna work?
And so we solved that problem. That whole category was called CASB, then came known today as kinda sassy and, you know, more, uh, kinda the zero trust architectures. And then in 2015, I saw a bigger wave coming, which was around, um, you know, moving from data centers to Cloud infra us.
So started a company called Red Lock, uh, in which was the defining company for cloud security Posture management, uh, that got acquired by Palo Alto Networks in 2018. Uh, and we rebranded to Prisma Cloud. So I think a lot of your viewers would've heard of Prisma Cloud by Palo Alto Networks, uh, which is kind of the, the, the Palo Alto Wiz equivalent product in the synapse space.
We defined it with how executed us, but, you know, kudos to them. And then, you know, swallowing the spirit of the large tectonic shifts in technology. While I was working in Palo Alto Networks, I had 400 engineers reporting into me.
The summer of 2021, SolarWinds happened and everybody started talking about software supply chain security. Sure. And for me, the biggest, uh, eye-opening moment was the fact that, um, you know, 80% of our code wasn't even written by our developers.
And it came from the wild, wild west of open source and everywhere else. And so we kind of said, how do you actually build software supply chain security for this modern ecosystem where your developers are mega assemblers of anything and everything available in the ecosystem? We made a bet.
We went really deep in understanding the risks around open source software. And long behold, AI coding agents came along two years ago that were all trained on open source, and now they're replicating more and more coding patterns that they have learned from code on GitHub and everywhere else. And wireless.
It's become the hottest, most talked about subject in AI today is just AI software development agent software development. You know, the thing that's really hard is engineers want to continue to innovate and move fast. And every security control and application security typically tries to slow them down, right?
So there's always this trade off of security or speed. And we said, look, there's gotta be a way to do security and speed in the software development lifecycle. And that kind of brought me to end or labs.
And today, the world's most prolific software companies, technology companies, financial services organizations use indoor labs. You know, whether it's Cursor, whether it's Atlassian, snowflake, Dropbox, um, we're just incredibly proud to support the future of software. I love it.
You know, Varun, what you just described was a lot of the reasons why I first, you know, got into DevOps. I I really thought that DevOps gave us the opportunity, you know, it was like that old song by the singer, meatloaf two outta three ain't bad, right? You Well, it was like you couldn't have quality speed security.
You couldn't have all three, though. Some one can argue quality and security are similar or the same, but you know, you, you just, you, you couldn't have it all. If you got two of them, you were really happy.
And I felt like with DevOps and modern, you know, agile to DevOps shift left software supply chains, we could have it all, right? Yes. And they call me selfish and, you know, and all everything else, but I want it all right.
I want secure software that we're going really fast. So, you know, it, it's very, I I think it's a wor it was a worthy goal and I think indoors made a hell of a lot of progress in, in helping us get there. Of course, the world has kind of cha it's changing on it.
These last three weeks have been like watershed weeks. I think as we look back, we're gonna say, Hey, you know, after the first of the year, things just really went bonkers. But how is ai, I mean, AI's having a profound impact here.
How's it impacting your world? Look, it's an incredibly exciting time for us because there's more lines of code being produced faster than ever in every company. And frankly, a company in middle America that never even considered themselves to be have a technology advantage.
I speak to them and today they feel like they do today they feel like they can compete with the mega Silicon Valley companies. 'cause they have the tools where there's 70 developers in South Carolina can actually go build market leading technology that will help them drive their revenue as a company. And so every company is certainly becoming more and more of a software company today than ever before.
Yet, Alan, the thing that's always happened time and time again is these shifts bring more ways for people to develop and innovate faster. But that also means if done unguarded, you're gonna have a lot of security risks that emerge into these new applications and architectures. Guess what happens?
It's no longer just your trained software developer's writing code. It's even my marketing team and my sales team writing code and pushing prs, right? So the whole vibe coding thing is happening at the speed at which you're moving.
No human, not even the most trained professional software developer has the time to review all of the verbose outputs of the AI coding agents. And so, you know, we said, look, let's tell you this, the models are getting significantly better and will continue to get better at providing functionally correct code. In fact, Columbia University and Carnegie Mellon just did a study in December with Claude four sonnet and it was impressive.
61% of the code produced is functionally correct. You wanna guess how much of that is secure? 5%.
I would say 20. Yeah. Uh, so, so you know, the, the thing is, these models are all trained on open source software.
They've learned the good practices, but they've certainly learned all the vulnerable patterns of writing code. And they don't have an easy way. It's not easy to filter and unlearn the stuff that's not great that you don't want them to replicate.
And so, as an enterprise that is promoting fast software development, I now need to put the harnesses to watch out for all of this code, review it, make sure we can rewrite it without vulnerabilities, make sure it doesn't introduce new business logic flaws. Like turn off session time out in your application because you told it to go build a new API endpoint. And so you need the guardrails, you need AI to combat that ai.
And the last piece is context of your applications, right? It's great if you wanna produce some new lines of code, but in a typical organization, you're maintaining historical applications and architectures and then you're building on it. How do I give my AI agents context about my existing applications, my coding practices, my security practices and requirements, my compliance obligations?
And so you need this security intelligence layer that's really missing as it comes to secure agent software development that the models don't have themselves. And so, and or is now becoming very quickly that security intelligence layout layer in the agent software development, which essentially helps customers do three things code really, really fast, but free of vulnerabilities, be able to automate review and security reviews and threat modeling and design reviews of all the code that's produced. And the third thing is fix vulnerabilities that are disclosed genetically really rapidly.
So you're no longer pushing a million tickets a year to your development team in their backlog, but rather working with them to be generate this flywheel to triage and fix vulnerabilities that can affect you rapidly. Because Ellen, the, the problem is the adversaries have access to AI tools as well. Just because you take six months to fix something doesn't mean they're gonna wait on you for six months to go attack you and exploit a new vulnerability.
It would be nice if they did, but neither the world don't work like that and, and that, and that exactly is it. You know, and I like you, I speak to a lot of people, speak to a lot of different organizations and, and you're right, the feeling out there today is, my God, I could build anything. I could build anything, right?
I have friends, executives, founders, past founders, serial entrepreneurs who have ENC coded in 30 years, 20 years who are saying, if I start a company today, I could build the whole thing right? In a couple of days it seems like, and have an MVP up there and I don't need to hire a couple of dozen people. It's game changing.
But at the same time, you know, we saw it with the, uh, the open cloth thing. Are we, are we thinking the right way about security? Are we building it in or are we gonna say, okay, we'll we'll catch up to that, right?
Um, and, and sooner or later comes back to bite you, right? We've learned this lesson how many times in our careers, if you don't do it in the beginning, it you pay the price. And, and you know, the interesting thing, Alan, is we've always tried to train the humans to do it the right way and we've failed at it, but now we have an opportunity to get the agents to do it, and they're pretty darn good at doing stuff if you give them the prescriptive guidance of which you want them to get done for you.
And so for us, that is why I feel like it's security in the shift left arena, when you were talking about DevOps DevSecOps, you know, it started with CICD pipelines and scanning the pipelines, then we said, no, let's get into the PR workflow and let's scan the pull request. Now, fundamentally to me today, it's how are you creating security experts that are pairing with your code generation agents in the agent software development workflow, well before it even becomes a pull request. And so the way, for example, and or surfaces the tooling for customers is you're in cursor, your in cloud use your favorite tool.
Those tools know that they need to be reviewing all the code they're producing with indoor. We give them continuous feedback. You can literally see it in the spec.
They're rewriting the code based on our feedback. When they say done, you know that there's gonna be vulnerability free software because Endor has helped cursor or claw or copilot just produce the code right from the onset. And so now I don't have a backlog I have to deal with, or if a new vulnerability is comes out in, in three weeks, I don't have to put it on a human to fix.
I'm gonna tell the agent where the vulnerability is, how to go upgrade that without breaking your application and then let it go, execute that action really fast and test your application. I love it. I love it.
So Varun, uh, I gotta ask a hard question, right? We're all talking about ai, we're all telling, telling each other what a great world it's gonna be, but rubber, at some point, rubber has to meet the road. Mm-hmm.
As we sit here today with Endor, where, where is your AI security, if you will, how real is it, how built in, is it, how widely used? Is it, right? Is is it here or is it still something we're talking about?
Well, as I mentioned earlier, you know, some of the world's most prolific software companies, the biggest AI company in the planet, all the way to the biggest coding agent company like Cursor on the Planet to Atlassian, snowflake, MongoDB, uh, they're all customers. They're actively every single day building and shipping a software that is secured by indoor labs. So it's here, it's working, it's scaling.
Um, for us, there's two parts to this, right? There's how are we using AI internally to solve decade old cybersecurity problems? Mm-hmm.
I'll give you a real example. You know, when you run all of these code scanning tools, you get like 50 to 80% false positives. Alan, like the stuff that they find may theoretically be a problem, but when a developer looks at the entirety of the application architecture may find, well, yeah, I'm not doing any validation of input here, but I have a framework here that handles it for me to repos or two files away.
That's the rate reality of modern software security tools. Never were able to understand them and or AI SaaS actually is actively for our customers today, automating that entire triage and investigation process and reducing the backlog by 70, 80, 90%. Saying like, look, you're safe.
Sure there might be a theoretical problem here, but we see it in the entirety of your application flow. It's no problem. So we're using AI to deliver better security outcomes.
So that's one. The second, Alan, is we're helping our customers adopt AI more safely and with confidence. An example being if you're trying to pull one of the 2 million models of hugging face and deploy it as part of your application indoors, doing all the scanning for supply chain risks, malware, you know, malicious pickle files, all of that as you're going and grabbing open source models from the internet or you want to use PI Torch, making sure you're getting a secure version of that from pi pi.
All of that analysis for malicious actions. Because look, the attackers know this open source ethos is a wild, wild west, right? We saw Shy Ude as a, uh, large attack campaign, a target open source.
And you know, we're seeing more and more of that, which is where we are able to protect the AI supply chain for our customers so they can adopt AI faster or they can use Cursor to write code faster. And so yeah, both facets of, uh, addressing decade old security problems with ai, as well as empowering you to use the latest AI tooling is something that's front and center here available now to use Arun. We're about outta time.
You know, we didn't mention Indoors website though. Can you just give us a know you, you know, what's the website? com.
Check out, um, you know, our recent announcement of our Newgen software development security platform called ori. com. I love it.
Varun, will you be at RSA? I'll be at RSA. And I look forward to meeting you and, uh, anybody else interested in catching up on this, uh, on this topic I'm extremely passionate about.
As you could tell, I know you are. I'll be a broadcast alley all week. Stop by and say hello.
Will do. Thanks so much. All right.
Varun Badis, founder and CEO of Vendor Labs. Hey, you know, doing what a good CEO and company needs to do today using AI to secure software, Varun will be in touch. Thank you very much.
We're gonna take a break here on Text Trunk tv. Be back.