The Cyber Team as Code Producer
For 20 years, security lived one step behind engineering — chasing vulnerabilities, running assessments, and pushing developers to build things more securely. Tom Tovar, Co-Founder and CEO of Appdome, joins Alan Shimel on TechStrong TV to make the case that AI is finally flipping that script. In a wide-ranging conversation covering 11 years of building Appdome with CTO Avi Yehuda, the wild-west state of mobile security in 2015, and where the cyber function is heading next, Tom argues that AI is transforming cyber from an evaluator into a producer — arming security leaders with their own agentic pipelines to code protections, anti-fraud, bot defense and ATO controls directly into the application. He unpacks why segregation of duties still matters in an agentic world, why cyber needs its own sovereignty and its own models, and how a unified threat-data schema lets security teams build the kind of proprietary IP that used to belong only to engineering.
Transcript
Hey everyone, welcome back here to Techstrong TV. Let me introduce you to our next guest. His name is Tom Tovar, and no matter what I do, I can never roll my R to make it sound as authentic as he can.
But Tom is the co-founder, CEO of Appdome, and we're happy to have him on here. Tom, welcome to Techstrong TV. It's great to have you.
Yeah, Alan, thanks for having me. I look forward to the conversation. All righty.
Tom, I mentioned you were the co-founder and CEO of Appdome. Give us a sense of how you came to be. How Appdome came to be, how you came to be the co-founder.
What drove you? What's your journey been like? Yeah.
So, I'm a latecomer to this whole notion of being an engineer, coding things and so forth. I kind of retrained myself as my midlife crisis, and I kind of retrained myself as a coder. And in the process of building mobile applications and things like that for myself and for fun, I came across this challenge of how to protect the application and the experience that I wanted my users to have.
And the tools and the products that were out there were very challenging, very cumbersome. I had to download things, I had to learn things. I had trial and error.
And so I built a machine to do this, and it became the start of an idea. I called it a vending machine for mobile app security at the time. I didn't have any funding or anything like that.
I took the concept to Menlo Ventures, a friend of mine there, and he said, "You know what? This sounds like a great idea, but let me do you one better. There's this company that exists called Appdome," that was building a slightly different product at the time.
" Yeah, exactly. Do justice. Right.
So, the lore of Appdome is I went-- I didn't know if this was a good idea or not, but I went and I met with the CTO. His name's Avi Yehuda, and he's my partner for all these 11 years. And we were only supposed to meet for 45 minutes, and we spent eight and a half hours talking about technology, talking about architecture, talking about platforms, talking about, at that time, AI or using machines to deliver outcome.
Remember, 10 years ago, 11 years ago, talking about those things was revolutionary. Nobody was thinking machines were going to deliver outcomes for humans. That just wasn't a thing.
" And we were like, "Wow, that's a big number. " But we hit it off. Yeah.
And that partnership really was the foundation of Appdome. The fundamental premise at the time was that security or protection of a mobile app and its experience is going to get more sophisticated over time. And as it does, humans, the developers, the creators, artists, creators of products, need an automated way to protect the thing that they're building and protect the experience that the user's going to have when they sign into that app.
And so our goal became how much of this work can we offload onto a machine, and how do we make that machine better and better and better over time so that it can deliver on the promise of total protection for the mobile experience? And that's what we've been doing for 11 years, and the product's gotten a hell of a lot smarter. It's gotten a hell of a lot broader.
It's gotten a hell of a lot better. It's added lots of bells and whistles to make it easy on people, lots of integrations to connect it to the pipeline. And thankfully, we've hired, in this course, some amazing engineers that have come on and now take over kind of the future and innovation of it.
So it's become a life of its own, and we're very proud and excited about where we are. Good for you, man. And you should be proud.
As I said before we started, I've started three or four venture-backed companies, and then Techstrong, which was not venture-backed. This came out of my blog. But I know what it's like.
I know what it's like to breathe life in every day, especially in the initial phases, right? If you don't believe in it, who will? And every day is making those donuts and doing what needs to get done and wearing a lot of hats.
A lot of people don't realize that the longer you're at your startup, the more hats you can take off. Yeah. You don't want to put more hats on, you want to take hats off.
Yeah. And 11 years is a long time, right? " No, there's 11 years of blood, sweat, and tears in there, man.
Yeah. And a lot- So I get it ... yeah, and a lot of- I get it ...
thinking you've got it figured out and you don't. A lot of saying- Right, well- ... " And that never ends either, right?
Look, I've been around the block a few times. You do learn more, you have seen more, but you never stop learning. Yeah.
Especially, look, the world we're living in now is a great example of what you thought you knew, you didn't know, or what you thought you were doing, we're not doing. And it's It's a historical crazy time that I'm glad I'm able to be involved in. Yeah.
But it's also a time where a lot of bedrock things that I grew up on here, cut my teeth on, are changing. Every day. I wanted to, before we get into that, though, I just want a little housekeeping.
For people who want to know more about AppDome, what's the website, Tom? com. app.
Easy enough. Yeah. Easy enough.
Now, over 11 years, so that takes us back to 2015. Think about the world in 2015. Mobile security.
It was a little Wild West in the mobile security world in 2015. To a certain extent, it might still be today, but it was worse- Yeah ... then, I think.
Yeah. Clearly. Yeah.
We've evolved. Oh. I would say back then, it was picks and shovels.
Now, I would say it's a little like gold rush towns that are popping up. If somebody has an app that becomes very successful, you'll have a little economy build around it and so forth. And then you wait for the next big hit to show up, and as applications grow up, first you have the prospectors, then you have the shops, and then you have the saloons and the hotels, and more vendors start coalescing inside these.
But these days, I think we're at a stage in the evolution of mobile, it dominates, by the way, the commerce and engagement of users. Mobile, just think of how we order- Sure ... food or trade stocks or check our balances or whatever.
So as mobile started to tip the scale above the digital, above the web, organizations started to get serious about it and say, "You know what? We need to make a real town out of this thing. We need to start planning for the future.
We need to have infrastructure. We need to have services," et cetera. And so they started to think, I think, more longitudinally about how to protect the business, the mobile business.
But Tom, when I think back about it, it was more about, and to a certain extent, this hasn't changed, how do we get the developers to be more thoughtful, careful about building secure code when they're developing these applications? And of course, we came all kinds of things. The SDK that we would give the devs to run on.
The whole world changed in how they build it. They didn't build bespoke code from scratch. A lot of them started taking down from repos.
Artifacts, snippets, distinct functionality. Now comes AI. Why go download something when you could just ask the AI to do it bespoke for you right here?
We don't need that anymore. Maybe, maybe not. But it's made for a change.
What are you seeing from where you sit? Yeah. I'd say a couple of things.
So first off, AI is definitely challenging all the paradigms that we know and love, and the big questions we asked in the past are quickly becoming irrelevant now. These days, you don't actually have to train developers to care. Because increasingly, the agents will code security into, let's not say code security.
Will code applications securely, meaning they will code applications free of vulnerabilities, free of CBEs. And so as you start to think about that, machines actually taking over that function, where does the cyber role fit, and how does it change to adapt to this new reality? Is it still an assessment, an evaluator function, or is it changing?
Is it becoming more part of the production line? And we believe, and we see out in the market, that the role of cyber is changing from evaluator to producer. In other words, the people who adopt our product are no longer looking for vulnerabilities.
They're delivering active protections into the application. " They're saying, "My job is to be an active participant in the software development life cycle, and I'm going to add the security, the anti-fraud, the bot defense, the ATO protection. " So I think this world of where cyber sits behind the engineering team and pushes on the engineering team, and you needed to have security champions, and you needed to have teach-ins and all this kinds of stuff, I think that's moving away.
Cyber is saying, "Hey, wait a minute. " And that step, that's huge. That's like tran- Yeah Beyond huge.
Because after 20 years of banging our head on the wall, trying to get developers to be serious, not that they're not serious, I don't mean to use that word, but to be more dedicated about building that security in. We have these agents who don't say no, they never take off, and that we can kind of make finally someone listens to us about security being really important and make sure you build it in. The interesting thing about the challenge that we used to face, and maybe the better option is to take what we call segregation of duties, where engineers do their job, cyber does its job, and you have centers of excellence build on either side.
The engineers are good at building workflows and payment and user experience and things that attract the user to the application. And cyber is responsible and great at protecting the business. And so if you can say in this agentic world, we're going to transform human segregation of duties into agentic segregation of duties and arm the cyber team with their own agentic platforms to code the protections into the application as part of the pipeline.
You have the best of both worlds because you still get the oversight and the governance of the cyber team, right? And you still can maintain the segregation of duties and the centers of excellence between the engineers and the cyber function. I think that's where it's going, personally.
I think that people are thinking about how AI will help engineers be cyber coders, and I think it's actually going to help cyber teams be cyber coders in there, because you need to preserve that segregation of duties, and you need to codify that in the agentic systems that are used to produce the outcomes. That's where I see my customers going. That's where I see the market going, and I think it's just going to be wildly, it's going to be fun times.
Yeah. No, but you know what's nice, Tom? That's a- Yeah ...
it's a, now I don't want to use the word optimistic, but it's a positive outlook, right? We hear one of, I think, the biggest knacks- Yeah ... wraps on AI right now is we're getting all this pessimistic stuff, right?
It's taking people's jobs. It doesn't work as good. It's this, it's expensive, it's that.
I think when we talk about security, it's funny, I started what's today Techstrong. Yeah. com because I had gotten into DevOps early 2012, something like that.
And the reason I got into DevOps is because I spent the last, since 2000, 1998, I've been in security, InfoSec. We didn't call it cyber then. And I felt like DevOps was our last great hope to get security right in development.
We helped a little. The whole DevSecOps thing helped, but it's still far from perfect, as we know. I feel like this AI thing is yet another bite at that apple of righting past wrongs in terms of getting this right, whether we're talking about mobile security or general cyber or what have you.
So I'm in your camp. I'm an optimist- Yeah ... about what this could mean for us, what we could do better.
Well, don't get me wrong, there's going to be some massive disruption. So for example- Oh, yeah ... let's assume you're a vendor that sells a point product.
Let's assume a vendor who relies on manual implementation, SDK-based implementation or whatever. You're going to have a hard time living in this fully autonomous agentic world. That's just a reality.
And if you know DevOps, then you know that engineers and businesses are now built around machine-to-machine communication, automated pipelines, and human governance sitting above those systems. And so AI is just another evolution of that same architecture. It's not like a- It's a scale.
It's a scale issue. Not an issue, but it's a scale multiplier. Exactly.
Right? So all of those things we built, but we built them for human senses- Right ... and human speed, if you will.
Now we've got to get used to doing them at AI scale, which is going to mean you've got to build scale from tip to tail across the entire thing here, because you can't afford, it's not going to wait for you. Yeah. And cyber- It's just going that fast.
But we will. I'm more confident than ever we will. Yeah.
Because we have to. And cyber can't use the same system that the engineering team is using, obviously. Got to have its own.
No. It's got to be, like I told one customer, it's got to have its own sovereignty. It's got to have its own pipeline.
Mm-hmm. It's got to have its own future. It's got to be in charge of its own agentic outcomes.
One of the things I'm most excited about is the nature of unified threat data. So now, today, you got, whatever, 17 point products or whatever, and they all have different data schemas, right? One calls an attack an attack.
One calls it an event. One calls it a threat. One calls it a risk.
Imagine taking that divergent data stream and plugging that into an LLM. You're going to get random outcomes. But now let's assume you're using a kind of all-in-one agentic platform with a common data schema.
I, as a cyber leader, I can start to create my own models. I can start to create my own fraud models. I can start to create my own IP inside my cyber organization that gives me a competitive advantage to stopping fraud or ATOs or social engineering or whatever.
I can start to create my own models for the future and not be heavily reliant on vendors because AI allows me to do this. So internally, for the cyber team, it's going to be very empowering if they take the leap. If they don't take the leap, then obviously it's going to be a risk.
But you don't go forward either. If you don't leap, you're stuck. Anyway, Tom, we're way over time.
I got to pull the plug here, but hey, thank you for coming on. com, check it out. Tom, come back.
Let's continue the conversation, okay? Absolutely. I very much enjoyed it.
All righty. Tom Tovar, CEO, Aptome, here on Techstrong TV. We're going to take a break.
We'll be back with more.