Graphiant Use Cases with Arsalan Khan
Graphiant’s CSO, Arsalan Khan, detailed use cases focused on this challenge, beginning with unified connectivity. He explained that the Graphiant fabric treats all endpoints, public clouds, data centers, and emerging AI neoclouds, as part of a single any-to-any fabric. This model eliminates the need for traffic backhauling, providing lower latency and guaranteed paths for high-bandwidth AI workloads, all while ensuring data privacy with end-to-end encryption that is never decrypted in transit.
Khan then highlighted business-to-business data exchange and data assurance as key enablers for AI. The platform simplifies partner collaboration, which is critical for many AI ecosystems, by handling network complexities like IP overlapping and NAT. This capability extends to partners not on the Graphiant platform and includes the ability to dynamically revoke access if a partner is breached. The core data assurance use case provides a centralized tool for CISO and governance teams. Using role-based access control, they can enforce network-level policies, such as ensuring specific data never leaves a geographical boundary, rather than relying on individual application developers to implement compliance.
Finally, Khan addressed how this infrastructure specifically serves AI workloads. He clarified the strategy is “networking for AI,” meaning the platform is designed to offload the complex burden of security and data governance from AI applications to the network itself. This accelerates AI deployment by simplifying compliance. The system supports this with threat intelligence that, without inspecting encrypted payloads, uses public feeds and behavioral analysis. By classifying normal application flows, the network can detect and flag erratic behavior, providing an essential layer of security for moving and processing the large, sensitive data “haystacks” required by AI.
Presented by Arsalan Khan, Chief Security Officer. Recorded live at Networking Field Day 39 in Silicon Valley on November 5, 2025. Watch the entire presentation at https://techfieldday.com/appearance/graphiant-presents-at-networking-field-day-39/ or visit https://techfieldday.com/event/nfd39/ or https://Graphiant.com for more information.
Transcript
My name is Alan Khan. I am the Chief Security Officer at Grapht. Now we'll jump into a few use cases that we have been focused on how they relate to the AI space.
Now there's again, going to be overlap with existing problems that need to be solved and how those are being extended to try and solve problems for this new a IH, one of the key aspects that we work on is connectivity across your different locations. Now, from our perspective, connectivity into the cloud, whether multiple different cloud clouds, different regions is not a unique problem. It is not separate from simple any to any connectivity.
I don't care if you're pro, if you exist in four different cloud providers. Doesn't matter if you're in 10 different regions and you have four different data centers. Cloud regions are no different than data centers.
They need to be able to connect it to all other data centers need to be connected to edges. Your consumers may sit anywhere. Our focus is how do we make this part of the graphene fabric?
So when you are looking to consume private, secure connectivity into a public cloud provider, for us, we have environments pre-built with connectivity into the cloud providers. So you are able to use direct connect, express route. Uh, we support most of the major public cloud providers.
You can consume this setup within a day where using our portal, you can set this up, it's going to connect you. Then we can support up to a hundred gigabit per second connections. We can support max act to make sure that even your connectivity into the cloud is secure and private.
All of this focused on the same use cases. We talked about high bandwidth, low latency, secure connectivity. This fabric now for AI use cases further extends into neo clouds as well.
There is no reason to treat a neo cloud any differently than another cloud provider, a public cloud provider. If you were to simply set up your own network, the problems you run into are, well, I need to connect it to a colo, which is my data center, and now my neo cloud sits behind my data center. Everything's getting back hauled.
Doesn't matter what region you come from, I'm back hauling you and then connecting you to neo cloud. You need an any, to any connectivity fabric that allows you to achieve is guarantees in your path lower latency and you need less bandwidth because not everything is getting backhauled to your data center anymore. The other key part here is there is no cost associated if you're using the graphing solution with connectivity into the cloud itself, you don't have to worry about cross connects within the Equinix space.
You don't have to worry about spinning up vfs. You don't need a virtual router running in that space that you have to pay for. All of this is covered within our solution itself.
We care about the bandwidth you're using. We care about the network that you're consuming. We do not care about VFS and BRFS or any of those.
Hi Mi. Mitch Ashley with future question then. How do you maintain the privacy of customer's data?
So they're maybe they're running over shared infrastructure in VPNs, or are you actually provisioning new physical connections? How does it work? It depends on the needs for customer use cases.
In various cases it may be VLANs if it's not as important to have, uh, separate infrastructure. But we do have customers who have the need for private infrastructure, in which case we spin up a separate environment for them in that space with similar turnaround times. So actually a phy separate physical network then it is that you're operating on for that Customer?
Yes. The network part, the network connectivity is separate. It may be running as a virtual machine, but it is still going to be separate connectivity into the cloud.
Okay. Yeah. And if I, uh, if I understand correctly from the previous presentations, I think one of the, the benefits that you do have is with this any, to any, it's direct.
So it doesn't force through any central location and that it's end to end encrypted with no decryption at any point in the middle. So the encrypted data, regardless of whether it's on a shared or a or a dedicated physical infrastructure, is not readable in the, in the transit process. Yeah, Exactly.
Exactly. This may be something you'll get to also from the customer's view, I've said they're probably operating some networks of their own mm-hmm. Connecting into you.
How does the management of that look to them so that they can have visibility not only to their network into you, maybe through you to the other side? Is there some kind of a fabric that you're using that you can communicate that back into their management systems? Or is it two screen solution?
Mm-hmm. We, we have our own portal. Uh, that gives you visibility into all of these aspects.
Our portal does also expose APIs. So most of the customers, when they're running multi-vendor environments, they consume all of this data through our APIs into some shared visibility solution. Okay.
So depending on their needs, both options are available. Now, the next capability that we briefly touched upon before is business to business data exchange. Now, this applies to a lot of existing use cases.
If you're looking at payment, if you're looking at financial transactions, there's a lot of partner collaboration that has to happen. Applications that you have to expose to your partners applications that they may provide to you. So in most of these cases, there's a peer-to-peer relationship.
The difficulty with existing solutions tends to be, takes a lot of time and effort to set up. And more importantly, a lot of expertise. Net networking expertise is at a fairly, uh, low availability in the market nowadays, given the kind of problem that we have to deal with and being able to set this up is not a trivial matter.
What remains key, whether you deal with healthcare applications, financials or AI, is how quickly you can get things out. How quickly can you do all of this in a secure, scalable fashion? So we will go through a demo of how you can set up this kind of connectivity within the graphene system.
But the key here remains whether you are two grapht consumers or you are a graphene customer and you have partners who are not graphene customers. You can use our fabric to set up this connectivity where we will take care of the networking aspect of IP overlapping. How do you deal with that problem?
That problems, all of that is something you don't really have to worry about. Then we give you visibility. If specifically these are both graph and customers.
You can see which one of your partners consumed which service, what path they took in the graph and core. All of that visibility is still available when you are running B2B data exchange. And then it gives you the critical ability of being able to revoke that access depending on whatever the need may be.
If a partner gets breached, you can choose to revoke their access and then restore that access fairly dynamically so that you're able to control your own environment And are not impacted by problems that might happen in another environment. Now, if this is someone who is looking, who is a partner looking to consume your graph and based service without their own graph and setup, we do support ike based standards. Ike based IPSec connectivity, they connect into the fabric and then they can start consuming the service.
I think we might go through how we do that in a demo because we generate a nice little configuration for them. They can pop that into a Cisco box, juniper box. They don't have to really think too much about it.
Maybe as part of your demo, if you can say a little bit about how the automation works. I of the automation, love to hear about that. Best part about that is vinne will have to explain it.
There You go. I'm trying to toss a few. Now.
The third main use case for us is data assurance. What this means, how this relates to security and governance. The key aspect for us here is what I mentioned before about being able to monitor, audit and control the traffic going through this grapht core, this all focuses on how do you give guarantees and assurances to your applications based on what their unique needs might be.
You may care purely about SLAs. That's something you can do. You may have more regulatory requirements of make sure this traffic cannot exit North America, or you may want to get complicated and say, I have an application that runs in the US and the uk.
You can talk to that application within each region, make sure it doesn't go across. All of those kinds of capabilities exist within the network itself, and you have a centralized place to be able to manage these policies. Go ahead.
I, so JD here, so one of the, one of the questions that this really brings to mind when we start talking about data, data governance, um, at this level, um, that's not normally a decision that's made inside the IT organization that's made inside this. The, the security, uh, security office, whether it's CISO or Suite or whatever. There's, and, and in some organizations it's an entire team dedicated to data governance.
Um, how does that get bridged in your product from the, from the perspective of where, where the decision and reporting is is being handled versus where the network connectivity is being managed? Very good question and very similar problem and network. You have to work with the security team who's focused purely on security.
You have a separate network infrastructure and the realization that you, if you build security into the network, it takes a lot of load off of application development. Plus it gives you a centralized place to be able to manage. This is going to be a similar process of we provide these governance capabilities.
Mm-hmm. It can't be done in isolation. Applications have to support it, security team, governance team have to be involved, but you are giving them an additional tool in their tool set to say, okay, I don't have to worry about this particular database not being able to give me the visibility I need because I can get that from the network.
So we can't do this on our own, but we are giving them the ability where they don't have to chase down a million different developers or a bunch of different databases. They have a unified place to be able to do this. Uh, can you, uh, and I'm gonna assume that because of that you have a, a pretty, uh, solid role-based access control to these things so that, you know, the engineers who are, are setting up the things can do what they need to do, but, uh, you can grant access to the overlords for the governance side with the engineers can't necessarily change and that sort of thing.
Could you talk a little bit about the, the control of the governance part? Yeah. Yes.
So all of that is based on the user accounts that you create, the permissions that you wanna provide using role-based access. There's fairly granular permissions that you can provide of even within the data assurance space. You're a compliance person.
You only need to look at stuff. I don't want that compliance guy messing with my engineering. Exactly.
Exactly. Yes. And I went from application development for networking to the security space.
All of what you're saying, I 100% agree with. I have been the person who's like, why is this security person bothering me now? I am the security person bothering other people.
So 100% agree with the points that all of you're raising now in this space. It's also about threat intelligence because even when you're looking at things from a governance point of view, like I mentioned, you're moving the entire data haystack from one place to the other. Is the destination that it's being sent to someone that has a high threat score, do I need to look into who was it that accessed this data?
All of those capabilities are built into the system itself. This is the fundamental place where we can apply governance. Now, there's a additional capabilities that we can keep building on as technology evolves, as new requirements show up.
The idea behind this is we give you full control. What you are able to achieve is going to evolve and we will be able to support it for You. I've got a question for you.
Mm-hmm. Um, again, this is Kevin Myers. I'm curious if you built your own transport network and you don't look into the payload, what is it that you're, what, what threat indicators are you looking at?
If this is mainly an overlay underlay transport and the payload itself is encrypted to the client network. Mm-hmm. What, what, what threats are you actually looking at when you're in a very closed system like that?
So there's two key aspects to this. One is if it's someone who's outside the network, some public intelligence that we can get around whatever public IP this is being accessed from. Okay.
That threat intelligence is also pulled in to make decisions or purely the closed environment. It comes down to you can identify all the applications that exist within this environment. You should be able to define what different flows exist, what applications they belong to.
And you have the visibility to see is this application behaving erratically? So we'll take a look at the different kind of buckets that we classify things into and how we help operators classify these applications so that they have full visibility into the network. And it's more about we can classify things properly, we can define what rules it should be following.
Anything that deviates, we can Call out. So essentially your clients as they're routing traffic into, into this now, into this cloud, into this fabric, whatever they're bringing in, you're looking at to see what is this, where is it coming from? Yes.
Okay. So I have a question for you. Mm-hmm.
I'm Rita Younger. Um, this presentation is titled, it's all about ai, right? Um, but I'm having trouble connecting this to ai.
So what is different about it? Because it's for ai and is there anything for the training part of the network, the backend of an AI network? So a key part of this is our strategy of AI is not just to adopt AI and make our network smarter.
Yes, that is a critical part, but we are also very focused on how do we help enable your other AI use cases by solving network problems. This entire focus on data exchange, data governance, if you have to solve that data governance problem in every single application or every single database, it is an extremely complicated problem because there's a bunch of different developers now you have to start pushing down various different compliance regulations on each and every one of them. How do I monitor this?
How do I know who applied these changes versus not? You look at, sorry, go ahead. So it's more of a AI for networking versus networking For ai, It's both.
We will go into what we do, how we use AI for the network itself right now is much more on network is going to enable your AI load that other people have had to deal with. Move to the network built in, you just consume it.