Snyk CIO Manoj Nair Unveils AI Trust Platform and Invariant Labs Acquisition
Manoj Nair, Chief Innovation Officer at Snyk, shares insights on the company’s mission to provide developers with security solutions. He announces the launch of the AI Trust Platform designed to improve software security using AI technology. Additionally, Snyk has acquired Invariant Labs to bolster the development of the AI Trust Platform.
Transcript
Hey everyone. Welcome back here to Text Drug tv. I am really happy to be joined by my next guest.
As he pointed out, I don't think we've spoken for a year, a year and a half, maybe more even. Manoj Nir, who I understand is now a neighbor of mine. He's the Chief Innovation Officer at sny.
I'm excited to welcome you to the Sunshine State, as they call it, and in the future, Manoj will be doing these in person here with me in the studio. So look forward to that. Manoj, welcome man.
How are you? Good, good, Alan, really good to be back talking to you and yes, definitely in person next time. Good, good, good.
So, Manoj, chief Innovation Officer, everybody mixed up a title these days, but we've heard chief Innovation Officer before. What's your take, what's your role there at Snyk? Uh, great question, Alan.
So I came, I've been here at Snyk for three years, and I came in as the chief product officer. First two years it was all about, you know, the hypergrowth company now getting used by the biggest enterprises in the world. And so that was the mission.
Um, you know, we went from a portfolio of products to platform that Fortune One down can use us and, and at scale. And so, you know, going back to my entrepreneurial roots, uh, this innovation officer mission is very connected to a lot of the conversations we'll have as we saw this Gen AI wave take off. What we have done is, you know, we we're gonna talk about our acquisitions, but we have a lot of entrepreneurial CEOs at our company.
And so we're incubating, you know, future bets and products, uh, and working very closely with those really big customers as design partners and some of the strategic partners that are investors in Snyk. So we've got this very interesting, you know, triangulation going on between technology partners of the likes of Google, Atlassian, uh, Salesforce, ServiceNow for all investors in Snyk, but now we're getting co build with them and then really large customers who are, you know, helping us incubate startups within snyk to solve some of these next generation of problems. So that's my role.
I Love it. Love it. We mentioned sny.
Look, I think most of our audience is familiar with snyk, but you know, this goes out on the internet to hunt to the whole tech strong network, and it's on LinkedIn and Facebook and X and YouTube. There might be people watching this that are not familiar with sny. How would you describe SNY to them?
Sny. Um, so now, you know, and you'll know soon, it's really simple in it's genesis. You know, for people who spend time in security and have been engineers, they'll understand this, uh, comment I'll make, which is computer science is one of the few engineering professions where safety is not required in the curriculum.
And so we're very surprised when there's a lot of vulnerabilities in everything that we're building and open source and first party code and AI generated code. They're all kind of feeding off from that foundational issue. The SNYs mission's, very simple, empowered developers with context automation and education right at the moment, right?
And so that's been branded with terms like shift left that I think, you know, if you like it, you can credit us. If you don't like it, don't blame us. But you know that that's the mission we started.
Let's move this problem from being a runtime problem that you are always, you know, tall walls and moats around castles. And instead of that just go to the root of the problem and imagine the productivity improvement when you're not chasing issues. What if you can prevent issues?
So this has been our mission. We're focused on any company that is building software and applications, which is basically every company now. And you know, now with our new platform, we're also focused on companies are building their AI software.
And so that's the mission. We have been every layer of an application all the way from code to open source to container to infrastructures code, to the AI stack. We are securing that, but by doing it right at the spot that I think it needs to be done, I love it.
So now, you know, I remember that from years and years ago. Um, so mano, I have a confession to make. You're not the only person at Sneak I talked to, uh, I've developed a relationship with my friend Danny Allen, who's now the CTO there.
We've been lucky enough to have Danny come on the show a few times, and he's been telling us a little bit about what's happening at Snyk. Just I think about two weeks ago, maybe less, he came on and we spoke about this new AI trust platform that Snyk put out there. And it's really, you know, uh, I mean, it it cutting edge, right?
Industry leading type of use of AI to help developers to help organizations deploy secure code secure applications, be more secure using ai. Mm-hmm. Hot on the heels of this, you guys announced today an an acquisition.
Tell us about it. Yeah, I think great. Uh, um, you know, uh, a great connect there and, uh, to what Danny just talked to recently about the AI trust platform.
And, you know, just think about AI adoption for a second before we even get into snyk and, and, and the platform. We see like various stages, uh, of AI adoption, and it depends on organizational maturity. But you know, just like, uh, you know, but, uh, some 10, 20 years ago, uh, I think Mark Andries said, software is gonna eat the world.
We believe AI is gonna eat software, and it is doing that. We're seeing that, but how does it do it in phases, right? And so the first phase of AI adoption, especially in the software, um, development realm, seems to be in the use of copilots and various, you know, it's Microsoft GitHub copilot or the hot new agent AI coding assistance like Windsurf and cursor and codes being generated using these LLMs and Gen ai.
But a lot of that code is trained on, you know, vulnerable code. That's basically what most of the open source code out there between that and the nature of hallucination of, you know, which is part of the magic of LLMs. There's also security issues with these.
And so our first starting point was, I would call it the, the, this January after the chat GPT December, 2023, we started. And, and some of these very large organizations started calling us saying, can you be the guardrail? Those who knew about this?
Now everyone does. Now there's a Georgetown study that says there's 40% of the code is insecure, or Stanford, or all these organizations have studied and researched this so much more well known problem. And so the pillar one was really about how do we make sure that the guardrails are put?
Because you cannot just be productive without security. In fact, it'll, it'll have an opposite effect that you're just generating a lot of insecure code and it's going out and, um, you know, we are having to fix it after the fact. It's the opposite of productivity.
So that's one of the pillars in the next pillar now that we're seeing is organizations are going, you know, those who have successfully done that phase are about to go about building AI native software. They're building AI software themselves. It could be a, a front end, you know, agent if you're a hotel or a bank, these agents are now showing up in external facing applications to drive a lot more productivity for these companies.
And so that's that next pillar. And our AI trust platform that we launched was across all these pillars, it was us using AI to accelerate our original mission. DevSecOps, how can we automate actually fix issues?
So we have AI fix, we have an assisted agent fix. Uh, we were doing things like prioritization and reachability using our AI techniques. So it was just accelerating that DevSecOps mission.
Well, we started talking about this next phase. We showed examples, demos, things like our AI security, posture management were directly targeted at that next pillar. And that next pillar, you have to start with visibility.
I've been in conversations, you know, you sit down with the CISO and go, you know, how many, uh, um, apps are you using? Uh, or how many models and agents are you using? And the answer is, you know, not many.
And then you talk to the engineering teams and they'll go thousands. And so CISOs and security professionals, you know, if they're not able to see what's there, they're not able to give instructions and guardrails and governance. So we started with visibility and then we started looking at what else could be done.
And that brings us to the acquisition, right? Well, we saw with the visibility phase was a lot of, you know, what do I do next questions. So I found people using agents, is this secure or is it insecure?
And so that's the context. We've been working on it as part of that launch. And today we're able to announce to, to the world that we acquired in Variant Labs, that's really going to accelerate that AI trust platform.
So hopefully that journey on this whole AI mission, you know, now gives you more context. Absolutely. Absolutely.
com days. I was part of a helped build a company that we did 30 acquisitions in 36 months, almost one a month. We got good at it after a while.
But, you know, all kidding aside, acquiring a company is sometimes just the first step, not the last step. Learning how to integrate that company, how to not have brain drain, how to take the IP and, and make it sneak a fire, it, if you will, right, is, is a talent and skillset unto itself. Now, as I said, this is your 12th acquisition.
It's not like you haven't done this before, but when do you think the invariant know-how IP expertise finds its way onto this AI trust platform? Great question. Um, we have, uh, something as part of our AI trust platform also launched something called Snyk Labs.
io, what we started is started doing our incubations in a very public design partnership mode. So we show here's what we're building, here's the research. We're also doing research on these new threats because, you know, the problems with AgTech AI and, uh, you know, gen ai, I can say non-deterministic till I'm blue in the face, but you know, that doesn't mean people understand that.
So part of what we will do is bring in variant into that SNCC Labs umbrella and start, and then, you know, they're very much research minded. They're the leading researchers, I would say, as we looked around in this very specific domain about what security risks exist for Ag Agent AI usage. And so we'll continue that research mode.
So there's immediate value that customers and the world actually gets is we will amplify their research and accelerate those research findings because we're still the world's still figuring out what these risks are. For example, in Arian Labs team was the one who found this term called tool poisoning. You know, how do you use agent AI and model context protocol to go and poison that gives the AI supply chain risk now?
And so those kinds of research is super important so that that continues without a pause. In fact, it gets amplified under the Snyk Labs umbrella, and then there's technology solutions that they started building. Part of what we're doing with Labs is, as I've mentioned, these very large design partner customers of ours, we actually talk to them as part of the acquisition process.
So these are very trusted customers. We'll tell them, look, what pain points are you having? We're seeing this.
We think this is important. Are you deploying agents in, in production? So they're already expecting to now try out some of this tech and harden it and get it ready for the enterprise?
And so we think all of that is by the end of this year, you know, these customers would've given their feedback and now we would've incorporated that sneaky fight it. I love that. I think you've been talking to Danny Allen, so, uh, uh, we do that too in parallel and get it in the hands of customers, you know, sometime later this year.
Fantastic. Well, no, we're about outta time 15 minutes ago, so quickly here, but I am, uh, first of all, congratulations to you and the Wholes Sneak team as well as to the Invariant Labs team as well. com the, the chairman of the board was this gentleman, Len Faser.
He was the mentor to a guy named Brad Feld. Brad's a very well known venture back guy, one of the co-founders of, uh, Techstars and stuff like that. But Len used to say something to every company, I'd go with him when we'd close, you know, handshake on the deal, and he'd say, look, be very proud of yourself if you built something that someone's willing to write you a check 'cause they value what you built like that, you, you should be very proud of yourself.
So congratulations to the Invariant Labs people as well. Next time my friend, we're here in person talking about these things. Maybe we'll invite Danny, maybe we won't.
Who knows if he'll be here. But, uh, thank you for coming on and, and telling us about this key acquisition building on this whole AI trust platform. You, you reminded me one last thing, Alan, this I, you know, this is probably my 20th m and a in my career on either side of it being acquired, Uhhuh requiring, and you know, absolutely Mark and Luca and then Variant Labs team and the research professors that they spun out backing them.
Major kudos to them. This is probably the most hotly contested acquisition in, in, in my entire career. We had come the trillion dollar plus market cap, you know, trying to chase these guys.
So partly they also picked sneak for all the things we talked about, and that is very, very, And that's what makes a good fit. Yes, sometimes it's not, you know, the early money isn't the smart money sometimes when it comes to these things. I, I, like you, I've been on both sides.
I've been lucky enough to been acquired, you know, had a few, uh, exits like that and then done acquisitions. That's what keeps it interesting. What can I tell you?
Osh again, thank you. Thank You. We'll be in touch.
Good luck to sneak in every, all our fr all our friends there. Thanks Alan. Talk soon.
Alright, Manoj na Nir, chief Innovation Officer, sneak here on Tech Drunk tv. We're gonna take a break. We'll be back.