How Lineaje is Rebuilding AppSec for the AI Era
For the last two decades, the AppSec industry has been chasing its tail, relying on reactive scanners that completely fail to detect malicious code deeply embedded within the software supply chain. In a compelling interview on Techstrong TV, Lineaje CEO and co-founder Javed Hasan explains why the explosion of AI-generated code means organizations can no longer afford to simply “scan and pray.” Hasan details Lineaje’s radical new approach, shifting from vulnerability discovery to proactive threat elimination by swapping vulnerable dependencies with “Gold Open Source,” ensuring that applications are inherently secure from the ground up.
Transcript
Hi, everyone. Welcome back to Techstrong TV, and thanks for joining us on RSA Week. RSAC to be exact.
Um, let me introduce you to my next guest here. His name is Javed Hasan. com, L-I-N-E-A-J-E.
Javed, it's great to have you on here. Thanks for joining us. Thank you, Alan.
It's great to be here with you. Thanks for the invite. Yeah.
So it's a busy week, especially, you know, for anyone in indus- in security, it's a busy week here. You know, someone said something on a video I was doing earlier today that the rest of the world outside security doesn't understand how big RSA is, RSAC is, because it is so inward-focused, right? Yeah.
It's kind of a security for security or security conference for the security industry. But, before we get into all that RSA stuff and what's going on in the world, Javed, let's, let's talk a little bit about you. I mentioned you are the CEO and one of the co-founders of the company.
But how, how did you come to that? Give us kind of, you know, what happened Javed before Lineage. So, so Alan, you know, I've gotten old for in, in cybersecurity.
So, you know, it's, uh- You and me both. Yeah. So, you know, for the-- for the last twenty-five years, I have been working at, two large security companies.
One twice each. One is Symantec, and one is McAfee. And, you know, so, so, so a number of roles in cybersecurity, worked with almost every cybersecurity domain you can think of.
You know, key roles I've done is I ran the largest business unit for Symantec, Endpoint Data Center and Cloud. And, I, I, you know, I ran overall portfolio strategy for McAfee and then helped, create Trellix and Skyhigh by merging, by de-- by, by defining the strategy for putting together McAfee and FireEye. Right.
And- Wow. Right. So, so, you know, so, so been around the block and, you know, being in Silicon Valley, I thought, you know, at some point, one should do a startup, and hence Lineage.
Mm-hmm. Love it. Yeah.
We'll talk off camera. I had so many friends over the years at both of those companies, right? From my...
I'm also in s-- We didn't call it cyber then. We called it infosec, right? Yeah.
But I'm also in security twenty-five plus years, and, it's been a lot of water under that bridge, right? Yeah. So but no one says, "Hey, I think I should do a startup.
Well, let's do one. " You know, and does it. Right.
We do a startup, and I've, I've founded three, four, or five companies myself over the years. I've interviewed hundreds, if not thous- probably thousands at this point of founders, entrepreneurs. There's always some passion that drives you to do this.
There's some problem that you feel absolutely needs to be solved. It may be a problem that you yourself faced, you know, in your past positions, maybe a problem that you see out in the industry, but there's some problem that you're gonna solve that somehow is gonna make someone's life easier. What was that passion?
What was that problem in Lineage? So, so the... If you think of, of software these days, so first thing is where is the cybersecurity industry?
So, you know, I'm a strategic guy. You know, I've done strategic roles. So I just sort of looked at it.
When we looked at it at, at the end of, McAfee/the creation of Trellix, we felt that there were a large number of companies in what we call runtime security. Yes. So if you think of, of Palo Alto, if you think of McAfee, if you think of Symantec, CrowdStrike, they invest all their effort in making sure that you run securely.
So the firewall runs, secures production areas, and so on. Now, as we looked at software and anew for the last twenty years, there have been attacks that are inherently built into the software before it is deployed. So when you have runtime security, you assume what you are protecting is clean, and so you're protecting it from outside attackers, fundamentally.
So if you start now looking at it differently, SolarWinds that had happened, right? Those kinds of attacks. Log4j had become very important at the time, right?
And what happens is that if the software is inherently malicious or weak, how do you secure something like that? And if the software itself is the attack vector, like SolarWinds was, so it's an inside out attack. So the interesting thing-- And so we call it a supply chain attack.
And for the last twenty years before that, supply chain attacks have been happening. And the most interesting thing about... And there is this category of tools called AppSec, but no AppSec vendor has ever detected a supply chain tamper or attack.
So if you think of it, the software as it is being built can be compromised. And no vendor, if you go back, and not one will claim that they would have detect-- or they actually detected a SolarWinds or a supply chain compromise. So we felt that with more and more software being built and becoming critical, how do you essentially build software, secure software from scratch?
And, and hence we've looked at it-And if you so-start thinking about it a little bit more deeply, which we did at Lineage, we've-- what we f- what you find is the problem is not the fact that developers are writing fundamentally insecure code. The problem is that we're using more and more of third-party components in our software. And so if you now look at a modern application being built in the, right, last five years, or last ten years, seventy to ninety percent components are sourced, and ten to thirty percent are built by developers in-house.
And AppSec fundamentally assumed that by looking at the code inside a company and scanning it, somehow you can get developers to fix the seventy to ninety percent that is sourced. Right? And that, we believe, is a fundamentally incorrect assumption.
The more-- The correct assumption is that if you can source safe components, then by and large, your software will be secure, will be built secure. So we didn't see a significant player in that space. We didn't think any of the AppSec companies were trying to solve the more fundamental supply chain problem, so hence Lineage.
So the name Lineage actually comes from lineage of software. So if the first thing you try to answer is, you know, so the clue is in the name, where does your software come from? What is its lineage?
And the second thing then you say, where does risk come from? Does it come from your code or the code you source or third-party code that you keep? And then how do you eliminate risk in your, in that code?
So that's Lineage in, in, in a nutshell. I love it. What a great story.
You know, this is why I ask these questions 'cause I, I, I, the entrepreneur in me that, you know, I find it fascinating, right? What... How we identify issues in the industry or issues in, in people's workflow and, and, you know, how, and how it leads to companies, real live companies like this.
com. So, you know, if you're interested, head on over there. You can get information.
Javed, I wanted to spend the rest of our time talking about what's going on in the AppSec world. You know, there are a lot of, there are a lot of people clutching their pearls and running around henny penny saying the sky is falling, that A-AppSec is dead, that AppSec will never be the same, that Claude Opus and Claude Security, code security, the amount of vulnerabilities, vulnerabilities or the, the amount of potential vulnerabilities that it's finding. The idea of checking the code right in, right, securing the code before we even put it into the supply chain.
All of these things that, that AI is bringing to the table have, have moved the cheese in AppSec, if not downright changed the whole game. Um, we're seeing o... You know, it's having a tremendous effect on open source, right?
These maintainers who aren't paid to begin with can't keep up with the avalanche of, of bug reports. Even pri-private company vendors- Mm-hmm ... can't keep up with it.
Um, so we're gonna need a better mousetrap, I think. I think as an industry, we need to adapt to this new reality. I wanted to ask you what you think about that and what you think, you know, the, the, the smarter AppSec or the better AppSec strategies are given this new reality we're living in.
So the... And I'll say a few things. So the first, first thing is, you know, Claude Code will become better and better at writing code.
No doubt. Right? I mean, it's, it's the beginning of that, right?
So and Claude Code, at some point, we should not need Claude Code Security to write secure code. So inherently, we, we should assume that a year from now, Claude Code, as are many of these tools, will inherently write secure code and don't need a layer, additional layer to find issues. Well, if-- Right?
You, you only need it if you're writing insecure code. So that's one, I think. So the-- So if you sort of now go back to the analogy I was talking about, Claude Code is writing what we would call first-party code and then bringing in dependencies from open source.
Now, if you touch open source inside a company, whether through Claude Code or through Claude Code Security, you then own the fixes of it, and now you are fixing open source code. So most companies, most organizations are not that interested in fixing open source code that they ingest, because now you have that responsibility of maintaining it, updating it, you know. There's a certain cost structure that comes with it, and in most companies don't fund their development houses for it.
So with the way we see it, Claude Code and other tools beco-will, are beco- going to make Claude Code Security and other tools working with Claude Code are going to make first-party code writing much more, much better and, and more secure. They will still have to bring in dependencies, and the dependencies are increasingly not just normal open source, but AI dependencies, right? At, you know- Mm-hmm.
So if you think of MCP servers, LLMs, you know- Sure ... all, all that stuff that's, that's coming in. Right?
So, so now you, you start moving i-into that domain. So which is why, like I started by saying this first-party code, I think first-party code actually did not have, when even it was developer-written, as many vulnerabilities and risks as, as the third-party code and open source brought in. In fact, ninety-five percent of the risk in modern applications is sourcedNot created by first party code.
So if you think, so this is the more fundamental problem, this why linear is born. So what we did is we have created we something we call Gold open source. And what is Gold open source?
Gold open source is we take on the responsibility, and we fix and give critical, high and exploitable vulnerability-free open source packages that developers can use. And Claude Code and Claude Code Security give us an opportunity, for example, and I think this is the future of, of AppSec, is to provide safe components that are already risk-free. And so as Claude Code writes code, it brings in a dependency A.
We just swap A with Gold A, making sure it's secure. So we think these are great changes. It does move the focus away in a very interesting way from finding bugs to, to or finding vulnerabilities and prioritizing them.
" So we no longer have to go, you know, companies no longer have to go and, and deliver applications that say they were ten percent of the vulnerabilities are fixed because ninety percent were deprioritized. And deprioritized still means they exist. It simply means that they were not-- we found a justification for not fixing it, right?
And like so today, about one and a, one and a half percent of all vulnerabilities are exploitable. Now, AI, offensive AI is already showing that with appropriate AI, tools, you can now exploit about eighty-seven to ninety percent of all vulnerabilities. So the number of exploited vulnerabilities will, will continue to increase, so you have to fix all of it.
And I think th-the way we see it, Claude Code Security, Claude Code, working with Gold open source can fix, eliminate one hundred percent of the vulnerabilities so that you don't have them at all in your, in your code. So I think it opens up a great future, but Claude Code Security plus, plus with safe open source is the solution there. I agree.
Yeah. I agree. You know, and, and frankly, that's the way it should be, right?
Because that's what good entrepreneurs, professional, you know, strategic folks, you don't, you don't clutch your pearls and say, "The sky is falling," you know? It-- I think every successful entrepreneur I know is a, is an optimist. " Right?
And, and, and it's the same thing here, right? Look, the game's changed a little bit, but it creates opportunities. It creates opportunities for us to do this better.
Yeah. And, and so, you know, and I'll just add one more thing to what you just said, and it, it does. Sure.
So, so then the question also is, you know, so if you now look at AI systems, we, we just touched on them, right? " Now what we are seeing is the rise of a new attack surface. So see, so now you're looking at we are, we are hearing terms like prompt injection attacks.
We are hearing things like reasoning compromise, LLM poisoning, data leakage, which is very different from threat. So what we are suddenly seeing is that new software, new a-agentic AI software actually is introducing a new category of risks and threats. And so one of the things that we are completely transitioning to is how do you build AI applications that, that are not just vulnerability free, which is just we have one narrative, that are now threat-free, that, that are self-hardening, they protect themselves automatically.
So no prompt injection attacks, no reasoning compromise, so on and so, right? No data loss. Agent identities are well controlled.
So as old things get better, the cybersecurity is a world where new challenges come continuously. And so we announced a new product and I, you know, it's the first time I'm talking about it, called Unifi, Unifi AI, so Un-Unifi AI, which is all about how do you build secure agentic AI applications, so you are inherently built secure, right? And, and which addresses all of these, new, new threat vectors and new weaknesses as you build agentic AI applications.
So we are very excited about that. So I'd like to say, you know, there is a horse in there somewhere, and we think- Absolutely ... that the secure AI is the new horse.
So, you know, there was a conference last week, they talked a little bit about agentic AI and security, right? Uh, the, the NVIDIA thing, and it, and it... Look, clearly, clearly, the agentic AI, I mean, even more than Claude Code Security and Opus and all these things, the idea of, of the code being generated and, and how agents are, are, you know, just exploding- Yeah ...
on, on our workflows and on everything we do, but the one thing that can really hold that back is, is security, right? Yeah. Because these things need guardrails, they need governance, they need compliance, they need security.
You, you, you, you, you, you, you, you nailed it, right? I mean, so, you know, in, in, in this last week's conference, they talked a lot about Gold Clock. Yeah.
And Gold Clock is phenomenal, right? I mean, we, you know, the question is how do you secure Gold Clock, right? So, so, so, so, you know, they announced a little bit of, of movement there.
Mm-hmm. And you will see Lineage go down the same path with saying, how do you secure any agent, right? And, and, and, you know, and so, so I, I think that's Unifi.
So we're very excited about, about that opportunity and what the new world is opening. So is that, is that available now, Javed? Yes.
We annou- we, we, we announced it last Thursday. Mm-hmm. So it is absolutely available just in time for RSA.
So very excited about it. It's the first industry's first autonomous AI policy orchestrator, enabling companies to define security policies and then apply them autonomously as software is, is built. Love it.
Javed, we're about out of time. I apologize, but it was a great conversation. You look, you know, you're gonna be out in San Francisco this week as well.
I'm there. Stop. We're on, we're on Broadcast Alley all week, live.
Come by, say hello. I'd love to see you in person. Yeah.
I, I, I will come by. A-and, and thank you for a great conversation, Alan. Thank you.
Thanks. Javed Hasan, co-founder, CEO of Lineage here on Techstrong TV. Enjoy our RSA coverage.
We'll be back with more.