Transforming Security: The Traceable and Harness Merger with Monish Advani | RSAC Conference 2025
Monish Advani talk about the merger of Traceable and Harness, creating an AI-native DevSecOps platform to improve software delivery and security. The discussion addresses the shortage of security developers and the need for unified security solutions. AI’s role in enhancing developer productivity is highlighted, along with the launch of Cloud WAAP for web application and API protection. The evolving responsibilities of CISOs and customer success stories are also explored.
Transcript
It is Techstrong TV coming at you live. Day three of our continuous wall to wall coverage of RSAC. We're in Moscone West and Broadcast Alley.
We have been having, as you know, because you've been watching some amazing conversations with practitioners, with C-levels, with product leaders, with customers, partners about the evolution of the cybersecurity landscape, especially in the era of ai. We're happy to have our next guest with us, Monish Avani, the Senior Director of Product Management at Harness. Great to have you on the program.
Manish, thank you for joining me. Thank you For having me. So exciting kind of year already.
Yeah. For you guys. Traceable and harness merged.
Yeah. Announced just a couple of months ago. Talk a little bit about why that is.
What were some of the catalysts in the market that demonstrated this is the right direction for the business? Absolutely. Absolutely.
Yeah. So just to take a step back, harness being, you know, an AI native modern software delivery company focused on helping developers, you know, ship software more efficiently and traceable, you know, founded by the same CEO Joti, SIL focuses on being the modern a PS security platform company. So when we were talking to our customers, it just made sense and there was so much synergy to bring these two companies together and create a AI, native DevSecOps platform that kind of unifies the story of bringing security closer to developers and making it part of like every step of the software development life cycle.
Where is that conceptually and culturally, the, the developers and the security folks coming together? 'cause I understand there's a lot of synergies with how they think, how they work, but there's been some cultural challenges of bringing that practice together. Yeah, yeah.
Where are we in 2025 with that merger? You Yeah. I, I think it's, it's still a challenge.
It's getting better, you know, security, there's a shortage of security developers. You know, at the end of the day you look at 37 million software developers on the planet, 37 million. Yeah.
And then 5 million cybersecurity professionals. Right. Helping them fix all those problems.
On top of it, you have this AI vibe, coding coming, helping developers be more productive, but then the problem of security gap increases. Yeah. With AI coming into play.
So, you know, it's the, the the issue. Select this, we're getting better. But, you know, and surrounding them by process and cultural challenges itself, it's, it's still, it's still works that needs to get better and we are just at the right place to do the transformation for them.
Can AI be that bridge? AI would definitely help between The developers and the security professionals? Absolutely.
AI would definitely help developers to be more productive. Yeah. But when it comes to fixing security issues, because these AI models are built on open source models, they're not doing the job of fixing security issues on the top or writing better code.
So, uh, at the end of the, it comes back to the security developers itself to make it better. And is that your target audience? The security developers?
We target both. Okay. We target the developers as well as security professionals.
You know, harness goes and talks to the dev, DevOps and developers first, but we always see both, both teams coming together and having a common conversation. Right. And security.
And, you know, developers are always there to help us do that. How, what is the optimal developer experience these days in the era AI era, and how are you guys facilitating that? Yeah, I mean, the experience is all, they want a single platform.
Yeah. They all want to live at the same place, make it more developer friendly, bring in all their core repositories and security tools together. So they, they just wanna breathe better and launch software and ship software better.
Yeah. So that's, yeah. Now unifying software delivery API security isn't a nice to have anymore for any business and any organization.
Yeah. Why is that? Why is it in this cloud native world, this AI era, why is it table stakes?
Well, first of all, none of the companies have the right tools to do it all together. Ah. And this is where harness and traceable kind of bring end to end application security all within one platform.
And if you think about DevSecOps as a term, yeah, you're talking about secure development, you're talking about building artifacts that have to be secure. You're talking about trusted releases, you're talking about monitoring and defending your applications once they go live. All of that in one platform together is where the real challenge is.
And we are doing that, uh, together. Is this kind of redefining DevSecOps in a way? A hundred percent.
Okay. Absolutely. And doing it with AI is where, you know, companies are seeing that challenge and bringing it all together with the one platform is where the opportunities, I feel.
Talk to me about, unpack some of those opportunities. 'cause I always love to find that, you know, we, we talk about the cyber landscape and the threats and the risks and this and AI and the opportunities, but the risks. What are some of those opportunities?
Yeah, I mean, if you look at the application security market as a whole, there is security testing, there is pasta management, there is supply chain security, there is Cloud web, which we recently launched yesterday. All of those tools together, unifying them is where, you know, customers find ease to consume those products and, you know, solve the security challenge that they're facing. And they go all the way from ity management to the time they're deploying the code and seeing the application live and defending against those attacks.
So it, it's a tough thing to solve, but that's exactly where Harness and Traceable are well positioned to do that correctly. And Cloud WAP web application and API protection, talk to us a little bit about that and the impact. Yeah.
Yeah. I mean, it was launched yesterday, an amazing day for us. You know, it brings in web API web application, API protection bot, defense, DDoS defense.
Altogether the most of the customers have these tools individually, and, and they're using static signatures to kind of detect those attacks. What we did was we took all of them, unified them, brought it under one platform, and then used behavior analysis to understand the context of user session. All in all, to understand what is happening with the traffic.
And if an anomaly is detected, we kind of stop it right there. So aut autonomously. Yeah.
Yeah. Yeah. So you're, you're freeing these folks up.
Absolutely. Some of Those Absolutely. That's, that's Menial tasks they don't wanna Do anyway.
That's what, yeah. You don't have to go to different tools to do that. You do it autonomously on a single platform, you know, through behavior analysis.
You don't even need, you know, signatures to detect those traffic events. And what's been the feedback so far? You said the announcement was yesterday, so Great day for you.
It, I mean, we won, we won an award already, you know. Yeah. Congratulations.
Which one? Yeah, so we are the leader from Secure iq IQ Labs and, and, and, you know, awesome. Trying out to be a leader on that space on cloud lab.
So this is exciting for us, you know, trace Miller Harness coming together just to do this correctly. And is this merger and the technical capabilities, are you gonna be giving, it sounds like Yes. Giving the developer folks the security professionals, the visibility Yeah.
That they haven't had before. Absolutely. It's, and that's critical.
It's, it's, it's deep inspection. It's the visibility you want for SecOps teams to understand what is happening in the traffic, what is anomalous, and to intervene at the right, you know, pace is, is extremely important for them. And are you, are you seeing the, the role of the CISO changing as a result and evolving as the cyber landscape changes?
As AI accelerates? I think the job is getting difficult. If you asked me, yeah.
There, there trends around, if you look at what's happening at r itself, security for AI and AI for security, right? It's just, there are two topics now to understand where that vision and landscape is going. What tools do they need to buy and understand can, can they get one single platform that helps them do that together?
It's, it's hard Security for ai. It's that a solvable problem. Yeah, Absolutely.
I mean, it's, it's, it's something a lot of companies are looking into now. Yeah. A you know, just, I hear a lot of it understand, hear, just to understand what is happening in terms of prompt injection, you know, hallucination, things of that sort.
Yeah. So that's acap, you know, a space a lot of the companies are trying to enter. Same goes for traceable.
We plan to intend achieve that through API security because at the end of the day, API is sort of the backbone for what code is written and what traffic flows. And we want to leverage that to solve some of the challenges there too. And if I think about API security on its own for a second.
Yeah. And I, I wanna elevate this conversation up to the C-suite, maybe the board. Yeah.
What's the business value, the business impact that AppSec delivers to an organization? Yeah, Yeah, yeah. I mean, at the end of the day, you have to think of posture management as one big concern.
Yeah. You know, the, the, the traffic that keeps on flowing for all the data that's written from code to the time you deploy, understanding the traffic, having an inventory around it using AI is critical. Swapping those attacks, you know, those notorious attacks on how the API is written.
Yeah. Sometimes there is like bad oath or broken oath, uh, you know, fixing those issues is extreme important when it comes to testing the code or the API itself. And then, uh, more importantly, you know, anomalous behavior around it.
Yeah. So there is, there's too much value for an exec to understand how my data is actually flowing. Mm-hmm.
And what is happening within the data in an outside organization? Well, I mean, they need to understand it in a time where data is just going to continue to explode. Absolutely.
Yeah. Nobody wants less data slower, right? Yeah, Absolutely.
The amount of events we process when it comes to understanding the API traffic itself is so large, scaling it for the amount of traffic and as the AI keeps coming and the data keeps growing, is always gonna be something that traceables good at. Yeah. What are, what would you define as like the top three differentiators of what Harness is doing with traceable that really delivers that customer impact?
Yeah, Yeah, absolutely. I think the, the way we think about software delivery at the end of the day is with security embedded in it is, is the way to go. That's, that's The can't be an afterthought.
Yeah. And, and then making it, you know, uh, driven mostly by AI as the world is changing and how we are thinking about software delivery. That's important.
And I think that, you know, deep dev adoption is gonna be key mm-hmm. With this because developers are attach to AI as much as possible now to do better coding and to, you know, ships off a better. So all of that, those, if you do all of that together well and good, then you're at the forefront of this problem.
And that's nirvana, I know, to get to the forefront. Absolutely. To be able to get proactive when there's so much reactivity been going on for decades.
A Hundred percent. And the sophistication Yeah. Of the threats and the attacks Yeah.
And all of the things that are the deep fakes and all the things that are just making it so much harder to detect. Yeah. We've gotta get to that nirvana, that proactive State.
All there's gotta be step ahead of this game. You do. Yeah.
Is it fighting fire with fire fighting ai with ai? Uh, I, I, I mean, I, I feel there'll be all the humans coming together to fight with AI at the end of the day. Yeah.
That's how, that's how I feel. Because if you look at the countries today, right? I mean, US is trying to do something with ai.
China is trying, I think they all will come together to fight again at the end of the day. Yeah. I hope so.
I hope there's collaboration. Yeah. That has to happen.
What's your favorite final question for you customer story of harness and traceable that you think this really articulates beautifully the value of what our technology delivers? Absolutely. Yeah.
I mean, you know, what's interesting is because the culture and the foundation of both these companies are similar. 70% of traceable customers are already harness Customers 70%. Oh.
Oh, that is outstanding. I know. Yeah.
And, uh, what's even better for us, customers like PayPal, Informatica and others are already using both of these technologies and, you know, platforms to understand what DevSecOps truly means for them. And that kinda synergy and resignation, you know, back from the developers and the security teams, just makes our life easy to solve their problems at the end of the Day. And you're making their lives easier as well.
That's, I imagine the, the onboarding, the migration process for those 70% is mapped out and going to be efficiently delivered. A hundred percent. A hundred percent.
And, and, you know, harness is built with that intent. You know, there's a startup within startup environment, so we treat traceable as a merger, but when it comes to merging these platforms to bring it all together, it's all unified in one way. And that's what customers want.
Exactly. Ah, Monish, this was a great conversation. Thank you for Thank you so much.
Sharing what's going on at Harness the Power, the catalyst for the merger, what's in this for the developers, the security folks, and ultimately the brand reputation of a business. We appreciate your time on your insights. Thank You for having me.
It was great. All Right. That was fun.
For my guest, I'm Lisa Martin. You're watching Techstrong tv, day three of our coverage from RSAC. Stick around more great content coming at you in just a minute.