Agentic AI Meets Cybersecurity + Solar Robots in the Desert | E2125

13 May 2025 · 52 min

Ask about this episode

Ask anything about it. ChatGPT or Claude reads this page and answers with the times it was said.

Connect VO and ask about every podcast you hear, including the moments you saved. Add to ChatGPT · Add to Claude

In short

Podcast Episode Notes: This Week in Startups - E2125

Episode Overview In this episode titled "Agentic AI Meets Cybersecurity + Solar Robots in the Desert," hosts Alex and Jason dive into discussions with two innovative startups: ZioSec, focusing on cybersecurity for AI agents, and Terabase, which is revolutionizing solar energy deployment using mobile robotic factories.

---

Key Highlights

Introduction

  • Hosts: Jason Calacanis and Alex Wilhelm.
  • Episode Focus: Examination of frontier technologies in cybersecurity and solar energy.

Guest 1

ZioSec

  • Topic: Cybersecurity risks associated with AI agents and the need for continuous adversarial testing.
  • Founders: Aaron Walls and Andreas Ushetkas.

Key Concepts

  • Agentic AI:
  • Defined as AI agents that operate within frameworks, performing tasks autonomously (e.g., sending emails, operating local systems).
  • Importance of understanding security implications as these agents expand their roles.
  • Security Concerns:
  • Traditional testing methods may not apply due to the probabilistic nature of AI models.
  • Existing security frameworks (OWASP, MITRE) inform potential vulnerabilities in AI systems.
  • Penetration Testing Approach:
  • Emphasis on continuous testing as AI technology evolves rapidly.
  • Importance of offensive security to validate and identify vulnerabilities before they are exploited.

Future of Cybersecurity with AI

  • Predictions:
  • AI agents will proliferate in enterprises, but security must rise to meet the challenge.
  • Continuous improvement and testing of security measures will be essential.

Guest 2

Terabase

  • Topic: Automation and efficiency in solar energy deployment.
  • Founder: Matt Campbell.

Key Concepts

  • Solar Energy Growth:
  • Recent reports indicate significant growth in solar installations in the US, with 66% of new energy generation in 2024 coming from solar.
  • Terabase's Approach:
  • Developing digital and automation tools to design, build, and operate solar power plants more efficiently.
  • TerraFab: A mobile assembly line that automates the construction of solar panel fields on-site.
  • Robotics in Solar Deployment:
  • On-site prefab facilities reduce transportation costs and time.
  • Human workers remain integral, working alongside robotics for complex tasks.

Future of Solar Energy

  • Market Potential:
  • With significant capital investment, Terabase aims to scale operations and meet the growing demand for solar energy.
  • Future plans include enhancing automation and expanding to larger projects.

Concluding Thoughts

  • Both ZioSec and Terabase are positioned to address critical infrastructure needs in cybersecurity and renewable energy.
  • The conversation emphasizes the intersection of technology, security, and sustainability as vital for future growth.

---

Timestamps

  • 0:00 - Introduction to podcast
  • 0:53 - Show kickoff with Alex
  • 1:15 - Introduction of ZioSec and discussion on AI security
  • 26:55 - Introduction of Terabase and discussion on solar energy automation

---

Important Links

  • [ZioSec Website](https://ziosec.com/)
  • [Terabase Website](http://www.terabase.energy)
  • [Pilot Accounting Services](https://www.pilot.com/twist)
  • [Superpower Health Membership](http://superpower.com/twist)
  • [HubSpot for Startups](http://hubspot.com/startups)
  • [TWIST500 Newsletter](https://ticker.thisweekinstartups.com)

---

Key Takeaways

  • The integration of AI into cybersecurity presents unique challenges that require adaptive testing and security measures.
  • Solar energy deployment is evolving towards automation, which could significantly speed up the transition to renewable energy sources.
  • Companies focusing on these technologies are poised to play a crucial role in shaping the future of their respective industries.

Written by AI. May contain mistakes. Listen to the episode to check what was said.

Hear the part that matters, and keep it.Open this episode in VO. Double tap your headphones to save a moment as you listen.
Get VO free

Transcript

Automatic transcript. May contain errors.

0:00Coming up on Twist today, we're talking to some of the best founders out there in the world. AI, solar, robotic, factories, and also what happens if you take agentic AI and bring it to the world of cybersecurity. We got a lot to talk about, friends. Let's go.

0:33dot com slash twist to join and skip the waitlist. And HubSpot for startups. Smart founders aren't piecing together random tools. HubSpot is the customer platform that thousands of startups use to scale efficiently. Get up to 75 % off plus three months of perplexity AI for free. Go to HubSpot dot com slash startups. Hey, everybody, welcome back to twist. This is Alex. I have two amazing interviews for you today. The first one is with a company called Zio Set. And it touches on two things that I care a lot about. One, cybersecurity, and two, agentic AI, a term that I'm sure you've heard by now.

1:08Zeosec wants to apply the latter to help with the former. Yes, agent-driven cybersecurity. I love the idea. I love talking to them. You're going to love it too. Then, after that, Terabase, a company from the Twist 500 that wants to use robots on-site to build simply enormous solar panel fields. If you've heard us talk about AI and the enormous power demands that come with it, well, this interview touches on a lot of those themes. And it's good fun. Let's get started. I'll see you on the flip. On the show, you have heard us bang on about AI week in, week out, day in, day out. I'm sure you're very sick of it.

1:42But one thing that I'm also very excited about is AI in a cybersecurity context, or perhaps I should say cybersecurity in an AI context. The world now has digested AI models and is getting used to AI agents, deploying them across the enterprise and the consumer landscape. But what that does is open up new security issues. And there's one startup, Zeosec, that is working on agentic AI security. So I wanted to bring him on, talk to him and learn more. So please join me in welcoming Aaron Walls and Andreas Ushetkas. Hi, guys. How's it going? Hey, thanks for having us. All right. So let's start absolutely up at the top, guys.

2:17We're talking about agentic AI security. Everyone's heard the phrase AI agents or agentic AI. Perhaps we should just start with some ground level here. How does your company define that concept? AI agents are effectively an LLM that sits within a framework, right? You have a web application that connects off to different tools, and they do different things. It can be as simple as going to open up an email program and sending an email on your behalf, all the way down to operating something more local and physical within an environment, security systems, locking doors, unlocking doors based on inputs.

2:54they have far, far reaching applications. So LLMs are powerful, but LLM agents are game changing. Okay. And the reason why I think cybersecurity or security in general in an agentic AI context matters is because the thing is doing its own activities. It's executing on its own frameworks per se, but like it's still out there on its own. And that to me, from the lay person's perspective, of, Aaron, really opens up a lot of worrying security issues. Am I driving down the right road here? You're exactly right. And really what's happening is we have guardrails that are being developed by the model producers, by the hyperscalers.

3:35But really the challenge when it comes to adopting these from an enterprise standpoint, from a corporate governance standpoint, is we currently don't have very many good ways of confirming that those guardrails are working properly i'm going to try some big words here is that because ai models are inherently probabilistic instead of deterministic and therefore old tests the old methods of testing to see if something is operating as it should don't exactly apply effectively yeah and i think audress can actually go into a little bit more detail on that. Absolutely. So if you look at the models these days, they're not just models.

4:14They're not just answering your questions anymore. They're integrating with all these tools. So they have all of these new protocols coming up, like model context protocol, like MCP, that allows you basically to call all of these tools in a standard way. Now that gives the model a lot of power, and there is not much validation and security for that power. So basically, they can interact with the databases, they can interact with APIs, and that opens not just new ways of hacking into the systems, it also opens new ways to hacking into the systems using all the vulnerabilities. So you can still, if you have a model, for example, that interacts with the database, you can still use like old school vulnerabilities like SQL injection, and basically tell the model to execute the SQL injection against the actual database and get the data that way out of it.

5:03Now, when would that come up? Because when I think about AI agents, I think about someone instead of a corporation, setting something up, setting some rules for it, and putting it to work. It's not something that I thought you could do from the outside. So when I think about someone who might want to do SQL injection, I'm thinking about an external person who wants to get in there and cause mayhem. But my view of AI agents was always that they're internally sourced. So Andrews, what am I missing in this picture to make this make sense? So not all agents are internally sourced. I mean, there are a lot of offerings out there, obviously, that can call APIs to send an email, for example, like an assistant agent or something like that.

5:40So that's an interaction that happens from the public perspective. Model context protocol allows for interaction with other data and other sources of information, say, and so from them, you could have, ah, okay, I understand. Absolutely. So just MCP is basically what the model calls in order to get the data out of the actual tool. So it's just a way to talk to the actual tool. But you mentioned the private models as well. I mean, obviously, they're not exposed, but there's still an issue there. But it's, you know, local user exploit availability. So basically, somebody could still do like horizontal privilege escalations, vertical privilege escalations, and get data that they're not allowed to access to, even if they're an internal employee.

6:19okay aaron as if i understand this correctly if i'm using an ai agent and i'm using mcp which is the anthropics new framework that everyone seems to really like and people are adopting to bring in information into my ai context is there no built-in security there whatsoever it just brings stuff in and then huzzah you can the agent can use it because that seems uh even from my perspective relatively insecure it's less that there's no built-in security and more that the fact that when you are bringing this information in, your attack surface is now expanded. And there are more things, there are more links in the chain that could have a vulnerability exploited in it.

6:59So really, it's just a matter of, well, we used to have something, you know, a gen AI that was all contained. And all we really had to worry about was, can we make it give us, you know, an answer that is clean or prevented from telling us how to make a bomb. Whereas now we're really expanding out the different areas of infiltration that can happen with the advent of NCP and A2A frameworks. A2A is agent to agent. It's the recent Google standard that allows agents to talk to one another. So NCP connects to applications externally. A2A is essentially an agent to handshake as far as I can tell. Okay, so this actually now makes perfect sense to me.

7:41I was a little confused why you guys were choosing agentic AI as your focus area, but based on the last two minutes of conversation, I now really get it. I guess my silly question, Aaron, is given how much the tech service is being broadened here, why aren't we hearing more people talk about the cybersecurity risks of using AI agents? Because based on what you guys just told me, it seems like a pretty glaring issue for a product that seems to be gaining real enterprise market share and share. Right. And I think you hit something that's endemic to the cybersecurity market in general, is that a lot of the cyber defenses tend to be chasing the problem.

8:21And the development of these secure services first has not really been a thing we've done as an industry. A lot of what's going on now is we have these enterprises, the development teams who are building brilliant AI solutions and transforming the way these companies are operating. And then you have governance committees within the organization. And then the security team saying like, let's pump the brakes here and talk about like, how do you know what you have built is secure? And a lot of what the development team will say is like, well, we are utilizing AWS Bedrock. We have the right guardrails in place, or we've trained the model, or it has the correct permission sets.

9:07It's like, great. That's a great step one. But what about the 67 other potential issues that are very well documented by the company, the likes of OWASP, as well as MITRE? They have gone forward and published an incredible amount of information on where all of these holes could be. So we have this... Aaron, I'm going to just pause you into some acronyms here.

9:35OWASP is the acronym. I missed the second one. I'm not familiar with it. Can you just explain that to the folks? If you're a startup founder, you've got a million things that you're worrying about at this moment. You know what you shouldn't worry about? Your bookkeeping. Your bookkeeping should be perfect. And you should have a partner who makes sure it is so. And that partner is Pilot. It's the industry standard. Pilot is the largest accounting firm out there built for startups. They know how high the stakes are. And that's why companies like OpenAI, ScaleAI, and Airtable trust them with their books and have done so since day one.

10:10When you use Pilot, you're going to get a dedicated team for everything you're doing from booking to taxes. And now, you know, listen, if you need that CFO level guidance, they're going to give you that. So you can stay focused on what matters, building your team, building your product, and delighting your customers. You should not be stressing over spreadsheets with your P &L and all this nonsense. You want accurate financials delivered on time every time, and you want to be compliant with your taxes. You don't want any last minute surprises. And when it's time to raise your next round and you're scaling up, Pilot's CFO services team is going to help you plan and grow with confidence.

10:43Startups that use Pilot tend to raise a bigger Series B and a bigger Series C round than the average startup. Why? Because when you're buttoned up from the start, everything gets easy. Focus on your product. Let Pilot handle your bookkeeping. This week in startups, listeners get$1 ,200 off their first year. Just go to pilot.com slash twist. That's P-I-L-O-T.com slash T-W-I-S-T. Yeah. So Mitre and Mitre Atlas in particular is this new framework for establishing where the specific holes are when it comes to these agent frameworks. So MITRE has a long history of providing intelligence and attack service management to the industry.

11:31And they have this great MITRE attack framework that has been used for a good part of the past decade. They've updated with the MITRE Atlas framework, which is now focused on AI deployments. Okay. Now, Andrews, I think I now understand why we need to secure AI agents more so than we are today. Tell me why you guys have picked pen testing, offensive security, continuous testing. Why is that the right approach to this issue as opposed to a different angle to start? Well, first of all, pen test is my background. I've been doing pen testing now for 25 years. Is that why you're on Linux today and you couldn't use QuickTime like everyone else who comes on the show that is why i'm on linux yes it's much easier to do testing from linux environment than it is you know from a lot of other environments why why offensive because again validation is needed and the best validation is basically acting as an adversary so basically you're you're the hacker in that case you get into that persona and you try to break into these systems llm is advancing so much that you cannot just hire a pentester once a year that's usually you know industry standard.

12:38So if you're running like e-commerce environment or something like that, you will hire and do a manual pen test once a year. But these environments advancing so fast, you need something that can do it on a weekly basis or sometimes even daily basis. That's why continuous pen testing. And again, you know, coming from this background, we're not just aware of these new attack vectors, like, you know, prompt injection and things like that. We're also looking at all the old school stuff that we can do just through the LLM. So we're using LLM not as, you know, all in one, so to say, we're using it as a way to get into the system and see just exactly how far we can go, just like an actual attacker would do.

13:16Okay. And in most cases, when you run a pen test on a company that hasn't really worked on its agentic AI security, what do you find? Are they wide open, like a barn door to exploitation? Or is their security okay, but just needs a little extra help? It depends on the environment, but these days, we're early in this game. So we see a lot of issues like, you know, getting access to things like financial reports and financial information and getting access to the user information that you're not supposed to have and things like that. Which could be a HIPAA violation, a GDPR violation, a breach. A HIPAA violation and so on and so forth.

13:55Yes. All the bad acronyms, essentially, will come and bite you. Okay. So, Aaron, I now understand the problem. Why are you going about it this way? I'm curious about the market itself because, to me, we've been talking about AI agents industry-wide for like 18 months or so. I presume that that's a little bit late. But what I'm not clear on yet is just how far they've been rolled out inside of actual enterprise-scale customers. Basically, how much out there today is hype and how much out there is real use, driving real need for what ZioSec is working on. Well, so I think that is such an incredible question because we are at this point where the interest from the executive team is there.

14:36They're pushing the organizations to deploy. Their investors are asking, how are we adding AI to our workflows? How are we adding AI to our products? So the momentum is going, but the challenge is the security teams don't have the tools to fully evaluate and fully mitigate that risk. So they're pumping the brakes. So you see a lot of talk about this, but if you talk to the organizations and you see how many agents have you onboarded, we're talking two or three, maybe, right? We're not talking a lot. But so just to put that number into context, how many agents do you think the average, I don't know, Fortune 50 company will have in say five years?

15:20Thousands. They're going to have - They have basically zero compared to what they're going to have down the road. You got it. And it's because of these systemic issues that we're facing. The technology is new, kind of like you're saying, probabilistic models, they can get things right most of the time, right? But it's not perfect. So a lot of what we're trying to do with our testing, we're offensively testing, but we can also do things like make sure that the model is giving the same answer, or at least within the same context of an answer. And being able to report out that degree of granularity to the security team, the compliance team, and the governance teams will then empower deployment of AI throughout the enterprise.

16:00Because right now, that's the major holdback is they don't know what they don't know. And they're pulling back because the risks are huge to having an agent you don't know how it works completely have access to all of your critical internal company data. Yeah, that's what interns are for, not agents. I mean, I joke, but it sounds like a real problem. But to me, it feels like everyone who's currently trying to sell AI agents, be it Microsoft or Sierra or whomever, should be piling capital into Zeosec because if you guys can solve this issue, it could unlock an enormous explosion of adoption of agents that right now are sitting somewhere between the C-suite and actual implementation.

16:45Is that fair? Uh, that is exactly how we feel. Yes. All right. Microsoft, come on. You have a VC firm. Cut the check. No, I, my next question is what's the curve going to look like here? Clearly there are still some issues that you guys are helping to sort out, but when do we reach the actual agentic era? If you will, cause I feel like we're not quite there yet, but we've been on the cusp of it for some time here. Yeah. And I think in talking to a lot of the leaders in the industry, um, you know, the leader of Anthropic. I mean, we've got, you know, Mark Betty off at Salesforce, I mean, it's saying there's going to be over a billion agents, you know, deployed within the next, what is it, six months, 12 months, you know, I think there's a lot of expectation about this.

17:30But until we truly have those business cases that work within the enterprise, and ones that are safe to deploy, then it's going to be a matter of like solving these problems in order to get to that point. I'm guessing six months is when we're really going to start seeing the floodgates open. Andrews, do you agree with that timeline? Six months until the floodgates open and the agents come and take over our lives and ruin our ability to have jobs? I think it's optimistic. But again, this industry is moving so fast that I can't really predict at this point. I'm not even going to venture, I guess.

18:06but yeah, six months to two years. Well, that's also Fusion and a whole bunch of other things. Okay, so we mentioned MCP from Anthropic. We've talked about A2A from Google. You guys wrote a post digging into kind of multi-agent systems. And to me, like there's gonna come a time in which the idea of an agent that does multiple things probably gets collapsed into chains of agents. Does that make the security issue simpler or more complicated? Yeah. way more complicated because now these agents basically interact with each other and you know they can talk to each other and extract information from each other so it's not just testing one agent at that point you're basically testing an entire environment so to say entire infrastructure right and so that's where the idea of pen testing in an agentic context to me andrews doesn't seem to be as effective because if you have so many agents constantly talking is penetration testing the the right way to go about it?

19:06Or maybe I'm asking, what's the next step in securing agentic AI past pen testing? Because it doesn't seem to cover every single problem that I could invent in my head that you might want to solve. Yeah, but usually pen testing is not limited to single application. Usually when you hire a pen tester, they will test an entire environment. They will even go to like LinkedIn and get the profiles and see what they can hack into, who they can send spam emails to or phishing emails and get information that way. it's the entire like holistic testing and that's how the agent testing is going to become as well so eventually depend testing is not going to be this simple single agentic ai it's going to be an entire environment that you're going to be testing at the same time okay founders it's all about efficiency and performance in your startup but what about you what about optimizing yourself when's the last time you got in there and said how could i be better stronger faster sleep better diet, exercise, mentally, all of that stuff gets skipped until now because there is a new product that I'm using called SuperPower.

20:11It's the ultimate health membership, specifically designed for founders, but anybody can use it. It's built to keep high performers at peak performance. You get full body testing across 100 plus biomarkers. This is your organ health, your hormones, inflammation, and it gives you actionable data and clear insights. You track all of your KPIs in your startup, why not track these for yourself with Superpower? Visit superpower.com slash twist to claim your spot and unlock peak health today. I can't say enough about self-directed healthcare, which I believe this is the foundation of. I've used a bunch of other services, and this is the best one I've ever used.

20:50Better health equals better founder. It's that simple, which equals better business. Again, superpower.com slash twist. How long until we have AI agents doing pen testing for other AI agents? And I'm not being facetious, I'm actually curious. Right now, so our solution is based on AI testing AI. It's not just one-off prompts, basically. It can interrogate the other AI. So we can basically tell our system, you have 10 turns and you have to extract this information from the other AI. And it's our model doing that extraction. So you guys are literally like the AI police? yeah i guess it's a really interesting paradigm that we're moving into because you know police are for bad actors and ai itself can be trained to be bad actor or just the negligence of an ai can have bad actor tendencies so we need to do the discovery of these tendencies and provide visibility into the org where it's needed the most and give them the ability to say like this you know exposure here like yeah maybe they didn't get the answer right all the time or whatnot but that's okay because it's customer service and we're only going to be getting 70 of those right anyways even with humans so right so it totally depended on the application whereas let's say you're now dealing with loan processing and applications, totally different set of requirements.

22:22So I think, you know, saying like, we're policing this is a really interesting way. But these agents are, I think the right way to think about agents is they should be treated much like humans in the organization. They are unpredictable, much the same way humans can be unpredictable. But they are given jobs, and they need to be evaluated on the work that they're doing. And I think that's where we can play a critical role. Talk to me about the future, though. I think I have a reasonable grip on pen testing in this context, but what's next for the company? Well, I think the most interesting piece of this is the company where we're going now, the people who understand this problem are on the security side of the equation.

23:03That's their job. That's what they've always been there for. That's their function in the company is to secure the assets of the organization. Where I view us going is if we can expand that purview into the engineering side of the world too, and allow the engineers to understand that code is not innately secure, it's your job to secure this code. And being able to lever a lot of these vibe coding assistants, you know, which are phenomenally powerful tools, the code that they're producing, not necessarily the most secure code. And that's not any fault of the vibe coder or of the engineer. It's just, you're taking again, probabilistic, you took the average of 10 years of stack overflow, and that's what we're getting.

23:56So now, where we have this code that's being generated and we're not able to confirm out of the gate is this stuff secure so i i really see us moving in the direction of fitting within that model of code being produced by ai and then checked by ai as well but from an offensive perspective okay well that sounds very exciting sounds like a future that's both very fast, very flexible, and also secure. And that would be lovely because currently I feel like development isn't any of those things. So that sounds like a much better future. All right. Last question before we go is just how are you guys doing on landing first customers going out to the market?

24:40How are those conversations going when the rubber meets the actual enterprise road? It's going great, right? So we have, we've had a lot of really great conversations with design partners, as well as companies that are really just starting to get a sense of the new landscape. And we've been able to identify certain companies that style, right? Who is our ICP? And they tend to skew larger, they tend to skew towards finance, They tend to skew towards those critical regulatory environments because that's the kind of company that truly understands that the problem is there and they have to deal with it because they've been working in these frameworks forever.

25:28And we're also partnering with a couple of hyperscalers, which is incredibly exciting. And being able to offer innately our services if you are, you know, signed up with this particular hyperscaler. Well, there's only so many. There are only so many, but that's... Blink twice if it's Azure, blink three times if it's Google, or four times if it's AWS. No, no blinks at all. All right, fine. Well, actually, I was just thinking that it'd be a really smooth way to sell this if you had a partner like Sierra, which builds AI agents and just kind of work with them as like a preferred, essentially, software vendor.

26:07And then you could probably just grow alongside some of these other companies that are doing well. But I think going the hyperscaler routes even better than that. All right. The website is ziosec.com. Just before we go, what is a role you guys are hiring for where you desperately want that excellent candidate? Andres, you want to take it? Yeah. So at this point, we're looking for security analysts, especially, you know, ones that have been doing band testing in this space. There are not many of them. So those kinds of people that we need. We're also looking for a couple of full stack engineers, particularly with the expertise in Rust and TypeScript on the front end.

26:43All right. Well, guys, thank you very much. When you have those first couple of enterprise customers, please come back and tell me all about them and we can wrap on about business models. But in the meantime, good luck. And here's to our agentic future. Thank you. Thank you. I hope you're ready for us to stop saying AI every third word for the back half of this show. But if you're curious about where all those GPUs are going to get their juice, well, look up to the sky and then say the word harabase out loud let's go if you are a long-time listener of the show you have heard jason and i bang on ad nauseum about ai and the enormous enormous energy inputs that doing all that number crunching is going to take now some people think we need to bring back nuclear cool by me some people think that fusion is closer to a commercial viability than other people do cool but one thing we do have today is a whole lot of sunlight and we have amazing technology, we as humans, to capture that energy and turn it into juice.

27:36Juice that can power data centers, homes, whatever you want to call it. Now, we all know this exists. Why isn't it everywhere? Well, there are some labor issues, some supply issues, but there's one company called Terabase that is doing excellent work to try to bring mass-scale solar to the world using automation out there in the field. I wanted to learn more. I added them to the Twist 500, so please join me in welcoming Matt Campbell from Terabase. Matt, hey, how you doing? great how you doing i'm i'm doing pretty good because when i was prepping for our chat today i was surprised at just the scale of progress in installing solar power in the united states the the narrative out there is that it's all happening in china and that we are infinitely far behind but according to the solar energy industry association 2024 report we installed 50 gigawatts here in the united states of solar power last year which is more than i expected and And I thought rather encouraging.

28:28So from a high level perspective, are we doing okay at overall solar install here in the States? Fantastic. Yeah. I mean, I think like you said, 2024 was a banner year. I forget the exact stat, but it's like more than 80 % of the new generation in the US was solar. 66%. Oh, 66. Okay. But still, I mean, it's a huge percentage of the new energy coming online. And I think it bodes well for what's ahead. so terabase is a company that melds uh software both for planning and operations and then in the middle there is an element called terra fab that helps you guys as far as i can tell construct solar panels out in the field for folks who are not familiar with terabase can you just walk me through the product mix really quick sure yeah so terabase is focused on and let me just start explaining the utility scale solar market so these are good point yes giant solar power plants out in remote areas that span thousands or tens of thousands of acres um and so 100 megawatt to multi-gigawatt type sites and so what we do at terabase is we build um digital and automation tools to design build and operate these giant projects more efficiently so there's three parts to this there's the engineering work that goes in before boots are on the ground then there's the construction element of this which is terra fab which i want to start with and then at the there's stuff to help run the solar farms.

Read the full transcript

29:55So it does seem kind of like a vertically integrated company. Is that a fair estimation? All right. Everyone knows that CRM isn't just software. It's basically the heartbeat of your business, but it can get ugly quick if your data isn't organized and you're dealing with a messy tech stack. That's why I love HubSpot for startups. It's the all-in-one customer platform. So you don't need a Franken-sight of tools. No, right now, early stage companies are going to get 75 % off. And with this one system, you're going to automate marketing that actually converts, track your sales pipeline without spreadsheet chaos.

30:34And you're going to manage your customers like the Amman Hotel, six stars all the way. You're going to get investor ready analytics that tell your story perfectly. And man, when you pull up HubSpot and you got those metrics, you got those analytics, things are going to go really faster for you as a startup with potential investors. Plus, you're plugged into an amazing community of founders who've already tackled what's ahead. They've been around those sharp turns and they can tell you how to navigate them. HubSpot was built by scrappy founders. I know them and they understand every dollar counts.

31:05That's why hundreds, thousands of startups trust HubSpot to scale their businesses. Here's an amazing call to action. So generous from my friends at HubSpot, 75 % off. That's right. 7, 5. Not 7 % off. Not 5 % off. 75 % off HubSpot for startups. You're going to get three months of perplexity AI for free. That's a great pot sweetener. Head to HubSpot.com slash startups. Yeah. It's sort of like a synthetic vertical integration through a software platform. Yeah. Synthetic. Why synthetic? Just because it's digital? Well, because a true vertical integration, you would actually be the developer and the contractor and the operator.

31:47And it's just the software is doing those functions, but we ourselves aren't playing those roles in the value chain. Okay, so back in late 2023, you guys were talking about the successful completion of your first commercial TerraFab project. That was, I believe, 17 megawatts, so a portion of a larger project. And then in late 2024, you wrote on LinkedIn that you were wrapping up your latest TerraFab project. So I'm really curious, how many projects has TerraBase been involved with that have used kind of its soup to nuts software planning through construction through operation software size project?

32:23Yeah, yeah. So we've been involved in dozens of projects around the world. And then, as you mentioned, like the big thing called TerraFab, which is the system which robotically automates the construction. So we've completed three of those projects uh today actually we started our fourth uh so um good good coincidence with this chat uh and then uh in two weeks we'll start our fifth project so um and we're kind of at this point of graduating from sort of mid-scale commercial pilots to be like sort of large scale um deployments you know and sort of the hundreds of megawatts is that why you guys raised the very large$130 million round from Vision Fund 2 in March because you're moving from the pilot-ish stage to the kind of enormous project stage.

33:14And so more capital, more capacity is just useful for this stage of the business. Exactly. Yeah. I know that capital is really to help fund the growth inflection for the company, but also to accelerate our investments in robotics, software, AI, and really, you know, how can we, because the market is there, the need is there, the value is there, but we want to go faster. And so with more capital, we're able to do that. All right, let's talk about TerraFab, because I've seen drone clips of this, and we're going to play one in just a minute. But I think it might help people if you just explain what kind of in situ or on-site manufacturing you're doing with this process and kind of what you bring on to site and then what you put together for actual installation?

34:00Basically, the problem statement is we want to find a way to automate construction of solar plants. Now, no construction industry has really been automated yet, right? Like this is Greenfield. And the nice thing about solar is it tends to be a very repetitive type of install, you know, row after row after row after row. And so it kind of lends itself to more of an industrial automation approach to construction. Now, there's a lot of ways you could imagine to do the automation with, you know, humanoid robots or other types of robotics. But the approach that we've chosen is an on-site prefab facility.

34:39So, if you're familiar with prefab as a concept, it's like pre-assembling things to enable rapid deployment. And in our analysis, we concluded that doing an on-site prefab facility called TerraFab was the way to affect automation as opposed to off-site because these projects are super remote. So if you prefab off-site, you'll have too many trucks going out to the site. Okay. Tell me about remoteness here because I was in Boy Scouts. I've been out in the sticks, but I'm curious, how far off the beaten path are we talking about when you say remote? Because that could be two miles out of town or that could be 500 miles out of town i'm not sure the scale here well well first you head out to the sticks and then you keep going for another six hours got it okay so pretty remote generally you know because that's where you find the big pieces of land and the sun and um so so generally you know at least a couple hours from a major city but sometimes it could be even days from a major city before we get back to the prefab point, I have a question about transference of electricity, because I read back in the day that taking a lot of juice and throwing it through copper cables over a long distance is lossy, that you lose some of the power generation.

35:54I've also read that that's gotten better. So I'm kind of curious, if you are 5, 6, 10, 12 hours out of a city by car, and the power needs to get to a, let's just say, major urban center, how much do you lose in transference? Yeah, it depends, but it's not as much as you might think. I mean, it could be 6%, 8%, 9%. Again, it's a function of distance and voltage. And there's already transmission in general is a constraint on the industry, but there's a lot of examples. There's a high voltage line that goes from Arizona to California, and it passes through a lot of desert where you can do solar. So those pathways exist.

36:34And of course, we need more of that capacity the more solar we want to do got it okay back to prefab uh your point is that if you do the prefab on site you limit the total number of trucks that are coming in i presume because that's the parts you're going to assemble on site are much more compact uh before they're put together exactly exactly so so what we do is we come to the site we have a pop-up factory so you know think of it as a 200 foot long assembly line you can set it up in four hours um it's um it it could produce a megawatt in eight hours so of course in the solar business we have everything's a megawatt or a kilowatt or a gigawatt or a terawatt um and so um so that's our unit of production and and then you build a section of the plant and then you pick it up and you move it and you build the next section and and um and you sort of go around until the farm is completed oh so you actually move the terra fab facility itself you don't just plop it in one place and then export oh okay i guess if you're doing as you said earlier acres of coverage you want to reduce the amount of travel time after prefab okay now once terabase has taken in uh materials and components and done the prefab you're still using humans to take those solar panel arrays and installing them because after your first um terrified project you said that you guys quote demonstrated labor productivity improvements of 25%.

38:03And so I read that as humans still in the loop, but just more efficient. Is that correct? That's right. Yeah. Yeah. And I think in the field of automating construction, humans are going to be in the loop for a very long time. And so humans and robots and machines have to work together. But yeah, definitely there's a lot of tasks that humans are best suited for, especially fine motor activities and other things. So it's a combination of our robotics along with workers. So my question about your overall goal is, is the goal of TerraBase to speed up the pace at which we can build out domestic solar capacity, or is it to lower the costs thereof?

38:46Because I feel like you could make the argument either way for what kind of the North Star is for the business. But I'm curious from your end, what gets you out of bed in the morning when it comes to improving our kind of grid health via more solar? Yeah, I mean, I think it's speed is certainly critical. Like the world needs to build more solar faster. And labor is a constraint everywhere. It doesn't matter if you're in, even in India, where you think there'd be no labor constraint, there are labor constraints, especially at the scale, you know, the name of the company is Terra, like Terawatt.

39:16At the Terawatt scale, you really think about these scaling limits that you run into and people is a big part of it. So faster is certainly one thing. Cost is always center. Quality is a big thing. We're building assets that need to operate with little maintenance for 40 or 50 years. So you want to build them with the highest possible quality so that they last. 40 or 50 years is a much longer timeframe than I would think we would have for in the field solar installs. And this may just be my sectoral ignorance speaking out, But when I think about things left outside after five years, they tend to look a little worn.

39:54And after 15, I mean, my Lord, 50, what about hail? What about dust? I mean, it seems like solar would struggle to last for that many decades. So what am I missing here, Matt? Well, I mean, most power plants, whether it's a hydro like Hoover Dam or a coal plant, most of them are operated for decades, three decades, even the nuclear power plants. I mean, so there's no like intrinsic reason it can't last long. I mean, you have to think about things like UV degradation, but like steel and concrete and cables, they last a long time. And then the panel has to just be engineered for that duration. And so I think, you know, a 30-year life for the panel, 34 years, totally realistic.

40:38Probably what's going to happen in practice is the panels will be replaced. Because in 20 years, there'll be a panel that's twice as good and half the cost. And you just go in and you swap out the panels. But once you've done all the work to set up the actual, I call them solar farms. I think you're calling them solar power plants. Potato. Yeah. You can take off the cells and replace them and you can leave the underlying foundations in place. Okay. Yeah. Like Hoover Dam, the turbines generating electricity, you know, have been replaced multiple times with more modern, more efficient. But the concrete dam is the same.

41:17I mean, I hope so. No one told me they replaced it. On the point you just made about solar getting better and the pace at which we've seen improvements in efficiency in terms of capturing what share of the solar rays that are coming down and converting them into power, it's been insane to watch the cost curve of the solar industry. I guess maybe the question is how much more efficiency is there to be squeezed out of actual solar cells in the next five or 10 years? Is it going to continue to be impressive or have we reached a point in which improvements are going to be a little bit more incremental?

41:51You know, for the current generation of technology, we're definitely at the point of incrementalism. You know, the cost is extremely low in most countries. and the performance for silicon, which is the predominant type of solar cell, is at the limit of kind of what you can achieve. There are some next-gen semiconductor compounds. There's a whole family called perovskites that would, you know, today we're at like 22 % efficiency. So you convert 22 % of the sun's energy into electricity. Clearly, you know, we can get to 35%, 40%. That takes a step change. Now, how long that will take is a question.

42:34I would guess it's going to be about 10 years to get there. That's not bad. Yeah, no, it's not bad. From 22 % to 40 % in 10 years? My lord, that's crazy good, actually, now that I think about it. That would make solar even... I mean, everyone, I think, believes that thermal power production via burning coal is going to eventually fade away. And I think a great way to do that would be doubling the efficiency of solar panels. I mean, that would be crazy. Okay, well, that all feels pretty good. I presume that for your future terawatt installs of solar, there's going to be a storage component to it.

43:11But when I was just going through kind of all the terabase products and history, I didn't really see a lot about storage. And so I'm kind of curious, do you guys team up with other companies to handle the storage site? Is that always done by the customer themselves and so not your business? How does that play into your planning and processing? yeah i mean we definitely work closely with the storage companies and we're building some software that that manages the interaction between the solar farm and the grid and charging the batteries so sort of the sort of the control level system i mean storage at this point is i mean in a way it's a prefab system so these they show up in these containers and it's sort of plug and play so it's like minimal work that's required on site the stack here is going to be exciting because you guys have software to help design solar power plants you have software terrain pro to help people sort out how to actually set them up on hills and so forth actually if you have a second you're watching this you're listening to it look up terabase and look up their software for terrain pro it's the graphics are pretty cool uh then you have construction and then you also have stuff to help run it if other people have plug and play storage it really does feel like the the barrier to building out a solar power plant is just capital in time now but there's no like tech risk or vendor risk it feels solved in a really positive way is that is that fair matt yeah no i mean solar is super well established i mean um you know globally the market last year was i mean we don't have a precise number yet but it's probably about five six hundred gigawatt um i mean that's it which is unbelievable i mean when i started in the industry it was a gigawatt a year oh okay that helps a lot of me explain the differential i was just my face and disappointment there was realizing that our all-time record-breaking year brought us up to less than 10 percent of the the global total last year this is an unfair question but i have you here so why not what percentage of that should we be targeting like 25 i mean clearly we're a big nation we have a lot of places that have a lot of sun so to me i feel like there's no reason why we shouldn't be at the absolute tip of the spear when it comes to solar installation at the national level.

45:24Yeah, I mean, I think that the US should get to the point of doing a couple hundred gigs a year. Now, a couple things have to happen because I think within the existing sort of framework, 50, 60 gigs is probably about the right number. And when I say existing framework, I mean, the existing transmission system, building solar projects, most of which now include batteries and connected to the grid in Texas or California, Arizona or wherever. But the future, and this is sort of where there's an interesting convergence with data centers, which is in the future, we can get off the grid. It's actually, it's an interesting because solar started as an off the grid thing, like people would use it in remote areas to get power.

46:11um and and we see it going for full circle because at the point that you've got other forms of backup in the form of batteries or maybe some gas backup or something you can pull the plug and you could all you need into the data center is a fiber optic cable and you don't need to connect yourself to the electrical system and at that point there's no constraint i could build five gigs i could build 10 gigs um so there's an interesting and we see this all over the world where people are looking at getting to the point of cutting the cord and doing multi-gigawatt systems on a standalone basis. We call it an island basis.

46:45That's awesome. But just because I have no idea the answer to this, what would that cost? Let's say that I wanted to do, I don't know, a one gigawatt install as an island to use your parlance. How much capital? So in the United States, if it was just solar, it's about a dollar a watt. So a gigawatt is about a billion bucks. Now, if you go to other parts of the world, it's a lot cheaper. So there was a project announced in January this year in the UAE. This is a really important one to track. So this one has got 5.2 gigawatts of solar. It has a 19 gigawatt hour battery, which is gigantic. And then it has one gigawatt of 24-7 solar as the output so so basically the math is you've you've built five times as much solar as you need and you put a big battery so that you can charge the the battery and then at night and then you get 24 7 power and the total cost of that project is about six i think it's about six billion okay um but if you compare that if i built a one gigawatt 24 7 nuclear power plant you know best case would probably be 15 or 20 billion so and 15 or 20 years if we're lucky 20 years i mean you could build this in a year i mean it's you know the economics are there and then part of the gap that we see is the the construction part of the deployment is stubbornly expensive which is why we want to apply digital and automation because you say well to really unleash the potential i want to cut the cost in half again yeah is that what terra fab v2 is going to be?

48:27Does it increase throughput, make things more efficient, and introduce cost savings? Yeah. Yeah. So our next-gen TerraFab that's coming out this summer, it's going to be a fully automated system. It's going to be twice the speed as the current generation. It's going to have a lot of other unique capabilities. And it's really kind of setting the foundation to get to this lower-cost, faster deployment world. I kind of think of SpaceX is sort of an inspiration for me where, you know, they had to start by building a rocket to get to orbit. And then they got to a reusable rocket. And then they could launch Starlink.

49:07And then they could... Eventually, they'll get to Mars, right? So, you know, we know where Mars is for the solar industry. But to get to Mars, we've got to do like 100 things. And so, part of that is getting the automation with the TerraFab V2 and then building in more automation and more software and more AI to get to this sort of entitled future state. We've talked a lot about growth, bigger projects, more TerraFab, TerraFab V2, that huge$130 million round. How much is the company going to grow this year, do you hope? And then also, can I put you on the 2026 IPO calendar?

49:49Well, 2026 might be a little soon, but... Okay. 2027. All right. Don't worry. You know, I was fortunate to ring the bell on NASDAQ when SunPower went public a long time ago. And, you know, we hope to get there someday. So, you know, right now we're just focused on building an awesome tech platform and a great business. You know, and we're also, I should say, active globally. So U.S. is an important market, but Australia, Europe, other, you know, Middle East, those are markets. we're kind of at that classical inflection point um as as most tech companies go through it's like 100 growth this year what's the target oh oh i'm sorry uh yeah yeah we'll double year over year yeah okay and if folks want to learn more terabase.energy and we ask every founder the following question what's a role you're having a hard time hiring for just we can shout that out into the ether and maybe it'll bounce back we're always looking for awesome uh programmers and roboticists.

50:48So, and we've got lots of openings. And if you want to help secure essentially a less carbon full future, go check out terabase dot energy. I think this company rocks. Let's light up the planet. Thanks, Matt. Thanks. I've been doing this job for roughly 10 ,000 years and it never, ever, ever, ever gets boring talking to founders. Every single time I do it, I leave with more energy than I came in. It's just an absolute treat, especially when I get to talk to people building such cool stuff. So shout out to both the companies today. And if you are excited about more interviews like this, well, just go to twist500.com where you'll find a list of more than 300 of what we think are the best companies in the world.

51:27More interviews coming. We're taping all the time. So expect more goodies in your feed soon. This is Alex. This is Twist. I think you're the best and we'll talk to you soon. Bye.

From the publisher

Today’s show: Alex interviews founders from two frontier technologies reshaping our world. First, ZioSec is tackling the cybersecurity risks of AI agents with continuous adversarial testing before real attacks happen. Then, Terabase shows how mobile robotic factories are transforming solar energy deployment, assembling massive solar farms directly in the desert. With AI scaling across enterprises and clean energy demand surging, these startups are building critical infrastructure for our future.


Timestamps:

(0:00) Introduction to the episode(0:53) Show Kickoff with Alex(1:15) ZioSec is Putting Agentic AI in Charge of Cybersecurity(9:41) Pilot - Visit https://www.pilot.com/twist and get $1,200 off your first year.(11:07)How Complex is ZioZec’s Testing?(19:48) Superpower - The best founders know: better health = better business. Visit http://superpower.com/twist to skip the waitlist.(21:01) ZioSec’s Vision for the Future(26:55) Terabase Wants to Transform How Solar is Built(30:00) Hubspot for Startups - Visit hubspot.com/startups and join the founders who are turning growth challenges into opportunities.(31:30) Is Solar Our AI Power Problem Savior?


Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com

Check out the TWIST500: https://www.twist500.com

Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp


Links from episode:

Check out ZioSec: https://ziosec.com/

Check out Terabase: http://www.terabase.energy


Follow Aaron:

LinkedIn: https://www.linkedin.com/in/aaron-walls/

X: https://x.com/aaron0walls


Follow Andruis:

LinkedIn: https://www.linkedin.com/in/auseckas/


Follow Terabase:X: https://x.com/terabaseenergy?lang=en


Follow Lon:

X: https://x.com/lons


Follow Alex:

X: https://x.com/alex

LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm


Follow Jason:

X: https://twitter.com/Jason

LinkedIn: https://www.linkedin.com/in/jasoncalacanis


Thank you to our partners:

(9:41) Pilot - Visit https://www.pilot.com/twist and get $1,200 off your first year.

(19:48) Superpower - The best founders know: better health = better business. Visit http://superpower.com/twist to skip the waitlist.

(30:00) Hubspot for Startups - Visit hubspot.com/startups and join the founders who are turning growth challenges into opportunities.


Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland


Check out Jason’s suite of newsletters: https://substack.com/@calacanis


Follow TWiST:

Twitter: https://twitter.com/TWiStartups

YouTube: https://www.youtube.com/thisweekin

Instagram: https://www.instagram.com/thisweekinstartups

TikTok: https://www.tiktok.com/@thisweekinstartups

Substack: https://twistartups.substack.com


Subscribe to the Founder University Podcast: https://www.youtube.com/@founderuniversity1916

More from This Week in Startups

All 653 episodes
Agentic AI Meets Cybersecurity + Solar Robots in the DesertThis Week in Startups · 52 min
Listen in VO