Enhancing Data Security: A Partnership Between Allure Security and Hydrolix
Josh Shaul, CEO of Allure Security, discusses the rise of scams due to generative AI and the importance of security solutions. Abby Ross, Head of Channel Marketing at Hydrolix explains their role in addressing big data challenges. The partnership between Allure Security and Hydrolix improves data management, efficiency, and cost-effectiveness.
Transcript
Hey everyone. Welcome back here to Techstrong tv. Hey, I've got two people to introduce you to here, and we're going to hear how their companies are working together and also maybe find out a little about their company's name, may be companies you haven't heard of.
Let me first intro introduce you to Josh Shaul. Josh is the CEO of ALO Security. And Josh, welcome to Textron tv.
How are you? Hey folks. Uh, doing great.
Nice to meet you. Great. Josh, I'm gonna come back to you in a second, but let me introduce our second guest, and she's Abby Ross.
She's head of channel marketing for a company called Hydraulics. Hi Abby, welcome to Tech Drunk tv. Thank you.
Thanks for having Me Here. Thank you. Thank you both for coming on.
Josh, let's start with you. You're the CEO of Allo Security. How did that come about?
Tell give us a little bit of your, uh, personal history. Gee, I'm one of those folks that spent my entire life working on cybersecurity. I was like the idiot teenage hacker in the late eighties and, and never did anything different.
So, uh, grew up as, as a developer early in my career, eventually made my way into, uh, some leadership roles. Was running the web security business for Akamai for a few years where I saw that the world had a really big account takeover problem. Uh, Akamai had great solutions for stopping bots that would take over accounts, and, uh, once we were able to do that, scammers popped up and they started stealing credentials for accounts directly from folks.
And that's how, uh, allure Security was born and, and how I ended up here. Okay. Were you there with Andy Ellis?
I was. I was Andy and I got to keynote r RSS a together, uh, seven or eight years ago. Sure.
Actually, I think I remember John. So I, I've also been in security, a lifelong pack I bang on my head on the wall too. Um, so I had started a company called Still Secure back in the day outta Boulder, Colorado, co-founded and been in security 25, 30 years.
But I, I do, I think I remember the year you keynote noted with Andy. Um, so give us that. That's it, you know, six degrees of separation and security.
It's a really small, even though it's because such a big industry, it's still a small community. John, talk to us about allure though. What's the mission there?
You mentioned a little bit, but let's dive a little deeper. Yeah. So what the Lord does is we provide comprehensive disinformation security solutions.
So we protect enterprises from digital impersonations, reputation attacks, and sophisticated mis misinformation campaigns. And there's been this enormous acceleration and scams and fraud and disinformation that's been driven by generative AI over the last couple of years. And what we've done is build AI systems that can fight that generative AI that can go out and actually figure out what's real and what's fake differentiate between the legitimate website where you're actually should trust putting in your credentials and the fake site where your information's gonna get stolen, the fake profile on social media that you shouldn't trust versus the one that you should.
So that's, that's the battle that we've been fighting and using some pretty interesting tech to do it. You know, we're seeing more and more and they're getting better and better. Let me just quickly ask you, are you using AI to fight ai?
We are. It's the only way that you can keep up really, is to have your own models and, and, and train 'em properly and use that, uh, to scale out your capabilities that you can keep up with what the attackers are gonna have gotten their own hands on and what they're gonna do next. Absolutely.
John, if you don't mind, I want to turn over to Abby for a quick second or more than a second. Abby, I mentioned you're head of channel marketing at Hydraulics. Why don't we give us a little bit more background on you and then let's talk about how hydraulics.
Sure. Well, I've also been in cybersecurity for a long time, since 2013, which is when I met Josh. It is a small community.
We both worked at Trustwave together, um, and I, I mainly worked in public relations and then moved into marketing. And since then I've worked for large companies like IBM I've worked for smaller companies like Bay Dynamics, and then I also worked at Akamai, and now I'm at Hydraulics. And Hydraulics is a streaming data lake company.
Uh, a lot of people use us for observability. We have major partners like AWS and Akamai. And the, the reason why Hydraulics was formed was to solve the economic and big data challenges that are plaguing many companies today.
Uh, the fact that we have an explosive amount of data and it's data that has details about the data and there's just data everywhere across all these distributed systems and services and getting all that data together into one platform so you can use it, has been a challenge. And retention, as many people know out there, is extremely expensive, especially when it comes to long-term retention and large data sets. So our founders, uh, they created hydraulics to solve this problem.
Excellent. You know, and it is a problem. I, I think, well, you know, I always call it a little bit of the Splunk issue, right?
All of a sudden we came to the realization that we could, we could log everything and we could capture everything and we could store everything. And then we found out that we really want to afford or pay for everything. And then, okay, if we're not gonna pay for everything, what should we pay for?
And what shouldn't we pay for? And what is important and what's not important. Just because she can doesn't mean you should.
And, uh, and that that's a, that's a big issue here. Josh, I have to apologize. I think I refer to you as John earlier instead of Josh, and if I did, I apologize.
Um, so let, let's focus in on how Josh you are partnering with hydraulics. It, it seems on the AWS platform and getting, getting you more than your money's worth, right? Better application performance at a better price.
Sounds too good to be true. You know, you, you sort hit it on the head and you described the problem, Alan. Well, well, we've been dealing with at a lower security is massive amounts of data that flow through our systems that we need to collect and store for AI training purposes.
Yeah. We process more than 50 petabyte of data every day through our system. So we're talking a lot of, Just think about that though.
50 petabytes. That's nuts. It it's impossible to really wrap your head around.
Yeah. It's like light ears We're, we're dealing with. And, and just to collect logs on that, just to know what we've actually touched, what we haven't touched, the important parts of the data, it becomes an enormous, enormous data storage and retrieval problem.
We've been using the traditional log tools to do our work for, for years now, and we've run into limitation after limitation. We can't spend, spend unlimited money to store the logs. We just run into, hey, we've got economic issues here that we gotta run a business that's led us to have to make tough calls about which logs flow into the systems that we get visibility and where we don't.
And then when you don't have visibility because, oh, I couldn't afford to put my logs here. The frustration's enormous. We've also run into trouble over and over again where we can't look back far enough, can only keep a 30 days-ish of logs and, uh, in the system because that's all the real data volume that we could afford given the massive amount of data that we're processing.
So, hey, oh, that we, we learned about it 32 days after the, the thing we needed to go back and look for. Data's gone, frustration after frustration there. And then I think for us, the real, the the, the real fine point that I'll put on it is we had occasions where we rolled out new capabilities into our software and we are, we are a go fast and break stuff kind of, kind of company.
We move really, really quickly rolling out new capabilities, especially in our non-production environments where, you know, we're, it's okay to move and break stuff, but we're still of course, logging and collecting data in those environments. There have been times where because of those new functionality rolling out, we blew through our logging limits with our provider, and that provider just didn't give us enough time to deal with it and ended up shutting us down and having to go back for, Well, because your impact, look, as someone who was doing web hosting in the late nineties, when when you blow past your limits like that, it's not just a question of do you have the money to pay for what you're going to use, but you're, you're affecting my other customer's performance. And should everyone suffer because you're a log cog, you know, for lack of a better word.
And, and so I, I get where they're coming from. I'm Not sure if I'm on that page with you when you're talking about a big time company who's running a cloud-based logging service, who's happy to sell you as much cloud-based indexing as you're willing to buy, but mm-hmm. Hey, the real pain is, Hey, we can't, we, we, we need to stop indexing this data.
We can't. We need a new license, we can't get in here anymore. And for us, that meant outages of certain capabilities and like those outages were just unbearable.
So we ended up meeting hydraulics. Uh, we were connected actually through Akamai who, who told me, Hey, if you're frustrated with what you're doing today with your logs and the way you're doing it should check out hydraulics. They're, they're saving folks money and, and giving them great performance.
So, uh, so that, that's just what we did. We took a look at hydraulics and we found that it, it, it met our use case perfectly. Didn't really change our workflows in any way, but allowed us to expand our data storage to a much longer term.
Allowed us to, to throw away all of the, Hey, can we keep this log? Can we not keep that kind of data and bring it all into one, one store that we can query all at once and, uh, replace all of the workflows and, and functionality that we had built up in, in our, our legacy log log management and alerting system. And we did that at a ridiculous pace with, uh, with hydraulics.
In fact, today was cut over a day this morning we woke up and our legacy log system was shut down. Today, I'm sitting here, it's two o'clock in the afternoon. Every one of our systems has been updated to use the hydraulics endpoints.
Hydraulics helped us through the, the, the transition. And you know, I'm able to sit here, calm and do the interview together with you, rather than be in the middle of, oh my God, hair on fire incident we shut off. Oh Yeah.
That, that, that says something. Sure does. Unless you're really a good poker player.
I, you know, maybe, uh, Abby, so is there black magic here? How are you doing this? Well, I mean, that's music to my ears, um, what Josh just said.
Uh, yeah, I mean, we have a lot of differentiators in the market. Uh, you know, our decoupled architecture makes it really easy to scale up in real time. Um, ingest endless amounts of data.
I mean, we ran the Super Bowl. We were the sole multi CDN observability provider for Fox Corporation during the Super Bowl. We were ingesting at peak time, 55 billion.
No, we, we ingested 55 billion records throughout the whole event. And at peak time it was more than a petabyte a day. So our platform is used to ingesting massive amounts of data, um, no matter the amount of that data without log limits.
Uh, and we do it all in real time. 'cause data, data also remains always hot in hydraulics. So querying data takes subseconds, um, and then just even time to glass.
So the time that you ingest all that data to the time where you see the analytics on a dashboard, less than 10 seconds. Wow. Um, yeah, so, you know, we, we've built something that solves the problem of ingesting massive amounts of data and correlating it from all these different sources into one dashboard, but also the retention component of it.
We have a policy that's at least 15 months and it's 75% less the cost of other observability providers on the market. So Companies can, lemme lemme just wrap my head around this. You are ingesting and retaining that data for at least 15 months.
Yep. That's our, that's our standard policy. So companies can retain it for years at 75% less the cost.
So, and I think I've mentioned this before, but we're also known as headless observability. So it's, you know, if, if, if folks wanna keep their front end dashboards that they love, they can, uh, and use us for the ingestion, analytics, retention and save money and keep data always hot, or you could do a full rip and replace whatever works best for people. But we are very flexible in that sense.
I'll be honest with you. You blew my mind here. So how, how are you, how are you doing this?
It obviously, if you could tell, I mean Yeah, Well, I mean, I, I can't tell everything that's, uh, that's under the hood, but the, uh, the architecture has a lot to do with it and how, and how we built it, um, with that decoupled architecture and in indexing too, we do right at the point of ingest. Um, so is it A lossless kind of algorithm though? Or What do you mean by lossless?
I mean is are you really retaining a hundred percent of that data Yes. Or are you somehow indexing, summarizing, using some ai, some things we have, We have summary tables Yes. To summarize the data, but we are ingesting all of it and retaining all of it and using all of it.
I love it. What a great story. So Josh, you switched over totally today as you sit here calmly with not a beat of sweat on your forehead.
Um, how long did this process actually take though for you guys? So we've been, uh, we, we, we performed a free thorough evaluation with hydraulics where we split our data stream and, and, and had that data flow to both our legacy provider and the hydraulics. And one of the really cool things hydraulics was able to do was use our legacy observability providers UI as the UI for their data.
So we could compare side by side in the same software using the same graphs, charts, dashboards that we've been using for a long time to run the business. How are we doing? Are we actually getting all the data into hydraulics?
Is the data there, can we query it the way we want to query it? Does it populate the way we need it to populate? That allowed us to build tremendous confidence.
We knew everything was gonna work, and at first our plan was to leave the, uh, the legacy provider's UI in place and just use that as the front end of hydraulics. But as we sort of moved through the path and we got to migration time and hydraulics said, Hey, here's the, here's the API documents you need, here's the info you need to query us directly. My team took a look at that and said, it's just as easy for us to go direct to the hydraulics endpoints, start getting the data directly from them, cut out the, the piece in the middle and, and just move forward.
You know, some, sometimes you end up with, uh, an unexpected, uh, uh, boost to your, uh, to your systems. Like a, you take a pat, you take, you take that. Ah, it's not that important to work on this now.
Oh, I guess we're gonna work on this now and boy, am I glad we worked on this now. Hey, we just just went through one of those, uh, experiences with, with, with hydraulics. And honestly, the, the toughest thing that that happened was us not understanding our own schema and having to ask questions back to hydraulics about, Hey, how come we don't see the data where we expect to see it?
Oh wait, uh, we need to do a better job reading the manual. Yeah. Or we come back and Kill myself.
Yeah. Yeah. That's crazy.
So, and if you're not allowed to say this, just tell me. But your currently, your, your hydraulics instances is running on AWS um, Abby, do you run on the other major clouds as well? We can run on any cloud.
Um, so we are agnostic in that sense, but our major partners are AWS and Akamai. But yes, we can run on any cloud. I got it.
So I I I would assume maybe you're running on top of Akamai, CDN, kind of, We ingest Akamai CDN data, so for AWS and Akamai in those, with those partnerships, we ingest data from those specific sources. So for AWS we ingest edge services data, so that's CloudFront, waf, elemental, those are the main ones. And we're always adding in, in new integrations.
Um, with Akamai, it's their CDN of course, and their security services. So we can, we can, we're constantly adding in more integrations on that front too. So it just depends on the cloud we wanna run in.
But we're also a multi CDN, so, you know, like for the Super Bowl we were ingesting I think from five CDNs all at once, all that data. So we can do that too. It's crazy good stuff.
Hydraulics, uh, US based, Oh, yes, we, uh, our, our main headquarters are in Portland, Oregon, but we are global. We are everywhere around the world. Well, you'd have to be with, with that kind of footprint.
Um, I didn't even ask websites guys. Abby, what's the hydraulics website? io.
And that's H-Y-D-R-O-L-I-X, just like it is under your name in the bottom third there. Um, Josh, how about allure? com.
All right. Hey guys, I appreciate you both coming on here and, and, and actually opening the kimono a little bit and giving us a look behind the black curtain and what's going on. What a t.
Tremendous story. Now, Josh, we may have to have you back on here and see if you're still a happy customer in three months, you know, or, or if we see you sweat. Uh, but it sounds like a beautiful marriage.
So congratulations and good luck to both of you. Um, hydraulics, all lost security here on Text Drunk tv. We'll take a break.
We'll be back with Mark.