Revolutionizing AI Management and Governance with Eve Security’s Nadav Cornberg
Eve Security, co-founded by Nadav Cornberg, addresses the challenges organizations face with AI integration. The company focuses on effective management and governance of AI agents, introducing an ‘agent in the loop’ concept for better observability and policy enforcement. Currently in beta, Eve Security is refining its platform with partners and has secured a $3 million seed round, preparing for an upcoming product launch to tackle critical organizational pain points.
Transcript
Hey everyone. Welcome back here to Techstrong tv. Uh, you know, I love introducing you to new companies and people who we haven't had on before.
So let me introduce you to our latest find, um, company's name is Eve Security, like in Adam and Eve. And if you look at their logo, the Eve sort of looks a little bit like an Apple. Um, and on behalf of Eve Security, we're happy to have Nadav Cro Kornberg.
Nadav is the, uh, co-founder and CEO and Eve. Nadav. Welcome to Techstrong tv.
It's great to have you on. Great To be here. Thank you, Alan.
So before we get into Eve, let's hear about Nadav. How, how did you chair Come here. Go ahead.
Um, I'll start on like half Israeli, half British, which I think equals an Australian in some ways. I've been in technology and product for the last 20 years. Uh, started in security from RSA and Checkpoint.
Had the privilege to kind of be on the endpoint side when it was growing at Checkpoint and really saw how you're taking an idea, excuse me, a small group of people and kind of growing something into a product that's then been sold to, you know, many, many companies and having a big impact. And you know, as I moved on and I even moved to different industries, uh, gaming, hospitality, my previous startup, uh, was in the hospitality space, but it was always the same drive from that origin, which was, we're solving a real problem, you know, now how do we make that into a product? Start small, grow that, you know, nurture it, see how it grows, build it up.
And that's always kind of been a drive of mine as well to kind of in that inter kind of world of being able to build something, understanding true problems. And I've always had affinity as well that kind of trying to understand operational pains and problems and then transforming that into automation products and then see how that is deployed in the, in the real world. So, you know, from there, uh, kind of February, March, you know, obviously AI is, you know, not new from the last year, but you were starting to see the real problems and pain points that, uh, organizations were starting to face.
Even my previous organization. How do we start handling AI and organizations? One of the new challenges and when we identified the gaps with the existing solutions and how to handle those problems, you know, I got, I had the privilege to meet my other two co-founders through mutual friends, and we really clicked together.
We all kind of thought and believed that that problem is just gonna grow and grow in, in today's dynamics of how AI agents are really evolving in organizations. Brought us to kind of found Eve and start tackling the problem of how agents are managed governed in organizations, in areas that matter. I Absolutely, I love it.
So I gotta go the, the Australian thing. You got me going with that. You, you didn't spend time in Australia or anything?
No, no, no. Just in the UK for five years and then in Israel for a majority Of my, I I could hear sort of that Australian thing going on there though. Um, so, you know, look, I, I don't have to tell you everybody, everybody is on the AI kind of bandwagon, or at least in the tech world.
I think it's gonna go through all over. What about what, let's start with this Eve security. Let's, let's frame it for people who maybe didn't catch it as part of the whole thing.
What is the problem Eve security is looking to solve? So when we were talking to, uh, more than 30 CISOs, the, the kind of the broken record that you were hearing again and again was people are asking me to deploy these AI agents and put them in the organizations. What's concerning me is what happens when I start connecting them to critical systems?
Okay. And uh, and the joke was, okay, if it connects to GrubHub and orders 20 sandwiches, uh, okay, it's not a big deal. But if it accidentally connects to a critical system like GitHub or NetSuite or Salesforce, Atlassian suite and starts messing around with those systems and you know, and can perform actions and not just read data, that could be really devastating for an organization.
So really we saw the emphasis was what could the agents do with critical systems and the terminology of, we want another set of eyes, we want to put them in a box, we want to police them. And the tools that they have today don't allow them to do so because the protocol, which is now the English language is just so different of what we've seen before. So they're facing this massive push from top grassroots department heads, all want to now achieve their business objectives, believing that AI is gonna be the force to do so.
'cause all of their competitors are doing so. And now the poor CISO now is stuck in between. Well, it's gonna be a, you know, on me if our systems get compromised because of that.
Yeah. Well today it's on the ciso. What's gonna be interesting is if these things don't work is intended, someone's, someone's head's gonna roll, right?
I, I was out at a conference last week out in uh, Napa for a company called Jfr. And um, they had some data, I think it was from Gartner, 40%, 40% of CIOs are increasing their budgets because their board, their board is pressuring them to do more AI gens and stuff like this. And so the gold rush is in, right?
The headlong rush into doing these is in, and, and look, I've been in security 25, 30 years myself, unfortunately, very few times in all those years has I, have I seen something where people say, wait a second, what about the security? Right? No, they, they dive in the pool and then figure out if there's water in it or not.
Um, and this is probably no different unfortunately. So what did you develop here at Eve to, to solve this problem? So when, when we were looking now at the problem, uh, and as this is being developed and the adoption is, is kind of growing in organizations, we understood we had to provide three key components.
The first one is observability. We need to give eyes on what's happening and in the most deep manner possible. And we categorize in, let's say four main questions.
What agents do I have in my organization? Who are they talking to? Which assets are they talking to?
What are they saying? What are the requests? What are the responses that are coming back?
And even to the depth of why are they saying that integrating with even the platforms that those agents were built on top of to understand the reasoning, why did they even attempt to make that request? The reason for that is if we can give that, give that in-depth observability and understanding of what we call intent and the data that's being requested, we can then put a layer on top of that of policy enforcement. 'cause I truly understand what the agent is doing and I can truly understand what the organization is asking for them to do and not to do.
And then I can police that. And now one of the feedbacks that we received as well from CSOs world, well don't give me a platform now that's gonna give me 5,000 alerts a day. I can manage that.
Which then brought us to the perspective of, well we saw some of our competitors mentioning agent, a human in the loop. Just put a human in the loop. Just add that's not been a skip.
So we built our first agent in the loop, which basically means we have an agent security engineer basically that is looking at all the events that are raised from the platform and then handling what we call the low risk or medium risk events based on their ability to interrogate the agent and what they're doing. So if they understand the risk and they understand the reason, we can make a decision. And just like any employee in organization, if I see a high risk item and I can't justify it, I'm gonna escalate it to my manager.
So if we can curate those very, you know, small amount or really critical events, that's when we generate value for that, uh, security organization. So, and the component that our agent in Loop is built on top of is we can understand anomalies which are new behaviors or repeated block behaviors that are impacting business continuity. We can understand the risk of the operation and we can understand the justification of why they're trying to perform that.
And with those calculations, that's how we can automate the process. And then the value that we generate for organizations are, they can have a full understanding of what's going on. They can police the activity with minimum overhead and minimum impact to business continuity.
Excellent. You know, as I look at this problem, one of the things, I don't wanna say it's unique 'cause it's, it's, it's probably more analogous to APIs, but your AI agent can be dealing with so many external and third party APIs, other agents, you know, interactions that it, it becomes, it's hard to police that, right? It's hard to enforce that kind of, you know, I guess you start with like a zero trust and build it up from there.
But it, you know, it's, it's sticky. These agents are sticky in that they can, you know, and now you got a to a protocol with the Linux Foundation and the MCP servers and, and all of these things, how, you know, it seems like a big job. It's, it's definitely a big job.
And I'll say that at the end. Um, the way that we built it is you have components, what we call sensors that are feeding information to us. MCPA two A and every API at the end is gonna be a data source for us to understand how these agents are behaving and what they're doing.
It's gonna be our job to normalize that and then be able to make a decision on that activity. Now we're giving two options for companies and we call those critical systems crown jewels 'cause we consider them like to be the crown jewels of an organization. And that's what we want to protect is those critical crown jewels.
Now we'll have an option to say, do you want us to detect and response meaning that, that the action has happened, but we can now still see its impact what it's done and give you an alert to handle that. Or we can give you, even give your abilities or block. Like we will actually sit in line and we've seen organizations now being open to both.
It very much depends on the crown jewel. There are gonna be very critical systems that they are gonna be very concerned about different types of activities that can have there and they really want to lock things down. On the other hand, it has impacts for business continuity and other areas they want to detect and response saying, I wonder after the fact if something happens and I wanna be able to address it, our agent in the loop as well can adapt policies based on behaviors and say, we've been too strict here.
We should open it up. We've been too open here. We need to stricter down.
So that adaptive continuous improvement is something as well that our platform provides. But yes, the complexity of what we're dealing now with MCP APIs and A two A is still a necessity for organizations now to resolve. They need companies like us now to step up and provide solutions for these new protocols due to the, again, forcing function of adoption.
I love it. Very cool. Nadal, I, I gotta spend a little time nuts and bolts for people who want to get more information about Eve's security.
Where do they go? Eve built security. They'll be able to go Eve do security EVE do security.
Hey. Exactly. They'll able to go and Do you have any kind of, uh, pre trial three product, something to get people started?
Yeah, de definitely. We've got now not only a design partner program, but a beta program as well that we have, that we work together with companies. And our focus now as things are evolving are really to make sure that we're solving and providing value for the pain points they're experiencing.
So very much we're working very closely now with all of our design partners and beta partners to ensure that and what we're hearing from them is like, great, you know what I mean? Like yes. You know, thank you.
Like when we, because we always start our conversation about talking about the problem and if they're facing it 'cause we like to mm-hmm classify the success that we can have of our customers or we wanna make sure we're investing our time with companies that are truly gonna benefit from our solution. So when we do that type of vetting, we talk about the problems, they're very much like, yes, that's exactly what we're facing now and we need help in that area. You know, we didn't mention, you guys recently announced a $3 million seed round.
True, I guess first money in and um, so it sounds like the product's still in beta. When do you think it'll go gp? Listen, I think it's, what I'm looking for is, is I would say I'm looking for multiple success stories that we have with customers to kind of pull that trigger.
I believe that's gonna happen in the next eight to 10 weeks as we're now working already with customers and we're receiving feedback and we're going through that. But at the end of the day at get you kind of that, that gets answered you by your customers, they're like super happy to reference about our experience. Well this is solving so many pain points for us.
Like, you know what I mean? Like how can we expand now too? This is gonna be what I've seen just in the past, the driving points for me to understand guys.
Yeah, we, I feel confident now of our product market fit that we've proven enough. Agreed. Very cool.
Nadav, I wish you a lot of luck, you and the whole team there at Eve Security. You know what, I'm going to hold your feet to the fire on this. I expect to see you back here in about eight weeks talking about general availability and, and what the customer reference customers are saying.
Okay. Pleasure. Alright.
It's a great conversation, a great idea. The Do Kornberg co-founder CEO of Eve Security here. Ont TechOne, stay tuned.
We're gonna take a break. We'll be back with more.