Democratizing Access to Risk and Compliance Tools – Sravish Sridhar, Kintent
Sravish discusses why democratizing access to risk and compliance tools should become an industry standard for startups and SMBs and how Kintent is now uniquely delivering a free cloud offering for startups to help them become SOC-2 and NIST-CSF compliant so they can successfully compete and thrive in today’s business world.
Transcript
This is texturing TV. Hey everyone, welcome back to Tech strong TV. I've got a first-time company here on techstrong TV to tell you all about and their co-founder or CEO.
His name is shravish. Shruttar if I mess that up, I apologize. But Travis welcome.
Correct me on your name, please. And tell us you already did a fantastic job. Thank you.
Is that really? I appreciate that. But I Travis I know I got right.
You didn't finish stravish reader sridor. Okay. All right.
So we're ahead of where we're starting off. Okay, Travis, we're gonna talk about you and your company and you need to have a good discussion today. But why don't we talk about you as I said it first.
Well, you give us maybe share a little leave your background with our audience. Alan first off. Thank you for having me on the show.
I really appreciate it. It's great to be here. Our pleasure.
I am a three-time Founder. I'm an immigrant entrepreneur that moved here to the US in 1996 went to school. At the University of Texas did my undergrad and I've done three startups.
Over the last 20 years and for you. All three were Venture backed the first two were successful exits and I'm on to my third one and we've been building this company called content. Which is based in Boston, but our entire team is completely distributed all over the world.
And we are building a company to completely disrupt a market called governance risk and compliance or GRC. And come up with ways to improve it significantly. Absolutely.
Let me just get some housekeeping out of the way. How do you spell content? K i n t e n t content and I'm gonna assume the website is content.
com. Excellent. All right, so Savage look, I've been in security 25 plus years GRC.
GRC frankly has been a pain in the butt for everyone who's 25 plus years, right? It's a problem that used to be it was a big Enterprise problem, right? Because big Enterprises how to worry about GRC.
Governance risk and compliance, right the as you went downstream generally companies had much less. GRC issues to deal with and and the more simpler those GRC issues became the easier it was to kind of give me one size fits all type of solution because they're they're GRC issues were relatively simpler, of course in today's complicated world. Around compliance and regulations and Reporting and so forth third-party reporting it is no one has a simple.
GRC task, right it becomes it's a bit of a complication for everyone. So I'd love to hear how you guys are going to disrupt this and what What makes you think it's doable? I don't like I said, this is my third startup.
My first two companies were B2B companies selling to large Enterprises. And as part of every Enterprise sales process. We had to prove that we had a strong security program a strong privacy program and a strong compliance program if we couldn't do that.
We couldn't drive Revenue Enterprises would not do business with us. and 20 years of shuffling paper uploading documents taking screenshots and answering security questionnaires and spending hundreds of thousands of dollars on compliance. Got me frustrated that there isn't a better way.
To achieve compliance and more importantly prove it. To not only your internal stakeholders in other words your board. But also your customers and regulators.
Sure, we are still pushing papers. In the world of GRC GRC still in the 20th century. Yeah.
you know I used to make so By way background. I've also started. A few Venture back companies.
Yeah, and been there done that and GRC is always been a component of that because you know when you're doing Venture back companies you you have Your board made up of professionals and and even if you're not a public company. There there are compliance and governance. You know protocols that you that you must follow so that's right.
I've had to do this and It's it's hard. I mean, there's no there's no. Sweet talking it or sugarcoating.
It can be hard. I always used to hear from my VC friends though that hey if you're biggest. Competitor is a spreadsheet.
You know, you're in a good market, right? Because that's a market that needs to be fixed. That's right.
a lot of companies that spreadsheet their GRC I agree with you and I'll add one more layer to your statement if your competitor is a spreadsheet. And your primary use case? Is focused around accelerating or driving Revenue?
And you bring those two aspects together? You're in a phenomenal Market. Yeah.
Because you could take the manual nature. Of maintaining a spreadsheet and figure out how to automate it. But more importantly attribute those automations to driving revenue and now you go from being a cost center.
to a revenue enabler and that's a phenomenal business to try to build. Absolutely because I think for the most part GRC is or has been viewed certainly as a court center, right? This is you supposed to doing business cards.
now to be fair there have been others over the last years who have also tried to slay this Dragon they have why is this time different I guess is the question. Kinds of approaches that have been taken in the last 20 years when it comes to the GRC space. Phase one was taking the spreadsheet and moving it into a web-based platform and primarily focused on the ability to manage the workflows of GRC.
And these are companies like Archer. They are the large Bender in the space Tugboat logic, which was recently acquired by one trust a couple years ago and a whole host of others. They essentially took the spreadsheet.
And gave you a SAS based interface to manage workflows. In the last three years there have been startups that have come about. That have said we can do better.
We can automate. The ability for you to collect evidence. To achieve compliance.
This industry is called compliance automation. Right? And if you go to all their websites, they look exactly the same.
And their promise is things like put your compliance on autopilot put your security on autopilot and things of that nature and my opinion is although that is much better. Then just managing workflows. Automating compliance is a very dangerous statement to make because like you said earlier governance risk and compliance is a board level issue.
You don't take something as serious as that and just say I'm going to automate it. There's got to be governance around it. There's got to be truth around it and there's got to be accuracy around it.
And so the approach we took is different because we're bringing together two ideas, which nobody has enabled in this industry, which is one. assurance Do you actually know that what you're claiming to be doing is 100% accurate? and second verification Can I as an internal auditor an external auditor or a customer or board member?
verify programmatically that what you're saying is true. and if you can bring assurance and verification together What you end up doing is you transform GRC into trust. And so I I took a long time to get to the punchline.
What content is trying to do is to transform the GRC Market. into a trust Assurance platform I like that. I like it a lot.
And and also I like the fact that you're not. You're not over promising on the automation. No, right because I think that is some.
With some people have gone off onto the dirt road. You're right by saying. Okay, we know this problem is really hard.
We're just gonna automate it so you don't have to do it worry about it anymore and it's not something that is just a hundred percent automatable. What am I whatever the word may be? Right?
I don't think automatables the word but it's not something that you can just automate totally like that. It's you know, and anyone I I think we've all grown tired of Magic Bullets and silver bullets right that are gonna fix things. Like that, and I I think we we're looking for real world Solutions.
That you know don't over promise. Allen you're absolutely right. I think a disservice that the startups in this space have done to the industry your point.
Has provided unreal claims around automation? And in their mind what they have said is automation equals Integrations. And so they've they've weaved this amazing marketing narrative.
That says I have 80 Integrations. I've got a hundred Integrations. I've got a hundred and twenty Integrations and they weaved a narrative that the more Integrations you have the more you can automate but what they are failing to educate the market around.
Is that it's not about the number of Integrations. It's about can you programmatically determine? Whether a company is satisfying a control or not.
And a control is a very personalized and Custom Concept. That is Catered towards how a business runs its operations. And so yes, you can have hundreds of Integrations, but what's really important is that there is governance around how controls are designed.
And then there is programmatic verification to determine if the control is meeting its objective. That has been designed for that business. A great I I couldn't agree more with you.
So let me just you know, they talk about moving the goal posts and trying to hit a moving Target. I I think some of the things that I'm interested in your take on this some of the factors that a company like yours has to take into account is number one kind of the changing. Guidance for for governance and risk compliance, right?
We have many new statutes and regulations and jurisdictions, right? That's kind of an ever-changing recipe mix but at the same time You know with the modern software Factory and how quickly software is developed and deployed and updated and feedback and deploying it on. Things that the edge of the network and Beyond and stuff like that.
It's almost harder than ever to get, you know called a snapshot. of what what your current GRC, you know kind of profile is It's got to make it a harder job or it seems it would seem to me it's kind of make it a harder job. Yeah, you're right.
There are four the way we look at it a content is that there are four pillars that are constantly changing that affects a business when it comes to GRC. The first pillar is the regulations. That change from time to time new laws that come up from time to time as well as your customer requirements that change every year you may have done.
A contract with a large Bank this year next year. They're going to change the way they're going to assess you for risk. So the customer requirements change as well.
So the requirements that govern your business are changing every year, so that's pillar number one. Pillar number two is we live in a cloud-native world. And net new projects are being done with Cloud infrastructure as well as with SAS businesses.
And the number of vendors that companies are using are changing all the time. And the number of breaches that affect those vendors are changing all the time. So that's issue.
Number two issue number three is software itself. There's a modern phrase that is. Making its way in the industry called software develop materials this describes the stack that you're using to build your software.
A lot of it is based on open source technology. So software is changing on a continuous basis and keeping track of the risk associated software is very very hard. and finally and probably the most underappreciated part.
Of the governance risk and compliance industry is people. We live in a remote world. We live in a hybrid work environment people live all over the place.
We're hiring people from different parts of the world different cultures different education backgrounds. How do you make sure that the people are doing the right things that they need to be doing so that they are protecting your business and their custodians of trust for your business. That's really hard.
Right? So to sum it up regulations. Vendors software and people are constantly changing and that creates risk in your GRC program and so our approach.
Is to make it systematic in programmatic. To validate and test your controls across all those four vectors. And determine if there is change or deviation.
From what is expected of you? And as soon as that change in deviation happens, the appropriate people in the organization are notified and action needs to be taken. excellent Here's the key.
And this is the number one issue in my opinion with governance risking compliance. Nobody understands why? Okay.
If I go to you Alan. And say Alan you need to attest to a policy or you need to solve for a control or you need to fix a breach a potential breach. But I'm explaining it to you in compliance language.
You're going to look at me and say I don't understand what you're saying because I'm in marketing or I'm in sales or I'm in devops. But if I come to you and say I need you to do a specific thing and describe it from the framework of your daily work. So instead of saying I need you to fix a control.
I tell you I need you to complete. a testing to our security policy or I need you to make sure all our databases are encrypted. You Now understand it in the concept of your job part one and part two if I then describe it from the perspective of the business impact That you're creating.
So in other words if I tell you by satisfying this control you're helping protect us. Against liability worth 50 million dollars because we've committed in a hundred contracts that we do this. Or you're protecting us.
from enabling our salespeople to represent to our customers that we do this, right? So you're driving Revenue. So if I if I'm able to explain the business impact of you being a custodian of trust and Enterprises what we found is people really want to do the right thing.
I don't disagree. I don't think anyone raises their hand and says I want to do the wrong thing. Right.
They do want to do the right thing. It's their jobs. It's their professional responsibility.
It's just I think when the when the task becomes so difficult or obtuse. They just they have other tasks to do and they and they depry our prioritize. that task let's if you don't mind should I sweet we probably over time array, but I wanted to just kind of hit on this how how is content packaged?
How do people engage? It's a great question. Condensed product is called trust Cloud.
That's the name of the platform. And the way trust Cloud works, is it on boards a customer into the platform? And as part of the onboarding process, we understand who their people are.
This helps us understand people risk. We understand who their vendors are. we get a sense of what their software repositories and their software products look like And finally, we get a sense of what governance risk and compliance Frameworks.
They need to adhere to that's part of the onboarding process. Once that happens two things are immediately Unleashed first. Is we've taken Concepts from the world of cicd or continuous integration continuous development.
And enabled programmatic testing of controls. So just like you would constantly test your source code. You would deploy your source code after you test it or to use a human analogy some of us where an Apple Watch to validate if our blood pressure and the number of steps.
We're running Etc means our goals similarly. We turn on continuous testing for control verification. So that's part one.
Part 2 is we've built an AI engine. That auto detects an auto-generates policies based on the controls in your program in case you don't have those policies. But it's also used to do things like respond to security questionnaires.
So if a customer sends your security questionnaire the AI can auto-generate and autofill 65% of those security questions because it knows about your security program and your compliance program. The AI can also have a conversation with your prospects your prospects can come in and ask a question. For example, the prospect prospect can ask how do you encrypt my data and the AI generates an answer and pulls artifacts from your trust cloud?
That supports the answer. So we're taking concepts of ci/cd and apis and Ai and bring together in a modern platform. to make trust verification completely programmatic for not only yourself but also your customers.
excellent As I mentioned, I think we're way over time, but that's okay. com. Is that correct?
content k i n t e n t i n Okay. com. Alan just like I told you earlier that my name is ravish with an s in front of it.
It's content with an eye is the word intent with the K in front of it actually. All right, so there's a rhyme and a reason to it as well. Savage thank you so much for coming on text drug TV and telling us all about content as well as a good discussion of what current state of GRC is so important stuff come back and join us again.
Keep us posted on progress there and best of luck to you. I'd love to do that on thank you for having me. All right content here on Tech strong TV.
com. Go check it out. We're gonna take a break.
We'll be right back.