Techstrong TV – February 1, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hello everyone, and welcome back to Techstrong tv. Today is Thursday, February 1st, and I'm your host of the Tan Solomon. Today we have a full slate of great interviews and conversations with some awesome guests to start.
Alan is joined by Bill Bruno to discuss the latest version of the Celebrex platform. Next at Kub Con, Alan talks with VMs Michael Kade about the casting K 10 release. Afterwards, in an AI Leadership Insights interview, Amanda and Kit's Ron kbs talk about the dangerous presented by online video gaming for children and teens.
Then from AI in Action 2023, our special panel discusses how to get started operationalizing ai. Finally, we have back to back episodes of View with Vard. First, Mike is joined by Tim Miller to talk about open source tracking and software supply chains.
Then he welcomes Prismatic Michael Zuercher, and they dive into embedded SaaS applications. That's what we have coming up for you here on Textron tv. Let's get the show started.
Enjoy. This is Text Drunk tv. Hey, everyone.
Welcome back here to Text Drunk tv. I am happy to have, uh, he's a repeat guest. I had him on a few, a few months ago.
Um, he's Bill Bruno. He's the CEO of Celebrex, and I hope I pronounced it correctly, but I, I think I, I did. Hey, bill, welcome back.
It's great to have you back on. No, I'm thrilled, thrilled to be back, uh, hanging out with you. Alan, really, really appreciate you taking the time.
No, my pleasure. So, bill, as we mentioned, uh, Celebrex is the company name. That may be a name that people now know may not.
Uh, just a few months ago, actually, when you were on last, we were talking about, you know, the company having under undergone a name change. So for those who we could, we could play hardball and make 'em go back and watch the old one, but we won't. Why, why don't you give them the gist of, of the name change and kind of, and we'll, we'll, we'll ride it from there.
Yeah, no, no, no worries. Yeah, we talked about a lot of fun stuff, so I do recommend people go back and, and listen to it in the, in the archives, right? Mm-Hmm.
But, uh, um, you know, it's really a simplification thing for me. So, I, I took over the company globally a little over two years ago now. Um, I've been in the analytics industry for about 23 ish years, something like that.
Um, and I've been aware of the platform for a long time. Uh, but the business, uh, CEUs was a technology platform acquired by a company called D four T four solutions back in 2013. Um, now from a simplicity perspective, I'm a guy that likes to keep things simple.
You're not gonna hear me use a lot of buzzwords. You, you know, I think it's important when you're selling software to make it easy to understand, you need to be easy to buy from, and you just wanna eliminate confusion. So us balancing two names just didn't make sense.
It didn't really fit with the ethos of how I like to run a business and how my management team wants to build the business. So we just aligned under the Allus brand. It was welcomed by all of our investors.
We're publicly traded out of the uk. We're a global business. Our software's operating in, I think, 32 countries now around the globe.
Um, so it was just a, it, it was a no brainer, to be honest. It, it was just a matter of prioritizing when to do the paperwork, and, and we, we hit a good time to do that a a few months back. Excellent.
And, and, and what a great recap there. And that was great. Now, if you do wanna watch the whole last video, though, as Bill mentioned, it is available, it's on text drunk tv, as are all, I think almost 6,000 text drunk TV interviews that are up there these days.
Um, but if you search under Celebrex or under Bill Bruno, it'll, it'll pop right up. You can search under my name, but there'll probably be a lot of other ones that come up. So I would definitely recommend searching Bill Bruno, B-R-U-N-O.
And, and Bill, as you mentioned, you've been CEO at Celebrex for about two years now. But just again, real quickly, a little bit of your background. Yeah, so like I said, I've spent about 20, 23 odd years in the, in the analytics industry.
So coming outta college, um, I, I helped build a, a consulting firm that was, uh, focused on helping customers better use data to make decisions. Um, during my time there, I've worked with and been on the advisory boards of a lot of the vendors that are out there today, um, including CEUs way back in the day when it was under a different name. Um, eventually sold that business to a different UK company, and then spent several years running sort of their analytics practice globally.
Uh, working with a lot of media, uh, and, uh, advertising organizations, helping them optimize their spend across the globe, which was a lot of fun. Um, and then made my way here to, to Celebrex. Um, you know, for me it's a, it was a passion project.
I, I, before they paid me to say it, Alan, um, you know, I, I thought this was the best data capture and contextualization platform in the industry, and you could find articles I've written years and years ago about that to, to prove that I'm not full of it. Um, but that's why I came here. Um, you know, it was a technology that needed its time in the sun.
Uh, it's a technology platform that solves for a lot of the industry challenges today. Um, and I knew the team there. I knew the product team, the engineering teams, and was really excited to join.
Um, when I joined, I was just running the US business. I was just, you know, running sales and growing a, growing a market, didn't expect to get handed the keys to the city. Uh, but here I am, uh, running, running it globally, and it's, it's just been so much fun.
Um, you know, to, to have a platform that actually delivers on the promise of building better relationships between brands and consumers via better data, um, you know, and living that mantra on a daily basis is my passion. Excellent. Love it.
So, let, let's talk about kind of our topic of discussion today. And that is the release of a, a new version of, of, uh, the Celebrex platform containing something we're calling Celebrex Digital Analytics. So CDA and, uh, and that has a lot of new capabilities, including, dare I say it, ai, um, everyone else is saying it, why not?
You gotta throw it. Uh, yeah. Um, tell us, bill, what, what's the deal with this new, the new version and what's CDA all about?
Yeah, no, so, so again, it kinda stems from my background again. Um, you know, we, when you look at the industry today, there's, there's a big challenge in the industry for analysts all around the globe, and it's data quality. Um, and that has been something that the CEUs platform through all of our various in, uh, feature releases and enhancements and innovations has been striving to, to fix.
Um, well, one of the areas that's really sort of diminished in my opinion in terms of quality is, is analytics reporting, you know, the ability for organizations to be able to understand what invest investments are working, what their return on investments are, et cetera. And so we saw an opportunity and we decided to go for it. And what we, what we wanted to do was build a better wheel, I suppose.
Um, now within that wheel, uh, there's a lot of reporting that organizations have been using for years, uh, to report on their campaigns, report on their digital traffic, et cetera. But with the Apple intelligent tracking prevention changes, with the Mozilla total cookie protection changes, with some of the most recent updates in, in the last few weeks from Google, those historic systems have become very inaccurate because the way that they identify consumers is depleting and, and degrading by day. And so, your things like visitor counts or being able to maintain a history of what campaigns a person has interacted with have become extremely difficult.
Uh, those platforms are third party in nature. So when you're setting them up as a, as a brand, you're sending your consumer data out to some third party at the end of the day. Right?
And in the states, it's becoming more and more of an issue globally. It's been an issue for quite some time with various versions of GDPR, but here in the states with healthcare and HIPAA compliance, um, with some of the FTC regulations recently, sending your consumer data around to third parties is frowned upon. So we, we looked at all of that and said, I think we can fix this.
Um, and so we launched Celebrex Digital Analytics, which is a fully enclosed solution. What I mean by that is brands own it, control it, and the data never leaves their four walls. It's all the reporting that they know and love.
You know, reporting is a commodity, in my opinion, right? You're not really gonna build a new innovative report like they've all been done. But what's within the reports, the data itself, as I mentioned, has become garbage.
And we fixed that with the Celebrex platform capabilities that we've had in place for years. And a lot of our patented capabilities around digital identity verification, consent management, et cetera, such that all those challenges I mentioned go away. And you end up with all of the reports, you know, and love with better data available more in real time and secure.
Love it. That's a great thing. Um, you know, bill, for people who aren't familiar, the, the platform is, it's SAS based, or no, So it, it is, but it's a bit unique in that regard.
So I'm glad glad you asked that question. So we don't do any shared architecture, and CEUs is not a shared platform. So if you're one, uh, banking institution and a travel company working with us, you have your own dedicated, uh, private cloud existence of Celebrex, right?
So we stand everything up. So it's Hosted, but it's hosted but not multi-tenant. Exactly.
It's a single tenant private cloud instance specific for each customer and for customers that are afraid of the cloud. And we do still have a few that don't want to go to the cloud, we do offer the ability to install it in and host it in your own environment. But most customers today choose to have us manage it for them 'cause it's easier, and it gets them up and running more quickly.
And, you know, we just signed a new customer that we announced a, a few weeks ago, and they're already collecting data, um, you know, within the first week of having the solution deployed. So, you know, the benefits of us managing that, that, uh, single tenant private cloud instance for a customer, you know, uh, with all of the security that you would expect and all the compliance you would expect has become quite welcomed in the industry by our customers. Very cool.
We mentioned ai, you can't, you can't take three steps without tripping over ai. Yeah, that's fair. There's gen, yeah, there's generative ai, there's kind of the machine learning kind of model of ai.
When, when you are referencing AI in regards to Celebrex and the, and the platform and CDA, what exactly are you talking about? Yeah, so I'm gonna, I'm gonna split it into two topics. Um, 'cause I think, I think often when people talk about artificial intelligence or machine learning, um, they kind of cobble it all together as this amazing thing that's just gonna work, right?
But there's, there's sort of two elements in my opinion. The first is data quality. Um, and why, why that's so important is for all the reasons that you could, if you google data bias or data ethics, you're gonna see a laundry list of mistakes that have been made because of bad data or incomplete data, et cetera.
So the first thing we do in the Celebrex platform is offer you the ability with a published, tabled structured data model that we give you out of the box to make sense of digital in a way that allows it to be usable, that allows data scientists to understand what the data means so that they can interpret it correctly, and they can choose how to use that in any model of their choosing. The second thing that we've done in the platform is we've naturally continued to, to roll out our own machine learning models for customers. The most recent has been around bot detection, which is a big issue in the industry.
You know, where, where you've got fake traffic that looks way too human these days and is very hard to discern. And being able to do that is saving our customers millions of dollars in advertising due to invalid traffic and getting things like rebates and refunds, et cetera. But what we've also done, and I think this is, this is a core ethos to Solidus as a company, is we recognize that we're gonna innovate some things.
We're gonna give you some models, we're gonna continue to build more and more, uh, ways of contextualizing data to help you find the needle in the haystack more quickly. But customers are also investing heavily in this. You know, our brands have data science teams that are building their own solutions.
And so we've built the ability for, for our customers to import their own models into the platform and have Celebrex train them, um, in real time with the data. So there's a lot of flexibility to the platform. Yes, naturally, we're gonna continue to build machine learning.
And then foundationally, we're making sure that the data itself is hitting a level of compliance and ethics that's required for these models to actually work. Excellent. Very, very, very, very cool.
Um, you know, I, if you don't mind, I, you know, people out here maybe listening and saying, that sounds really interesting, I'd like to check it out. I'd like to try it. What, what is the, what's the on-ramp?
What, what, how did they go about given this a whirl? Yeah. So, you know, I'd urge you if you're, if you're interested and you're listening to this, um, and you wanna learn more, you can reach out to me directly if you'd like, on, on LinkedIn.
Um, and I'd be happy to get you access to some workshops and get you, uh, a bit hands-on with the tool with some of our solution architects. We have some, some fantastic ways where we can actually demo it, um, and show it running on your website as if you've deployed it. Um, which is really, it's, it's a lot of fun, uh, when we get into that with customers.
'cause we can instantly show your use cases being solved by Celebrex instantaneously. Uh, we do offer several sort of, uh, um, trial periods, evaluation periods as well for the platform. com, take a look at some of the use cases that we've been, that we've been driving in the industry and, and just reach out to us.
We, you know, I I, I spent so long in my career being vendor neutral and being the consultant that worked with a lot of vendors, right? And I've seen the good, the bad, and the ugly of how vendors behave. Um, and it's really important for me as a company that, that we're the vendor that's easy to work with, easy to talk to, and easy to get you sort of an understanding of how Celebrex might alter what you're doing today in a very positive way and add a lot of value to your business.
So if you're interested in it, we'd be thrilled to show it to you, and we'd be thrilled to give you access to some of the phenomenal people we have here to, to help you understand what's possible. I love it. Bill, we didn't even mention the website though.
Uh, yeah. com. com.
That's, That's what I was looking for. Hey, man, I appreciate you coming on and, and keeping us up to date on what's doing over at Celebrex. Uh, congratulations on the new release, uh, the new version of the platform out here, and CDA, it'll be interesting to see.
I look, I mean, things are starting to really gather steam now, right? And momentum. It'll be interesting to see.
Yeah, It, it's really exciting. Um, I'm really, really, uh, proud and humbled by the team that we've got and what they're bringing to the market and how quickly they're doing it, um, when these challenges are arising. And we, we've already got several clients up and running on Celebrex Digital Analytics.
We had a few that were beta testing it before we launched it, and the feedback has been phenomenal. Um, and, and that's all we can ask for, right? If you want to build something that people actually use and enjoy, um, and if they don't, you gotta figure out how to fix it.
But fortunately for us, we've, we've got something that, that seems to be really picking up some steam here. I love it. Bill, thanks for coming on.
We hope to see you back on here soon. com. The, uh, the Celebrex, uh, the platform is out, including this new Celebrex Digital Analytics CDA.
Check it out. We're gonna take a break here on Tech Drunk tv. We'll be right back.
This is Tech Drunk tv. Hi everyone. Hey, we're back.
We're here in Chicago for Q Con. Wrapping up our cut three days of coverage here in Chicago. Um, it, it's our last day.
I think we have maybe one or two, uh, more. I think the, the expo floor closes around two o'clock Chicago time does today. So we gotta wrap it up.
But, you know, in many ways we saved the best for last. Right. Let me introduce you to my friend Michael Cade.
Unfortunately, I don't get a chance to see Michael as much as I'd like. I think the last time was Amsterdam a fine. So I'm gonna assume I'll see.
Maybe you, I'll maybe see you in Paris. We Will indeed. It's my wife's birthday though, so I'm My wife's birthday too.
So you gonna have to bring either We got a party to make here, man. Either we're, uh, bringing them with us or, Oh, I'm bringing 'em. Yeah, exactly.
I'm bringing her. I'll send it now. It's on camera.
Uh, maybe she'll watch For a small fee. I'll make sure this never sees the light of day. Kidding.
But yes, my wife is gonna be there for her birthday. If you're there with your wife, let's do drinks. Yeah, very good.
Yeah, we'll do it. All righty. Hey, for those who don't know, Michael is with Casting by Veeam.
And you know, before we get into anything else, Michael, there are people who are watching this who says, I never heard of those guys, or I'm not, I think I heard of 'em. I know Veeam, but I don't know Caston. Yeah, that's fair.
That's fair. So we're focused on Kubernetes backup, right? So, or in fact, a little bit more than it's easy just to say Kubernetes backup.
Think about data management, data resiliency in particular in Kubernetes. Now Veeam is a platform we can back up virtual machines, physical, unstructured data, NAS cloud. We are focused here, we are focused on Kubernetes, data protection, data resiliency.
So when you put your database inside of Kubernetes, we are gonna give you the ability to protect that, orchestrate that, offload that onto a different cloud if need be. Provide that mobility of that. But equally, if you've got a data service such as A-W-S-R-D-S and your bit of your application lives in Kubernetes, we can protect the whole, whole story, the whole application.
Sure. Got I got it. So that's really the, the, the two minute, this is who we are and this is why we're here.
You know what, that's a good start of where we're going now. We are here though, and, and you guys have been, as always, right, ca there's always things going on with cast for our audience. And this goes to the people who do know who you are as well.
What have you guys been announcing or, you know, highlighting at the show? So, so every cube con we bundle up everything that we've done over the last six months or whatever it was since the last cube con, right? 5, and there's two key focuses.
One is around security. Everyone's talking about security data backup or data resiliency. You have to have security in involved in that.
And then you also, about scalability. One thing we are seeing is people are deploying multiple clusters, not just one or, but as well as, or one big massive cluster that holds everything. A bit like what we saw in the virtualization days, right?
You just have a big, big cluster full of virtualization, and that would be where you'd run all your workloads. From a security point of view, it's about integrating into your scene type projects or products like Datadog. So we know what our swim lane is.
We're going to, we're not gonna go and create our own Datadog type offering. No. So we're gonna leverage the best, best ones on the market.
We've made it extensible, launching it with Datadog, but really can very cool it, it can really go to any other scene that that's available. And that's really about, I, I talk about the, or the US Navys talk about, they talk about, um, left and right of bang. If you think about a bang being something bad happening, like a security threat, malicious activity, ransomware type situation.
If you think about left being prevention, I want to prevent something bad from happening, or at least gimme visibility of that. And then right of bang is remediation. How do I get things back as fast as possible?
That left of bang is more the Datadog. How do I get insight when something bad's about to happen and what can I do? What, what would we do from that point of view?
It might be take a backup. It might be, uh, like, encourage us to then start a replicate replication or migration of that workload into a different cloud. So that was a big part there.
The other part of that security story is around secure supply chain. So we've always had that secure supply chain building our software, but a lot of the DOD Fed type, uh, environments, they want, uh, they use a, a secure hardened repository called Iron Bank. So we, that's another part of our launch is making sure that we've got casting K 10 in Iron Bank, secure, safe, and we are the only, only data protection, uh, enterprise data protection service inside of that Iron Bank repository.
It's, that's big stuff. It's big stuff, you know, uh, we do a lot of work with Datadog and uh, AWS with them as well. And, um, it's a, that's a gotta be a huge channel for you guys, right?
And, and to have that integrated in there, as you said, rather than trying to go out and reinvent the wheel and get someone to, and the last thing we need in the world is so people have to adopt another interface. Exactly. Another, They already know it, right?
We already, and, and that ecosystem trend of us partnering with these, uh, enterprise solutions, whether it be like verno or whether it be open policy agent or OpenShift and all, everything, all the good stuff that come with OpenShift around like guard duty and uh, a CS, we're not gonna go and build it ourselves. People want to roll their own platform with their choice. And it, and that freedom of choice is important to keep Yeah.
You, you can't shove it down people's throats. It's just, it don't work. Yeah.
Simple. Let's talk, what else you got coming on here? Uh, so another big thing that we did, so we have, we've, we've had an open source project called Canister probably since 20 16, 20 17.
I Think I've spoken to you about it. Yeah. And, and, and the focus there was around enabling the community to have something that would allow them to take a consistent copy of their database Yes.
Or data service. And what, what that means is that, let's say with Postgres for example, they use a a tool set and a built in tool set called PG dump, and then we offload that off into object storage. Canister gives that that functionality to be able to do that.
So what we've done is we've donated canister to the CNTF landscape, so as a sandbox project. And that's really our, our, our aim as castin is to drive and ri raise awareness of, uh, data protection, but also application consistency across data services within and external to Kubernetes. And this gives us that, that capability for the community to go and use this framework to try to, to get to where they need to be from a protection point of view.
Absolutely. Let me, let's, let me peel the onion back a little bit on that. 'cause I, I think it, you know, not everyone in our audience sure knows what it means to donate a, a, an or a project to CNCF.
So CNCF at this point, I I think have like 140 or some weird number. There's a lot of Yeah. CNCF projects.
But when a company like, you know, CAST does, you are actually assigning the handing over the IP management and marketing of that project to the Linux Foundation and c ncf Exactly. That. Our native computing foundation, and they own it.
They operate it. Now, that's not to say that you, you know, you or did or you shoved it out the Yeah. Won door and said we won't stop, Maintain, won't your own.
Yeah. You, you still going to be, you know, I imagine very involved in the maintaining Absolutely. Of it and of, of steering it, right.
Of help managing where it's going, what the audience needs. The flip side of that though is that this now becomes part of the ecosystem. This now becomes part of the, the class, if you will, where all of these projects begin, you know, working together.
They have some common, uh, road mapping and common, you know, there's an end game in store here where these Yeah. Absolutely. Play nicely together.
And I mean, in many ways, you know, you, if you love something, set it free, right. And you set it free and it really grows. And so it benefits not just you, it benefits, and not to sound corny, but it benefits the whole community.
EE exactly. That. And the value of that is that we we're already drinking from our own fire hose.
Agreed. So the perspective that we can get from the community, the feedback that we get from the community will help us ha take the blinkers off. Yeah.
And we can get really into, or what is it you need? Like I expect we've been working quite closely with Enterprise DB around Postgres. Yeah.
So having that, that community meet in the community type model, which I mean canister, it's not like it's a brand new project. It's been around for 5, 6, 7 years. Absolutely.
But open source is different to A-C-N-C-F guided visibility and, and a, and a community. It's a focused community around everything that we do. So, yeah.
And, and it's also in an environment where they have, it's a very structured environment. We say, okay, how many contributors do we have? How many downloads do we have?
How many maintainers do we have? Right. Based upon what we know, a successful open source project needs to be really successful.
These are the metrics we want to see the project happen. Exactly That. Like, so you can't just go, oh, I've created something open source and throw over the fence and C ncf f go.
We'll have it. Right. There are, there are entry requirements to get in there, whether it stars And then there's a graduation Exactly.
That mention you were sandbox. So we go sandbox, then we look into that Inc, Inc. Incubating and then graduated, if you look at that as well.
But you mentioned if you're go and look at the CN CCF landscape, because I've spent a lot of time on there. There's a, there's over a thousand projects that there's logos everywhere. Then you start drilling it down to what is not a commercial or a proprietary bit of software, it starts to slim down.
And actually, if you look at like the graduated and incubating and you start filtering that out, there's actually 55, 56, I think it's 55 actual projects that are in that incubated and graduated phase of there. And you like the likes of Kubernetes and the likes of Helm and Prometheus, the big ones. Right.
They're the ones that you expect to see, uh, Open telemetry. Actually, the third biggest one I found out this week is Argo. Yeah.
I can quite believe that. You literally, you walk around this show floor and everything is used in Argo. Yeah.
Like we, and we've, we integrating backup into your CI CD pipeline, a hundred percent big fan of Argo CD and Absolutely. And what that brings to the, But no, but that, but that, when I say that's the class you're in. Yeah.
That's what I mean. You're in that class and they're, they're all, you know, they're all going to the same school, if you will. Yeah.
Right. As a parent parents out there, you want to send your kid to the school where the other smart kids are. So they they network and they do their thing.
It's the same kind of thing. Exactly. That.
And hopefully Sword raising a good open source project today. And Hopefully like come, come Paris, where we've, you've got the open source, I think it's called the Project Pavilion, where you see all of those, those graduated incubating projects. Hopefully we can, you'll see.
Yeah. Hopefully we can get a canister, canister one over there and we can, So if we are, we'll have you there, you know, bring your wife with you. Yeah, There.
Exactly. And we'll, we'll, she Canister happy birthday. And then have a demo canister here for it.
Great. What else do we have, Michael? Um, so I think, I think the other thing is that, that evolution of the conversation, when I first started coming to CubeCon, we were talking to developers, engineers, I'm not a developer or an engineer, a hacker.
A hacker at best. Um, but now we're starting to see, and this probably started in Amsterdam, where we're now starting to see people that are responsible for the data. So, and I think that's a, that's another important milestone that we're seeing.
So you've got the developers still there here, but equally the, uh, the, um, the SREs, the platform engineering, the, the people that keep the lights on, the people that are responsible for when bad things happen. They're not necessarily always ransomware or newsworthy headlines, but people make mistakes. We delete stuff all the time.
So we might need to recover, recover that workload. So conversations, Happy start, swap. Yeah.
Conversations is a, is a big evolution that we're having here as well. Definitely. Like, people are coming up to me, up to us at the booth, oh, I know Veeam, what do you do for Kubernetes?
So we then tell 'em that, that whole story, right. The, what we started the, the session with, uh, around, we can back up Kubernetes workloads. Very cool.
Hey, last area I wanted to ask you about. So, you know, you're a Q Con, uh, veteran. What, what'd you think of the show this year in she in Chicago?
I think the weather's been pretty good. Uh, Could have been worse. I mean, look, I'm from South Florida.
It's not exactly been good. Yeah. But it could have Been worse.
Oh yeah. Well, I'm UK so this is, this is Basically some, it's good for you. Yeah.
I get it. But Weather aside, I think the show floor great conversations. I think the maturity of some of the projects that we've seen, maybe that would've been in that, uh, like the style grow are now they have a bit bigger, they, they're like, they're mature.
Yeah. No, it would, it's definitely Progressive. And I think that is, that's exciting to see the different, uh, tele like observability, the, the storage, the security side.
Like I think there's some incredible projects and products that we have here. And I think there's a maturity around, there's always where there's open source, there's always an enterprise requirement for supportability and actually just well, And some enterprise features that really doesn't appeal to the mass. That tends to, you know, open source projects work on volume.
Yeah, very. I mean, that's part of the CNCF Right, Exactly. That.
But, you know, a lot of enterprise pro, uh, type features may not appeal to that broad base. It's, it's like a pyramid. Yeah.
And so if you want the top of the pyramid kind of functionality, I mean that, that's the open source business model right there. Exactly. That funnel, right.
That funnel. Yep. So I, I, I get it.
And, and that's what a lot of these companies up and down all these rows are here for. Exactly that. Yeah.
It's been good. It's been like, like I say, conversation community, big part again of the C ncf F is around that community. Um, I think there's still a lot of people learn on their learning journey.
I think there is, that's great to see as well, that, that change. But people embracing change, there's one constant in it or tech, there's always gonna be change. Right.
Every 10 years I'm quoting Kelsey Hightower's talk that he did on our booth, but basically he said, you have to look to reinvent yourself every 10 years. And I think we, we are definitely seeing that as I think we do. Yeah.
I think we are coming up on that boundary that, That yeah. It feels like we're on the cusp of that. The adoption is real.
Oh, the adoption's real. I think. I think you have one.
You know, it's like being the scrappy kid on the block, the underdog who has to fight for every inch versus being the heavyweight champion of the world and defending your title E Exactly. That and, You know, staying on top. I Think the other thing as well that I've been excited about is seeing virtual machines, like think about like, so Kubernetes, and I know it's not just about Kubernetes here, it's about cloud native.
Absolutely. But Kubernetes being that container orchestrator, and we've always said about it being a container orchestrator, but now think about it as a, as a control control plane and API that can drive anything. So have a, like speaking to OpenShift and they have OpenShift virtualization running VMs inside of Kubernetes and MongoDB.
They have a, an operator that controls their paths, MongoDB Atlas. So it becomes a, a reconciliation loop for so much more than just containers. So we are focused over the last year about protecting those virtual machines, OpenShift virtualization, using Bert, all of that.
So it's been exciting to see as well. And there's some stuff out there in the, in the virtualization space that is like maybe a, a, a potential bump, some bumps in the road, come in from acquisitions and stuff like that. I think that it's very interesting for Bert as a project, but also OpenShift virtualization.
Suse have, uh, harvester that does something similar, uh, kind of flips things on its head a little bit. If you start running virtual machines under the Kubernetes hood. I think that's exciting for me coming from that world.
Last question for you. So I'm hearing rumors that Yes, Paris in, uh, in March. Yeah.
Salt Lake City next, uh, fall for the US and then London. Oh wow. Have you heard that?
I haven't, I have not heard that. So I have heard though, that there is gonna be a cube con in India as well. I know there was one in In China.
That'd be in New Asia. Yeah, there Was Shanghai, but I think there will also be one in India. Nice to be One in India.
They should. Yeah. I think a lot of projects and a lot of the talent is, And there's also a lot pe there's just a lot of people there too.
Exactly That. Exactly that they know where the people are excited for that. I might see you there.
It's not my wife's birthday, but there you Go. I'm you, my Michael. Always a pleasure seeing you, mate.
We're live here. We're wrapping up. I think we have one or two more interviews before we conclude our day Three coverage here.
Cube con, cloud native con. Stay tuned. We'll be back on in a moment.
Hello, I'm Amanda Ani and I'm with Techstrong ai. Excited to be speaking with Ron Curbs. He is the CEO of hedis.
How are you doing today? I'm good, thank you, Armando, for having me here. Happy to have you on our show.
Can you explain to our audience what is Kedi and what services do you provide? Yeah, so kedi is an AI based solution for video games. We monitor v voice conversations within the con within the video game to protect kids and other gamers for toxicity.
So we're talking about things like camps, bullying, harassment that are unfortunately happen quite a bit in video games. Um, so our technology is able to detect those scenarios in real time, uh, protect kids, alert the community managers, alert the parents about those situations, and hopefully make those communities a little bit, uh, you know, less toxic. Wonderful.
I know that would bring peace of mind to parents because it seems like children of almost any age are playing online and on, um, more tablets and screen time, and so we wanna ensure the safety of our children. So can you talk about what are some of the biggest safety concerns you are seeing right now, um, as it comes to children being online? Yeah, so definitely what you said is correct.
So more than 90% of the boys in the US play video games and more, 70% of the girls in the us uh, play. Um, so everyone is almost every, you know, everywhere is connected. And, and what we're seeing is, is, is a lot of, uh, scams, bullying, harassment.
It's actually estimated that 60% of the kids will be bullied or harassed in video games before the reach 18. So that's of course, unfortunate. And those are the situations that we wanna deal with.
Our system specifically, uh, monitors millions of conversations every month, and we see a lot of private information that is being shared with, uh, with strangers. So we see kids sharing their parents' credit card information, date of birth locations, um, of course things that they shouldn't be sharing with strangers. Uh, a lot of swapping of accounts or kids sharing their passwords.
They, they don't even, you know, grasp the, the, the option that someone will, you know, use their password to prevent them accessing their accounts and a lot of financial frauds. And so kids that are being, who are being offered Bitcoin or, or other, or other things in order for, for them to send, uh, photos of themselves or, or, or those kind of things. So we're dealing, uh, with a lot of, you know, dangerous situations all from, you know, camps, uh, and online predators, sexual predators, um, to bullying, even bullying between friends.
Uh, we had a, a few cases of kids who were bullied by their friends from school. So it's not only strangers and it's not, um, just, you know, the unknown people bullying those, those kids. And sometimes those are kids that they know from school, um, who are using the existing connection and relationship to arrest those kids.
And that's sad. I know that nowadays more than ever, we're even more concerned because AI has come onto the scene, and I know there's a lot of people concerned with AI as it relates to DeepFakes and, um, things, uh, like ai phishing scams and things like that. Um, so how can people, using people playing online these video games, how do they know that, um, who they're speaking to is a real person or that the information isn't being, um, gathered by an AI of some sort?
Yeah, it is, it's very, very hard to tell it. Like even for for grownups or, or even for experts in the field, it, it is very hard to tell. Um, we have been seeing kids and adults using voice changers within, uh, uh, video games.
So kids who are pretending to be adults and adults who are pretending to be kids in order to, to scam the other side or in order to join certain communities. Um, we've seen actually a lot, a lot of those cases. So, uh, it's very hard to tell.
Uh, and you know, again, you, as, as the scammers get, um, more experience, they use new, new techniques. Uh, so it's on our end the protectors of, of kids of gamers to develop new technologies to detect those scams, to detect those, um, new technique, uh, developed by scammers. Um, so in our case, our technology is able to identify the tone of the speaker, um, the context of the, uh, of the speaker.
So is it the first time that they're talking, is it a long conversation, uh, detect past experience that they had? Is it the first time that they're playing together or, uh, more than that? Uh, and then we're using, uh, the conversation itself to understand if for dealing with, uh, a scam or we're dealing with a bullying or harassment, um, or if it's something that is, is okay for, for the kids.
We have cases of even, you know, famous YouTubers with millions of followers that are, um, bullying or harassing kids because they think that, you know, nothing will be done because they're, uh, they're famous and they're using the, the influence that they have over those kids who follow them and, you know, are big fans of their YouTube channels to, to wrap them while they play. Um, so all of those things are things that were taken into account when we're, you know, when our algorithms, the AI based algorithm analyze the, the information and basically decide, uh, whether it's bullying or asking, uh, scam or something that is, is okay for those kids. So in other words, you're combating the AI risk with AI tools to solve the problems.
So, um, can you share some, some use case scenarios of, um, how you've been using the AI to provide more safety and security? Yeah, for sure. So yeah, yeah, definitely we're using AI for, for that, but we also have experts behind the scene, uh, behind the scenes learning what are the, you know, recent scams and what are the things that we should be aware of and training our models to, to deal with those situations.
Um, recently we, we've seen a lot of, uh, you know, cases of kids who are being asked to share, um, you know, private information of themselves, something that looks completely, you know, benign. Um, and once they share the first, uh, the first de detail, then they're being, you know, they're being asked to share more and more and more and more. And, and always they executed like, Hey, you already shared that.
Like, it's, it's not a big step just to share another, uh, a little bit more information, a little bit more information. And then the stern step there, the information is being used against them. And so, um, we saw a lot of cases of extortion, Hey, you already shared this photo, I'm gonna tell your parents, Hey, I'm gonna share this photo on social media.
And so then they're forced to share more and more information against the will. And so, and it always starts with, you know, a tiny bit of information, something that looks completely benign, that is being shared, uh, and gradually, um, the intensity and the type of information that is being shared is increased over and over, and sometimes it can take a few months. So we, we imagine it as, hey, one incident that is happening, you know, within few hours sometimes, um, those scammers, those only operators are billing the relationship.
For months they were going online, they were talking with hundreds of kids, basically like, you know, a a fishnet, like, like, it's, it's bad to say that, but like, um, they were casting on that and trying to see who will, who, who can they catch. Um, so they're talking with hundreds of kids, and eventually a few of them are sharing the information that are being asked, and then they're using the, the information against them. So what advice do you have for not even just parents, but teachers, anyone who's directly working with children who are playing online, what advice do you have for them?
And are your services something that's out there that can be harnessed and used, um, say in the school system and at home? Yeah, so I think the, the biggest advice that we're giving to, to parents, to teachers, to educators is first of all to inform themselves about the online gaming world. Uh, we see a lot of parents, you know, giving pieces of advice to their kids without even knowing, you know, what is happening there, Hey, don't talk with anyone.
That's not how it works. Everyone is speaking with everyone when, when you play, you cannot even, you know, in certain games, you can't even play without talking and communicating with your team members. So I think the first step for educators, for parents is to inform themselves what is happening.
Have honest conversations with your kids, um, about, about those situations. What are you doing there? Who are you playing with?
What is the goal of the game? Are you paying to play this game? Or is it completely free?
Those kind of questions and, and be actually, you know, curious about what they're doing. And after, after you do that, then you can, they'll feel, you know, more comfortable to share information with you. So the the first thing that we, we tell parents, also parents who are using our platform is familiar yourself with Roblox, with Fortnite, with Minecraft, with Discord, all of those games and platforms that kids are using.
Um, so you can be, um, a guide and show them how to safely use those platforms. And we always compare it to, you know, driving, you wouldn't let your child drive without supervision for the first time, you're gonna be sitting right next to them. You're gonna show them, Hey, that's, that's how you drive.
That's what you you need to do. You're going to be there and, and guide them through your experience and show them, show them what is right and right or wrong while, while driving. And the same is, is completely true for, for gaming.
Show them learn from, help them learn from their own experience, and then at some point they'll be ready to, to do it on their, so on their own. So our, our system is basically, we, we, we see it as a, as a training, uh, program for, for parents and kids, um, especially in the young ages to, uh, inform themselves and to detect those dangerous situations together, deal with them, uh, together and have, you know, a conversation starting on, on what should or shouldn't be done online, uh, especially while playing. Wonderful.
So as this technology advances and it's, it's more open and available around the world, um, what do you foresee the future looks like as far as video gaming and, um, children playing online? What are maybe some of the, the things to consider moving forward? Yeah, I, I, I think moving forward, we, we could all understand that, you know, video games is here to stay.
Um, we're, you know, progam, I'm progam the company's programming. We don't think that, you know, kids shouldn't be playing. We don't believe that, you know, video games are only bad for you.
There is actually a lot of research that shows that video games are good for kids. They're good in developing social skills, they are good in, uh, developing problem solving skills, coordination, and all of those things that are things that, you know, could be developed while playing video games. So video games are here to stay, uh, and parents and educators should, you know, adapt to the situation of, you know, instead of, you know, kids just going to play outside, they're also playing in the online virtual world, and should be, that should be encouraged and that should be done in a safe, uh, environment.
So we're seeing a lot of, a lot of teams of eSports teams, eSports venues that are providing an organization that are providing coaches, um, to those kids who actually wanna specialize and get better. Uh, we're seeing a lot of colleges that are actually, um, bringing, you know, eSports stars, teenage stars to, and get scholarships to, to play on behalf of the universities. Actually, there are 800 universities in the US that are actually giving those scholarships to eSports players.
So it's here to stay and we should, you know, adapt accordingly, um, and accept it. Don't, not just treat it as, hey, that are a hobby that you know, someone is doing in their basement or late at night. That's not something that we, you should do that hobby the same as playing football, soccer, or basketball and tennis.
That's one of the activities that, you know, kids are, kids are doing. And, and we should encourage them to, to make the most out of it. Yes, absolutely.
I know my son really had a good time on the eSports chess team that his school provides, and I'm seeing more and more e teams being provided by the school system for people to participate in, and he has really advanced his chess skills through that. So, um, definitely a learning environment. Um, so if there is one key takeaway that you can give our audience today, what would that be?
What do you want them to remember? Yeah, I, I think the one key takeaway that I would want 'em to remember is that, you know, gaming is positive. Don't think only about the bad that think in, in gaming, um, really the, the way the tool and to advance the social skills, the problem solving skills.
Um, but definitely understand that there are the same as cars. You know, there are a car accident, um, the same as, you know, planes and, and other, um, tools that we use. There are risk associated with, with gaming.
Um, and you should be aware of those with risk, but it doesn't mean that you shouldn't be using this tool for your own on your kids' benefit. Well, thank you so much for coming and sharing your insights with us today. Oh, sure.
Thank you very much for having me. Here I am Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with the sustainability pulse meter offered exclusively from Techstrong Research. Hello, I'm Amanda Ani.
I'm the custom content editor for Techstrong. I know you've been enjoying the AI and action event, so many wonderful topics being discovered today. And we have three amazing speakers on our panel.
We have Alan Shimmel, he's the CEO, we have Mike Biard, he's the editor in chief, and Mitch Ashley, he's the CTO and, uh, in charge of research at Textron. Happy to have y'all on our panel today. Thanks Amanda.
It's great to be here. Awesome day. Yes, it is.
We've learned so much and we've had some great topics we've been discussing. So to start, my first question would be copilots, they seem to be the big topic of discussion right now and the dominant means for leveraging ai. Um, but how are they gonna to be managed?
Can y'all speak to this because that seems to be an issue? Sure, I'll, I'll jump in and, and kind of get the conversation started. I think it goes to a central question of is AI gonna replace everybody?
And I think most of us think no, it's, it's going to enhance and, and help us be more productive. So copilots are an easy way to say this is an adjunct assistant in some way helping you, whether you're writing code or marketing or documentation or whatever it might be, particularly around generative ai. But that seems the market is responding with how that's a lot of times how they're introducing generative AI as an assistant co-pilot.
So I I will tell you, oh, I'm sorry. Go ahead, Mike. I think the challenge is gonna be not so much whether we have co-pilots, is just that, how many of 'em are there gonna be?
I mean, Microsoft's got a co-pilot for every little thing, and every other vendor is building something that either looks like a co-pilot that they're gonna call it that or they're gonna call it something else. But essentially it's the same thing. And I'm scratching my head going at some point, will all the co-pilots know about each other?
It's kinda like having an assistant, but none of my assistants know any of your assistants. Have your people call my people, have your AI called my ai. So, so I, I'm, you know, surprised, I'm gonna take a little bit of a contrary opinion here.
So first of all, I, I have to tell you that I was amazed at the amount of companies that are actually calling their AI assistant co-pilot. Knowing Microsoft is idu for 30 plus years, their lawyers must be sharpening their teeth and billing their hours right now saying, how can we be the co-pilot? Right?
And I think Mike pointed it out to me, we were in Las Vegas, that it's co-pilot with a small C maybe Microsoft's is a big C, but sooner or later is copilot become a generic term, Like, uh, you know, Reynolds wrap for aluminum foil or, or, you know, pick, pick a or Kleenex or something like that. But more importantly, beyond the what's in the name, you know, I think initially a lot of people use that chat bot interface for chat GPT or borrowed or whatever chat bot, you know, AI you're interfacing with. And it was, you know, you would ask it a question and, and what separated the, the pros from the amateurs, and we're all amateurs still really is how well you put your prompt in, right?
Who, who's the better prompt engineer? And I used to laugh that that wasn't a real term, but over time, I've, I've, I think I've come to the conclusion that a prompt engineer is a real job. That being said though, I think when we talk about copilot, what you're talking about is embedding AI functionality right into your, your app that you're working in.
So whether it's Microsoft Word or, or, or, or Excel or it's, it's PagerDuty or it's GitLab and, and a lot of 'em have different names besides copilot, but whatever, whatever the app you're working in Salesforce, the ability for it to copilot your mission, to copilot your flight is, is I think what, what's inherent here. So it's not just answering a prompt, it's actually helping you drive Your, your app or whatever your workflow is in your app. And so from that point of view, copilot becomes a term of art, a generic term.
And not everyone's using copilot. Last week at AWS or the week before at a WSI heard Davis and Duo and, and, uh, Mitchell and Mike, you probably heard a bunch of 'em yourself, Einstein and Bedrock, I think of Fred Flintstone, but you know, all, all of these names. And we heard quite a bit of companies using copilot, so I'm not sure they have to talk to each other.
I think copilot is generic term for built in help. It's your built in assistant in whatever app you're working in. I always think we're, we're living with the rapture of Watson, you know, IBM named their Watson there, big computer, right?
Uh, or Alexa, right? Everybody's got a name, a person name for their, for their bot or whatever this, whatever their, whatever their interface is, their assistant. And that's sort of the really what copilots are, is designed to be assistant maybe really helpful maybe not.
I mean, and Visual Studio, I mean, it makes a big difference. Code completion. Sure.
It does. Even does write a little bit of code for you. We'll do more.
But, you know, is, is a chat bot as an interface into your customer service helpful? Well, it all depends, you know, about what it's gonna Respond With. I'm gonna wait, I'm gonna disagree with my most learned colleague over there.
Co-pilot. Go ahead. Disagree with Alan.
Co co-pilots would definitely need to be integrated with each other. If you look at any process in the enterprise, it spans a minimum of four to five different applications typically. And they're all gonna have co-pilots, and they're all gonna have to have some way of invoking each other.
There'll be need to be some automation framework that sits between the co-pilots. And these things are gonna, you know, need to become The same way every app integrates with each other. We'll have APIs.
Yeah, right. I, I don't think that's an AI specialty thing. I think that's just right.
I think it's just an a an API kind of thing. But, you know, Mitchell, a funny thing about what you said about whether it's a Alexa or, or sir, whatever, you know, my, my, our latest car came with the BMW help built in, and you can name it whatever you want. So I thought I was gonna be cute.
I named it Esther until we had someone in the car named Esther. Don't do it. I just, I, that's my only, that's my only advice to you.
Don't, don't name your AI some common name that, you know, we Yeah, it's, it's bad news. It's bad news. No, well, well it depends.
It, you know, that depends on, you know, are you worried about it sending you out, opening the pod bay doors or something. But, um, in, in any event though, but certainly, I, I, I'll give you an example. I spoke with, uh, chief product office officer at GitLab yesterday, David, and, you know, they have this talk to code copilot, they call it duo, but it's copilot where you just tell it, Hey, I, I, I want, I want my app to do this, blah, blah, blah, blah, blah.
And it generates the code. It actually could generate a, you know, an app for you just telling it what you want. That, that kind of freaks me out a little bit, to tell you the truth.
But it's amazing. Amazing. Yeah.
There's other, just to that point, other folks are talking about, um, Microsoft is a good example where you're just gonna describe what you're at and want your app to do in the project management app and then the code will get generated. I'm not entirely clear if that works to what degree, but it's gonna be interesting times. I, I think one of the interesting parts of this too is when we go through another person to get who is using the copilot or whatever it is I was doing, going through a troubleshooting problem on some Linux stuff the other day.
And I asked the asked the person that works with the, where'd you get this script? This is actually really helpful. He says, I got it from chat GPT.
I'm like, oh, okay. Oh, hopefully you embedded it before we ran all this stuff. Right?
But, but here's, here's the point though too, guys, we're having this conversation because this isn't even the beginning of the end. Yeah. Or the end of the beginning.
Excuse me. This isn't even the end of the beginning. We are at the very first leg of this marathon and we're still trying to figure out what the ground rules are and what, how everybody plays nice together in the sandbox, so to speak.
But I think these things will, you know, in hindsight they'll be obvious whether or not Copilots should talk to each other, how we should hook them up. What are the right, right APIs here, is it a bunch of zaps or something, you know? Um, and, and I think that's why we're having this discussion because it's still kind of uncharted territory a little bit.
So have your copilot talk to my copilot. We're good for now. Well, you mentioned chat, GPT, and that's a good segue into really the main AI focus seems to have been generative AI this year, uh, with open AI and chat GPT.
So how are we going to embed generative AI into workflows across the enterprise? Well, I kind of started that conversation already, but jumping into it a little bit deeper. Um, the issue is gonna be we need some standards.
I think we need some ways that these things can talk to each other. It may be an API, it may be something that's a little more direct, but I feel like, um, there's an opportunity for more technical standards to emerge in this space. And everybody seems to be rushing out building their own little, you know, quasi open box.
But I think we're gonna have to at least take a step back and say, what are the specifications that we can all count on to be there as a fundamental thing? I don't know. Mitch, what do you think?
Well, Alan and I met with the, the, uh, tech vendor. I don't know if I can say who they are during AWS but their approach was, I, I'm gonna create a layer between your workflow and all of the LLMs and, you know, generative AI things. 'cause we may wanna use different LLMs for different things, but they actually kinda create their own prompt layers where they prebuilt the prompts of what workflow actions might look like, and then you can evoke that through their layer.
So it's, it's a sort of, um, kind of a cleanup layer, I would say, or simplification. Well, it's a trust layer too, right? I think they called it a trust layer.
That, that's a really good point. I'm glad you brought that up. Say some more about that.
'cause it was a very interesting conversation. Can I name that company? 'cause they're kind of, Yeah, go ahead.
Salesforce. Are they paying us? Okay.
No, they're not sponsoring this event. I don't believe you. Okay.
Take, take that. Alright. Name them anyway.
Mike. Hey, it's the CEO in me. I had to mention it, but go ahead.
So, you know, at their base level and then gross over simplification, but to Mitch's point, they are creating a trust layer that says, um, we will validate the LLM for toxicity and governance and guardrails and all these policies. And the idea is gonna be that you're gonna have multiple LLMs optimized for specific tasks rather than one single general purpose chat, G-P-T-L-L-M. And we're gonna mix and match these things.
And you as an end user may never know what LLM they're using at any given time. They're just gonna swap those things out. And we could be looking at the commoditization of LLMs already.
A absolutely, and it, what, by the way, it wasn't just Salesforce in terms of using multiple LLMs on the backend. Uh, any number of the companies we met with at reinvent, you know, and there were 60,000 people at reinvent. Yeah.
But another interesting thing that we didn't mention about that trust layer was that it also prevents your data, whether it's data you're putting into the prompt or data, you're, you're getting out of it from being, you know, Borg bogged into the LLM from being, you know, assimilated into the LLM. And so I think that's another big issue, again, as we take these baby steps into this brave new world of how do I protect my IP with these copilots? If, if, do we have a multi-tenant copilot, like we're seeing, let's say in the Microsoft case, right?
How do I make sure, now the, one of the companies we spoke to and I, this, I don't know if we can mention, but one of the, the company's name. But one of the companies we spoke to contractually, contractually contracted, that's kind of a double entendre, but they, they, they entered into a, a contract with open ai, that open aiche. GBT would not use the data put into the prompt or what's coming out.
Now we talk about regulations around ai. You know, when I went to law school a hundred years ago, I had a law school professor who said, the law always trails technology by three to 10 years. I don't know if we could wait 10 years for this, I don't even know if we could wait three years.
But we need certainty around IP ownership if this stuff is really going to u take off the way we want it to take off, right? I can't, I can't trust Salesforce to trust layer to make sure that no one, or maybe I can trust Salesforce. And maybe that's what's needed.
I need that trust that my IP is secure, sacro sayt, it's not gonna be violated. And when we start talking about plugging into multiple LLMs and they, and chat bots and so forth, in the back end, I want to know who I'm plugging into and whether or not my IP is protected. And maybe that's, that's a great angle for Salesforce, right?
We're the trusted force. You don't have to, we don't have, you know, worry about who that LLM is in the back. I don't know.
But I, you know, I think, I don't know if we could wait for the government to, to figure this out. It seems like, it feels like we're at the beginning of the cloud era times a hundred where, you know, is kind of, is it secured, operate in the cloud, right? Eventually that question got answered.
IP is one issue. Data protection. I mean, just, there are dozens of unanswered questions for, But for instance, we have the GovCloud, right?
You have GovCloud where security and, and access and where stuff was hosted was very well defined. If you wanted to have, you know, the government using your cloud platform, I think we may need something similar here. Maybe not.
I, maybe, maybe Salesforce provide, maybe that's the, the ticket, you know, that they'll all provide this trusted layer. And maybe at that trusted layer is where they all talk to each other. That'll make Mike very happy.
Course It's about making, uh, Mike happy. Yeah, I'm glad we cleared that up. Trying to have do things here at text.
We always think what will make Mike happy? Oh, What would Mike do? What would, Mike, Aren't You glad you signed up Amanda for this?
I'm sorry. No, I love it. Okay.
I love hearing you speak about it. Um, so to that note you mentioned, um, so we're speaking about the large language models and how many there are and, um, we have the private ones and the open winds. And with all these large language models strewn all over the enterprise, how do business leaders best manage these?
Who is going to manage these? And since the government's, um, not really quite there yet, it falls on the enterprise, I believe. So what do y'all have to say?
I think there's gonna be multiple classes of LLM. So there's the foundational ones that, you know, the big tech companies have built and there's open source ones and they're all over the place. And I think people are extending those using things like vector databases that they stick in front of that so that it can see your data and kind of be extended.
But ultimately, I'm not sure that I need or want a general purpose. LLMI think you're also gonna wanna customize those LLMs, build your own and kind of build some data into that. Whether you wanna build an entire LLM from the ground up is, you know, maybe, maybe not.
That's a lot of work and maybe something that Morgan Stanley would consider, but there's a lot of nuances along that curve. And I think, you know, the answer might be all the above, You know, quick plug at the end of, uh, to know, towards the end of today's AI in Action virtual event, we have about a 40, 45 minute video playing of a hackathon that we hosted here at Techstrong Headquarters, I think back, I guess in late August. And, and we had, we had some, some really smart people, way too smart for me.
Um, some of the people put together the whole DevOps and DevSecOps movement and you know, they explored this, right? And, you know, for those of you who are new to AI or just dipping your toe in the water and are not quite sure, the way they explained it to me is think of these giant LLMs, like an open AI or Bard or LAMA or these as, as your long-term memory, if you will, right? There's a huge amount of data there.
It's a huge data like, and then the custom LLMs that you can create from a Vector database, you know, inject in, think of that as short term memory, right? So now you have your, your large LLM and let's say your custom LLM. And when you then query or, you know, chatbot put a prompt in it first looks into that short term memory, that custom LLM, and then what it doesn't pull from there, it pulls from the bigger LLMI don't that that secret's outta the hat, right?
That that's no longer gonna fool people in in Oz anymore. They know it's just the man behind the black curtain. So everyone's, and you mentioned, I think it was not, not, uh, what's the site developers go to when you could get code, uh, Mike, you mentioned it.
Open stack. No, no, no, not open stack. Um, Are you talking about hugging face or No, You go, you go and ask questions and the community answers.
Oh, um, Oh, oh, stack overflow stack over Stack Overflow. Thi this is ex, sorry, Mitch Senior moment, but this is exactly what Stack Overflow did. I, I interviewed their CEO, it's on our tech drunk TV if you want to take a look at it.
They took almost their entire base of questions and answers and created a custom LLM that sits on top of another broader LLM. And, and you can query is, is that gonna be the model going forward? Maybe with, you know, some sort of, uh, copilot that makes that easier to query that big thing for you and better gives you a better prompt?
Maybe, maybe, you know, I've spoken to other people who say, nah, that's not the answer. That's like a, it's an ex it's a dead end ex It's like the Neanderthals, right? It was, it was, it was, it's on the branch of, of humanity, but it's kind of a dead end Knuckle dragers.
Okay. I mean, the, the more, the more data that you throw into the LLM that's not vetted or specific to your task, the more likely you are to get a, you know, hallucination Or poisoning, right? Which is again, something about that trust layer.
The trust layer says, you know, they're going to weed out the hallucinations in poisoning toxicity or whatever you want to call it, coming up with some great names for this stuff. I think that's just one use case, which is, you know, I get this big massive amount of data, Wikipedia, you know, whatever, whatever it is, right? Put, put in an LM generative AI chat, natural language in front of it.
Um, I I, I seriously wonder like, is every organization gonna be going out there building LMS for themselves or training LMS for themselves? Seems to me this is a ripe for sort of like the cloud hosting environment. I want you to do my training, my LLM for me.
Yes, it may be my data and you'll protect it and I want you to operate it for me. 'cause are you, are you gonna have, you know, 20 different groups around an enterprise going around creating your own LM LLMs with different versions and aging of the same data and you know, you it, it'll be a mess. I don't see how you can, I, maybe we will figure it all out someday, but it seems pretty complex to me to say it's, you're gonna do this on, uh, on in many groups at large scale and have these things as sensical.
I think you're onto it. I think it's gonna be a mess because the LLMs are down into the size now of terabytes, right? I mean, it used to be these large language models where petabytes of stuff that you built and somebody had to go and curate all that stuff for you now.
But with each passing iteration, I can now use massive LLMs and I can use what are essentially by comparison tiny LLMs for a specific purpose. So I, every developer I know is gonna be like, yeah, I'll just use this. And away we go.
And, you know, somebody on the DevOps side, I'll figure out the best later. I I think eventually you automate, have a copilot that builds your custom LLM for you, puts it, you know, puts it in a gathers data, puts it in the vector database, and there you go. So that brings us to the next question.
Seems like a good question to ask now is, will there need to be a convergence of DevOps and ML ops? I think that happened way before generative ai. Yeah, I agree.
I think it already has that or already needs that. But if it Hasn't, in, in, in the, in the marketing lexicon, they called it AIOps, I don't think that those are necessarily the same thing. I mean, AI ops is more about applying AI to the actual management of IT operations.
ML ops is the, you know, the best practices that data scientists are using to construct a model. But the problem is, is once they construct it, they gotta throw it over the fence to a DevOps team to deploy it. And sometimes that's through an API and sometimes it's an actual artifact that will get embedded in the application.
But I think there's work to be done in that space though. I do too. I mean, think about it this way, is if you had multiple work streams that are happening in parallel that need to be quarter coordinated to, you know, produce some sort of, uh, releases into production and ai, LLM is very much like that.
It's not just a database, right? It's something's being trained and evolved and updated. And how does that flow in integrated into the workflow along with, uh, you know, other software that's being created.
So I think that's where the gap is, Mike, of figuring out how much, where, how do we, how do we kind of, uh, integrate the workflows to the degree necessary. So if we're not going down divergent paths, Right? And there's no concept of version control in the land of LLMs, right?
When you retrain the LLM, it's an entirely new thing. 54, that's version control at some level. They're, They're all different in, in the sense that they're not like version 10 of my previous app.
They're kind of fundamentally different software entities. Yeah. And with different functionality.
But you know, back to back to what we were saying about AI ops ML ops, I, I think unfortunately a lot of people meant ML ops when they said AI ops. And I think that's the way it came down to DevOps. Um, but, but that being said, here's how I ha to me, the real question is how does that world of machine learning and AI ops, if we can call it that, interact with generative ai?
'cause I think to me this is akin that you need an atomic bomb to set off a hydrogen bomb, right? Because that, that you, you need, that's how hydrogen bombs work. Now.
I think what's gonna happen is we can create great insights and, and recognize unbelievable patterns and, and, you know, observe for observability sake, amazing things using ml, ML ops, you want to call it AI ops, whatever. But taking the findings, taking what you find in those patterns and then creating actionable steps real, you know, taking action is I think where generative AI somehow gets that feed as a prompt or whatever you want to call it, and then does something as a result, you know, uh, using ai, uh, in, in its pure sense. So I think there's a world where these things converge and come together and, and you do have that nuclear age, right?
Then throw some quantum computing in there just to make your head spin. But that's where we're headed. I think you're onto something there in the sense that, you know, if I look back at AI models, there came in two flavors, right?
They were all machine learning derivatives, but they were, one was predictive and the other was causal. And now we added this generative capability. But I, you know, I don't think generative eliminates the need for the first two.
I think as we go along, all three of these things are gonna start showing up in various applications and platforms, and we're gonna need to weave that into something that feels like a fabric that works. Yeah, I think, I think maybe to the question about sort of, does, does the atom lead lead to hydrogen bomb? I'm gonna grossly oversimplify, but you get an idea of this from the video about the hackathon later on when we say training and LLM, really what a lot of that training is, is training, uh, the how to res what kinds of prompts to expect and how to respond to those prompts.
So you get meaningful information back out of the LLM, otherwise you'll get whatever. And, you know, it doesn't know what to expect. And that's why you can get really weird ization a lot of the time.
So I kind of believe over time that training process is something you can develop models for, right? There's certain ways of doing different kinds of training of different kinds of data. Like APIs behave this way, chat bots behave this way, you know, pick, pick whatever the use cases are.
Maybe that AI can then help us with the training. Maybe it's co-pilot for training of the LLM. I think that's where AI kind of could fold back on itself.
Alan, I'm not quite sure if it's as big as, you know, creating the next big, big bang or not. But Wait, wait, are you saying that the hiring of retirees to tell machines that this is a cat a thousand times is not gonna be a long term job? You mean I don't have job security?
Is that what you're saying? I'm not gonna go there. Um, you know, not into this one.
Amanda, back to you. Yeah. Moving on.
Um, so we know business leaders, they're all trying to implement this AI technology in some way. And we know there's many positives to harnessing ai, but let's talk a little bit more about, um, some of the cons and the cybersecurity issues. What are those issues and how can we address these issues moving forward?
Some of it is just classic phishing, right? People are gonna fish their way into these AI models, grab the credentials, and then then try to poison them. And you can get folks out there who will attempt to deliberately introduce a hallucination into an AI model if they're allowed to.
So that's gonna be, you know, I think the most common cybersecurity issue up front, Mitch, I don't know. Uh, I, I agree. I think there's a flip the coin the other way.
And the fisher could be the, the, uh, LLM, the generative AI that's talking to you. You think you're talking to a person through an email or chat bot, suddenly they're now man in the middle attacking you and you think you're talking to who, who you think you are. And that's not, so that, that seems like one, I think another really big one for everybody is DA is data protection.
Like, how do I know that you stole my model and all the training that's gone into it. What's the value of that ip? It's gotta be the value of the data times, whatever, right?
That would be talking about stealing ip. That, that seems to be a big threat is the data. Oh, And I know there's a gentleman in the back of the room that's a white shirt.
I think his name is Allen. He has a question or you, you No, well, no, no. I I I like to let Mike, usually you gotta give Mike three things to say.
'cause he always has three things. Mike's Gotta be happy. I I think the other big issue is that, um, it's software, right?
And it's built using open source components and the open source components have vulnerabilities in them, and they're gonna be exploited just like regular software. And, and we don't have, whether It's open source or not, there'll be vulnerabilities. I don't want to, I'm not gonna bash open source here.
No. All right. I'll have to do Hoover in Animal house.
Not gonna, we, we're not gonna be part of this. We'll start playing some patriotic music and walk out. I don't care what Dean Wormer says.
Either way. I think you're just calling me Dean Wormer, but okay. I know a Dean Wormer, I'm A husband Dean wormer, But anyone, um, the issue becomes, it's harder to remediate these AI models once they're in production because you gotta pull 'em all back and retrain 'em if you got an issue with the vulnerabilities.
So vulnerability, there's no like, concept of patching an AI model. So I think this is gonna be a bigger issue than we think. Yeah.
So as a security person who's been in InfoSec, cyber, whatever you want to call it for a long time, is anybody really care? Does anybody really care? Every, every innovation in my lifetime, the security people have stood up and said, wait a second.
This, this is gonna be a security nightmare. How do you look in stripes? Let me throw some fud.
Your away. We, we halt, halt immediately. Stop all activity.
The trains left the station folks, right? It's up for, it, it for security and for those interested in it, we gotta hop on the moving train here, right? But let's not delude ourselves into thinking we're gonna pull the emergency break and, and figure out a way to secure it.
It's happening, it's done. We gotta live with the consequences. So instead of trying to prevent security things from happening that are kind of, it's already, you know, the barn's door already open, the cows have run out.
We need to start coming up with strategies for how to respond to these possibilities. And response is, is is where it's at Again, we're at the beginning. We're at the beginning of the beginning.
Security will evolve, will adapt. We'll be there. But I, you know, I think AI's gonna have, make security better in some, in some ways, but it'll also pose some challenges that we'll, we'll have to figure out.
But let's not dilute ourselves into thinking somehow we'll slow this down as a result. The best, best Way don't work that way. Best way to stop a train is not by jumping in front of it.
Is that what you're saying? Yeah, exactly. As Dick dastardly would, would know, Tied to the train from Tying Penelope, whatever her name was.
To your point, whenever there's a threat or some, you know, something disruptive, you can, it can be disruptive. Or you can also say, well, how do I take advantage of that? How do we turn that to our advantage in security?
Yeah, right. That's where I think the energy should be. I think, I think when you pull the emergency brake, the first thing everybody asks is, A, who pulled the brake B, Y, and C?
Throw them off the train. Why are they still On the train? But you've been riding the Long Island Railroad and Metro North too long, Mike, in other places they don't necessarily say that.
Okay. Especially to throw 'em off the train piece. Um, but it's okay.
Evander, I think we probably have time for one more. Yeah, Yeah. Um, so yeah, there are two sides to every coin.
But, um, to your point, there will be some regulations down the road. I'm sure they'll, um, have some, some government say in, in ai. And so how do business leaders need to address the compliance, um, aspect that's gonna come down the line?
I think like They always do. They'll check the box, They'll fill the forms out. I think there's a little hesitancy though to kind of go in full bore into production.
I think everybody's experimenting, but they're looking for a little clarity. 'cause nobody wants to go build something and then have to roll it back. So there's kind of a lot of pressure, I think to, to at least put some regulation on the board that people can count on as being somewhat stable.
And hopefully there aren't 52 of them in various states. And I'm wondering at the end of the day, if, um, you know, these regulations come down the pike too, somebody's gonna try to start auditing this stuff and then there'll be, you know, explainability requirements and all kinds of funds, things will happen and they'll all come with a fine at the end of the day. So I think we should move sooner than later, regardless of what the regulations are.
And like, let's give people at least some sort of guardrail that count. So I disagree. We're not gonna have 52 different regulations.
We'll have two or three states, maybe California or New York, Florida and Texas ain't do it. And that's exactly it, Mitch, we'll look to the EU to come up with some regulations, and in about two, three years, they probably will 30. Are they already have it in, in revision, right?
Or review right now? Well, yeah, but it could take, it could take until they pass it. And then they just 'cause they pass it doesn't mean it starts being affected, effective day one.
It'll be two years, three years. But that being said, let's not again, let's, let's be realistic. There's a lot of frigging money being invested in this AI stuff.
They aren't waiting, they're not waiting for compliance. They'll comply later, right? The, the, again, the chains left the station, there's billions of dollars being poured into it.
Silicon Valley has taken a, a hard right turn into ai, as has the rest of the tech world, the VCs, that's all that, not all, but you know, that's where the money's pouring in. Follow the money. So lesson I've learned, I, I do agree.
I think there'll be a couple that most, you know, be the predominant whatever the reg regulations are. One from Europe, one from US North America. Uh, it it, to your earlier point, you know, Alan, about the legal catching up with the technology.
Same thing in regulation. We, we do, we are moving faster than we have in the past, but I, I think they'll, my guess is a total guess, they'll probably build off what they've already done around data privacy protection, and they'll kind of address that part of it first and maybe take some attempt at like, you know, what's responsible AI and not defining it, but do you have processes in place to make sure you're using AI responsibly? And you have a definite, you know, they'll have the, you have to define it, but then you have to follow your process, those kind of regulations, because they don't, they don't know any more than, I mean, we know more by, by implementing it than they're trying to write regulation for it, right?
So I, I think right now most of the talk around regulations revolves around data privacy and ip. And that's probably a good place to start. But I think there are other regulations here that are going to pop up.
I think you're gonna have something akin to like Asimov's Law of Robotics or something, right? In terms of what we're gonna let AI actually do, right? Let's not, let's not give them the key to the car, the keys to the car and regulate ourselves to the backseat and, and, you know, 'cause who knows, right?
Um, Isn't that a Tesla? But you know what? They tried the driverless taxis in California and they pulled back, right?
Um, I, I think, I think you're going to need some sort of laws of AI like, like robotics, where, you know, do no harm, do no evil, do whatever. I don't know. Yeah.
Elijah j Bailey, which I'll, I'll give a quick, a quick, uh, a quick, uh, plug. RSAC this year, again, we're putting on our DevSecOps, DevOps Connect DevSecOps, but it's DevSecOps in the world of ai. And our keynote speaker is none other than David Bryn, multiple Hugo New Nebula Award-winning PhD from JPL and probably the one of the foremost futurist on AI in the world for the last 25 years, who also happened to have written the sequels or one of the sequels to the foundation commissioned by Asimov's family.
So he's really familiar with the laws of robotics, and he'll probably talk about this stuff. If you're going RSAC, it's Monday May 6th with there all day in the Moscone Center. And we even have, uh, somewhere on Textron, you'll, you'll have a free code for an expo pass, which will get you in to our event that Monday.
So all those Asimov books, they end happily, right? Um, yeah, Yeah, something like that. Well, the next generation comes along.
Well, you read the next book when the other one next book, right? You read the next book. You read the next book.
My, my 2 cents, my 2 cents in the whole thing is we can't afford to be Luddites, right? We gotta move forward, we gotta kind of keep this thing going. But I would say that a certain amount of caution is required because as one folk shared with me the other day, he said, you know, think about ai.
It's one thing to be wrong. It's another thing to be wrong at scale. Yeah.
And it may happen, right? But that's counts. You know?
So to that note, as we get to a point where we have just a few minutes left, let's wrap this conversation up with your best advice or your best key takeaway for our audience as it relates to AI in the future. Mike, would you like to go first? Don't, don't quit your day job.
You're not gonna be replaced anytime soon. So show up. I agree.
Go to work, work might be better, might be less toil might be less painful. But the whole notion that, um, you know, we're all about to be, be replaced by a bunch of bots, uh, farfetched at best, Mitch, my my advice is go learn something about it, right? There are so many resources available to go try this or that.
I mean, you can try chat GPT if you want to, but it's not that hard to go do a little, little kind of kicking around and trying these things out and taking a Udemy course or whatever. The best way to understand it, I think is right now is to actually just apply some of it yourself in your own, you know, sandbox. I'm not saying go change the company, but that'll help you get beyond sort of the marketing talk and like, okay, I understand a little bit about what it means to train a model.
I couldn't do one, but I, I've tinkered with it enough to know I, I've, uh, tried an electronics kit enough. I can build a radio, but I'm not gonna build a real radio. You know, that kind of thing.
So I would say this, look, the three of us, we're a little older than most of you out here watching this, right? I wish I was your age right now with what's going on with ai because we're, we're set to boldly go, boldly go where no one has gone before. No humans have gone before.
And embrace change, embrace progress. Embrace these new technologies because as I've been saying all along, the trains left the station. Hop on that train, ride that train for everything.
It's worth the, the, the potential is boundless. There's so much opportunity there. Don't, don't be a stick in the mud and try to drag your heels.
Do what Mitchell said. Get some training. Don't be a Luddite.
As Mike said, embrace this opportunity for what it is. Every 20, 25 years or so or so, it seems like we throw the cards up in the air and we see where they land this time. This is one of those cards up in the air moments.
Take advantage of it. And that is a great note to end on. I wanna thank you all for coming and listening to our session today.
If you miss some of the other sessions, they will be available and stay tuned for more great information on AI in action. This is Textron tv. Hey guys, thanks for the throw.
We're here with Tim Miller, who's CEO for Qari, and they're a startup company that just raised $8 million to address this thorny software supply chain security issue that's been out there. Tim, welcome to show. Uh, thanks for having me, Mike.
So what is the core problem here? Because we've been talking about this forever and a day, and I don't know, we're making a whole lot of progress, but why do we need a new company in this space? And what is a problem that we're solving?
Uh, yeah, no, it's a great question. Um, so I think funda fundamentally, the problem really hasn't changed at all. Just the scale and the speed at which everyone is moving has increased.
And so the traditional approaches are, uh, are, are, are, you know, failing to scale with the same speed that everyone else is. Um, fundamentally, I think software supply chain security is really about knowing what you have. And a lot of traditional approaches take a single project view of the world, when in reality, most organizations have hundreds if not thousands of projects altogether.
And when you really put yourself in the shoes of an engineer at a, at a software development shop of any scale, trying to get ahead of that problem requires much more than a traditional, um, you know, plugin or scanning tool. Uh, you really need a lot more information at your fingertips. Uh, and that's really, I think, the problem that's been, that's been missed or avoided.
'cause it's pretty complicated. Uh, in all honesty, uh, software develop, software environments are messy. How does that therefore plug into my say, DevOps workflow?
I mean, where do you fit in that spectrum of things and, and, and where are the handoffs? Yeah, so I think to put it in perspective, where we come into play is trying to simplify the supply chain, uh, problem allow folks to see the gaps and understand what they have and make more pragmatic decisions. So that's a context in which we'll answer that question.
Um, but typically as a, as a DevOps folks, if you put yourself in the, in the shoes of someone trying to fix something, or like the first 10 minutes of what happens after log four J uh, you know, V two comes out, um, the first thing you're trying to do is find what's going on. And that's a incredibly difficult problem for a lot of folks. You end up with this, uh, approach of patching, the first thing you see running your software through your CICD systems, waiting for everything to come back and just hoping that the scans come back ne negative.
And hopefully they do. Um, but a lot of the time it's not like that. It's more complicated.
Software dependencies are not one layer deep. They're many layers deep. And what you really need to understand is where things came from in order to make a tactical and confident decision.
And that's really where I think, um, we're trying to play or we're trying to help folks. Um, but really it's about tying that information all together. You've got a lot of it, but you just don't know how to act on it or if you're confident in it or anything like that.
So it really ends up being an information management problem for, for these people. So in the same sense that we may have a business intelligence app, we need a security intelligence app for application development. Yeah, yeah, it's a good way to think about it.
Um, and, and again, you can, you can imagine that the amount of things that any one, uh, software team is dealing with is, is crazy. It's, it's a lot of, it's a lot of information to sort through. They don't necessarily know where things came from or who put it there or why.
Uh, so the context around things really ends up being something that folks have very little of. Uh, and so the more that you can help with that, uh, the, the quicker you can react to things and the less time you spend searching and, and, and waiting for things to go, and you just make the change and get back to your day job. And A lot of times the dependency that might be affected isn't even something that I, as a developer have control over.
It's a component that somebody included inside the app, but at the very least, I'll know where to start making my emails to and kind of get the process rolling, right? Well, yeah, at the very least, you want to know where it came from, um, and that that can help you and help inform you whether you have control over it or not. Uh, if it's critical enough, you might want to know that, uh, and then get control over it.
There's all sorts of different ways to to attack, to attack that problem. But yeah, know, knowing tends to be the first step of solving any of these things accurately and, and solving 'em correctly, uh, or at least creating a, a mitigation plan around it. Um, so at the very least, you know, you need to do that, uh, and then, uh, and then go forward from there.
Also seems like a lot of times the issue at hand is a component that's an older version of something, and I already have the new version of that, something located somewhere in a repository. And if I replace A with b, I could solve my issue and hopefully not break something along the way. But to your point, it seems like we don't even know what we have.
Yeah, I mean, it's a shockingly basic problem. Um, but it really is a problem. And oftentimes you, you may even have both versions of something in your stack and, uh, they're, they're just at different places or they're deployed differently or, um, but yeah, in order to get your head around it, and particularly to be proactive, you really need to understand what that, what that, uh, tree looks like and, and where those things are all coming from.
And then, uh, and then try to reduce the complexity on yourself going forward. But, uh, yeah, it's, it's a really, uh, shockingly hard problem to answer What exactly am I working with? Alright, so you picked up $8 million in funding to get started.
What comes next? Where, where are you guys on this journey? Um, so yeah, to date, we've been, uh, working on the open source project guac.
We've been working with Google, uh, Purdue University, um, city, uh, a bunch of great folks on, on that. And so far we've been getting great traction on the open source approach to solving this problem. Uh, next we'll be pivoting into making sense of that data and helping folks navigate what to do going forward.
Um, so to help identify gaps, uh, to, to know what to do in any of these situations, uh, 'cause that in and of itself can be complicated. Um, so working on our, on our, on our own product launch to, to get ready for that, we'll be investing in, uh, and engineering that. And hopefully towards the second half of this year, we'll be, uh, ready to show that off.
So is that essentially a curated instance of the open source project that is maybe tailored for a specific business? Or what is the relationship in your mind gonna be between open source and what you're offering? Yeah, so you can imagine that the open source guac project provides you the transparency and visibility into the data that you have.
And for a lot of people, that's enough. And we'll continue to curate that and keep that source, uh, keep that core open, uh, and then what you do and how to navigate that, what to do about any of that data is where we're gonna come in and help, uh, provide the buttons to fix things for you. Uh, and, and just generally take that, make answer the so what about any of those, uh, all that data and, uh, and just make that part easy.
Um, so it's really simplifying the problem and taking, taking away the co the, the complicated nature of navigating the supply chain issue. Do you think AI has a role to play in this someday? I mean, I could imagine me coming into your little console and typing in, show me the three things that are likely to get me fired today, and maybe you'll pop.
Oh, yeah, absolutely. Um, so there's already been some really interesting prototypes, uh, around that. Um, you know, so some, some folks created a, a little prototype tool called Guac ai moly.
And it did exactly that. It, it, it sat on top of guac and allowed folks to answer the question, Hey, do I have this vulnerability in any running containers? And where to come from and seeing that interface is, is, is amazing and, uh, really excited about where that can po potentially go.
So absolutely, we'll have a, we'll have a big role to play in this, particularly in how folks interface with the problem. I think one of the dirty little secrets about software is that we have this massive amount of technical debt in terms of vulnerabilities that fortunately or not heavily exploited, maybe only a single digit percentage of them are, but the bad guys will probably get around to 'em. What's your assessment of the current state of application security?
I know we can draw a line in the sand and say, you know, from here on out, we'll get better, but do we gotta go back in and fix all that stuff that's already out there? Um, so I, I think the current state is, is, is just missing a couple key pieces. And I, I think that's really where we're coming in.
So I don't think it's fundamentally broken, but at, at, at, at a, at a basic level, uh, a lot of the inform, there's been a big information gap between security teams and application development teams. They tend to, they tend to not share information very well. Uh, and so there's this information silo that exists that, that exists that the current tooling hasn't really helped enable.
Uh, and so really I think if we can tie all the data, get together, have one source of truth for what's actually going on, both on the vulnerability reporting and on the, on the folks who can actually do something about it on the dev side, I think that's really the missing, the missing piece. Um, 'cause fundamentally, as a, as a dev, when you're trying to fix something, you have an entirely different tool set than what the folks who, who told you you have something, uh, going, going wrong, uh, or at least, at least at a certain scale. And so really bringing those two things together in a real practical, uh, way, I think is, is the missing piece.
Um, but yeah, it's, it is only gonna get harder as things speed up. Can we get to some sort of kumbaya moment between these teams? Because historically, the cybersecurity people would be like, here's your list of vulnerabilities in a spreadsheet.
And then the developers would be like, well, thank you. And then they'd go look for all this stuff and discover that 99% of it's not running in a production environment or is not internet facing, and then they, um, mutter under their breath and then they stop paying attention to cybersecurity people. At least that's my experience and how it works.
So, you know, can this get better? We certainly believe so. Um, I, I think one of the fallacies is that you need to do something drastically different.
You need to completely restack, uh, in order to, in order to have that kind of, uh, interaction. And really, I think it's just about breaking down the walls and sharing the information in a way that's practically usable for both. Um, but it really starts off on, on unifying how both of those different sides of the house look at the data, um, because it really is a data problem.
And, uh, and then from there, you can make it practically usable, uh, for, for, for both folks. Uh, I think that's really been the, the difference is a lot of tooling either focuses on the vulnerability reporting and forgets devs or focuses on the updates and forgets that people have to pay attention to where these things came from and how to report them and understand the, the, the workflow around the, the issues themselves. Um, so I think, so that's what we're here to do.
All right, folks. Well, you heard it here. Software supply chain security is just like any other IT problem, it starts and ends with the data.
If we get the data right and everything else becomes reasonable, Hey Tim, thanks for being on the show. Thanks a lot, Mike. All Right, back to you guys in the studio.
This is Textron tv. Hey guys, thanks for the throw. We're here with Michael Zercher, who's CEO for Prismatic, and they just landed a huge amount of cash to drive what's known as an embedded iPads, and I'm gonna let him explain what that's all about.
But Michael, welcome to the show. Thanks for having me. So what exactly do we mean by embedded iPads?
I think people think of iPads these days at least as something that exists in the cloud as a service that I access, but is that whole function moving and getting embedded in other places? What's going on, my friend? Yeah, so I mean, what we've seen in The last few years is that, uh, end users more and more want native integrations to be part of the solutions they buy instead of buying solutions and tying them together with an IPAs.
And so that's put a lot of, uh, responsibility on SaaS vendors to provide integrations as part of their products. Embedded IPAs is a way to provide a platform to those SaaS companies to make that process easier, uh, as they connect their products to the other products that their customers use. Is this a concept that will eventually be extended out to enterprises who build their own applications, stick 'em up in the cloud, and in a lot of ways have the same issues?
Yeah, I think there's, there's kind of a spectrum there where, you know, we are focused and the embedded IPA space is mostly focused on SaaS companies who have all of the integration challenges that iPath solves, but also have the challenges of doing that in a large heterogeneous customer base, where you may have thousands and thousands of customers for which these integrations need to work in slightly different ways in different situations. And so, you know, certainly in the enterprise with, with homegrown applications or applications built internally, uh, you know, integrations are, are really key part. There is a bit of a difference though, in that you don't have the, the, the large customer base that has some of its own challenges with it.
So if I'm a customer of a SaaS company, what am I gonna see as a result of this? What kind of capabilities or how will this improve my experience? So anybody who's used, you know, just about any SaaS application today knows that it's very common to have a set of integrations where you can connect to, you know, depending on the industry you're in either other applications in that industry or some really common horizontal tools like, you know, QuickBooks or ServiceNow or, or whatever.
What, what embedded IPAs is encouraging and allowing is for that number of integrations that these SaaS platforms offer to proliferate. Uh, and that's something that end users want. And, and by making it more possible for SaaS vendors to do that efficiently, I think we're seeing more and more and more integration points, uh, in the SaaS market.
Are these integration points gonna be surfaced via connectors, or is this via APIs that are invoking, and if both, when do I pick an API versus the connector? Yeah, so we, we think that the best experience for most end users is an integration hub or a set of integrations that are just kind of native to whatever SaaS application they're using. So the way that actually looks to an end user is, you know, you go to the integration screen, you see, you know, maybe 50 things that this application can connect to.
You click the connect button, put in a username and password, and, and that's your entire exposure to the actual, you know, experience. Everything else happens behind the scenes to make that happen. Right.
Um, what is your sense of how much effort is required by the SaaS provider to embed this capability in their platforms? What's involved in that, and how long before you think this all just becomes commonplace? So I, I think, you know, that's a, that's a great question because, you know, essentially SaaS vendors can of course do all of this without a platform.
And the, the problem is, you alluded to, is that, that the effort is very high, and there's almost always a higher and better use for in, for development teams in a SaaS company than, uh, you know, than building the plumbing of integrations. And so with a product like Prismatic, you can, you know, embed it very quickly, uh, often in a week or less, and at that point start, uh, you know, building workflows and, and, uh, you know, and, and integrations as part of your product. So it takes that, uh, plumbing basically out of the equation where you don't, you don't have to build any of that.
It's just very quickly embedded in your product as far as how long it'll be till it's, till it's commonplace. I think we're already seeing it become commonplace. I think the SaaS companies that are growing the fastest and have the most aspiration around providing a really good experience for their customers are already starting to, you know, pretty commonly adopt solutions like this.
How smart can all of this get, and I'm asking the question because I think as we go along, one of the issues that people get confronting with is, well, there's just so many things to integrate. So what's the right thing to integrate? What's the one that will create the most optimal workflow for me?
Is this something I can throw AI at? I mean, what's the future look like? Yeah, certainly AI has a, has a place, and I think an increasing place in, in taking some of the monotony out of building these kinds of, of workflows for a SaaS company.
Uh, I don't think we're to the place yet where there's just a, you know, a magic button that that's, uh, you know, that, that reduces their, or eliminates the need, uh, for SaaS companies to provide the domain expertise and that kind of thing. Uh, you know, but, but certainly the tooling is getting better and better and, and essentially just making it more and more efficient for SaaS companies to, uh, to provide this As we go along. Um, do you think that, um, we're gonna see a lot of times these integrations require somebody with a lot of expertise, but are we looking at the democratization of these integrations because it will become simpler, and can the average business person kind of invoke this as we go along?
Yeah, I think, I think democratization is a big part of the embedded IPAs, uh, you know, category and, and, and increasing popularity. Um, what, what the way that we look at it is the, we want SaaS companies to spend the time that they spend on integrations. We want it to be specific to the domain that they're in.
That's where they're an expert. That's where they can really provide, you know, a lot of unique value to their customers. What we don't want them to have to do is reinvent the same, you know, plumbing over and over on which to build these integrations.
And so prismatic really provides an infrastructure a platform on which they can build the domain specific things that again, are where they're going to provide the most value for their customers. Do you think we might be on the cusp of an era where we can see an even bigger proliferation of SaaS companies because the infrastructure is becoming simpler for them to go build and deploy? I know we see a lot of them already and there's some consolidation going on, but it feels like the barrier to entry's getting even lower.
Yeah, I think, you know, I think whether integration platforms come along, you know, and, and increasing popularity or not, the proliferation of SaaS tools is going to continue. I think, you know, we've seen that in so many vertical markets where solutions get better and better at unique parts of the value proposition. And, and you end up with lots of point solutions.
I think embedded iPath and certainly, you know, the, the reason we started this company five years ago was to really say like, to make that serve end users well the integration problem needs to be solved for SaaS companies. And so we set out with just the very simple premise that we're going to solve the integration problem for SaaS companies. We're going to help them connect their products to the other products their, their customers use.
Embedded IPAs was kind of the solution, uh, you know, to to that, to that problem. Since you've, to your point, there's a lot of folks out there who are making cases for SaaS platforms that are essentially vertically integrated. They've got all these applications that are on a common platform and they have a common model and you know, for better or worse that maybe easier to work with, but it also locks you into one vendor.
Is your approach saying essentially we can have best of breed, but we can have the level of integration that's required to make all that work in a way that's useful? Yeah, I think a good, good integration hubs inside of SaaS platforms empowered by embedded IPAs or, or built on embedded IPAs, I think is a way to make best of breed actually serve end users well. Uh, and I think, you know, the pendulum will always swing in different markets between best of breed versus, you know, consolidated or, or, or, or larger kind of core systems.
I think integrations are what makes best of breed work really well and there are other major advantages to best of breed, uh, you know, that, that make it the right solution. In a lot of situations. I think in the post covid era, business execs went out and bought whatever SaaS app seemed to be handy and put all kinds of stuff up in the cloud.
Do you think it people need to take a step back and kind of look at all these applications and figure out which ones have integration engines that'll let, let you build workflows that, um, you know, work for the organization versus just creating a lot more work for the IT folks per se? Yeah, I think there's no question that, that a lot of SaaS applications come into organizations now, you know, outside of it out. It is not always the one that brings them in.
And I think it is often then, you know, saddled with, okay, great, we've got all these things that that individual groups are using. How do we make this a like an overall strategy for the business or how do we make it actually serve the business well end to end? I think integrations are, are a key part of that and I think IT groups, you know, increasingly are looking and saying, sure, we could go build the integrations between these things internally, you know, using a, a MuleSoft or a Boomi or something like that.
But, but man, it makes a lot more sense if those solutions just have integrations built in. And so I think, I think it is increasingly kind of focused on integrations as part of the part of the buying equation, um, you know, when they're, when they're buying SaaS. And I think that's kind of filtering down to the strategies inside of groups, uh, inside of companies as they buy their own point solutions.
So what's your best advice to folks as you kind of look at this whole landscape at the moment? I mean, I know on the one hand we want SaaS providers to do the right thing and uh, theoretically we want IT leaders to ion them to do the right thing, but, you know, how do we get from where we we're today to that? I think we're seeing it happen already.
Uh, uh, you know, if you look at tools five years ago versus tools today, the, the, the number of integrations provided by SaaS Solutions out of the box is increasing, you know, very, very rapidly. I think, you know, sure we can say we want SaaS companies to, to quote, do the right thing and quote, but I think at the end of the day, they're just looking to serve their customers and I think end users are making more and more clear that integrations are just a core part of making the strategy work for their business. And so SaaS solutions are responding by saying, okay, fair enough.
Then let's come up with a really solid integration strategy and, and that brings us back to embedded IPAs because as the SaaS companies are saying, how do we get our integration strategy kind of up to that, like that top tier? Well, it turns out that using a platform like Prismatic makes it a lot easier to bridge that, bridge that gap from where you are to where you're trying to get if you're a product leader. Alright, folks, you heard it here.
SaaS arguably is too much of a good thing at this point, so we gotta figure out how to get our arms around embedded. I pass to make it all work together. Hey Michael, thanks for being on the show.
Yeah, thanks very much, Michael. All right. Back to you guys in the studio.
Discover the cutting edge insights of our new show, AI Times, a series that explores the limitless potential of artificial intelligence sponsored by the AI Infrastructure Alliance. The AI Times is at the forefront of the AI revolution, tackling the crucial questions of how we can leverage AI for the betterment of humanity. Stay ahead of the curve as this show delves into all things surrounding ai, including trends, pressing concerns, and the positive impact AI is making around the globe AI times.
Hey everyone, I hope you all enjoyed today's episode of Techstrong tv. We had a great interview at KubeCon, as well as some amazing leadership insights interviews with Amanda. We also had some in studio interviews with Alan and view of Vard.
As usual, didn't disappoint. We'll be airing our next episode on Monday, February 5th, so please join us for that. Once again, thank you for joining us and we hope to see you again.
Stay strong. Text strong.