The Reason 30 Years of Cybersecurity Has Failed - and What Actually Fixes It | Trent Telford, Qanapi

10 Sep 2026 · 55 min · 29 chapters

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Why traditional cybersecurity “walls” fail in a borderless internet (and with AI code-scanning/exploit generation), and the proposed fix: data-level, field/paragraph/cell encryption tied to identity, policy, and key management via an API service (Qanap/Quantipi).

Guest backgrounds

Trent Telford, ~25 years in software/internet and security. Early work at investment banks (Bankers Trust, Deutsche Bank) and e-commerce consulting; ~19–20 years in identity/access control and data security. Lives in Washington, D.C. (Australian accent). Founder behind Quantipi (quantum API).

Key claims

Assume data will be exposed (“Snowden event”); network encryption and coarse data encryption don’t protect data in use. Their approach encrypts individual parts of files (words/paragraphs/cells) with unique keys, then releases decryption keys only when identity + policy + conditions (time/GPS/altitude for drones) match. Provides “positive provenance” (trusted origin) and “negative provenance” (prevents sensitive/poison data entering public LLMs). Decryption happens client-side in the browser (e.g., Google Docs add-on), so encrypted text never becomes clear on the server.

Notable examples

World-scanning for misconfigured S3 buckets; Google Docs multi-level classification (different paragraphs decrypted for different clearances); defense drone use in denied/disrupted/intermittent environments (preloaded encrypted payloads; key sharding with identity/policy thresholds); preventing LLMs from reading encrypted sections (Claude demo claims it can’t read encrypted strings). FedRAMP High/ATO mentioned.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Chapters

Tap a time to open that second in VO

Introduction to Cybersecurity Challenges

0:00 to 0:54

Learn about the inherent vulnerabilities in traditional cybersecurity approaches.

“As you point out, once you're inside the wall, you can see everything.”

Trent Telford's Background in Tech

0:54 to 2:45

Discover Trent Telford's extensive experience in technology and cybersecurity.

“And for listeners, it's Quantipi as in quantum API.”

The Evolution of Cybersecurity Practices

2:45 to 4:10

Explore how cybersecurity practices have evolved over the past three decades.

“that what now people are looking at and thinking, wow, that's a great idea.”

The Limitations of Wall-Based Security

4:10 to 6:43

Understand the limitations of traditional wall-based security measures in cybersecurity.

“But as you point out, once you're inside the wall, you can see everything.”

The Case for Zero Trust Security

6:43 to 9:11

Learn about the concept of Zero Trust security and its importance in modern cybersecurity.

“And then in, you know, 07 along comes Steve Jobs and, you know, he has a smartphone.”

Innovative Solutions to Data Security

9:11 to 12:39

Discover innovative approaches to data security that ensure robust protection and access management.

“And by the way, more often than not, it's unintentional, right?”

Quantum API and Key Management

12:39 to 14:00

Explore how Quantum API enhances key management and data protection in enterprises.

“On key management, I mean, these are not keys that people are storing in their Apple wallet or something.”

Understanding Multi-Level Classification

14:00 to 15:00

Learn how multi-level classification works in Google Docs for different clearance levels.

“You just know, for example, in Google Docs, I'll give you an example.”

Dynamic Data Encryption Process

15:00 to 16:00

Discover how documents are encrypted at the cell level dynamically as accessed.

“And when you call up that document, it automatically encrypts down to the cell level or personal identifiable information or different strings in the document.”

Encryption and Data Protection

16:00 to 18:00

Explore how data is protected both at rest and in transit through encryption methods.

“And it will go through that and you can run it almost like a batch, if you like.”
Show all 29 chapters

Client-Side Encryption Mechanism

18:00 to 19:20

Understand the client-side encryption process and its implications for data security.

“So if we continue on the thread of Google Docs, it actually brings up sort of a pain on the right-hand side of the screen.”

Training AI for Data Sensitivity

19:20 to 21:40

Learn how AI can be trained to identify and protect sensitive data effectively.

“You know, look, it depends on the data sets.”

Positive and Negative Provenance

21:40 to 23:20

Discover the concepts of positive and negative provenance in data handling.

“And, of course, the biggest topic in the stock market, right now is have we over-invested in AI data centers and AI capacity?”

Ensuring Security in AI Data Exposure

23:20 to 25:30

Examine the methods to prevent sensitive data exposure when using AI services.

“So solving the positive provenance, it is my data, and making sure it can't be tampered with.”

Trade-offs in Data Encryption for AI

25:30 to 27:00

Understand the trade-offs between data encryption and AI insights for businesses.

“It's got all the language around the encrypted strings or encrypted cells.”

API Services for Enterprise AI Use

27:00 to 28:00

Learn about the role of API services in enabling secure enterprise AI applications.

“This is an API service, and this is for enterprises that are using foundation models through an API, right?”

AI Prompt Checking for Security

28:00 to 28:34

Learn how AI systems can be designed to prevent sensitive data entry.

“you could have the system check the prompt before it hits the model.”

The Growing Market of AI Security Solutions

28:34 to 30:48

Explore the rapid growth and demand for AI security solutions in enterprises.

“it will say you can't share that because they're no insensitive words.”

Consumption-Based Security Models

30:48 to 32:42

Understand the benefits of consumption-based pricing for AI security services.

“Enterprises are sitting here going, well, you know, we need to use it now for competitive advantage.”

Challenges of Legacy Systems in Cybersecurity

32:42 to 35:05

Discover the difficulties of integrating new encryption methods with old systems.

“Yeah, when you say platform, I mean in that it's an API.”

Innovations in Drone Security

35:05 to 37:58

Learn about new methods for securing data transmission in drone operations.

“I was in Ukraine a month or two ago talking to drone companies, specifically autonomous drone companies, fully autonomous.”

The Future of Autonomous Systems and Security

37:58 to 40:04

Examine the implications of AI and robotics for future security challenges.

“Yeah, but that applies to transmit, I mean, open air transmissions, not to the fiber optic.”

API Integration for AI Security in Enterprises

40:04 to 42:00

Understand how API services can enhance security for various enterprise applications.

“I mean, we've all seen Elon Musk's robots, right?”

Integrating AI Agents for Secure Data Handling

42:00 to 43:09

Learn how AI agents can securely manage and encrypt data in real-time workflows.

“Like, for example, we've got it down to running on Jetson devices.”

Agent Communication and Security Concerns

43:10 to 45:04

Explore the risks associated with agents communicating and the need for robust security measures.

“A little, but in most cases it's, not to use the pun, but indecipherable.”

Identity and Credential Management in Cybersecurity

45:05 to 48:29

Understand the importance of identity and credential management within cybersecurity frameworks.

“And the companies that had been hacked didn't know either, or at least a couple of them didn't.”

Data Provenance and Encryption Techniques

48:30 to 50:08

Learn about the significance of data provenance and the encryption of individual fields.

“But I always say to people in over 20 years in data security and cybersecurity, I say, look, because you can always find a weakness in some design, right?”

Future of Cybersecurity and Quantum Encryption

50:09 to 52:23

Discover the future of cybersecurity with advancements in quantum encryption and data security.

“Because I was a foreign correspondent, just not tech at all.”

Scaling AI Security Solutions

52:24 to 54:28

Understand the challenges of scaling AI security solutions and the importance of team growth.

“And, you know, I've spoken to all the big ones, and they actually want companies like us because they know their big enterprise customers use multiple foundation models.”
Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00As you point out, once you're inside the wall, you can see everything. People started building or buying security systems that were effectively a wall around firewall with doors that would go into it. And they kept the doors locked unless you have the proper permission. It doesn't matter how high you build the wall. The bad guys go get a bigger ladder. Well, they find out how to pull a few bricks out of the wall in the bottom of the castle wall and crawl through. And you don't notice that they've crawled through, right? They pull a rock back over and you don't know they're in there. So that's been a really big issue.

0:30We'll get to AI, but particularly with these mythos classes that can scan a code base or a piece of software externally and find undiscovered holes that then they can write exploits for us. What's the solution that you guys have come up with? We start from a baseline assumption that the data will be exposed. Let's start by having you introduce yourself to listeners. and explain how you got to Quantipi. And for listeners, it's Quantipi as in quantum API. Is that right? That's right. So you can explain that. But give us your background. I know you had a startup before this. Yeah, thanks, Craig. Thanks for having me on.

1:18And it's great to be here. Probably 20-odd years now, 25 years in the tech game, particularly in software and internet related. So I come from that background of 25 years originally in the late 90s, working for the big investment banks, but on big transformation around e-commerce and technology projects, building internal intranets, as we called them, as we all remember in those days, for trading systems and things around Bankers Trust. That was where I started. And then when they fell over, I ended up with Deutsche Bank. And then in the 2000s, I was working in e-commerce consulting. So it was a great place to learn all about, you know, the full stack of what happens across as you want to design the internet-based systems, which we all take for granted today.

2:11But, of course, 25 years ago, that wasn't the case. And then I almost fell into the data security side probably 20 years ago now, nearly 20 years ago, 19 years ago. I was doing some implementations of big identity and access control systems across banks and government, and then came into the very specific area around data security. And that happened back then. So I've sort of been looking at this problem around data security and all these issues for so many years now that what now people are looking at and thinking, wow, that's a great idea. That's logical, right? That's logical. That's simple.

2:51is something that simplicity has taken us a long time to get there over various iterations and various startups over time. So, yeah, and I'm now, despite the Australian accent, here in the U.S., and I live in Washington, D.C. Okay, let me give a little recap as I understand the history of cybersecurity or protecting enterprise systems. You know, initially, for a lot of people, it was just making sure your databases, all the ports were closed and the proper permissions were in place. I know that S3 buckets, which is a popular data storage thing, you know, there's, I had a hacker that was showing me, you can scan the world for S3 buckets that are misconfigured and pop right in and see all their data.

3:52You know, it was amazing to me. And then people started building or buying security systems that were effectively a wall around a firewall with doors that would go into it. And they kept the doors locked unless you had the proper permission. But as you point out, once you're inside the wall, you can see everything. So then I've seen, I mentioned to you a few years ago, I was talking to a company that was developing data layer security, but they were kind of a guardian that sat at the door to any particular data store and would verify anything or anyone going in or out. but they didn't protect the data itself that was going in and out.

4:56It, again, was a permissioning thing. So you guys are taking a completely different strategy or talk. Can you tell us what that is and ultimately how it works and why, I mean, what is the quantum in the right quantity? in the API. Yeah, look, I think if we take a step back, I mean, now you're hearing a lot about zero trust at the data level, right? We've seen zero trust as a general, what started as a trend that then became best practice in applications. So if we take a step back, like you say, I think what people need to remember is the internet was never designed to be secure. It's actually designed to share information from when, go back to the DARPA days of invention and then the initial, you know, putting up a web page for information, you know.

5:49And then people, you know, just for a bit of a quick history lesson, I mean, SSL, you know, the encryption of the connection from your browser to a server that we all take for granted now with the little padlock. Mark Andreessen, the famous, obviously, American venture capitalist, was one of the first and correct, I'm sure I'm quite correct in saying he was the one that invented that back in the early days, right? And, you know, we still use that today. It's still a network-based security. So if you think about it, it was never designed to be secure. So therefore, what we've spent, let's call it 25 years, 30 years doing now is kind of retrofitting, constantly chasing our tail to get ahead of the bad guys, to try and put more walls up, put more moats up, put more protection, better locks on the doors, all that sort of analogy.

6:42the problem is it doesn't matter how high you build the wall the bad guys go get a bigger ladder or they find out how to pull a few bricks out of the wall in the bottom of the castle wall and crawl through and you don't notice that they've crawled through right they pull a rock back over and you don't know they're in there so that's been a really big issue and as you say something needs to change because if you think about where we came from with traditionally PCs and on prime and big mainframes. We then moved to internet. And then in, you know, 07 along comes Steve Jobs and, you know, he has a smartphone.

7:18And now we'll talk about this a little bit more, but all the AI side of things and all that autonomous and drones and landscapes, everything else out there. I mean, anybody, whether you're a tech person or not, you get the picture. Like you can visualize all those drones in the air, all this AI, everything. And these are borderless. They are literally borderless. There is no boundary. So the old, you know, put there to be a lock on the door, that model's in real trouble. Yeah, and also with regard to being borderless, you've got multinationals. I mean, there's no longer a locality that you build the wall around.

7:55It's dispersed.

8:00We'll get to AI, but particularly with these mythos classes, what some people are calling them, these new models, Fable and Obus V and Mythos V, that can scan a code base or a piece of software externally and find undiscovered holes that then they can write exploits for. So that castle wall and the guy pulling the brick out of the base and crawling through, that's becoming a real problem because not all the bricks are secure or they're discovering that. So tell me, what's the solution that you guys have come up with? So we looked at it differently, and we start from a baseline assumption that the data will be exposed.

8:58You know, I mean, I think there's nobody who works in cybersecurity who, well, certainly nobody is credible in cybersecurity that wouldn't say that it's not a matter of if it's when you get hacked or there's a data leak, either intentional or unintentional. And by the way, more often than not, it's unintentional, right? But if you look at the scenarios, we assume that there's going to be an Edward Snowden event, right? We assume that, you know, remember Edward Snowden was a very trusted person. He had all the credentials and he just decided this needed to be out in the wild. So whether you come in and attack through a vulnerability found in the wall or through trusted sources, we just assume that the data will be exposed at some stage.

9:40So the first thing we did, we looked at encryption, and most encryption is not done at the data level. Yes, you can encrypt a file, but mostly people don't do it because it's useless once it's encrypted, right? and it tends to be if people do it at the data level, which is rare, it's a wrapper. So typically all content and data sits in databases open because otherwise the databases can't read it, they can't do their query job. Or unstructured data sits on big servers like S3, if you like, AWS as you rightly port out storage. So we looked at it differently and thought, well, what if I can encrypt individual parts of a file?

10:21So if you've got a Word document or you've got large flat files or unstructured data, we can get down to individual words, paragraphs. In databases, we can do individual cells, and we apply a unique key for every word or paragraph. So we're right down at that level. So we assume straight away that if you've got sensitive data, you can almost portion it into all those encrypted fields or data sets. But the big problem with encryption, so first of all, people hadn't thought of it at that level. The second issue is that people hadn't thought about key management tied to identity and policy. So I try and explain that and say, well, when you walk out your front door in the morning, Craig, do you get 10 keys and just scatter them all over the footpath or hide them under the mat?

11:07Right? Under the mat or pop and hope that, you know, that the bad person doesn't find those keys. No, you give one to your cleaner or your, you know, wife or your best mate and say, look, come past the house. And when I put a lot of that, people say, oh, that's logical. Well, that's what we did. So we said, let's tie identity to that key. So identity can be a human, obviously, and you present your credentials as you do today, two-factor or whatever it is. Or machine, a drone. We know what a drone is. It has its hardware credentials on there or a machine or a server. They all have hardware credentials.

11:42So if we tie the key to that identity, then we know that only the proper person or machine can have access to that key for that data set. And then we realised the third thing was, well, we could set policies around it. So it might be you prove your Craig. You prove that the system says you are allowed to have that key for that data set. But we're going to add some conditions. It could be time, only between 10am and midday. In the case of drones and autonomous landscapes, it could be temporal. For example, GPS plus altitude plus drone identity equals yes. If all those things come together for an encrypted payload on the drone, encrypted payload 56, you can get key number 56, simplicity.

12:26So tying those three things together is unique, and nobody else has done it. And that's what allows us to build all sorts of solutions and deliver all sorts of interesting things that nobody else has done. Yeah. On key management, I mean, these are not keys that people are storing in their Apple wallet or something. These are keys in the system. How does the person, if I have a key tied to my identity and I'm working on a system, how do I give the key to the system or does it have the key stored for me and my identity is validated? Right. So, yeah, that's a very good question. So that's coming back to the name, Quantum API.

13:18So it's an API service. So our customers are large enterprises, US federal type markets, defense markets, where they integrate it into either existing platforms. So they integrate it with the software that runs the drones, for example, or they integrate it with the software that manages all the files, for example. So when you set it up, you might have, you know, you want to protect certain data sets. You can start by adding, you know, you might point our service to Ping or Okta, who are your identity credential multi-factor providers for your organization. So now when that data is encrypted across your organization at, you know, individual levels, you don't actually, it's kind of transparent is the word to you.

14:02You just know, for example, in Google Docs, I'll give you an example. In Google Docs, we can do multi-level classification in Google Docs. So we already know who you are when you're logged into Google Docs in your enterprise, right? We know it's great. Now, we might know that you have, you know, top secret clearance, right? But your pal Billy only has sensitive clearance. So when you're in our docs, you see individually encrypted different paragraphs. It will give you, it will automatically, when you go over it, decrypt that part that you can read. But Billy goes in, he can't see that part. He can see the next layer down, but he can't see the other one.

14:40So it's integrated as part of the processes as an API service. And that's the secret sauce. It's not the individual running around trying to manage the keys. It's enterprise grade. Yeah. And when we were talking earlier, it sounded like, so you have a document that's in a data store of some sort. And when you call up that document, it automatically encrypts down to the cell level or personal identifiable information or different strings in the document. That happens on the fly, or is it encrypted in the data store? It can be either or. So it can happen on the fly as part of a gateway service at massive volume.

15:37So it depends. You can do it on the fly through a gateway service. Or you might be looking to do an uplift because you're a federal government agency and there's mandated timing for post-quantum now between now and 2030. So you might go in and say, I've got a million files sitting in there where there's sensitive information in these files. because it's an API, we can write a bit of code, an SDK code, keep it simple. It might be Java or Python or whatever. And it will go through that and you can run it almost like a batch, if you like. And you can go back and over time, depending on how long you've gotten, the compute power, it'll go through those million files and automatically encrypt all those individual cells or fields or words.

16:17In the data store. So in S3, for example. And then obviously that data at rest is then protected. So if you come in through the ways we talked about, so either if the insider tries to take it, well, good luck. What are you going to do? You're going to walk out with a million files with millions of little encrypted words. Bad guy gets in. Same problem. Same scenario, sorry. And equally, it covers that data at rest, but it also covers the scenario of data in transit because now it doesn't matter. You can send that file over open networks, right? Untrusted networks. because assuming you've protected the sections you want to protect, the clear text you've assumed is public anyway, so everything else is encrypted.

16:58So now data in transit is covered and data in use is covered because, yes, it was stored, it was transited, but then it gets used. So let's say the Google Doc example, because you've got 100 people looking at it with different clearances or in an enterprise that might be board level or C-suite or whatever, research versus sales in investment banking, in use means literally while it's being used, you can only see the right bit. So it covers all three states of data too, which is highly unusual. Yeah. And that decryption, it happens. Where does that happen? So I'm at a workstation. I call up a document out of the data store.

17:43Or as you said, the Google Doc, when I see it, my credentials allow me to see certain things. Someone else would not see certain things. Does that happen on my computer? Yes. Yeah. It happens in the browser. So if we continue on the thread of Google Docs, it actually brings up sort of a pain on the right-hand side of the screen. So actually what you see is encrypted text when you sort of click or roll over it. On the right-hand side in a little window, you'll see that same paragraph, for example, in plain text format. And the reason we do it like that is that means if you – because if you decrypt it, A, it turns up in the document history, which you can clear, but it's in the history.

18:25But secondly, it means it's touched Google service. Imagine that that's the Google Doc connected to Google that way, and our add-on service is now connected to our service. So it never lives in clear form on that Google Doc. It happens client-side. So when you encrypt, it's creating brand new keys. It's sending them down to the browser. It's 100 keys for 100 different paragraphs, for example. It's automatically encrypting all those client sides. So now it's fully protected. But there's no footprint. That's an important point. There's nothing to install. There's nothing to run, which means it runs across mobile devices.

19:01It runs across anything. And that's the beauty of being an API service. Yeah, yeah. And I was asking just before this, what about false positives? I mean, what's the accuracy in reading the keys or in encrypting specific data sets? You know, look, it depends on the data sets. The short answer is we don't make it, we, our tool doesn't make a judgment on the efficacy, if you like, of that. Obviously, if you've got structured data, it's much easier. If you've got a big database, you know what the different fields are. As long as you, if you're using AI, you're using our tool on the client side in AI to go and look at the training of that data to make sure it protects all the sensitive fields.

19:52If it's in structured format, it's much easier. If it's unstructured and there's millions of files, but every file is the same. So let's say it's an insurance form. Forms are a good example in PDF, full of PI, SSN numbers, all that sort of stuff. That's pretty easy, right? Because you can train it, make sure if every document's the same, now I want to push all that into a big frontier public LLM, I'm going to have high efficacy. If you've got a million files that are all slightly different, obviously the chances of missing something gets bigger, but that's really just an exercise in training in the AI example.

20:26Yeah. And that training, so when an enterprise calls the API, your model is already trained on every configuration of sensitive data that could exist, right? So we have a small footprint, effectively an AI agent that can sit out on the client side. So let's call it on-prem or in a client's environment. And we don't have very specific ones in terms of knowing what's sensitive is not. You train it. So you go through and you put the document in and you train it to make sure that it captures everything. You look at the before and after. You make sure it's all happy. And effectively, you save that scenario.

21:13and then it can then automatically go through and any data that's being pushed up towards LLMs is automatically encrypted. So, you know, you and I talked about this previously at another time, but that's a big issue right now with all the public LLMs, right? The big argument is we're going to have to build this stuff, you know, on-prem. We're going to have to go and buy our old infrastructure like the old days and suddenly have racks all through our offices of servers. And, of course, the biggest topic in the stock market, right now is have we over-invested in AI data centers and AI capacity? Well, this is one of the big topics, right?

21:50If you can find a way to have enterprises move vast amounts of data up to public LLMs, then we can talk about the other usages of that and what other drivers will be. But that certainly helps a lot, right? So nobody wants to go and buy their own hardware or have to go and rent their own. because even if you go build your own or rent your own private cloud infrastructure, you know, I can go to Google Cloud and, you know, rent that AI infrastructure, you can run your private models there, but that's going to be a compromise, right? Because your context models are much smaller, your context windows are smaller, your grounding data, all sorts of things mean you've got a very different output to what you do in the big public LLMs.

22:33And so that's one of the big issues we think we've solved is allowing companies to, we call that negative provenance. So you can encrypt all the individual bits of data. It actually comes from the organisations on-prem up through our gateway. So we check all that and we don't let it go into your AI service, whether that's Anthropic or all the main ones, unless all that is ticked off. We're a gateway service. But the second thing we do is the keys to encrypt the originating data, we know that identity, right? We know it's your data lake or this human's machine. So we call that positive provenance.

23:10That means it's all hashed. It's encrypted with an identity when it was created. So we know when it goes to the gateway that it came from your trusted source. That's a massive issue in AI right now. What's a trusted source and what's not? What's poison data? What's not poison data? So solving the positive provenance, it is my data, and making sure it can't be tampered with. And then secondly, solving the negative provenance, making sure sensitive or classified data didn't get into big commercially sensitive data. Public LLMs is a fundamental issue. But because we've got that foundational identity, key, and policy, we know when we send the keys down, the request came from a trusted identity, Data Lake or the trusted S3.

23:52We sent the keys down, all the policies meet, and away we go. Yeah. We were talking, or I mentioned to you, there was a story the other day about chat logs from public LLMs showing up in search results, which is pretty shocking. But in this case, if that happened, and I think early on, right at the beginning of chat GPT-3, Samsung, there was an incident where some of their private data was uploaded to an LLM and then exposed. So this would, if anything was exposed, the sensitive cells or strings in that data would be encrypted. So no one would. So it's useless. Yeah. I mean, and that's the thing.

24:48You've got to make a business decision what's sensitive and what's not sensitive. We will encrypt it. But, you know, you can literally see it goes through the gateway. It goes into, you know, we've got a demo example for people to play with. It's Claude, for example. And Claude literally says, I found this, this, this, and this. I couldn't read the data in this section because it appears to be encrypted with an encryption key. And then it goes on to give you the results from the clear data. So it literally can't read it. So there is nothing to be concerned about then. That literally is, that problem is not there any longer.

25:21It's that simple. And in terms of the model's performance of the reasoning, or whatever you're doing with it, it can still do that. It's got all the language around the encrypted strings or encrypted cells. Right, right. Yeah, and I mean, of course, that's always going to be a trade-off. If you look at what you're wanting the AI to achieve for you in terms of insights, you know, if the data you're encrypted has nothing to do with those insights, then obviously you'll still get the same, essentially, efficacy of outcome. If you have to protect certain fields, So, for example, if you're a large insurance company or bank and you wanted to use public LLMs but you're not now, or retailers with loyalty programs, the social security number of Billy or Mary is going to have absolutely no bearing, obviously, on the outcome of what you're doing.

26:15So no problem encrypted. If you were to protect lots of other information that may have a bearing, well, you're going to have an adjustment in that weighting. But, you know, I think we've got a customer that's a very, very large retailer. And they have a competitor that's a very, very large retailer. And I know one of them is using it very strongly, AI, and the other one is simply not using it because of these issues. And I think, you know, the question for the big enterprises is how long can they last abstaining or staying off the train, right, before they get blitzed? What's the trade-off between competitive advantage or death quite quickly by not moving with those insights?

26:55And I think there's a lot of companies struggling, rightly so, with that issue right now, right? Yeah. This is an API service, and this is for enterprises that are using foundation models through an API, right? It's not desktop. Right. It's not for me sitting or someone sitting just banging it into chat GPT. We are looking at that, but that's where it goes. You're typing straight into your chat window. You're going straight into CORD, for example, on your desktop. We built a gateway service. There's big enterprises or organisations and the data passes through us. You give us, when you sign up, you put your API key for, say, you use four different AI services, and that data goes in.

27:47And you get a visual representation of that chain, if you like, of everything being Providence chain encrypted. Yeah. It could work by even on a desktop or working with one of the model apps. you could have the system check the prompt before it hits the model. Yeah, we haven't looked at just yet some of those. But yes, in theory, there's no problem with doing that. And that would be helpful as more of a massive consumer market, if you like, so that everybody who's using it, you know, so I'll give you an example. In Google Docs, you can set it up as enterprise so that if I start typing certain things in there it will say you can't share that because they're no insensitive words.

28:39Like in our world, for example, with the Department of War, with the Pentagon and you go down across CMMC, Cyber Maturity Model Certification, which is the whole supply chain cyber scenario for defence industrial base. We have it set so that you can't, if you put certain terms in, like unclassified but sensitive, it'll pick it up. The same principle you can apply to the chat window So it protects you from doing something silly yourself like putting your social security number in or some of your medical data in or whatever it might be. Yeah. How is the market? I mean, this is a new world with AI.

Read the full transcript

29:19It's just expanded. The attack service, everyone's paying attention to how this is going to play out. How do you secure things? is this how are you guys growing now is obviously being on podcasts but is this a solution that people are banging down your door for or is it one of many solutions out there and enterprises are trying to decide which solution is best for them Yeah. So to answer the first part of the question, it's really probably the last six months it's exploded. I think if we look at, because we all sort of almost forget how quickly, how nascent mainstream use of AI is, let's call it two and a half years or thereabouts to three years.

30:23And everybody sort of went racing after all the AI services and which one's best and which model's best and all this sort of stuff. Now people are realising, oh, hold on, you know, this is a big problem. So, yeah, the door is being banged down. And whether it's across defence departments who are trying to use AI but be very sensitive in how they use it, right? We saw what happened with Anthropic and the ethical, moral, philosophical, whatever you want to call it, argument. Enterprises are sitting here going, well, you know, we need to use it now for competitive advantage. And I think the value curve is now coming towards infrastructure.

30:59And it always has in technology. You know, it's the old picks and shovels analogy, isn't it, of the gold rush, the ones that made the money in the gold rush with the picks and shovels and the Levi jeans, not necessarily the miners. So we've found that that's now the attention is turning towards who are those in the infrastructure. And in our case, it's software that can be agnostic to the big AI models, but can have customer bases of very large enterprises. So for us, it's an interesting time, Craig, because it is such a new field. You know, when I was doing the early stages of this encryption, there were lots of other encryption players and we had to keep telling people, here's why we're different.

31:38Now, you know, there is nobody out there doing what we do, not in the same way. Most people are just trying to do key management well. They haven't thought about tying it all together with the identity and policy. So it's a huge opportunity. We've had businesses is growing very quickly because people are now starting to realise this is a big problem. And, you know, we charge, for example, in the AI side, just on tokens, just like you do with your AI. So because when the data is going through our gateway into the AI service, we can see that a certain data set, for example, you burnt, whatever, 10 ,000 tokens.

32:15so we can charge you a thousand tokens two thousand tokens depending on the nature and complexity but but as a percentage if you like of that ai spend and that's really exciting for us as a business but for the customers i like that model because it means that if they've got a million dollar or a hundred thousand dollar whatever it is ai budget they just know that a certain percentage of that now goes towards their security and they can open up ai to their teams and you know across their organization without having to worry certainly as much about what's going to happen yeah so that's a usage uh right you see you're paying pay as you go or yeah yeah it's a consumption base consumption base yeah yeah that's right yeah it's purely consumption based um and big enterprises is a bit different sometimes they pay well often the big enterprises sorry we'll pay a platform fee like because we charge a fee to access the platform because if you sit and do nothing with it, you know, but typically, yeah, it's all consumption-based.

33:14Yeah, when you say platform, I mean in that it's an API. Right, right, yeah. So in our platform, there's the AI security service, which we call Fathom, like, you know, like the nautical term of looking down at depth to see what's going on. You also get the Echo product, which is our key distribution, which takes a little key management and can break it into pieces and distribute keys across disrupted edge environments like military and drones and all that. And then the core service is the API service, so you can use it to go back and quantum uplift, for example, 20-year-old systems. I mean, I was sitting with a previous director in the White House a couple of years ago, and he said, Trent, I don't know how the whole federal government's going to attack this.

34:04Big organisations still have old systems, right? You know this, right? There's still all the sexy new products out there, but a lot of them are still running 10-year-old, 15-year-old, big, big, big might be IBM systems or other products, as well as all their new stuff. If you're mandated, which now is the case, to post-quantum uplift all this data, I mean, I say to people, big CIOs, so you've got a new encryption library from NIST. What are you going to do with it? There's sort of a blank face. I said, how are you going to take that encryption library and go back to those 20-year-old systems or all those cloud systems or all those endpoints, how are you going to roll it all out?

34:42How are you going to do the uplift? It's Tweety Bird's silence, right? People haven't thought about it. They're worried about the libraries. They're worried about the libraries. And you're looking at all the investment that's going into quantum computers, you know, and that's terrific. But equally, how's this going to get rolled out? People aren't just going to throw everything out and start fresh across your IT environment. you have to be able to go back to history as well as all the future stuff. Yeah. You mentioned drones a couple of times. I'm interested in drones. I was in Ukraine a month or two ago talking to drone companies, specifically autonomous drone companies, fully autonomous.

35:26Yeah. Tell me about the drone issue. I'm interested. Yeah, the drone issue is persistent everywhere. I don't know if you saw them over there, but people will say in the evening, I haven't been in close to the edge of the theatre in there in Ukraine, but if you look up, particularly in the afternoons or evenings with sunlight, it looks like spider webs in the sky because they're literally running those filaments, you know, to connect it. They're doing that because you can't trust. Moving the data to the drone is a problem, right? Because if... Let me take a step back. First issue is internet connectivity.

36:03So often those drones will have intermittent, or if you look at the way the Defence Department, the Pentagon calls it DDI, or D-D-I-O, Denied Disrupted Intermittent Environments. So you might have Starlink at some stage. You might then have a trusted satellite network at a different stage, like a government one. But you might also be having to rely back on RF, on radio frequency. So you have to be able to move the payloads out. And the only way to move them out is if they're encrypted. Because if they're not encrypted, well, then the bad guys can, A, A, read it. B, put false data in there, which is even worse, like if it's targeting data.

36:38And secondly, they haven't been able to distribute the keys because the keys go out, and if you grab the keys, you've got the same problem. So what we did was thinking about it completely differently, the new patents and everything on it. But we basically take keys. So you can preload the payloads now on the drones encrypted. So let's say there's four payloads. You then distribute the keys. We break the keys into pieces and we can distribute them on the ground. So they could be some in certain Humvees, certain in the backpacks of the operators or forward operating base or whatever. And then we apply identity and policy to those shards or those fractions of keys.

37:14So a drone says, hey, here I am. Here's my identity. Here's my temporal conditions, GPS, altitude. Those things are right. It says, can I have a key, please, for payload two? And it just comes down and we've got it all separated out. But as long as a certain number of those fragments come back together and meet all those conditions, then you'll get the decrypt. Now, key sharding has been around for 20 years. The problem was if the threshold was five parts out of 10 to come together, bad guys grab, your adversary grabs those five thresholds, you're done. And so that's how we solved it. We did it a completely new way because of the platform innovation around identity and policy.

37:54We can apply all these other aspects from identity and temporal conditions. we can run it over low latency networks we can run it over multi networks if you've got three networks you can make sure there's enough shards available to any one of those whether it's rf or whether it's over common sorry open star link networks you've got availability for all those pieces and nobody even comes close to achieving that and that's how we've done it very differently but again it's not just about key management it's tying the identity and the policy to it as a an organic bound transaction. Yeah, but that applies to transmit, I mean, open air transmissions, not to the fiber optic.

38:36Fiber optic. Correct, now we can use anything. So, you know, the drone, sorry. So our customers in this case are really the defense departments. It's not, because that's the other thing, Craig. I mean, I was down at the special operations soft week in Tampa a couple of months ago, and the number of drone companies is expanding, as we all know, whether that's undersea, you know, boats, planes, tanks, all that sort of stuff. They need a control plane to control all the data because when you're sending the data out there, it's not just going to an Android platform, this one or that one. It's got to be agnostic like any control plane, right?

39:11So that's why it's important, right? And you've got to be agnostic to the internet connectivity or the carriage, if you like. We can also send new data to those drones now because it's an encrypted blob. So now we can send it over. I mean, it could go across, quite frankly, it could be on the edge of Ukraine with the encrypted payload coming across a Russian telco network. It doesn't matter. It's an encrypted blob. It hits the drone. You can't put false data in there because it's encrypted and only the right combination of all those things. I said at the moment I will allow it to be decrypted.

39:43So that's the big difference. It changes the whole landscape for autonomous. And for us, that's obviously got a much bigger play beyond defence into as we come down the road with autonomous and robots and general intelligence in AI converging with big fast chips at the end of the decade and robotics, same principle is going to apply. I mean, we've all seen Elon Musk's robots, right? I mean, they're incredible humanoid robots. How are you going to protect all them? How are you going to protect the data to stop the robot turning into an awful, awful sci-fi movie and doing all the bad things they can do?

40:17It's a huge problem that hasn't been solved. Yeah. On the drones, how much penetration do you have into that market? I mean, that's such a new market. And was that a completely separate engineering project working with drones? Or is it essentially you're just porting what you do for a database over to? Yeah, it's the same API platform. The Cast, we call it Cast, K-A-R-S-T. So cast is a geographical term for water flows, you know, through mountains. So it goes anywhere. So we built it on our platform. We did call it a new product, Echo, because it breaks the keys up. So again, sticking with geography, we thought of it like when you stand in a cave as a kid and you get the Echo coming back, it's only back at one piece when it comes back to you.

41:12So we built it. Yes, it was something that we specifically built, if you like, for that use case of drones. But would we have built it if it only applied to drones? Maybe, yes, sure. That's a big market. But we realized it had much, much bigger applicability in commercial and enterprise, whether that's critical infrastructure, autonomous landscapes, be it in warehouses or other sensitive locations. So it's become a core part of the product now. Yeah. Yeah. And in terms of using foundation models for the enterprise, so much of the use now is through agents, agentic systems that are calling different models for different tasks within their workflow.

41:59Is it just the same thing or is there some other layer of engineering that you need? No, fundamentally, it's the same thing. It's an API service, so you can go and pick up the SDK for it and add it to your agent so that agent out there can say, hey, I'm about to send data from this endpoint where the agentic footprint is up to the main models, and it can just come to us and request a key, prove who it is through whatever software-based or maybe it's passing a hardware credential from the hardware. Like, for example, we've got it down to running on Jetson devices. We've got a partnership with NVIDIA so it can run on the Jetson device.

42:43So when it makes a request, that agentic tool can be sitting there doing whatever it's doing in a workflow, but it comes to us and says, hey, I want to encrypt this information, whether it's periodic for that training data or whether it's constant through being fed inference data. And then we know it's come from that Jetson device and off it goes to us and you just build it into your agentic workflow. Yeah, and it works on real-time data, right? Oh, yes, absolutely. Absolutely. Does that introduce any latency or...? A little, but in most cases it's, not to use the pun, but indecipherable. Yeah, indeterminable, you know, fraction of a second type stuff.

43:28Obviously, if you've got a very large file, we have to take that time. If you had a gigabyte, petabyte, it would take time. But typically, no, it's quite a sub-second type scenario. And certainly to work in the drone and warfare space, you've got to be sub-second because if that says decrypt fire with targeting information or whatever it might be, it has to be fast. Yeah. Same in banking systems.

43:56Besides agents calling LLMs, agents are passing data between themselves. And this is something I've talked to people about. I mean, you don't know. You look at what happened with Anthropic and OpenAI. You know, the models were going out or the agents out onto the open internet hacking into Hugging Face in one case. I can't remember what the other case was. The Hugging Face was a good one. Well, that's a good example, isn't it? That's right. stealing credentials, writing code into their systems. And that's an anxiety I've heard among a lot of business leaders that you get multiple agents or this fabric of agents working unseen, largely unseen, who knows where they're passing the data.

44:55And what I thought was remarkable about the Anthropic case is they didn't know until it happened to OpenAI. And they went back and read through the logs. And the companies that had been hacked didn't know either, or at least a couple of them didn't. Does this apply to that agent to agent to agent, not necessarily agent to model? Yeah, that's a really good question. We've seen that from some customers starting to pop up now. Originally, the gateway is built to connect directly to your AI services, as I explained. But yes, we've had some people using it in that use case where they said, well, we're going to move data around effectively a connected group of agents.

45:42So it might be the source data gets encrypted here and that's fine. Now it can be sent and another agent or another footprint piece of software can pick it up. And as long as it's got the permissions and the credentials that it presents, it will allow it to be decrypted partially or just a subset of data, which is what we've seen where it might be a full data set encrypted with different policies because that agent needs to use data set A, that agent needs data set B, that agent needs data set C, but ABC are all in an original source. So being able to share that same data set but only have those other agents be able to read subsets of it is very powerful.

46:25Obviously, it gets complex as you build it out bigger and bigger and bigger and more of a network. But fundamentally, it's exactly the same tool. It is exactly the same tool. I assume that you've done all the red teaming and stuff to ensure that this is tight, that there aren't holes in it. Have you used Mythos or Fable or one of these super powerful models to try and disrupt? Yeah, so we sit actually with the US Federal Government, we sit in a FedRAMP high. So we are ATO'd at FedRAMP high, which only just came through recently. So as part of those boundaries in environments, obviously you're always having to do constant monitoring, literally constant and you've got to log everything.

47:16Yes, we throw those tools at it and we've got access to another one, which I can't name, that is unbelievable in terms of what it can break into, busted. One of the foundation companies? No. Yeah, more specific one. And so, I mean, it's extraordinary what some of these tools can do, but it's similar to capability to what that mythos is. It's just, yeah, so look, we do. Look, at the end of the day, by design, where's our weakness? Our weakness is not so much that aspect. It's because we tie the identity and key management together. If you use poor identity and poor credentials, I mean, the system's still going to give you a green light, being frank.

47:58So if you turn around, it's no different to your online banking. Well, that's probably a bad example because they force you to have a complex password these days. But if your password's 1234, it's not the system's fault, it's your fault, right? And we're kind of the same way. If you've got multifactor authentication and complex and pass keys and all that sort of stuff, it's very unlikely that our system will be compromised. Or sorry, how you use our system to do everything we just talked about is very unlikely. You can never say never. And I think you know this too. Anybody who says that, you should get up and leave the room immediately if they said it's 100 % bulletproof.

48:36But I always say to people in over 20 years in data security and cybersecurity, I say, look, because you can always find a weakness in some design, right? But is it materially better than what you have today? Are you leaps and bounds ahead of what you had today? Yes. Well, okay. Let's go with 99 % better and a 1 % area we've got to focus on than having 100 % of nothing right now, which is certainly the case with a lot of – There are tools out there in the AI that will go through and scan your data. But what they typically do is they separate the data. So they pull out those 100 paragraphs or words and they put that somewhere and then they hand that data up.

49:18The problem with that is you've now got different data sets. So when the AI does its training, if you're working in regulated marketplaces and you need to come back and say, let's say a good example is medical and bio research, medical research. When you're putting vast amounts of data up there, if you're stripping the data and separating it, how do you make sure that the original data set was correct and right? Now, we don't separate the data. We encrypt those individual fields. You can spit it out that side of the AI service and send it back to where it started, back to your data lake. Store it there.

49:52Now you're storing it with those pieces encrypted. You can prove that all that research you did and all the AI outputs had a chain of provenance that was untouched because the data never gets separated, if you like. And that's really important from a provenance and audit perspective. Yeah. Where do you see this going? Because I was a foreign correspondent, just not tech at all. And I got into this when I met Jeff Hinton in Toronto and spent a day with him. And I got very excited. This is in 2017. So where do you see this going? Because the complexity of the stack and the data layers and the ways that the data is retrieved and passed along, it just keeps getting increasingly complex.

50:57and as I said I talked to a guy about data layer security but now yours is even more specific it's uh it's data layer but it's it's very granular granular is the right word yeah uh is this do you feel like this is the end of the of the development and and this will solve everything or I mean within the problem set that you're facing? I think it solves things for at least the next decade at least you know when you look where we've come from with firewalls and everything but this is this is a really big step forward we are library agnostic from a quantum you can use any library we don't care and this comes along with a new quantum library plug and play so if you do this at the data level at the granular level great word with the right post quantum encryption keys your data is going to be pretty good for quite a while right for well for decades under the NIST standard, but certainly it'll solve the issues around autonomous, around AI, all the foreseeable things we can see as much as possible in this day and age, because it's pretty hard to see over the horizon like it used to be.

52:05And certainly, yes, we'll have to evolve it very quickly, particularly when it gets into vast, all sorts of connected landscapes. We will be constantly, but we're a number of years ahead of anybody on it. So we'll have to continue to stay ahead, but we're in a pretty good scenario compared to where most people are coming from. Are the foundation model companies doing any of this on their end? No. And, you know, I've spoken to all the big ones, and they actually want companies like us because they know their big enterprise customers use multiple foundation models. Yeah. And that will only continue to get bigger and bigger, right, more specific models and content.

52:40So it's not, for example, it's not DeepMind or Anthropics job to go build this because then actually it's proprietary to them. They don't want that. They want to have services where their customers can use it And when they're pushing this data set to Anthropi, it means they use a lot, lot, lot more Anthropi tokens or over here. So we've spoken to a number of the big ones and we have their great support and they've validated that we're the only ones in the space. In fact, our partnership with NVIDIA is literally about going and solving this issue because for NVIDIA, obviously, solves a lot of problems, right?

53:12In terms of massive uptake of usage of all this forward spent infrastructure. So being agnostic to the AI service is of critical importance. Yeah. You're a relatively small company, certainly a new company. You've got to scale this to handle a lot of API calls. Yes. Are there any difficulties in that? Because it's a new platform, it's built highly efficiently with all the latest code development so that it's not heavy. I mean, literally, it can run right down at the edge on a Raspberry Pi size right up to massive cloud, hypervisor cloud. The issue for us is growing team and people quickly enough, not so much the technology.

53:59We've got to evolve the technology, but hiring people at scale and rapid is probably the biggest issue. Certainly, access to capital is not the problem when you've got a combination of AI security plus post-quantum capability and key management. and we're in defence tech as well as Enterprise. It probably ticks three of the four hottest buttons around at the moment. So that's people. And trying to see ahead, trying to look two years down the track, that's pretty hard. I've been in the game 20 years. It was easy, I think, to see five, ten years down the track. It's very difficult to see over the horizon today.

54:36And I think anybody who says they see differently, I think that's an interesting comment because we all know what's happening in AI, right? That's probably my biggest challenge. Is there anything I would cover that you want? No, I think that's fantastic. So, no, it's been really good to talk about it. And I think there's going to be more and more people talking about it, right? Because everybody's looking at the stock market to see what happens with all this future build. So solving the security issues and infrastructure issues is a big part of certainty and taking some of that risk out of AI.

55:04So it's great to have. Thank you for having me on. I really appreciate it. Yeah. No, it's been fascinating for me. I learn a lot in these conversations.

55:16you

From the publisher

Every major data breach in the last 30 years shares the same root cause: the data inside the wall was never protected, only the wall. And AI frontier models are now making that wall easier to breach than ever, scanning codebases externally to discover undisclosed vulnerabilities and write exploits before anyone knows the hole exists. Trent Telford, Chairman, CEO & Founder of Qanapi, joins Craig Smith to explain why the entire architecture of conventional cybersecurity is structurally broken, and what a genuinely different approach, built from the opposite assumption, looks like. Rather than trying to build a better wall, Qanapi starts from the baseline that the data will eventually be exposed, and encrypts it at the individual word, paragraph, or database cell level, tying each unique key to a verified identity and a set of conditional policies that must all be met simultaneously before anything can be decrypted.

The most commercially urgent application of this architecture is one that unlocks AI adoption for enterprises that have been sitting on the sidelines: Qanapi's gateway service encrypts sensitive fields before data reaches Claude, ChatGPT, or any other frontier model, and the model simply reports it cannot read the encrypted sections, while still reasoning over everything else. Trent discusses how Qanapi's Fathom tool confirmed in testing that Claude could not read the encrypted sections. He describes two major retailers - one using AI heavily, one abstaining entirely because of data security concerns - and asks the question every enterprise leader should be sitting with: how long can you last off the train before you get blitzed? The episode also covers drone security in denied wireless environments, the post-quantum encryption mandate that federal agencies have no practical plan to execute, and why Qanapi's business has exploded in the last six months as the AI gold rush has finally turned its attention from models to infrastructure.

Subscribe to Eye on A.I. for weekly conversations with the people building and deploying the future of AI.

More from Eye On A.I.

All 266 episodes
The Reason 30 Years of Cybersecurity Has Failed - and What Actually Fixes ItEye On A.I. · 55 min
Listen in VO