Why AppSec Needs an Agent Experience, Not Just a Dashboard
AppSec was built for humans clicking through dashboards — but vulnerabilities now get weaponized in minutes, not weeks. In this Techstrong TV interview, Detectify CEO and Co-Founder Rickard Carlsson joins Alan Shimel to unpack the company’s newly announced MCP Server and why he believes “agent experience” — AX — is becoming as important as UX in security. Rickard explains how Detectify’s deterministic, hacker-built scanning engines now plug directly into AI coding agents, why a token-burning frontier model alone can’t pen-test 300,000 domains, and what the death of the 30-day PCI patch window means for every security and DevOps team. Plus: long-running multi-agent systems, the next bottleneck after vulnerability discovery, and the case for best-of-breed over one-stop-shop platforms.
Transcript
Hey everyone, welcome back here to another Techstrong TV interview. I'm really happy to introduce you to my next guest. His name is Rickard Carlsson, and Rickard is the CEO co-founder of a company called Detectify.
Hey, Rickard, welcome to Techstrong TV. It's great to have you on here. Thank you for having me.
Pleasure. So Rickard, before we get into Detectify, and MCP, and all the things we want to talk about today, let's spend a quick moment with about you. Tell our audience a little bit about how you came to co-found Detectify and what your path has been.
My passion has always been, as a kid, playing and tinkering with technology. So through university, my background was applied physics, applied math, building robots, and doing a lot of technical things. And then I went a few years into, as a sidetrack after university, I went into management consulting, primarily towards IT.
And then I started to have a few projects that touched upon cyber, and this was 15 years ago, when cyber was maybe not as mainstream as it is today. And then I was introduced to a few people that were some of the maybe really elite, world-class, white hat hackers. " And that's actually how I came into security.
This was sort of an itch to get back to technology, but with and also an interest that I think cybersecurity is going to be more important in the future, so I would like to learn about. So it was a fairly, maybe a bit naive, but still the way to go. You know what?
I think a lot of us were naive back then. And so you're not alone on that, but look, nevertheless, you're here. Yeah.
So talk to us about Detectify then. How did that come about? It came about originally from my co-founders being really skilled at bug bounty hunting, and they hacked all the large, then early American tech giants in bounty programs on the weekends.
And they started to automate a software to hacking them, so to say programmatically instead. And through that, so we focus on AppSec as a company and then, of course, some different packaging throughout the years. In the early days, a pure single DAST scanner to then we were the first ones that invented, I guess, the tech method of sub-domain takeovers back in 2014.
And that started a journey that we started to building an attack surface product already 2017, before it was a thing. Then attack surface become popular a few years. We put more emphasis on that.
But I think, and now we has decided we sort of going to drop some of these segment labels and say, we do things, we're using dynamic methods and DAST type of methods, but we do it in a way that benefits AppSec people in the best way. " Love it. So look, this is since 2013.
It's 13 years, right? It's actually 2013 is when I founded Techstrong, so I know what 13 years is, Rickard. Yep.
It wasn't on your bingo card 13 years ago to have the world sort of disrupted here with by AI, and agentics, and everything we're seeing. But nevertheless, here we are, and we have to, and we live with it, and we embrace it, and we run with it. And that's what you guys are doing at Detectify, right?
You recently announced an MCP server. Now- Yeah ... well, let's- Who cares?
A lot of MCP servers out there, right? Yep. Amazing.
In a little over a year now, probably almost a year and a half, it's become the standard, right? Yep. For good or bad.
There's a lot of people who don't have great things to say about it. But why should we care about this MCP server? I think this is a transition for us.
First of all, the reason why we're building it now is, I think now is actually the need, some customer size that's really starting to become strong. Early on, we decided not, for example, to build a chatbot because we felt that maybe that was not the best invested in our time, then it's better that we improve falling algorithms, or fuzzing methods, or ML methods for how to fuzz things, rather than to just build a chatbot. But I think now we sort of say the MCP server is becoming so also going to be so fundamental in how we architect the product going forward, because I think we see it as, I think it's equally important to build a good AX, agent experience, versus building only for a human with a U experience.
Because, software volumes and software vulnerability is just going through the roof, and humans won't be able to process it. And I think customers are feeling the pain that they cannot really manually process things in the same way. And then hence, there's a need to actually get a different type of interface to the data.
Explain to me kind of the flow, if you will, right? So this MCP server is really if you're using Detectify's scanning tools Yeah. One clear use case I think that comes with this, there's quite a few different, but I don't think maybe that this universal vulnerability management platform that consolidates all the data is maybe the way that customers will consume vulnerability information in the future.
Rather, they will actually have the agents that connects to the different types of sources and then combines information from different sources because I think there's a very strong direction in the cyber market general for platformization. Cost cutting, simplification. But in the same time, if you want best of breed, I think the headache now gets much less to actually to combine different products and platforms into sort of, say, your own suite, compared to by going to a one-stop shop where you maybe get sort of, say, a half-baked product of everything.
Mm-hmm. Got it. And look, the fact of the matter is, I think I mentioned, I just got back from Cisco Live.
Yep. Spent all week talking, and security was obviously a big thing there. Mythos and Glasswing and- Yeah ...
the OpenAI security product, it's having a huge impact, right? Wrong or indifferent, it's having a huge impact here. How does that figure into what you're doing?
Because scanning and finding vulnerabilities is now a changed, it's changed right under our feet. Right under our noses. How does that play into all this, Rickard?
I think it plays onto where we're also heading with the product. I think, of course, the big difference with agent or models to reviewing code is, of course, going to impact SaaS and SA tooling quite a lot. How are you going to combine, sort of say, deterministic tooling, but with them, sort of say, the agencies, everybody agrees on it, and fundamentally how they architect and build, they are stochastic in its nature.
So I think also what needs to be combined is then how do you couple an agent with the right type of deterministic tooling? Because we have customers that have 300,000 domains exposed on the internet. If you would run a Mythos or a similar frontier model to try to pen test that 24/7, your token cost is going to be enormous.
However, I think what is needed is that you need to have deterministic technology that feeds data that models then can interpret. And so it's more about providing the tooling for the agents rather than saying that the agent's going to do everything themselves. Fair.
Fair enough. Of course, I think the other thing that I see happening is we've moved from finding vulnerabilities to remediating vulnerabilities, right? How does that change what Detectify's mission is and how you guys go to market?
I think the main challenge here is for quite a lot of organizations. If you think about maybe the old PCI standards that allowed you to have a critical vulnerability on your external attack surface live for 30 days, and you were still compliant. If you would keep something that is new and when you then consider new vulnerabilities, that they're being weaponized between 10, 15, two, three minutes of a CVH being exposed by people doing deep searches on coded and reverse engineering the vulnerability automatically, and you consider that you can stay compliant with the 30 days and keeping something on your attack surface for 30 days, I think this is going to be the main shock for most organizations, that they drastically need to change the way that they do things.
And to change things and to maybe then make your processes much more automated, of course, the data then needs to be accessible to the agent that's going to run the processes, because you can't run the patching processes in a manual way anymore. That's going to be impossible. But I don't know if you're familiar with the theory of constraints, right, and bottlenecks.
As soon as you fix one, the next one pops up. So what's the next bottleneck? I think the bottleneck is that to try to find, because also, if you're looking at agents, I think they, in general, they will produce, I guess, if you have a skilled person using it, or if you're still controlling it well, it's going to produce fairly secure code.
The question is how are they going to produce secure systems over time? Because vulnerabilities will sort of say happen in the interaction, so to say, the serialization to de-serialization between Python and Golang, because they serialize and de-serialize data in different ways. And will an agent that overlooks them, will it have enough context to operate and oversee both systems?
Or how it's going to be chaining things? I think that's one thing. But I think also, if you look at most organizations on how they use the agents today, they're still, so to say, I would not say stuck, but they use agents as coding assistants.
Then there is quite a few of the tech companies, and all of the AI startups and tech startups at the momentWhen you start to move to long-running agents or multi-agent systems instead that sort of say autonomously builds and create merge requests, I think that's going to be the big difference in when we code. We have one system like that internally that sort of say it scavenges internet for new vulnerabilities, and then it tries to build its own research note database and threat intelligence database, and then it creates and builds new security tests and weaponizes them automatically. That system we have had live for about a year and a half ago.
And I think that's the example of a long-running agent. And I think when organizations are moving to this pace, that I think is going to be the interesting shift in security testing, where it's actually, it's not a human in the loop. It's almost no human in the loop any longer.
You know what? We're running low on time. I didn't really do-- For people who want to find out more about Detectify, where should they go?
com, I guess, or our LinkedIn. And the MCP server, how do people get started with that? It's just get into your account and, I don't know if it's on-- I think they just reach out then to one of the support, and then they will activate it.
Excellent. Yeah. Rickard, I want to thank you for coming on here today.
I'd like to have you back in about two, three months and hear more how the MCP stuff is working for you. Because I can't help but think like another shoe is going to drop with this Mithos stuff. I think we're sort of normalizing it, but now we'll have to see.
But in the meantime, look, it's interesting times. I wish you the best of luck. The same.
Have a great day. Bye-bye. All right.
Rickard Carlsson, CEO, co-founder of Detectify here on Techstrong TV. We're going to take a break. We'll be back in a minute.