In short
Int’s on-device “endpoint agent” uses AI embeddings and corporate policy context to detect risky or unsanctioned actions (including human clicks and agent behavior) and stop them in sub-second time, shifting security from reactive to preventive. It also provides “work observability” for security teams and potential downstream productivity/process insights.
Guest
Brandon Dixon, co-founder and CTO of Int (formerly at Microsoft). Focuses on endpoint security, policy enforcement, and AI risk reduction for enterprises.
Key claims
Most breaches come from human mistakes; AI increases new risks. Int starts with baselines and policy (e.g., allowed/sanctioned software) to flag violations, then learns normal behavior by user/department/cohort. Embedding models run on CPUs for fast decisions; architecture can run on endpoint or backend for data sovereignty.
Notable examples
Unsanctioned AI tools; citizen developers deleting artifacts or leaking sensitive context; developers running many agents; stopping risky actions before they occur.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOIntroduction of Guest Brandon Dixon
0:57 to 2:20
Host introduces Brandon Dixon, co-founder and CTO of Int, discussing the startup's focus on AI in cybersecurity.
“How is that possible, given that we've already gone deep into like the Silmarillion to find startup names?”
Exploring Int's AI Tool
2:48 to 4:52
Discussion on Int's on-device agent for endpoint security and its significance.
“Like, um, you know, when my co-founder and I formed and like the, the thesis to this was that we've largely given up, uh, prevention inside of security, right?”
The Role of Human Behavior in Cybersecurity
4:52 to 6:14
Brandon explains how human mistakes lead to security breaches and the need for proactive measures.
“I think it really depends on the maturity of organizations.”
Understanding Corporate Policies and Context
6:14 to 8:05
Discussion on how Int understands corporate policies to prevent violations in real time.
“Well, that's really interesting to me because it's a bit broader than I thought.”
The Architecture of Int's System
8:05 to 9:49
Brandon describes the flexible architecture of Int's system and its operational capabilities.
“I think the big advantage that, you know, or what makes this possible today and why it wasn't possible, you know, a couple of years ago is the advantage that we have in things like embeddings.”
Performance and User Experience
11:31 to 14:00
Brandon discusses the performance of Int's system and its impact on user workflows.
“So cost, you know, not everything requires like the most, you know, the greatest model or the frontier model.”
AI and Corporate Policy: Observability and Intervention
14:00 to 20:20
Learn how AI can enhance corporate policy enforcement and observability.
“I don't want to run, you know, and like, you know, prompt them in some form unless I have information from the company.”
Employee Monitoring: Balancing Privacy and Productivity
21:10 to 26:32
Explore the implications of employee monitoring and how to balance privacy with productivity.
“I would say, you know, lineage and substrate are a bit too technical.”
Business Strategy: SaaS vs Self-Hosting
26:32 to 28:00
Understand the business rationale behind offering both SaaS and self-hosted solutions.
“Let's talk really quickly some business questions.”
Understanding the Funding Landscape
28:00 to 31:15
Learn about the reasons behind raising significant capital in tech startups.
“Yes, there's a licensing cost associated with the product.”
Show all 12 chapters
Market Reaction to Product Launch
31:25 to 34:15
Explore the market response following a startup's product launch from stealth.
“Given how many different endpoints, clouds, and services you have to make work to have this actually function at the speed you need it to, I'm never going to listen to a developer again.”
Innovations in Video Generation AI
34:15 to 42:00
Dive into advancements in AI for creating high-quality videos with ease.
“He had Clara, the open claw AI girlfriend.”
Transcript
Automatic transcript. May contain errors.0:00Hello and welcome back to Twist. This is Alex and right now AI and cybersecurity are hot topics because the leading frontier models are increasingly capable of finding and exploiting software vulnerabilities. Precisely how to harden global software is an open question that we're all working on resolving. But there are startups working in the AI and cybersecurity domains that are not trying to build the next hacking tool. One startup fresh out of stealth has a novel approach to securing human action inside of corporations using AI that could help prevent the breaches of the world. of tomorrow. So please join me in welcoming to the show.
0:32It's Brandon Dixon, the co-founder and CTO of Int. This Week in Startups is brought to you by YSecurity, the on-demand security team for startups. Need enterprise-grade security without hiring a$400 ,000 CISO? YSecurity gives you 40-plus expert engineers matched to exactly what you need by the hour with your first six hours completely free. Go to ysecurity.io slash twist. Superhuman. Get the AI that works where you work find out more at superhuman.com and vanta compliance and security shouldn't be a deal breaker for startups to win new business vanta makes it easy for companies to get a sock to report fast get one thousand dollars off for a limited time at vanta.com slash twist brandon how are you doing i am doing phenomenal trying to stay cool in this uh hot weather in virginia right now it's bad up here i can't imagine how bad it is down in the sticky south But before we get into anything important, I'm shocked that after all the mining we have done on Lord of the Rings Arcana, Ent was not taken yet.
1:34How is that possible, given that we've already gone deep into like the Silmarillion to find startup names? You know, I think it's just a happy coincidence. Like when we were building out the company brand and the name, we were thinking of, you know, Enterprise as like kind of our core customer that we're going after. and so like and like security for the enterprise uh was kind of the approach there and then of course being more technically inclined people there was a little bit of a nod to the to the kind of lord of the rings uh trees and the protection and as we were building out that brand it was important to me at least like i don't like the hoodies and hacker depiction of like you know the the the bad guys i i like i like being outside i like doing those sorts of things.
2:17And I wanted to try and carry that through in the brand as well. Yeah, well, it works out well. It's very memorable. It was not hard to recall who I was talking to today. Now let's dig into what you built, because I don't think people are going to be as familiar with this tool, but to give people a quick summary from what I understand, you have built a on-device agent for endpoints. So, you know, laptops, phones, and so forth that can essentially tell when someone's going to do something they shouldn't do, or maybe risky and then stop them. Now tell me what I got wrong and break it down for me why we need this.
2:47I'm really curious. No, I mean, no, that's effectively it. Like, um, you know, when my co-founder and I formed and like the, the thesis to this was that we've largely given up, uh, prevention inside of security, right? We're very reactive. We wait for the bad thing to occur. We have the requisite information to troubleshoot, but it felt like there was, we were just accepting that the adversary was going to compromise the, the infrastructure. And a lot of the breaches occur because people are well inclined trying to do their jobs, but they make a mistake. And so when we were looking at the current AI advances with some of these reasoning models and the ability to scale up understanding words and representing that in dimensional ways, we wanted to apply that directly to where people worked.
3:34So we wanted to meet them in that moment, look at the work that was taking place, and then make an assessment as to whether or not they were going to violate corporate policy or do something they shouldn't and effectively stop that from happening. So why do we need it now? Well, unfortunately, like breaches still occur from humans, right? Like people click things. They want to do the job. If they were otherwise security experts, we wouldn't be dealing with breaches, right? Everybody would do the right thing. But on top of that, we do have AI in the mix and it's a new technology and it just brings new risks.
4:07So we believe that having that level of reasoning and capability at the end point is an important advancement in the future. I want to get to the end point point and talk about models and such in a second. But the idea that people are doing more thanks to AI really resonates with me. Because up until when I had, I mean, frankly, OpenClaw codex and CloudCode, I was not messing around in PowerShell or with the CLI. And now I'm doing all sorts of insane things with my computers that I'm absolutely not qualified to do. But that's the homebrew side of this. So take me inside a corporation that's rolling out AI tools that give job functions more capacity, capability than they would have had before and are now seeing these problems.
4:51I'm curious about how it manifests and which jobs are really pushing the envelope, if you will, and getting into trouble. I think it really depends on the maturity of organizations. So a lot of the people that we're working with are obviously adopting AI. They're kind of all in and they're looking to retool processes. I've heard the term and I kind of like it, citizen developers. So we run into those people, ones that don't have a technical background, who are being encouraged by their leadership to solve problems with AI and accelerate their workflows. And in that case, they run the risk of deleting artifacts off their system, pulling in context that might be sensitive, and then accidentally leaking it outside of the corporation.
5:35On the flip side, you have your developers who, of course, are trying to take advantage of new technology. And in that case, they might have 20 different agents running to go and perform various roles across the enterprise. And there, the same risks take place as well. But it's not even just innately tied to AI, right? Like there's still just mistakes that people do by accidentally sending an email with the financial information to the wrong person, right? Or sharing credentials across chat ecosystems that otherwise could lead to a compromise. So we see both sides of the house. We still look at the user behavior and we look at how they're working with agents and then we look at the agent behavior as well.
6:20Well, that's really interesting to me because it's a bit broader than I thought. How can you have enough context about a company, its individual job functions, what they are allowed and not allowed to do from the corporate perspective to determine in real time if person X with job Y in group Z, responsibility Q, is doing something that is suspect? Because to me, that implies a level of specificity that's almost crazy. So I'm impressed that you managed to figure it out. How? So for us, the setup of the product itself is predicated on getting a corporate policy or getting something as simple as what is the sanction software that you use across the enterprise.
7:00And you'd be surprised with that little bit of information and understanding the context that we're collecting. I can guarantee that there are policy violations that are occurring across the company. So people come to us and they say, look, I'm not going to restrict AI usage. I'm going to let it happen. But now my concern is I can't keep up with all the AI tools that are coming out. And I've given people access to use these tools, but I don't know how they're using them. So right away, if I understand what the allowed software is, I can immediately tell you people that are using other software, be it AI, remote access, or something else that is not sanctioned for them.
7:40So that's our one sort of output for us. And then over time, Ant basically understands the operating aspects of the business because we're constantly forming baselines of what's normal for that user, what's normal for that department, what's normal for their cohorts. And that allows us to essentially start to put the policy to use on the endpoint itself and stop bad things from happening. So we don't really require a lot of information. I think the big advantage that, you know, or what makes this possible today and why it wasn't possible, you know, a couple of years ago is the advantage that we have in things like embeddings.
8:19The ability to take semantic words like things that we understand have meaning and translate them into something that a computer can understand and make decisions on top of. You're talking about vector databases and tensors more broadly. Sure. Yes. Yeah, I mean, in its essence, it's basically, you know, words have meanings. We know how to interpret those. But it's been difficult to represent a lot of dimensionality for computers to understand. But now, because we have these large language models, as part of what makes them work really well is that extreme amount of dimensionality, right? That they understand when these words are put together, they have a more specific meaning than maybe when they're split apart from each other.
9:05And so that was an advantage that we were able to take within building the product, and that serves us well. I mean, you're literally talking about why people are moving away from vectors because they want to have a more multi-dimension way to represent data as numbers. I'm sorry, words as numbers. That all tracks with me. That all makes good sense. But I'm curious about the learning loop because you said you can provide value right from the start with some corporate policies, but then you keep learning. On the other hand, the way that I understand the way how it works is that there's basically an on-device agent, which I think is doing local compute.
9:36So I presume there's kind of an SLM involved there. and then does it then federate information back to a centralized database to learn about Alex incorporated and then send that back to the on-device agent how does that process function yeah so quite simply when we were building out the architecture we didn't want to have a back-end process and an endpoint process we wanted to have one architecture that could work for either scenario because you might have some systems where they don't want to run anything at the endpoint itself because of, you know, regulatory compliance, whatever. So the way that we've designed the system is it can run completely on the backend or it can run on the endpoint itself, but it's the same architecture.
10:17So you asked about. No, I'm just curious why. I mean, I feel like if you can centralize the compute, why not have a more powerful model? You have more flops to play with. As a founder, you've taken the time to become an expert in your niche and you fully understand the entire landscape, but with so many regulations and rules that you need to follow from federal agencies and offices here in the U.S. to the European Union and beyond, it's impossible for even the most diligent person to keep up with every exacting requirement. That's why you need to simplify compliance with a trusted partner like Vanta.
10:50All my startups use Vanta, and they love Vanta's AI-powered platform that automates your entire compliance process. Whether you're preparing for a SOC 2, or you're running an enterprise GRC program, or you're doing an audit, Vanta is going to worry about the security so your team can focus on building great products. That's why some of our favorite companies like Ramp and Ryder are spending 82 % less time on their audits by working with Vanta. Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate. Vanta is here to help you automate your security and compliance and earn and prove trust.
11:25So get started today at Fanta.com slash twist. That's V-A-N-T-A.com slash twist. So cost, you know, not everything requires like the most, you know, the greatest model or the frontier model. The way that we use models, we use open models that have been published out there. We do rely, like we'll make use of like the cloud service provider models or if a customer wants to bring a model. When it comes to embeddings, we control those and we're using open models to dictate that. Those embedding models can run on the endpoint. They can also run on the backend. We've made changes to those models to optimize them to be very performant and to do particular use cases to solve certain problems.
12:09And so we control that architecture. But if a customer otherwise wants to do deep investigations on all the data that we've collected, they have the capacity to do so. Effectively, the way that the system works is we're building out a pipeline where we put this context in. We start with the raw behavioral information, and then we're decorating it with who's logged in, what is it that they appear to be doing, and aligning that to whether or not it's a corporate violation or not. We have a single architecture that basically is built to run on the endpoint or can run on the backend. Because of the way that embeddings operate, we want to control that process, and we use embedding models.
12:50Embedding models are great because they're very performant. They don't require like GPUs. They can operate on CPUs. And when it comes to decision-making, they can make decisions in sub-second timeframes. Like we don't have to use a heavy amount of reasoning. The sub-second timeframes thing is what the most interesting thing because the way that I think about Int in practice and it hasn't been rolled out at the company that I work at, so I'm kind of theory crafting here. But as I go to do something I shouldn't do, it goes, Alex, don't do that. That might be insecure. Is it that fast of a process or am I overestimating how quick technology is today?
13:22No, it has to be that fast to get prevention. So the idea, like the way that we roll out inside of a company is generally speaking, if you ask like a CISO, who are your riskiest users and why? They can't really tell you, right? They know the workflows that are taking place. They know roughly what people are doing throughout the day, but they don't emphatically know this. And so typically the way that we roll out is we start in more of a baseline mode. We install ENT across like the ecosystem, It starts absorbing the information. Again, it has that corporate policy. We're surfacing violations. The company is going to have more than enough things to do based on what we're surfacing in that moment.
13:59We don't want to necessarily get in the way of anybody's workflow. We don't want to annoy people. I don't want to run, you know, and like, you know, prompt them in some form unless I have information from the company. So there's typically a burning period where you might have two weeks to establish baselines of what's normal, what's not. You know, where are the violations occurring that I actually care about? Because in your corporate policy, you might have something that stipulates nobody should use social media, but you may not actually care to enforce it. But you might have, on the other hand, that AI use and sensitive data that goes into these models has to be done in this particular way.
14:39And so for that moment, like we're going to drudge up that behavior. We're going to say, here's your unsanctioned AI usage. By the way, here's what people are doing. This is the information they're sending in. This is the work that's taking place. And it allows us, we've built the product to basically isolate that workflow and then say, well, when I see this activity in the future, now I want to intervene. And an intervention can be customized. The way that I think about the product as this stop you before you do it thing is one portion of it because it can also do that for humans and apparently also for agents and it can provide a bird's eye view into how a company is using software and in particular ai more broadly so people can learn from their own usage correct so the idea here is like yeah i've toyed around with like the lingo but it's like an organization work model we we talk about world models sure um and world models were like super advantageous to cars right because prior to a world model existing that encapsulated the environment, we were trying to tell the car like when to stay in the lanes, when to apply the brake, when to like kind of, you know, change lanes, whatever.
15:47And the problem was, is that you were overfitting to a particular set of environment variables. When you had the world models, it allowed the car to essentially become more predictive, right? Oh, I'm anticipating that somebody is going to walk out in the crosswalk, or there's a stop sign and I need to apply the brakes. It allowed the self-driving car movement to be more accurate. So when I say that most sisters aren't aware of the behaviors that are taking place, step one is to make them aware from an observability perspective of you have some problems inside your environment that you probably didn't realize.
16:20And step two is to figure out which ones do you actually care about? And then step three is to determine how do you want to modify that user behavior, if at all, or your corporate policies, and then enact those using end. So really, I think that calling this a cybersecurity company almost feels too narrow. You are building kind of a work model in a sense. How far can you push that? Because once you have this information about how a company works, you could do all sorts of fun things like tell them where they're being inefficient or recommend different ways to go about stuff. It seems like if you can get wide adoption and a lot of information, this is a really potentially lucrative and useful tool that you're building with a lot of future applications that go outside of just cyber safety.
17:02Absolutely. I think the, you know, again, toying around with like kind of lingo here, I don't know the best way to describe some of these things because they feel new. Like we haven't had it at our disposal. One of the ones that I was playing around with was like the semantic substrate for security. So all of a sudden I have this, like all of this information that's describing the work that people are doing inside of the business. And that is a, that is a massive uh you know set of contexts that we have at our disposal that can help accelerate closing out true positive benign tickets in the sock right it could give further context to dlp related events it could surface inside risk activity be it the one percent bad guy or the 99 mistakes that take place yeah it could be used to isolate and identify people that need training so like there's a broad applicability and having context that describes what's taking place across the organization.
17:57And you hit the nail on the head. There's a productivity angle to this as well, in which if I understand what people are doing throughout the day, then it becomes ripe to figure out what things might agents benefit, right? What is the mundane, monotonous work that is occurring across different departments inside of the business, or ones that like, particularly risky across my enterprise that might benefit by having an AI agent do it? And then once that AI agent is in place, how do you ensure and keep it on the rails, right? How do you know that it's doing the right thing, that it's aligned to the task?
18:32And so for us, we're concretely focused in security, but we go and target big enterprises. Our environments are global 2000 and above. So think Fortune 500. And the thing that you articulated is what they're after as well. They say, I can start with security. I can bring a level of visibility and stop problems from taking place. But then there's this downstream applicability that becomes really attractive. Like, can we start mining out of that information ways to do process distillation, ways to identify who are like, who's using AI the most and how are they using it in ways that we can help others learn from that?
19:10And this is why I'm terrified that one of the, you know, AI lab, JV, FDE, private equity working groups are going to try to scoop you up and then take all the data you have and then apply it because it's going to be incredibly valuable. But just listening to you on the lingo point, work obs, maybe? I mean, it does feel kind of like general work observability, lots of data. You can do different things with it. We could we like we've also used like, you know, I heard data lineage for a while, which is like looking at how data moves through the enterprise. And I think that that has merits and it's proven in the market.
19:45We've been toying around with behavioral lineage as well. It's like, what are the behaviors that people do and how does that like then intersect with data lineage? How does the behavior of an agent, you know, operate where we've settled on the marketing side is like the intent aware. That's why you see that. But, you know, I don't. TBD and like how people respond to it so far, that's been, you know, the way that we've been pitching it. Most AI tools are adding friction, not making your life simpler. And it's another tab to switch to. And maybe you forget to even do it. It's arduous. What you really want is one system that's going to make you more efficient and save your time every single time you do work.
20:23That's why I love Superhuman Go. from the amazing team behind Grammarly, which I have insisted all my team members use since day one. Now it's an AI chat that lives on the side of your browser. It's always there. Maybe you're drafting an email mid-meeting. It goes and helps you finish it without switching apps. Maybe you got a 40 email thread to get through before that call. It's going to summarize it for you in seconds without losing your place. No new tabs, no starting from scratch, no context switching. Superhuman Go has the context of everything you're working on. It works inside the tools and sites you already use.
20:57Your inbox, your docs, your browser. Maybe you're doing social media all day long like me. It's part of my job. You can try many of Superhuman Go's features for free. Find out more. Superhuman.com. That's superhuman.com. I would say, you know, lineage and substrate are a bit too technical. But then again, I have to say the words agentic orchestration at least three times a day. So what do I know about branding? Okay. Let's talk about a couple of other things. One is just the employee element of this. Now this computer that I'm on right now, because Twist is owned by Launch and Launch is a financial company, has all sorts of tracking software on it, right?
21:31Just for this, you have to do that. I don't love it, even though I don't actually care because no one cares what I do, but it still feels a little bit weird to me that, you know, there is a record somewhere of every tweet that I click on, right? Now, in what you're building, it is more granular. And so I'm trying to kind of sort out how much do employees care? Because on one hand, I think it's becoming the norm to have your work observed to some degree. On the other hand, Meta just made a big push to really look at what their engineers were doing. And that was very unpopular. So where's kind of like opinion and norms around this type of observation?
22:08You know, I think it's TBD to some extent, at least on the enterprises that we work with. A lot of them have corporate policies that stipulate the asset that you're using is subject to monitoring for the purposes of like it's their corporate asset. Right. Like the intellectual property is there. So I think, you know, most of the security software that has been deployed, even in a traditional EDR sense, has been historically collecting all of this information about the actions people are taking on their system. Right. And I do believe that we bring a new level of granularity to it. And we have to determine, you know, what businesses are comfortable effectively deploying.
22:49And I think it's just a matter of being straightforward with your employees. Yeah. And so it's a matter of if it's in the corporate policy and you're able to collect it, then, you know, OK, that's fine. Our kind of general view is we when it comes to the information that we collect, we don't want it coming back to a central authority. We can be the people that host that environment so we can deploy as a SaaS based as product and host on behalf, give you a dedicated tenant. But more importantly, what we've heard from Global 2000 and above is they want to own their data. right they don't want it going to somebody else so ant is deployed within the customer's boundary like we don't even get to see it so the limiting factors there are that's one way of kind of retaining that like it's only staying within the corporate environments not being shared with other people and then the secondary item is how much do you want to collect and centralize back to that you know uh that that corporate back end and so we've provided uh an ample amount of configurability that if you don't want to send something to the backend, you don't have to, you can keep it on the edge.
23:55Now, obviously there's an operational gain in putting everything in a central store, but there's smarter, more data to learn on. Yeah. Yeah. But like a corporation may not want to do that. So for everything that we collect, there's toggles that basically allow the business to turn it on and off. We support user groups, endpoint groups in terms of like, You might want to collect more on your developers just because they have a higher risk pattern, whereas you're legal, you may not really want to collect anything at all. And then beyond that, within the product, there's role-based access control and attribute-based access control.
24:33So if we're collecting something like screenshots for an investigation, I don't want the SOC to necessarily see that. So we allow the business to basically hyper-tune the information that's exposed to any given party. I feel like you're nibbling around the edges of agentic identity and the issues and lack of maturity in that product world somewhat. Am I wrong? If I want to know what the agents are doing, I'm going to want them to have a distinct permission set and a distinct identity. And well, it's the same thing with people, too. Right. I mean, I like you could I think part of the problem with like a corporate policy is that it lacks teeth.
25:10It's only as good as its ability to put it into a control point. And because corporate policy is written in natural language, there's some level of like interpretation that takes place by the employee. And I think that's sometimes what leads to, you know, mistakes being made is that the employee feels they're working within the boundaries of the corporate policy when they may in fact not be. And the way that you get around this, right, is you have a draconian, you know, way of stripping down the asset and removing the freedom. And you're saying, like, thou shall work this way. And I don't think that's particularly fun to work in those businesses.
25:46I understand it. But, like, what I want to do is balance, like, being able to give a new control point layer to actually stop bad things from occurring while also not infringing on, like, privacy. Right. And so it's up to me as I design that product to put the controls in place to not build something that could otherwise be abused. And that's something that's very top of mind for us. I don't want to be nanny software. I don't want to, you know, police, you know, how many, you know, how much AI somebody used throughout the day. That's not what I care about. What I care about is stopping mistakes from taking place, removing adversaries from environments, making sure that people can adopt AI safely.
26:27And that requires some level of observability and understanding what's happening. Work obs. I'm telling you, it's going to be big. All right. Let's talk really quickly some business questions. So you've mentioned how there's a SaaS version of this and a self-hosted version of this. Now, when I usually see that breakdown, it tends to be open source software. As far as I know, you guys are not pursuing the open source approach. So talk to me about the business decision there to allow for self-hosting. And then also, how do you charge for that? Yeah, so self-hosting, the reason for it was when we were at Microsoft, we learned during this AI movement, people are really sensitive to their corporate data.
Read the full transcript
27:03And I think from a regulatory perspective, we're seeing more emphasis on data sovereignty. We're seeing the intellectual property of a business wanting to be contained within its environment. They don't want it to go to, you know, third party supply chain. And so it was a first principle decision for us. In the same way that we said we're not going to depend on any other security product to get our telemetry because that impedes our ability to be preventative and make decisions quickly. We also said we're going to make it out of the box, one click, deploy inside of whatever cloud you guys operate in.
27:38And we support the major ones. And so that was just an important decision for us. If we host it, then effectively we take on the hosting costs and we pass that on in the licensing. If you host it, that becomes like a COGS implication that you have to effectively manage that spend. And we give you the predictability of what that looks like. But I'm still paying you yearly, quarterly. Yeah, there's a licensing cost. Yes, there's a licensing cost associated with the product. It just will change if you're hosting it because you're going to take on the actual hosting. Okay, that makes good sense. But it's still basically charged the same way, lower cost.
28:11That's okay. Okay. That makes sense to me. Uh, now you guys came out of stealth and announced a$100 million round. Uh, these happen more often than they used to. And I'm always curious why you need that much money. Uh, it's a lot. That's, that's an old seed fund from when I was younger. Um, so what are you going to do with a hundred million dollars? So the thing with endpoint is it's a well-established market, right? It's, it's something there's a lot of players and incumbents there. And to be able to like penetrate inside of global, global 2000, Fortune 500 and above, you need to like building that endpoint company takes a lot of effort, right?
28:47I have to build an agent that works across multiple different platforms. I have to like concern myself in the research and development of putting AI directly at the edge while also being able to run it on the backend. We talked about like, you know, hosting inside the customer's environment, making sure that all of that infrastructure is supportive, be it if you're using AWS, Google, or Azure, right? Like all of that takes a significant amount of engineering to get it right, to make sure that it's tested, to not make those mistakes. And so there's a lot of money raised to basically go and do that.
29:22It's just expensive to build a product, but it's also expensive to then like get out in the market and land inside of these like big enterprise accounts. Like people come to us and they say, Hey, look, are you going and competing with the traditional EDR? And the short answer is no, right? I don't want to go and compete with them on the same playing field. Why would I do that? From my perspective, EDR is a commodity at this point. Everybody's got something in place. They might be reasonably satisfied with what they're getting. My job is to augment where that EDR solution is not meeting the needs, where an inside risk solution is not meeting the needs, or a DLP solution is not meeting the needs.
30:01So we talked about like the semantic substrate for security. My business is trying to build, you know, like the programmable endpoint. Can I solve a variety of different use cases using AI as my advantage across any platform in any cloud and give someone that level of visibility to understand what is happening inside their enterprise? It just takes money and capital to do it. The team is pumped because you're about to close a massive deal, but then the client's lawyers get involved. What happens if you get hacked? How are we going to protect your data? There's no need to panic. This is why you brought in YSecurity.
30:37YSecurity is staffed with over 40 experienced engineers who have actually worked security for world-class companies like Apple, Uber, Microsoft, Robinhood, Brex, and so many others. But the best part is you don't even need to hire YSecurity. Your company can rent YSecurity's elite team by the hour. That means no massive salaries to pay, no costly consultants, just real experts embedded in your company, helping you out with your SOC 2, ISO 4200, or any security or compliance challenge you're facing. You can even set a monthly cap so you know exactly how much you're spending. And your first six hours are completely free.
31:15Head to ysecurity.io slash twist and book your free six-hour strategy call. That's ysecurity.io slash TWIST. Given how many different endpoints, clouds, and services you have to make work to have this actually function at the speed you need it to, I'm never going to listen to a developer again. He tells me they can't launch on iOS and Android at the same time because it's too hard. I feel like you're taking on a much more difficult challenge. All right. Last question for me is pretty simple. When you guys came out of stealth, you announced that int was generally available, which means your go-to-market starting gun was shot off.
31:50Correct. How has reaction been? How has the market responded? It's been like a floodgate. Even before that, like we were like, the reason why we effectively, like we've been in the kind of market to some extent, not like out of stealth, but like kind of pseudo out of stealth for a couple of months. And the reason why we just kept consistently holding it back is like, I've retained a pretty healthy pipeline of like, you know, folks that are interested in what we're doing. So when Lou and I left Microsoft, they were like, man, you guys are going to do something crazy. And I want to know what that is.
32:23And so like, we've got a lot of goodwill and having multiple exits and startups that we just had a bench of people that were like, tell me what you guys are doing. And the second that we were ready, we were entertaining, you know, POVs and people that wanted to go and deploy the solution tested out because they're like, we've never seen anything like it. This is exactly what we were expecting. And so beyond that, like typically you come out of stealth because you want help in hiring people. And I I've hired well over, you know, 75 people now and I've not paid a single recruiting fee. And so like coming out of stealth was not lackluster.
33:02Like we've got a lot of like for us, like it didn't feel like any material difference. Like we've retained a healthy pipeline of people that are interested. I've got more people now asking me like, dude, I want to see this thing in action. Uh, this is what I was waiting for. And so for us, it's just a healthy amount of demand beyond what we already had. Do you have enough GTM infrastructure in place, sales teams, et cetera, to handle all the new inbound? That's exactly where we're hiring right now. So we've got, uh, several sales reps we're hiring for sales engineering. Um, you know, we got folks on like the forward deployed engineering side that's been staffed out.
33:38And so like, we're, we're getting our pieces there. I feel pretty comfortable, but like, you know, now it's just a matter of like going through the motion and executing, right. You know, having multiple deals in tandem, managing the POV process, making sure that we're delivering success and outcomes. That's the biggest focus that we have right now. So early beginnings of it, we're hiring. And then it's a matter of just like continuing to turn the crank here. Well, we are looking forward to when you start announcing ARR milestones. But in the meantime, it's int.ai. Brandon, congrats on the round.
34:09Congrats on coming out of fake pseudo stealth and come back on in six months and tell us how it's going. Appreciate it. Thanks, Alex. All right, everybody. Next up on today's Twist. You remember David M. He was previously on our show. He had Clara, the open claw AI girlfriend. Do you remember this, Jason, from February? Yes, I do. I do. So he's back. He's got a new product from his company, Sumay Labs. It's an agent orchestration layer utilizing multiple video generation models. The goal is generating high quality video outputs in just one attempt, Jason. The idea, you could finally one shot your AI videos instead of multiple go rounds to get it exactly the way you want it.
34:50David, thank you for coming back to the show. Yeah, it's good to have you back. I mean, when you make video, it is literally like a slot machine. You put in your prompt. I did it the other day. Pull up my Yoda one. I did it in Grok. I'll take a look. It was relatively good. It got it right. I said, I want Yoda from the Clone Wars style to say Frontier Model Wars begun. Oh, I see. Yes. Here I go. Frontier Model Wars begun. They have. Which is a favorites line. The Clone Wars begun. They have. There we go. And I honestly, I got to be honest, I give it like a nine out of ten, eight and a half out of ten.
35:31It's pretty good. But it knows what it's doing. It's pretty good. The voice is off, but I mean, I'm not paying a royalty to Disney here, so I don't know. You might get in trouble with Disney. But David, why don't you show us what you built? Because I do think there is something here to taking... When you get rid of the slot machine nature of these LLMs, it becomes more predictable and your utilization goes up. Yeah, yeah. The slot machine is not fun when you're making videos and images and they take 30 seconds. It's incredibly frustrating. Right now, you know, the balling right now is like prompting the videos again and again to get the right results because it's unpredictable because, you know, video generation models are stochastic.
36:15So what we're trying to do is make an API that is basically a wrapper of like, let's say five or six models to get the production result. So our belief is that once we make these one piece, piece, piece, let's say production lab, production ready, like API primitives, then once we got the APIs, then we could make our agent one shot a marketing video very easily. Okay. I'm guessing you have a killer demo to show us. Yeah. There it is. Can you see a screen? Yeah, we can see it looks like your X feed. Yeah. So, yeah, this is kind of like our UGC API. It's our offer to API. Right. And then you could do kind of like.
36:59So this is basically the same prompt. So it's a basic prompt with Gemini Omni, Seedance and Sumi Avatar. And basically what we did is we are basically basically on a router of multiple models, not only video, but image, video, audio and clipping and everything. We were a wrapper around all these models. And this is what we got with the same prompts. You're seeing on the left Gemini Omni and it looks like a young adult, maybe a 25 year old or younger. in their apartment in a city, or maybe they're in high school in the second one. They're doing the classic selfie marketing, like I'm making a TikTok video about this product.
37:40Yeah. So same prompt, you see three different results. Then what happens? What's next? So what we're trying to make at the end goal, let's say like after six months, is a video agent that wants us marketing videos. So our users, our brands or marketers, want to promote their product and make video ads for them. And right now our first model was for UGC. So as you know, like if you want to make UGC videos with AI right now, you have to combine a lot of different models, let's say like C-Dance or like touch the image or Grog and everything. And then after that, you have to combine those videos to make a long because, you know, video generation models only like support up to 15 seconds.
38:22It's like 30 seconds for our like C-Dance's like next model. like it's only 30 seconds so what we did is we made a router of video video generation models and image models and audio to like get the like audio persistent to like make this kind of videos and then finally you could generate up to 60 seconds of consistent after videos right now okay all right so you put in a script hey i want to promote my new uh app it's called uber and you open your phone, you go outside, it's raining, you can't walk home, you want to get a ride and you write the script for this and then it goes and makes you a bunch of different scenes or do you tell it what scenes to make?
39:07No, actually. It's only for the user, it's basically just picking on avatar and then writing the script. Got it. That's it. The user writes the script or the LLM writes the script? The user writes the script. Got it. So after I write the script, then each scene gets done three times, and then it's up to me to stitch them together. So I might say, oh, I like this one where it shows the car in the pouring rain. I like this one when it shows the guy getting out with his umbrella or putting his jack. One of them has him put his coat over his head to walk to his front door. And I just get to essentially vibe code my way around a longer form video.
39:46Yeah. 100%. Okay, cool. Do you have any outputs like that that we can see? I would love to see where you got to with this. Okay, so I could show you the video. Yeah. So this is like 16 seconds, so you could see that it's up more than 15 seconds. But yeah, you can make these kind of videos with 60 seconds. So it's using multiple ones, and then it stitches together with one clean audio file across it, so a little bit of a hack there. Yeah, yeah, yeah. And if you go to... Yeah, so round now, yeah. It's also consistently, her face remains totally consistent throughout. A big problem when you're generating these kinds of like video clips, I find, is that it'll, for the first like seven seconds of the video, it'll look like the person's face.
40:30And then it sometimes gets like distorted towards the end. Like that's a big problem with, it's like keeping that facial consistency the whole time. What is the website? Do you have a website for this that we can see? Yeah, you can search sume.com. Ah. S-U-M-E dot com. Cool. Oh my God, you got a good domain name. How much did that cost? Yeah, we got it cheap. Really? That's a$100 ,000 domain name. 70 % discount from the initial price on GoDaddy. Love it. All right. Well, this is like a great start. And who's it for? Who's the customer? You think startups making marketing videos or just general D2C marketers?
41:07Who's your customer base currently? Yeah. So right now we have 20K users and the main customers, especially about 90 % of the paid customers are brands. Got it. Our main audience is not on Twitter, but they're on Instagram and TikTok. Got it. Yeah. People are trying to flood those spaces. I can't even tell what's AI anymore unless you're paying attention. I got a lot of shark videos because one of my daughters loves sharks and I'll do shark videos with her. and now I'm starting to get AI slop sharks. And they start out and it's like a person on a boat and they're pulling in a fish and you're like, oh my God, there's going to be a shark.
41:42And then this ridiculous shark jumps up, eats the fish. The person falls in the water. The shark is jumping in the water. I'm like, sharks don't interact for 90 seconds with a human. This is getting a little ridiculous here. All right, well, great job with the startup. Keep grinding and we'll see you when you have your next update. Awesome. Thanks, David.
From the publisher
This Week In Startups is made possible by:
Vanta
https://www.vanta.com/twist
Superhuman
https://superhuman.com
YSecurity
https://YSecurity.io/TWIST
Today's show:
*Cybersecurity has long focused on cleaning up a system AFTER a breach but Ent founder Brandon Dixon says that's backwards. He just raised a $100M seed round to put an AI agent on everyone's company laptops that catches the risky clicks, leaked files, or rogue agents BEFORE they wreck havoc.
PLUS Clawra creator David Im return swith his new project, Sume's Avatar, a multi-model orchestration layer that generates 60-second UGC videos from a single prompt… and gets it right on the first try, rather than falling back on trial and error.
Guests:
Brandon Dixon on LinkedIn: https://www.linkedin.com/in/brandonsdixon/
Ent: ****https://ent.ai/
David Im on X: https://x.com/davidim
Sume: https://www.sume.com/
Relevant Links:
WSJ: "Cyber Security Startup Ent Raises $100 Million in Seed Funding": https://www.wsj.com/pro/cybersecurity/cyber-startup-ent-raises-100-million-in-seed-funding-a3e9b6c6
Microsoft Security Copilot: https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot
Engadget: "Meta 'pausing' employee tracking program…": https://www.engadget.com/2199458/meta-is-pausing-employee-tracking-program-after-it-let-the-whole-company-see-sensitive-data/
Seedance 2.0: https://seedance2.ai/
Timestamps:
0:00 Intro: Why AI + cybersecurity is the hot combo right now
2:29 How INT stops breaches before they happen
4:56 AI is giving non-technical employees dangerous new powers
10:26 Vanta - Compliance and security shouldn't be a deal-breaker for startups to win new business. Vanta makes it easy for companies to get a SOC 2 report fast. Get $1,000 off for a limited time at https://www.vanta.com/twist
13:54 Why on-device AI beats cloud-based security
20:08 Superhuman - Get AI that works where you work. Unlock your Superhuman potential at https://superhuman.com
25:18 INT's business model and go-to-market
30:26 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST
34:18 David M. of Sumi Labs: one-shotting AI video
36:10 Live demo: Sumi's video orchestration API
40:05 Consistent faces, 60-second videos, and who's buying
Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com
Check out the TWIST500: https://www.twist500.com
Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp
Follow Lon:
Follow Alex:
LinkedIn: https://www.linkedin.com/in/alexwilhelm
Follow Jason:
LinkedIn: https://www.linkedin.com/in/jasoncalacanis
Check out all our partner offers: https://partners.launch.co/
Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland
Check out Jason's suite of newsletters: https://substack.com/@calacanis
Follow TWiST:
Twitter: https://twitter.com/TWiStartups
YouTube: https://www.youtube.com/thisweekin
Instagram: https://www.instagram.com/thisweekinstartups
TikTok: https://www.tiktok.com/@thisweekinstartups
Substack: https://twistartups.substack.com




