Eric Brüggemann on Code Intelligence Launching Spark
Eric Brüggemann talks about Code Intelligence launching Spark, its AI test agent that autonomously uncovers vulnerabilities without human interaction.
Transcript
This is Textron tv. Hey everyone, welcome back here to another Techron TV interview. I've got a new company and a first time, uh, guest here on Textron tv today to introduce you to, his name is Eric Gelman.
Eric is the CEO of a company called Code Intelligence, and he joins us today from beautiful Cologne, Germany. Great background out there. I don't know if that's a real background, but it still looks pretty.
Hey, Eric, welcome to Techstrong tv. It's great to have you on. Hey, Alan, thanks for having me.
Very happy to be here. Thank you. So, Eric, as I mentioned it, it's bru, you are the CEO of Code Intelligence and you, you're based in Cologne, but you've had a, you know, you've moved around in your life.
You've had an interesting journey to get here. Share, if you don't mind, with our audience, a little bit about your journey. No, please El no.
Hap I'm happy to do so. I'll try to keep it short. So, hey guys, it's really great to be here.
Uh, my name's Eric. I, I'm basic alone these days, but I, as you might be able to tell from a little bit of a bachelor at Accent, I used to live in the States. So I did my masters at MIT up in Cambridge, um, and then actually started working in a non-tech field.
So I'm not a techie, let's say by background, but I used to work as a consultant for BCG for eight years in total before I then started basically dipping my toes into the, it into the tech world, starting in a construction tech company, uh, down in Munich called Think Project. A lot of, let's say building information modeling, spatial AI being used. And then two years ago, roughly, I switched over to Co intelligence initially as a COO.
And um, yes, since then I've been, uh, basically working on helping the company scale, helping the tech basically be made accessible to a broader audience and just get the word out there in all honesty, because we've always had a great tech, we've always had a lot of smart people developing the tech, being experts in their field, but we've initially struggl a little bit to, let's say, make that digestible for a broader audience and really get people to realize the value that that tech can provide in their daily lives. Excellent. So let me get it to Steve from Germany, grew up there, studied there, then came to, uh, Boston, MIT for your masters.
Mm-hmm. Then spent eight years kind of in consulting. Was that here in the US or back in Germany?
Um, That was all over the place, to be honest. So, uh, I worked mostly in London and Johannesburg. Really.
So basically on that vertical axis, because what always fascinated me was to innovate industries or processes that need innovating. And most of the time I actually spent on international expansion for, uh, let's say resource heavy companies, mining, industrial goals, something like that. And specifically on digitizing those processes, because as you can imagine in that industries, there are a few processes that need digitizing.
Yeah. Talk about transformation, right, Exactly. So you were originally the COO of code intelligence.
That is correct. Um, So give us like what was the, what was the reason for code intelligence to come into being, if you will? Right.
Every, Eric, over the years I've interviewed hundreds, if not thousands of founders mm-hmm. Of, of entrepreneurs and everyone. No one, no one does a startup lightly, right?
No one says, yeah, maybe I'll do it. There's nothing else to do. You, you jump in with both feet, your both hands, your head, your body, your guts and everything else.
Right. It's a, it's a commitment as they said. What, what was it about code intelligence that say that made you make that commitment?
So I think initially it was the first launch that I had with the prior CEO and co-founder Sergei, who basically was able to, to paint me a picture of the reason for basic code sales having coming into existence, but also the vision that it wants to achieve. And that is really having a premium security testing solution that is not just thorough and basically gets you to basically find anything that there might be in your code, but also do so in a way that's really accessible for people. Because, I mean, I've worked in strategy consulting for a long time, right?
So basically what I always saw, what bucked me out to no extent is to have a great strategy or idea in place, but then not be able to execute on it because there are resource constraints, budget constraints, it just you and you're not being able to translate it into reality to not make it happen. And I think code intelligence for me was this basically beautiful example of a great idea being born of the University of Bon, uh, let's say professor with three of his PhD students were all still involved in code intelligence to this day who just saw the potential of something from the academic world and wanted to basically bring it into the, let's say, business world to really make it accessible and make it used across the globe. And this is what fascinated me, because this is also how I as a basically non-techie saw a purpose of me being here because basically they had all the tactical expertise in the world and had a great product and a great idea, great vision, but what they didn't have in my opinion, was someone who helped them translate it and make that digestible.
And I think this is also where I see my role here to say, I won't basically be able to tell them what the vision for software testing is because this is basically where they already excel at. This is where why we have customers such as Google, such as Volkswagen, such as, uh, woven out there who work with us on these topics. But what we've seen is that scaling that solution, making that accessible to not just experts, but really at scale to get to the value that it can create, this is something we need to get better at.
And this is something where I felt I could help code inte and our customers in doing so. Got it. Excellent.
So, Leo know, it's funny, right? 2001, I started a security company out in Boulder, Colorado called Still Secure in 2003 or oh four, we launched a product called Van Vulnerability Assessment and Management. And this is when I first really got really involved in the whole vulnerability space, you know, and the world was very different than Eric, right?
No one, almost no one did a vulnerability scan on code pre-release. Almost all of vulnerability scanning was scanning your existing infrastructure and mm-hmm. Code and fixing it.
I was gonna say in real time, but no one fixed it in real time. Fixing it over time, you know, while it was out there it was like changing the engine while the car was driving around the track. Not a great way of doing things.
Not exactly. Uh, and then the whole sort of AppSec shift left. Yeah.
The idea of fixing vulnerabilities in code re-released. Mm-hmm. Uh, you know, it started with, well, pen testing was, was was before, but you know, it, but using those pen testing tools, pre-release AppSec testing, my friend Jeremiah Grossman at White Hat Security early, early on, uh, uh, AppSec as a, as a service basically.
Uh, and we, and that's become, you know, today I always, this always makes me laugh today, 75 or 80% of code is scanned before it's released or deployed. It makes you say, what about the other 20%? What are they crazy?
I mean, how do they release it without scanning it? But nevertheless, most code is scanned. Mm-hmm.
Why is code intelligence better different than other, you know, pre-release vulnerability tests out there? So for me, I would always try to divide the, let's say, current approach that exists to two categories, right? I mean, you have those fully automated, let's say SaaS solutions, static nozzles approaches that do go through your code line by line, but at the end of the day, they don't test your code in execution, right?
So they won't, it will never be able to, let's say, get out to the, to the high complexity vulnerabilities that then only might become present when actually the code has been deployed and when things are too late at the end of the day, right? Or you do, you do have those, let's say, high quality premium security solutions such as fast testing, such as penetration testing as well, but they come with their drawbacks. And the biggest one for me is that there are just a lot of effort and they, a lot of, let's say, time and money that needs to be spent to adopt them and to continue to, to, to leverage them.
And where I see the gap here is that we need, again, to have some that isn't just good in theory, but that also creates the impact that it can potentially create in practice, right? And this is why I think basically having code intelligence as an, as a startup that combines deep security testing knowledge with artificial intelligence and thereby makes it accessible to a broader audience, that in times of resource constraints, in times of budget constraints in ti in times of a tech world that is no longer just going up, up, up without let's say any, any end in sight. I think this is what's needed to also make sure that we can keep up with the times, right?
Because lines of code being created every year is exponentially growing every year as well. Complexity of code and vulnerabilities within that newly created code is also exponentially growing. If you multiply those twos, you just need to change your test strategy, in my opinion, because you'll just not be able to keep up with the times if you don't.
And this is, I think where we come in to help companies keep up with that, those developments and actually be able to sleep at night and confidently tell themselves and their customers that, hey, our product is safe because we haven't only basically run it through the typical, let's say, traditional automated approaches, but we've employed deep security testing in a manner that basically can't really guarantee, because you can never guarantee, right? This is how, it's the issue here, but that's that security exactly. That gets as close to guaranteed guarantee that there are no, uh, vulnerabilities in the code as possible.
Excellent. I, I know you guys recently launched something called Spark, and we're gonna hit on it in a second, but I just want to tie a few loose ends up. Um, who, who is the average cu?
You mentioned some, you know, household names mm-hmm. Earlier as customers, but who's the average customer of Code Intelligent? Is it intelligence?
Is it the large enterprises or anyone, or, you know, how would you describe that? Yes. So large enterprises tick, but for, I always present it as we wanna focus on Word hold her most, right?
We wanna focus on the industries where the downside of having undiscovered security vulnerabilities are the highest. So we work a lot of, with automotive customers, match tech customers, critical infrastructure aviation companies that traditionally might not have been in the software space to such an extent, but for which software continues to play a role that is almost as central as the hardware, uh, one used to be. And I think helping them basically keep up with the times and really ensure the highest level of security possible, I think this is where we want to spend our effort and time.
And for people who wanna find out more about Code Intelligence, what's the website? com. Simple as that.
Easy. Good. Alright, let's jump into Spark.
Yes. So you guys recently released a new, uh, product service called Spark. Tell us about it.
Hundred Percent. Well, this is basically embodying what I've been trying to explain the last couple minutes to really make premium security testing accessible, right? Combining artificial intelligence.
So large language models, genetic algorithms with testing approaches such as static analysis, such as fast testing, white box, fast testing, and really making sure that you don't only find anything there is to be found in your code, but you also do so without the typically required manual effort. So for example, we always, let's say better test our product with code base of roughly a hundred thousand lines of code because we feel that's a good estimate that basically is tangible and let's say digestible for people and represents, let's say, at least a small part of a typical company's repo. And what we've seen is that typically our people spend roughly a thousand hours of manual effort testing that code really at a depth that we felt, look, this is something that we feel comfortable with with Spark that we're now launching to the market end of this month, and that's already being used by our key customers.
We reduce that down to one single command in your CLI. So basically all you need to do is you need to point our tool at your code repository and our tool does the rest for you. So it scans the code, identifies the most critical areas where let's say the most potential threats might lie.
It automatically builds and runs the fast tests required to really thoroughly test your code, make sure it runs in your local build environment, your local infrastructure, and then obviously also adds the benefits from fast testing by generating thousands of different unique test inputs per minute that are automatically refined and smartly generated. So basically they learn from previous iterations and try to discover all unique, uh, let's say paths in your code that might lead to crashing input. And uh, that's what it does all at the push of a button, Really.
Now, um, so it's an agent that runs though in, in your infrastructure? Exactly. So for example, what a lot of our customers do, they plug it right into their CICD, let's put it simply put, right?
'cause what I've learned in my time in tech in the last couple of years is that especially for security testing, if you talk to the developers who build the code, if there's one thing that I can avoid doing and like to avoid doing, it's basically writing security tests, right? Because they wanna focus on what they're good at is what they're we're hired to do. And that's built code, right?
Not test code, not right security tests. And I believe that you will only be able to have a fully scalable test strategy if you will almost go beyond shift left, right? Because if you still need to continuously involve the developer who built the code, you will never be able to scale with the, let's say, uh, demands of the, let's say, modern world of the demands of the, let's say size of the code basis.
You won't be able to deal with legacy code, which continues to make up an even bigger and bigger portion of company's code bases. And this is why we said yes, obviously having the developer involved in that process has no downside, but you no longer need them because you can basically do this automatically by having it in your CICD and then, and this is our, uh, let's say target for 2025. Not only identify the critical vulnerabilities in your code, but also provide an automatic fix for those vulnerabilities that has been proven to work.
Because basically we can just rerun the fast test with the new code that we've been, that includes the fix and make sure that it actually fixes the issue that it found. And even more important, in my opinion, also doesn't create any new issues that hadn't been there in the first place. So I think this is what we're trying to aim towards, to really basically try to provide a central C-S-C-D-A central security team with an AI test agent that helps them focus on what they are good at doing.
And that also frees up the developer's time to allow them to focus on what they're good at doing. And that is building code and actually moving the company forward. Love it.
How is it sold? Wait, ca is it a service monthly, yearly or It's a license model? So basically you only need our license and that typically is sold on an annual basis, uh, for companies to profit from it, from it.
But shorter timeframes certainly have happened in the past and longer ones as well. Um, initially, basically we typically have a proof of value phase of in between two weeks and, and six weeks where we do spend some time with the customers trying to understand their requirements, trying to understand their infrastructure. But the good thing is that typically on day one, we make sure that it runs in their system.
Day, day two, we start finding the first vulnerabilities. So, um, it is quick to implement because again, if it's only good in theory, no one's the wiser. At the end of the day, it does need to work and it does need to be easy to access.
Absolutely. So Eric, let's assume for the moment, spark and code intelligence discovers vulnerabilities without human interaction. Of course, the question becomes what's next?
Right? Who's fixing them? When are they fixed?
How are they fixed? Do we automate the fixing of them? Do we have to let people approve fixing them?
The, the whole remediation piece of it, how does, how does code intelligence interact with that? Yeah, so I do believe that remediation needs to be part of this, let's say test strategy because only a fixed bug is a good bug. Let's, let's put it simply right, that's Bug is a fixed bug.
Uh, But I do believe that especially let's say with the developments in ai, and AI is still, let's say, being in its, let's say early days, right? And people still being for good reason, distrustful of AI and wanting to make sure that basically it does what it's supposed to, uh, but not anything beyond that, that the final fix does need to lie with the, let's say, person in charge with the security professional, right? So what we working on in 2025 is to say, look, you provide a pull request right in your COCD and be it GitHub GitLab during, I think this is basically something we are quite agnostic of, but it only provides, provides a pull request with a proven fix.
But it still needs, there needs to be a human element accepting that pull request and saying, yes, this is something that works because we don't wanna take the control out of our customer's hands. Quite the opposite, right? We just wanna make sure that we focus their time on where it's best spent.
And that is basically reviewing the pull request, making sure that everything has been considered. If it's a complex vulnerability to be fixed, maybe actually check in with the developer who built the code to triple check that nothing can can go wrong, but not get into an automation mode where basically things are happening that go beyond the control of the individual user of the individual company employing code intelligence and employing those, let's say a automatically generated, um, let's say security tests and remediation fixes. Got it.
Alright, Eric, we're about outta time. I just wanna remind people mm-hmm. com Yes.
Is the website Spark is the new AI test agent service. Eric, thanks for joining us. I appreciate you jumping in from Colon.
Best of luck with Code Intelligence and keep us posted. Thank you so much, Ellen. It was great being here.
Happy to talk again. Pleasure. All the best.
All right, you next time. Bye-bye. Yes, Eric Brueggeman, CEO Code Intelligence and spark their AI test agent autonomously uncovering vulnerabilities here on Tech Drunk tv.
We're gonna take a break. We'll be back in a moment.