This Week in Startups

An AI that watches your every click may be the future of work | E2314

42 min
Jul 20, 2026about 1 month ago
Listen to Episode
Summary

Host Alex Wilhelm interviews Brandon Dixon, co-founder and CTO of Ent, a cybersecurity startup fresh out of stealth that uses on-device AI agents to monitor and prevent risky human and agentic behavior inside enterprises. The episode also features a brief segment with David M. from Sumail Labs, who demos an AI video generation orchestration API that stitches multiple models together to produce consistent 60-second marketing videos. Together the segments explore how AI is reshaping both enterprise security and content creation workflows.

Insights
  • Prevention-first security is now viable: advances in embedding models enable sub-second behavioral decisions at the endpoint without requiring heavy GPU compute or frontier-model inference.
  • The biggest enterprise security risk is not malicious insiders but well-intentioned employees and 'citizen developers' who make mistakes while adopting AI tools faster than policy can keep up.
  • Behavioral observability data collected for security has significant downstream value for productivity analytics, agent governance, process distillation, and insider-risk identification — making pure cybersecurity framing potentially too narrow.
  • Data sovereignty is a first-principle buying requirement for Global 2000 enterprises: self-hosted, single-tenant deployment with customer-owned data is becoming a baseline expectation, not a premium option.
  • AI video generation is still fundamentally stochastic; the near-term product opportunity is orchestration layers that route across multiple models and stitch outputs to deliver production-ready, consistent results in one attempt.
Trends
Rise of 'citizen developers' using AI to automate workflows without technical backgrounds, creating new enterprise security exposureShift from reactive to preventative cybersecurity using real-time AI reasoning at the endpointAgentic identity and agent behavior monitoring emerging as a distinct security discipline alongside human user monitoringData sovereignty and regulatory pressure driving demand for self-hosted, customer-boundary-deployed SaaS productsEmbedding models replacing heavier LLM inference for latency-sensitive, on-device security decisionsBehavioral lineage and semantic substrates emerging as new frameworks for understanding enterprise data and workflow riskAI orchestration layers abstracting multiple generative models to reduce stochastic unpredictability in creative workflowsEnterprise security vendors expanding from point solutions toward programmable, multi-use-case endpoint platformsGrowing tension between employee privacy expectations and corporate monitoring as AI tooling increases observability granularityAI-generated UGC video flooding social platforms, making authenticity detection increasingly difficult for consumers
Topics
Companies
Ent
Main guest company; builds on-device AI agents that monitor and prevent risky human and agentic behavior in enterprises.
Sumail Labs
Second-segment guest company; builds an AI video generation orchestration API for consistent 60-second marketing videos.
Microsoft
Brandon Dixon and his co-founder Lou previously worked at Microsoft before founding Ent.
OpenAI
Referenced indirectly via 'OpenClaw Codex / Claude Code' context when discussing AI tools enabling non-technical user...
Anthropic
Claude Code mentioned as an example of AI tools enabling non-developers to perform advanced technical tasks.
Meta
Cited as a recent example of corporate monitoring of engineers that proved very unpopular with employees.
Amazon Web Services
Listed as one of the major cloud providers whose environments Ent supports for self-hosted customer deployments.
Google
Listed alongside AWS and Azure as a supported cloud provider for Ent's self-hosted deployment option.
Microsoft Azure
Listed as one of the major cloud providers supported for Ent's customer-boundary deployment architecture.
Ramp
Mentioned as a Vanta customer that reduced audit time by 82% — cited in sponsor context but as an editorial proof point.
Grok
Referenced by host as a video generation tool used to create an AI Yoda clip, illustrating stochastic video generation.
Google DeepMind
Gemini Omni cited as one of the video generation models compared in Sumail Labs' multi-model routing demo.
GoDaddy
David from Sumail Labs mentioned purchasing the sume.com domain at a discount through GoDaddy.
People
Brandon Dixon
Main guest; explained Ent's AI-powered behavioral prevention platform and $100M funding round.
Alex Wilhelm
Host of the episode; interviewed Brandon Dixon and co-hosted the Sumail Labs segment.
Jason
Co-host who appeared in the second segment discussing AI video generation with David M.
David M.
Second-segment guest; demoed an AI video orchestration API producing consistent 60-second UGC marketing videos.
Lou
Brandon Dixon's co-founder; previously at Microsoft, referenced as part of Ent's founding team.
Quotes
"We've largely given up prevention inside of security. We're very reactive. We wait for the bad thing to occur."
Brandon Dixon
"If they were otherwise security experts, we wouldn't be dealing with breaches. Everybody would do the right thing."
Brandon Dixon
"I don't want to be nanny software. I don't want to police how much AI somebody used throughout the day. What I care about is stopping mistakes from taking place."
Brandon Dixon
"Corporate policy is only as good as its ability to put it into a control point. And because corporate policy is written in natural language, there's some level of interpretation that takes place by the employee."
Brandon Dixon
"The slot machine is not fun when you're making videos and images and they take 30 seconds. It's incredibly frustrating right now."
David M.
Full Transcript
7 Speakers
Speaker A

Hello and welcome back to Twist. This is Alex and right now AI and cybersecurity are hot topics because the leading frontier models are increasingly capable of finding and exploiting software vulnerabilities. Precisely how to harden global software is an open question that we're all working on resolving. But there are startups working in the AI and cybersecurity domains that are not trying to build the next hacking tool. One startup fresh out of stealth has a novel approach to securing human action inside of corporations in using AI that could help prevent the breaches of tomorrow. So please join me in welcoming to the show. It's Brandon Dixon, the CO founder and CTO of ENT.

0:00

Speaker B

This Week in Startups is brought to you by YSecurity, the on demand security team for startups need enterprise grade security without hiring a $400,000 CISO. YSecurity gives you 40 plus expert engineers matched to exactly what you need. Buy the hour with your first six hours completely free. Go to ysecurity IO twist superhuman. Get the AI that works where you work. Find out more at superhuman.com and Vanta. Compliance and security shouldn't be a deal breaker for startups to win new business. Vanta makes it easy for companies to get a SoC2 report fast. Get $1,000 off for a limited time at vanta.com twist Brandon, how you doing?

0:36

Speaker C

I am doing phenomenal. Trying to stay cool in this hot weather in Virginia right now.

1:16

Speaker A

It's bad up here. I can't imagine how bad it is down in the sticky south. But before we get into anything important, I'm shocked that after all the mining we have done on Lord of the Rings, Arcana Int was not taken yet. How is that possible given that we've already gone deep into like the silmarillion to find startup names?

1:21

Speaker C

You know, I think it's just a happy coincidence. Like when we were building out the company brand and the name we, we were thinking of, you know, enterprise is like kind of our core customer that we're going after. And so like ant, like security for the enterprise was kind of the approach there. And then of course being more technically inclined people, there was a little bit of a nod to the kind of Lord of the Rings trees and the protection. And as we were building out that brand it was important to me at least. Like I don't like the hoodies and hacker depiction of like, you know, the bad guys. I like being outside, I like doing those sorts of things and I wanted to try and carry that through in the brand as well.

1:38

Speaker A

Yeah, well, it works out well. It's very memorable. It was not hard to recall who I was talking to today. Now let's dig into what you built because I don't think people are going to be as familiar with this tool. But to give people a quick summary, from what I understand, you have built a on device agent for endpoints. So, you know, laptops, phones and so forth that can essentially tell when someone's going to do something they shouldn't do or maybe risky and then stop them. Now tell me what I got wrong and break it down for me why we need this. I'm really curious.

2:20

Speaker C

I mean, no, that's effectively it. Like, you know, when my co founder and I formed ent, the thesis to this was that we've largely given up prevention inside of security, right? We're very reactive. We wait for the bad thing to occur, we have the, the requisite information to troubleshoot. But it felt like there was, we were just accepting that the adversary was going to compromise the, the, the infrastructure and, and a lot of the breaches occur because people are well inclined, trying to do their jobs, but they make a mistake. And so when we were looking at the current AI advances with some of these reasoning models and the ability to scale up understanding words and representing that in dimensional ways, we wanted to apply that directly to where people worked. So we wanted to meet them in that moment, look at the work that was taking place and then make an assessment as to whether or not they were going to violate corporate policy or do something they shouldn't and effectively stop that from happening. So why do we need it now? Well, unfortunately, like breaches still occur from humans, right? Like people click things, they, they want to do the job. If they were, if they were otherwise security experts, we wouldn't be dealing with breaches, right? Everybody would do the right thing. But on top of that, we do have AI in the mix and it's a new technology and it just brings new risks. So we believe that, that having that level of reasoning and capability at the endpoint is an important advancement in the future.

2:48

Speaker A

I want to get to the endpoint point and talk about models and such in a second. But the idea that people are doing more thanks to AI really resonates with me because up until when I had, I mean frankly, Openclaw codecs and Claude code, I was not messing around in PowerShell or with a CLI. And now I'm doing all sorts of insane things with my computers that I'm absolutely not qualified to do. But that's the homebrew side of this. So take me inside a corporation that's rolling out AI tools that give, you know, job functions more capacity, capability than they would have had before and are now seeing these problems I'm curious about, like, how it manifests and like, which jobs are. Are really pushing the envelope, if you will, and getting into trouble.

4:15

Speaker C

I think it really depends on the maturity of organizations. So a lot of the people that we're working with are obviously adopting AI. They're kind of all in and they're looking to retool processes. I've heard the term, and I kind of like it. Citizen developers. So we run into those people, ones that don't have a technical background, who are being encouraged by their leadership to solve problems with AI and accelerate their workflows. And in that case, they run the risk of deleting artifacts off their system, pulling in context that might be sensitive, and then accidentally leaking it outside of the corporation. On the flip side, you have your developers who of course, are trying to take advantage of new technology. And in that case, they might have like 20 different agents running to go and perform various roles across the enterprise. And they're the same risks take place as well. But it's not even just innately tied to AI. Right. Like, there's still just mistakes that people do by accidentally sending an email with the financial information to the wrong person. Right. Or sharing credentials across, you know, chat ecosystems that otherwise could lead to a compromise. So we see both sides of the house. We still look at the user behavior, and we look at how they're working with agents, and then we look at the agent behavior as well.

4:56

Speaker A

That's really interesting to me because it's a bit broader than I thought. How can you have enough context about a company, its individual job functions, what they are allowed and not allowed to do from the corporate perspective to determine in real time if person X with job Y in group Z responsibility, you know, Q is doing something that is suspect because to me, that implies a level of specificity that's almost crazy. So I'm impressed that you managed to figure it out.

6:20

Speaker C

How so for us, like, the setup of the product itself is predicated on, like, getting a corporate policy or getting something as simple as, like, what is the sanctioned software that you use across the enterprise. And you'd be surprised with that little bit of information and understanding the context that we're collecting, I can guarantee that there are policy violations that are occurring across the company. So people come to us and they say, look, I'm not going to restrict AI usage, I'm going to let it happen. But now my concern is I can't keep up with all the AI tools that are coming out. And I've given people access to use these tools, but I don't know how they're using them. So right away, if I understand what like the allowed software is, I can immediately tell you people that are using other software, be it AI, remote access or something else that is not sanctioned for them. So like that's like our one sort of output for us. And then over time end basically understands the operating aspects of the business because we're constantly forming baselines of what's normal for that user, what's normal for that department, what's normal for their cohorts. And that allows us to essentially start to put the policy to use on the endpoint itself and stop bad things from happening. So we don't really require a lot of information. I think the big advantage that or what makes this possible today and why it wasn't possible a couple years ago, is the advantage that we have in things like embeddings. The ability to take semantic words, like things that we understand have meaning and translate them into something that a computer can understand and make decisions.

6:48

Speaker A

On top of, you're talking about vector databases and tensors more broadly?

8:27

Speaker C

Sure, yes, sure, yeah. I mean, in its essence, it's basically words have meanings, we know how to interpret those. But it's been difficult to represent a lot of dimensionality for computers to understand. But now, because we have these large language models as part of what makes them work really well, is that extreme amount of dimensionality that they understand when these words are put together, they have a more specific meaning than maybe when they're split apart from each other. And so that was an advantage that we were able to take within building the product. And that serves us well.

8:32

Speaker A

I mean, you're literally talking about why people are moving away from vectors because they want to have a more multidimensional way to represent data as numbers than, I'm sorry, words as numbers. That all tracks with me and it all makes good sense. But I'm curious about the learning loop because you said you can provide value right from the start with some corporate policies, but then you keep learning. On the other hand, the way that I understand the way how it works is that there's basically an on device agent which I think is doing local compute. So I presume there's kind of an SLM involved. There's then. Does it then federate information back to a Centralized database to learn about Alex incorporated and then send that back to the on device agent. How does that process function?

9:11

Speaker C

Yeah. So quite simply, when we were building out the architecture, we didn't want to have a backend process and an endpoint process. We wanted to have one architecture that could work for either scenario because you might have some systems where they don't want to run anything at all at the endpoint itself because of regulatory compliance, whatever. So the way that we've designed the system is it can run completely on the back end or it can run on the endpoint itself, but it's the same architecture. So you asked about.

9:50

Speaker A

No, I'm just curious why. I mean, I feel like if you can centralize the compute, why not have, I don't know, a more powerful model? You have more flops to play with.

10:19

Speaker D

As a founder, you've taken the time to become an expert in your niche and you fully understand the entire landscape. But with so many regulations and rules that you need to follow, from federal agencies, agencies and offices here in the US to the European Union and beyond, it's impossible for even the most diligent person to keep up with every exacting requirement. That's why you need to simplify compliance with a trusted partner like Vanta. All my startups use Vanta and they love Vanta's AI powered platform that automates your entire compliance process. Whether you're Preparing for a SoC2 or you're running an enterprise GRC program or you're doing an audit. Vant is going to worry about the security so your team can focus on building great products. That's why some of our favorite companies like Ramp and Ryder, are spending 82% less time on their audits by working with Vanta. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate. Vanta is here to help you automate your security and compliance and earn and prove trust. So get started today@vanta.com twist that's V A N T A dot com twist so cost.

10:26

Speaker C

You know, not everything requires like the most, you know, the greatest model or the frontier model. The way that we use models, we use open models that have been published out there. We do rely like, we'll make use of like the cloud service provider models or if a customer wants to bring a model. When it comes to embeddings, we control those and we're using open models to dictate that those embedding models can run on the endpoint. They can also run on the back end, we've made changes to those models to optimize them to be very performant and to do particular use cases to solve like certain problems. And so like we control that architecture. But if a customer otherwise wants to do deep investigations on all the data that we've collected, they have the capacity to do so. All right, effectively the way that the system works is we're building out a pipeline where we put this context in. We start with the raw behavioral information and then we're decorating it with who's logged in, what is it that they appear to be doing, and aligning that to whether or not it's a corporate violation or not. We have a single architecture that basically is built to run on the endpoint or it can run on the back end. Because of the way that embeddings operate. We want to control that process and we use embedding models. Embedding models are great because they're very performant. They don't require like GPUs that can operate on CPUs. And when it comes to decision making, they can make decisions in sub second timeframes. Like we don't have to use a heavy amount of reasoning.

11:33

Speaker A

The sub second timeframes thing is the most interesting thing because the way that I think about int in practice and you know, it hasn't been rolled out at the company that I work at. So I'm kind of theory crafting here. But as I go to do something I shouldn't do, it goes, alex, don't do that. That might be insecure. Is it that fast of a process or am I overestimating how quick technology is today?

13:03

Speaker C

No, it has to be that fast to get prevention. So the idea like the way that we roll out inside of a company is generally speaking, if you ask like a ciso, who are your riskiest users and why, they can't really tell you. Right. They know the workflows that are taking place. They know roughly what people are doing throughout the day, but they don't emphatically know this. And so typically the way that we roll out is we start in more of a baseline mode. We install ENT across like the ecosystem. It starts absorbing the information again. It has that corporate policy. We're surfacing violations. The company is going to have more than enough thing to do based on what we're surfacing in that moment. We don't want to necessarily get in the way of anybody's workflow. We don't want to annoy people. I don't want to Run, you know, and like, you know, prompt them in some form unless I have information from the company. So there's typically a burn in period where you might have two weeks to establish baselines of what's normal, what's not, you know, where are the violations occurring that I actually care about? Because in your corporate policy you might have something that stipulates nobody should use social media, but you may not actually care to enforce it. But you might have, on the other hand, that AI use and sensitive data that goes into these models has to be done in this particular way. And so for that moment, like we're going to drudge up that behavior, we're going to say, here's your unsanctioned AI usage, by the way, here's what people are doing, this is the information they're sending in, this is the work that's taking place and it allows us, we've built the product to basically isolate that workflow and then say, well, when I see this activity in the future, now I want to intervene. And that intervention can be customized.

13:22

Speaker A

The way that I think about the product as this stop you before you do it thing is one portion of it, because it can also do that for humans and apparently also for agents. And it can provide a bird's eye view into how a company is using software and in particular AI or more broadly so people can learn from their own usage.

15:02

Speaker C

Correct. So the idea here is like, yeah, I've toyed around with like the lingo, but it's like an organization work model. We talk about world models.

15:22

Speaker E

Sure.

15:31

Speaker C

And world models were like super advantageous to cars. Right. Because prior to a world model existing that encapsulated the environment, we were trying to tell the car like when to stay in the lanes, when to apply the brake, when to like kind of, you know, change lanes, whatever. And the problem was is that you were overfitting to a particular set of environment variables. When you had the world models, it allowed the car to essentially become more predictive. Right? Oh, I'm anticipating that somebody's going to walk out in the crosswalk or there's a stop sign and I need to apply the brakes. It allowed the self driving car movement to be more accurate. So when I say that most CISOs aren't aware of the behaviors that are taking place, step one is to make them aware from an observability perspective. And of you have some problems inside your environment that you probably didn't realize. And step two is to figure out which ones do you actually care about. And then step Three is to determine how do you want to modify that user behavior, if at all, or your corporate policies and then enact those using end.

15:31

Speaker A

So really I think that calling this a cybersecurity company almost feels too narrow. You are building kind of a work model in a sense. How far can you push that? Because once you have this information about how a company works, you, you could do all sorts of fun things like tell them where they're being inefficient or recommend different ways to go about stuff. It seems like if you can get wide adoption and a lot of information, this is a really potentially lucrative and useful tool that you're building with a lot of future applications that go outside of just cyber safety.

16:33

Speaker C

Absolutely. I think the, you know, again, toying around with like kind of lingo here. I don't know the best way to describe some of these things because they feel new, like we haven't had it at our disposal. One of the ones that I was playing around with was like the semantic substrate for security. So all of a sudden I have this like all of this information that's describing the work that people are doing inside of the business. And that is a massive set of context that we have at our disposal that can help accelerate closing out true, positive, benign tickets in the SoC. Right. It could give further context to DLP related events. It could surface inside risk activity, be it the 1% bad guy or the 99% mistakes that take place. It could be used to isolate and identify people that need training. So like there's a broad applicability in having context that describes what's taking place across the organization. And you hit the nail on the head. There's a productivity angle to this as well, in which if I understand what people are doing throughout the day, then it becomes ripe to figure out what, what things might agents benefit? Right. What is the mundane, monotonous work that is occurring across different departments inside of the business or ones that like particularly risky across my enterprise that might benefit by having an AI agent do it. And then once that AI agent is in place, how do you ensure and keep it on the rails? Right. How do you know that it's doing the right thing, that it's aligned to the task? And so for us we're concretely focused in security, but we've, we go and target big enterprises. Our environments are global 2000 and above. So think Fortune 500. And the thing that you articulated is what they're after as well. They say I can start with security, I can bring a level of Visibility and stop problems from taking place. But then there's this downstream applicability that becomes really attractive. Like can we start mining out of that information ways to do process distillation, ways to identify who are like who's using AI the most and how are they using it in ways that we can help others learn from that.

17:02

Speaker A

And this is why I'm terrified that one of the AI lab, jv, fde private equity working groups are going to try to scoop you up and then take all the data you have and then apply it because it's going to be incredibly valuable. But just listening to you on the lingo point, work obs maybe, I mean, it does feel kind of like general work observability. Lots of data. You can do different things with it.

19:11

Speaker C

We've also used like, you know, I heard Data Lineage for a while, which is like looking at how data moves through the enterprise. And I think that that has merits and it's proven in the market. We've been toying around with behavioral lineage as well. It's like, what are the behaviors that people do and how does that like then intersect with data lineage? How does the behavior of an agent, you know, operate? Where we've settled on the marketing side is like the intent aware. That's why you see that. But you know, I don't TBD and like how people respond to it. So far that's been, you know, the, the way that we've been pitching it.

19:34

Speaker D

Most AI tools are adding friction, not making your life simpler. And it's another tab to switch to and maybe you forget to even do it. It's arduous. What you really want is one system that's going to make you more efficient and save you time every single time you do work. That's why I love Superhuman Go from the amazing team behind Grammarly, which I have insisted on all my team members use since day one. Now it's an AI chat that lives on the side of your browser. It's always there. Maybe you're drafting an email mid meeting. It goes and helps you finish it without switching apps. Maybe you got a 40 email thread to get through before that call. It's going to summarize it for you in seconds without losing your place. No new tabs, no starting from scratch, no context switching. Superhuman Go has the context of everything you're working on. It works inside the tools and sites you already use. Your inbox, your docs, your browser. Maybe you're doing social media all day long like me. It's part of my Job. You can try many of Superhuman Go's features for free. Find out more. Superhuman.com that's superhuman.com.

20:08

Speaker A

i would say, you know, lineage and substrate are a bit too technical, but then again, I have to say the words agentic orchestration at least three times a day. So what do I know about branding? Okay, let's talk about a couple of other things. One is just the employee element of this. Now this computer that I'm on right now because Twist is owned by Launch, and Launch is a financial company, has all sorts of tracking software on it. Right. Just for this, you have to do that. I don't love it, even though I don't actually care because no one cares what I do. But it still feels a little bit weird to me that, you know, there is a record somewhere of, you know, every tweet that I click on right. Right now in what you're building, it is more granular. And so I'm trying to kind of sort out how much do employees care? Because on one hand, I think it's becoming the norm to have your work observed to some degree. On the other hand, Meta just made a big push to really look at what their engineers were doing, and that was very unpopular. So where's kind of like opinion and norms around this type of observation?

21:10

Speaker C

You know, I think it's TBD to some extent, at least on the enterprises that we work with. A lot of them have corporate policies that stipulate the asset that you're using is subject to monitoring for the purposes of like it's their corporate asset. Right. Like the intellectual property is there. So I think, you know, most of the security software that has been deployed even in a traditional EDR sense has been historically collecting all of this information about the actions people are taking on their system.

22:08

Speaker F

Right.

22:39

Speaker C

And I do believe that we bring a new level of granularity to it and we have to determine what businesses are comfortable effectively deploying. And I think it's just a matter of being straightforward with your employees. And so it's a matter of if it's in the corporate policy and you're able to collect it, then okay, that's fine. Our kind of general view is when it comes to the information that we collect, we don't want it coming back to a central authority. We can be the people that host that environment. So we can Deploy as a SaaS based, as product and hosts on behalf, give you a dedicated tenant. But more importantly, what we've heard from Global 2000 and above is they want to own their Data, Right. They don't want it going to somebody else. So ANT is deployed within the customer's boundary. Like we don't even get to see it. So the limiting factors there are. That's one way of kind of retaining that. Like it's only staying within the corporate environment. It's not being shared with other people. And then the secondary item is how much do you want to collect and centralize back to that corporate backend. And so we've provided an ample amount of configurability that if you don't want to send something to the back end, you don't have to, you can keep it on the edge. Now obviously there's an operational gain in putting everything in a central store, but

22:39

Speaker A

there's more data to learn on.

24:01

Speaker C

Yeah, yeah, but like a corporation may not want to do that. So for everything that we collect, there's toggles that basically allow the business to turn it on and off. We support user groups, endpoint groups in terms of like, you might want to collect more on your developers just because they have a higher risk pattern where as you're legal, you may not really want to collect anything at all. Then beyond that, within the product there's role based access control and attribute based access control. So if we're collecting something like screenshots for an investigation, I don't want the soc to necessarily see that. So we allow the business to basically hypertune the information that's exposed to any given party.

24:03

Speaker A

I feel like you're nibbling around the edges of agentic identity and the issues and lack of maturity in that product world somewhat. Am I, am I wrong? If I want to know what the agents are doing, I'm going to want them to have a distinct permission set and a distinct identity.

24:46

Speaker C

And well, it's the same thing with people too. Right? I mean, I like you could. I think part of the problem with like a corporate policy is that it lacks teeth. It's only as good as its ability to put it into a control point. And because corporate policy is written in natural language, there's some level of like, interpretation that takes place by the employee. And I think that's sometimes what leads to, you know, mistakes being made is that the employee feels they're working within the boundaries of the corporate policy when they may in fact not be. And the way that you get around this, right, is you have a draconian, you know, way of stripping down the asset and removing the freedom. And you're saying like, thou shall work this way. And I don't think that's particularly fun to work in those businesses. I understand it. But what I want to do is balance being able to give a new control point layer to actually stop bad things from occurring while also not infringing on privacy. And so it's up to me, as I design that product to put the controls in place to not build something that could otherwise be abused. And that's something that's very top of mind for us. I don't want to be nanny software. I don't want to, you know, police, you know, how many, you know, how much AI somebody used throughout the day. That's not what I care about. What I care about is stopping mistakes from taking place, removing adversaries from environments, making sure that people can adopt AI safely. And that requires some level of observability in understanding what's happening.

25:01

Speaker A

Work obs. I'm telling you, it's going to be big. All right, let's talk about really quickly some business questions. So you've mentioned how there's a SaaS version of this and a CEL self hosted version of this. Now when I usually see that breakdown, it tends to be open source software. As far as I know, you guys are not pursuing the open source approach. So talk to me about the business decision there to allow for self hosting and then also how do you charge for that?

26:31

Speaker C

Yeah, so self hosting, the reason for it was when we were at Microsoft, we learned during this AI movement people are really sensitive to their corporate data. And I think from a regulatory perspective we're seeing more emphasis on data sovereignty. We're seeing like the intellectual property of a business wanting to be contained within its environment. They don't want it to go to, you know, a third party supply chain. And so it was a, it was a first principle decision for us. In the same way that we said we're not going to depend on any other security product to get our telemetry because that impedes our ability to be preventative and make decisions quickly. We also said we're going to make it out of the box one click, deploy inside of whatever cloud you guys operate in and we support the major ones. And so that was just an important decision for us. If we host it, then effectively we take on the hosting costs and we pass that on in the licensing if you host it, that it becomes like a cogs implication that you have to effectively manage that spend and we give you the predictability of what that looks like.

26:54

Speaker A

But I'm still paying you yearly, quarterly.

27:57

Speaker C

Yeah, there's a license. Yes, there's a licensing cost associated with the product. It just will change if you're hosting it because you're going to take on the. The actual hosting.

28:00

Speaker A

Okay, that makes good sense, but it's still basically charged the same way, lower cost. Okay, okay, that makes sense to me.

28:08

Speaker C

Yeah.

28:12

Speaker A

Now you guys came out of stealth and announced a $100 million round. These happen more often than they used to. And I'm always curious why you need that much money.

28:13

Speaker B

It's a lot.

28:23

Speaker A

That's. That's an old seed fund from when I was younger. So what are you going to do with $100 million?

28:24

Speaker C

So the thing with Endpoint is it's a well established market, right? It's, it's something. There's a lot of players and incumbents there. And to be able to penetrate inside of Global 2000, Fortune 500 and above, you need to. Building that Endpoint company takes a lot of effort. I have to build an agent that works across multiple different platforms. I have to concern myself in the research and development of putting AI directly at the edge while also being able to run it on the backend. We talked about hosting inside the customer's environment, making sure that all of that infrastructure is supported. If you're using aws, Google or Azure. Right. All of that takes a significant amount of engineering to get it right, to make sure that it's tested, to not make those mistakes. And so there's a lot of money raised to basically go and do that. Just expensive to build a product, but it's also expensive to then get out in the market and land inside of these big enterprise accounts. People come to us and they say, hey, look, are you going and competing with the traditional edr? And the short answer is no, right? I don't want to go and compete with them on the same playing field. Why would I do that? From my perspective, EDR is a commodity. At this point. Everybody's got something in place. They might be reasonably satisfied with what they're getting. My job is to augment where that EDR solution is not meeting the needs, where an inside risk solution is not meeting the needs, or a DLP solution is not meeting the needs. So we talked about like the semantic substrate for security my business is trying to build, you know, like the programmable Endpoint. Can I solve a variety of different use cases using AI as my advantage across any platform, in any cloud, and give someone that level of visibility to understand what is happening inside their enterprise? It just takes money and capital to do it.

28:29

Speaker D

The team is pumped because you're about to close a massive deal, but then the client's lawyers get involved. What happens if you get hacked? How are we going to protect your data? There's no need to panic. This is why you brought in Ysecurity. Ysecurity is staffed with over 40 experienced engineers who have actually worked security for world class companies like Apple, Uber, Microsoft, Robinhood, Brex and so many others. But the best part is you don't even need to hire YSecurity. Your company can rent Ysecurity's elite team by the hour. That means no massive salaries to pay, no costly consulting, just real experts embedded in your company helping you out with your SoC2ISO4200 or any security or compliance challenge you're facing. You can even set a monthly cap so you know exactly how much you're spending and your first six hours are completely free. Head to Ysecurity IO Twist and book your free six hour strategy call. That's Ysecurity IO Twist.

30:26

Speaker A

Given how many different endpoints, clouds and services you have to make work to have this actually function at the speed you need it to. I'm never going to listen to a developer again. He tells me they can't launch on iOS and Android at the same time because it's too hard. I feel like you're taking on a much more difficult challenge. All right, last question for me is pretty simple. When you guys came out of stealth, you announced that int was generally available, which means your go to market, you know, starting gun was shot off.

31:25

Speaker C

Correct.

31:49

Speaker A

How has reaction been, how was the market responded?

31:50

Speaker C

It's been like a floodgate even before that. The reason why we effectively we've been in the kind of market to some extent, not out of stealth, but kind of pseudo out of stealth for a couple of months. And the reason why we just kept consistently holding it back is I've retained a pretty healthy pipeline of folks that are interested in what we're doing. So when Lou and I left Microsoft they were like man, you guys are going to do something crazy and I want to know what that is. And so like we've got a lot of goodwill and having multiple exits and startups that we just had a bench of people that were like, tell me what you guys are doing. And the second that we were ready, we were entertaining, you know, POVs and people that wanted to go and deploy the solution, test it out because they're like, we've never seen anything like it. This is exactly what we were expecting. And so beyond that, like typically you Come out of stealth because you want help in hiring people. And I, I've hired well over, you know, 75 people now and I've not paid a single recruiting fee. And so like, coming out of stealth was not lackluster. Like, we've got a lot of like, for us, like, it didn't feel like any material difference. Like, we've retained a healthy pipeline of people that are interested. I've got more people now asking me, like, dude, I want to see this thing in action. This is what I was waiting for. And so for us, it's just a healthy amount of demand beyond what we already had.

31:53

Speaker A

Do you have enough GTM infrastructure in place, sales teams, etc. To handle all the new inbound?

33:20

Speaker C

That's exactly where we're hiring right now. So we've got several sales reps. We're hiring for sales engineering. We got folks on the forward deployed engineering side that's been staffed out. And so like, we're, we're getting our pieces there. I feel pretty comfortable. But like, you know, now it's just a matter of like going through the motion and executing. Right. You know, having multiple deals in tandem, managing the POV process, making sure that we're delivering success and outcomes. That's the biggest focus that we have right now. So early beginnings of it, we're hiring and then it's a matter of just like continuing to turn the crank here.

33:26

Speaker A

Well, we are looking forward to when you start announcing ARR milestones, but in the meantime, it's int A. Brandon, congrats on the brown. Congrats on coming out of fake pseudo stealth and come back on in six months and tell us how it's going.

34:02

Speaker C

Appreciate it. Thanks, Alex.

34:14

Speaker E

All right, everybody. Next up on today's twist, you remember

34:15

Speaker F

David M. He was previously on our show. He had Clara, the open claw AI girlfriend. Do you remember this Jason from February?

34:19

Speaker E

I do, I do.

34:28

Speaker F

So he's back. He's got a new product from his company, Sumail Labs. It's an agent orchestration layer utilizing multiple video generation models. The goal is generating high quality video outputs in just one attempt. Jason, the idea you could finally one shot your AI videos instead of multiple go rounds to get it exactly the way you want it. David, thank you for coming back to the show.

34:28

Speaker E

Yeah, it's good to have you back. I mean, when you make video, it is literally like a slot machine you put in your prompt. I did it the other day. Pull up my Yoda one. I did it in Grok. It was relatively good. It got it Right. I said I want Yoda from the Clone War style to say Frontier Model wars begun.

34:51

Speaker F

I see. Yes.

35:15

Speaker E

Here I see Frontier Model wars begun. They have which is a favorites line,

35:16

Speaker D

the Clone Wars Begun.

35:23

Speaker F

There we go.

35:26

Speaker E

And I honestly got to be honest, I give it like a nine out of ten. Eight and a half out of ten. It knows what it's doing.

35:26

Speaker F

It's pretty good.

35:33

Speaker E

The voice is off. But I mean I'm not paying a royalty to Disney here so I don't make it in trouble with Disney. But David, why don't you show us what you built Because I do think there is something here to taking. When you get rid of the slot machine nature of these LLMs, it becomes more predictable and your utilization goes up.

35:33

Speaker G

Yeah, yeah.

35:56

Speaker E

The slot machine is not fun when you're making videos and images and they take 30 seconds. It's incredibly frustrating right now.

35:56

Speaker G

You know the ball name right now is like prompting the videos again and again to get the right results because it's unpredictable because you know, video generation models are stochastic. So what we're trying to do is make an API that is basically unwrapper of like let's say five or six models to get the production ready result. So our belief is that once we make these one piece. Piece, piece, let's say production live, production ready like API primitives, then once we got the APIs, then we can make our agent one shot a marketing video very easily.

36:04

Speaker E

Okay, I'm guessing you have a killer demo to show us.

36:41

Speaker F

Yeah, there it is.

36:45

Speaker G

Can you see your screen?

36:46

Speaker F

We can see it looks like your X feed.

36:47

Speaker G

Yeah. So yeah, this is kind of like our UGC API. It's our Avatar API. And then you can do kind of like. So this is basically the same prompt. So it's a basic prompt with Gemini Omni, Cdance and Sum Avatar. And basically what we did is we are basically on a router of multiple models. Not only video, but image, video, audio and clipping and everything. We were a wrapper around all these models and this is what we got with the same problems you're seeing on

36:51

Speaker E

the left, Gemini Omni. And it looks like a young adult, maybe a 25 year old or younger in their apartment in a city or maybe they're in high school in the second one.

37:20

Speaker F

And yeah, it looks like a selfie marketing, like I'm making a tick tock video about this product. Yeah.

37:33

Speaker E

So same prompt, you see three different results. Then what happens? What's next?

37:41

Speaker G

So what we are trying to make at the end Goal, let's say like after six months is a video agent that one shots marketing videos. So our users are brands or marketers, want to promote their product and make video ads for them. And right now our first model was for ugc. So as you know, like if you want to make UGC videos with AI right now, you have to combine a lot of different models. Let's say like Cdance or like touch up the image or grok and everything. And then after that you have to combine those videos to make along because you know, video generation models only support up to 15 seconds. It's like 30 seconds. For our CVS, like next model, it's only 30 seconds. So what we did is we made a router of video, video generation models and image models and audio to get the audio persistent to make this kind of videos. And then finally you could generate up to 60 seconds of consistent after videos right now.

37:46

Speaker E

Okay, so you put in a script. Hey, I want to promote my new app. It's called Uber. And you open your phone, you go outside, it's raining, you can't walk home, you want to get a ride. And you write the script for this. And then it goes and makes you a bunch of different scenes. Or do you tell it what scenes to make in your.

38:43

Speaker G

No, actually it's only. So for the user, it's basically just picking on Avatar and then writing the script.

39:07

Speaker E

Got it.

39:13

Speaker G

That's it.

39:14

Speaker E

The user writes the script or the

39:15

Speaker D

LLM writes the script.

39:17

Speaker G

The user writes the script. Got it. So after I write the script, then

39:18

Speaker E

each scene gets done three times and then it's up to me to stitch them together. So I might say, oh, I like this one where it shows the car, you know, in the pouring rain. I like this one when it shows the guy getting out with his umbrella or putting his jack. One of them has him put his coat over his head to walk to his front door and I, and I just get to essentially vibe code my way around a longer form video.

39:22

Speaker G

Yeah, 100%.

39:45

Speaker E

Okay, cool. Do you have any outputs like that that we can see? I would love to see like where you, where you got to with this.

39:46

Speaker G

Okay, so I could show you the video. Yeah, so this is like 16 seconds. So you can see that it's up like more than 15 seconds. But yeah, you can make these kind of videos with 60 seconds.

39:52

Speaker E

So it's using multiple ones and then it stitches together with one clean audio file across it. So a little bit of a hack there.

40:06

Speaker G

Yeah, yeah.

40:13

Speaker E

And if you go to.

40:15

Speaker G

Yes.

40:16

Speaker F

Around now, yeah, it's also consistent the. Her face remains totally consistent throughout the. A big problem when you're generating these kinds of, like, video clips, I find, is that it'll. For the first like seven seconds of the video, it'll look like the person's face and then it sometimes gets like, distorted towards the end. Like that's a big problem with. Yeah, it's like the keeping that facial consistency the whole time.

40:16

Speaker E

What is the website?

40:39

Speaker D

Do you have a website for this

40:40

Speaker E

that we can see?

40:41

Speaker G

Yeah, you can search zoom.com. ah, s u m e dot com.

40:42

Speaker D

Cool.

40:46

Speaker E

Oh, my God. You got a good domain name.

40:47

Speaker D

How much of that cost you?

40:48

Speaker E

Four letters?

40:49

Speaker G

Yeah, we got it cheap.

40:50

Speaker E

Really? That's $100,000 domain name 70.

40:51

Speaker G

Discount on the initial price on GoDaddy.

40:54

Speaker E

Love it. All right, well, this is like a great start. And who's it for?

40:56

Speaker D

Who's the customer?

41:00

Speaker E

You think startups making marketing videos or just general G2C marketers? Who. Who is your customer base currently?

41:01

Speaker G

Yeah, so right now we have 20k users and the main customers, especially about 90% of the paid customers, are brands. Got it. Our main audience, it's not on Twitter, but they're on Instagram and TikTok.

41:09

Speaker E

Got it. Yeah. People are trying to flood those space. I can't even tell what's AI anymore unless, like, you're paying attention. I got a lot of shark videos because one of my daughters loves sharks and I'll do like, shark videos with her. And now I'm starting to get AI slop sharks. And, you know, they start out and it's like a person on a boat and they're pulling in a fish and you're like, oh, my God, there's gonna be a shark. And then like this ridiculous shark jumps up, eats the fish. The person falls in the water. The shark is jumping in the water. I'm like, sharks don't interact for 90 seconds with a human. This is getting a little ridiculous here. All right, well, great job with the startup. Keep grinding and we'll see you when you have your next update.

41:22

Speaker G

Awesome.

41:59

Speaker F

Thanks, David.

41:59