Payton O’Neal on Apiiro’s Open Platform Strategy
Payton O’Neal, head of marketing of Apiiro, delves into how Apiiro is cementing its position as a 100% open platform by integrating with any security solution a customer requests within a few weeks. Initial launch partners include big names such as Bugcrowd, Mend, Snyk and Wiz.
Transcript
This is Techstrong tv. Hey everyone. Welcome back here to Techstrong tv.
I'm happy to be joined by my friend Peyton O'Neill. Uh, Peyton is the head of marketing at the company aro. That's a PII ro Peyton, welcome to Text Drug tv.
How are you? Hey, Great. Always good to see you.
Always Great to be here. Nice to see you. Um, Peyton, we're going to, well, we've got a lot to discuss today, but you know, not everyone out here knows Peyton, like I know Peyton.
Uh, why don't we, why don't we start a little bit about, well, for now, but we're gonna, they're gonna notate now. Tell 'em, tell 'em a little bit about you and I, I said you're head of marketing at API o, but let's, you know, let's talk about your journey. Sure, yeah.
I've been at API Rro a little, almost a year and a half. Um, prior to API o um, I was at a startup, kind of the first infrastructures code security startup, bridge crew, the creators of check gov. We were acquired by Palo Alto.
So an interesting journey there. And prior to that, over the past 10 years or so, I've been in DevOps, software testing, AppSec, um, DevSecOps all around. So marketing, We call a, well, a well rounded resume, huh?
Yeah. Yeah. Very cool.
I love, I love early stage startups, love building, um, from scratch and really creating interesting stories, and that's what I get to do every day. So it's great. Very Cool.
And talk to people like you. Excellent. Well, I always think it's my, you know, uh, blessing in life to talk to people like you because this is a great way to make a living.
Right. Um, so a piro, some of our audience, I'm sure is familiar, but I probably have lots of people who aren't. Give us kind of a piro, kinda where's it play?
What's it, do you know what gets you, what do you think of the special sauce is? Yeah, so I'll start at kind of like the, the textbook definition. So API's, um, a leading player in the new emerging market application security, posture management, really just kind of gained steam last year.
Um, Gartner kind of gave it the blessing with an innovation inside report. And, um, it's actually become quite a busy, uh, space since then. Lots of vendors kind of tackling it and coming out of the woodwork from different sort of niches in supply chain security, application security testing, um, and even like cloud security.
And I think we'll see more of that in the future. Um, but what the core of A SPM is trying to do is unify all of your security signals, um, help application security teams primarily focus on what the highest bid business critical risks are, um, and give them all of the insights they need to fix them, to automate fixes, to embed developer guardrails and their tools and workflows, uh, to ultimately, as the name suggests, strengthen your application security posture over time. Um, so API O came kind of from an interesting angle.
Um, many of the players in this space came from more of the, like aggregation. There was a, uh, sort of nascent category called application security orchestration and correlation as o so many of those just integrated with a bunch of tools, aggregated them, gave you kind of like the single pane of glass API came from a very different, um, direction and, and origin. What we focus on from day one is integrating into source control managers and making a full complete continuous inventory of your, all of your application components.
So we extrapolate literally everything from your code bases, from APIs and all of the, the development frameworks you're using, including gen AI frameworks, which maybe we can talk about later. Um, every languages we're monitor monitoring, all development behaviors, um, every single code change and creating this graph based model. And we enrich it with some runtime context as well.
You know, you need to understand if something is deployed or internet facing. Um, but with that foundation then we're able to bring all of your security signals in from your open source tools and your secret security, um, and then use that foundation to prioritize. So we came from a very different space.
Um, it's really our crown jewel. It's really what sets us apart, um, and gives us that rich context for much better prioritization. The word prioritization gets thrown out all over in A SPM, but your prioritization is really only as strong as the underlying context.
And that underlying context has to come from deep, deep, deep knowledge of your application architecture. I love it. So that's sort of the high level.
Um, I didn't really talk much about the, the business value or like really the, the outcomes. And there are three that we boil them down to. So one is purely visibility, uh, because EC teams are typically fairly siloed from development teams.
They don't even know really what's in their, their repositories or their code bases. Um, so obviously that has implications for like material or significant change tracking that many compliance and regulatory frameworks require. Um, it makes it really hard to know even where to focus your resources and even your tools.
You know, you don't know, should I be running daft over here? Is that a business critical application for me? No.
Um, so really just pure visibility is really, really important. And many of our customers come to us just starting there. Then two is being able to then prioritize what to focus on.
There's no way our customers are getting to, to, uh, backlog zero, you know, so it's all about figuring out what you can actually fix and what you should fix. And then third is the governance piece. So again, those guardrails, being able to prevent risks and harden your posture over time.
I love it. You know what I've always wanted to ask and I never remember to, what, what's the deal with the name of piro? The double I?
Yeah, it's funny, I dunno If you, you know, but it's, Yeah, I do. So in Greek actually it means infinity. So it's sort of this idea that the development lifecycle is an infinite loop.
Um, actually our logo is like a code bracket, but put together, um, to make like an infinite code loop. Um, and really that's the ethos. Like AppSec teams cannot keep up with just the continuous evolution of changes daily.
And applications are so, so, so complex, especially of course, with cloud native technologies. Um, last we chatted was at Kubernetes, so that's yeah, a very complex landscape that AppSec teams just don't have visibility into and just can't keep up. So that's what we're all about, trying to help them keep up.
Got it. You know, I actually, so this is studio A here in our Textron headquarters. Studio B is the big sound stage on the other side of our offices, and I just ran from there to here to do this, uh, interview.
But we were recording Textron Gang in there and, and, uh, on Textron Gang, which will air Monday. Well, by the time people watch this and it'll already air. Nice.
But we, there was a survey there about what developers, how developers think AI could help with AppSec, will it help with AppSec, you know, was the threshold, only a third thought it'll help with apps, AppSec, which I thought was low, but, um, interesting. Uh, I just, you know, and then another question was how can we use AI to give us better security Yeah. Visibility into Kubernetes.
Yeah. So it seems like every, you know, all roads as much in the world today is pointing to this AI thing, but specifically, how's AI gonna help with AppSec? And I know that's not the topic of our discussion necessarily today, but I'm sure it's Probably one of mine.
Right. And I'm sure you're getting hit with this too. Yeah, And we talked to analysts and journalists and customers all day and get that question a lot.
And we, we break it down into kind of like three buckets. Um, and even those three buckets are just a teeny tiny slice of how gen AI or LLMs, um, have security implications in general for software development and security. So one is, I think what you're getting at, which is how are app set companies or security companies leveraging generative AI to help detect or remediate?
So I think those are the two main use cases. Um, I think it's, it's a great technology especially to, to, to de detect, um, like malicious code where it's not easily, it's not like a binary thing, like a vulnerability. Um, so I think there's tons of, um, innovations we're working on some, uh, we've put out some research recently how, uh, we detected a very, very prevalent malicious code campaign on and GitHub repositories.
And a big part of figuring that out was using, um, an LLM methodology that we built. So that's kind of one, and also for remediations too, because there's so many factors that come into figuring out how to fix something at its source, who to work with on a development team. So I think there's some, uh, use cases there.
Two is actually being able to understand the models and the frameworks that are in use. Um, we're tackling a little bit of that now just by detecting what, um, development gen AI frameworks are being used, like hugging face. Um, there's lots of unanswered questions right now around privacy, even like intellectual property, um, and like security vulnerabilities as well.
So step one is just knowing what you have. And then the third bucket, which I think is, uh, there's a lot of debate on the internet around is, is generated code from like AI assistance like GitHub copilot, is that code inherently more or less secure, um, than what a regular human being would write. Um, and I think that that's a really interesting conversation.
There's no way, you know, we're looking at code and saying, oh, an AI assistant wrote this, but we can use different signals. Like we can tell, um, if a developer has a copilot license to say, okay, here's, here's one piece of information, we can maybe use that as correlation and say, make sure that we have security reviews on this commit or pull requests. But at the end of the day, you should have those reviews regardless.
So it's kind of like a, it's an interesting debate, like, is it, is it more or less secure? Inherently, I think the jury's out. Excellent.
Alright, let's jump into, I probably, it took more time than we wanted, but on the other stuff, but we really are here to talk about this new API integrations program that you guys are launching. Uh, it'll be in full out in full, uh, or said RSA net, uh, conference next week. People can see it there.
Um, but talk to us, what's it about Peyton? Yeah, so folks that know of API rro, um, probably mostly associate us with, um, having, as I kind of already talked about, really strong depth and visibility into applications. And we also have some native risk detection capabilities for secrets, open source, um, and supply chain, which we launched last year.
Um, and some other use cases. Um, I don't think that we've been particularly known for our integrations. Um, and so we decided early last year we're doubling down.
Um, we are building integrations with everything and anything. Um, and there's a couple buckets, uh, which I'll talk about, but really this program launch, um, the program is called shine, uh, which stands for our guiding principles for the program that all of these integrations are seamless. Uh, it's getting a holistic view, uh, across tools, processes, whatever.
Everything is interconnected, so it's not shallow, just aggregation. We're really creating this interconnected graph based model of all of these signals, um, vendor neutral. So there is a lot of competition in this space.
Uh, we really don't care. Uh, no tool is too big or too small. Uh, we'll integrate with it.
And lastly, back to our kind of like our crown jewel, uh, we're enriching all of these findings with our deep, uh, application knowledge. So love it. Shine program is launched, shine with API o.
Um, it's really reinforcing our commitment, uh, to be an open A SPM platform in addition to our core strength, which is really our, our depth. Um, so we like to say we're setting the diamond standard for A SPM, uh, we're combining this real deep knowledge and we have risk domain, uh, uh, specific domain expertise. We know what it takes to make a good secret security solution.
So we're taking all of that expertise to building the models for which we ingest security alerts. Um, and we have some awesome anchor partners that we are doing this launch with. Um, so yeah, it's this best of both worlds.
We have the dub now we have the openness, and that's what especially enterprise customers need and are looking for in an A SPM. It's this ability to get a complete unified view of their applications and their potential risks, and then use API o as sort of this single source of truth to then get to the bottom of the highest critical risks and fix 'em faster. Got it.
Let's, um, I I, I, I know it's early and everything else, but could any like, uh, participants in the program that you can announce already or? Yeah, so we have several You get in trouble. Oh, no, no.
Everything is public. Uh, we have a new kind of integrations catalog on our website. You can see across all the different categories from just like source control managers like GitHub, GitLab, um, to SIEM tools and communication tools like Slack, um, to really, like, I think what's more interesting for the story security tools, so right across SCA SaaS das, API, security, cloud security, um, even manual processes, uh, like your Bug bounty program or your pen testing, um, secret Security and Container Security.
I think I caught all of them in kind of a weird order. But those are the categories. You hit them.
And, uh, or anchor partners for this launch are check marks, men, JFR and Bug Crowd, which I used to work at at, so Oh, good friends buy, yeah. Amazing group of people. It's been really awesome working with all of 'em.
Um, and they, I think what's important about these anchor partners is they share the same sort of open ethos that we do. You know, we have overlap. Every single vendor in this space has overlap with at least another vendor.
Um, and we acknowledge that and we understand that at the end of the day, our customers do not care. All they need is a way to connect everything. And so this partner, this partner program, integrations program is really, um, enfor reinforcing our commitment to do that.
Um, and it's been great to work with these, these partners, anchor partners to, to help us make that a reality. Excellent. Good stuff.
You know, um, well premature I can and out yet anyway, so, but, um, those, those are great anchors to, to launch with. Good, good stuff, Payne. Good stuff all around.
App Piro, as I mentioned is A-P-I-I-R-O. com. com?
Just go to the main site? Or is there Anywhere LinkedIn? Yeah, our blog has, um, the launch and we put out a press release as well.
So anywhere you go on api, you'll find something. And again, you can see that whole catalog, several dozens of integrations beyond what those anchor partners that I mentioned. Um, so yeah.
And of course you'll be at RSA if people are coming to RSA, maybe they're coming for our DevSecOps AI program on Monday, May 6th at Moscone Center. It's the eighth year we're doing this with RSA. Uh, but otherwise you come check Us out.
We're the south, south expo hall, bright green as always. You can find us. Okay.
Um, we have some really cool giveaways this year. Uh, new brand new sock design, which everyone is very excited about. Um, and we do have a party on Wednesday night, again with some of our, our anchor partners as well.
So it's gonna be a good time. Oh, so I wanted to mention we have a party Wednesday. It's not really Wednesday night we start at five.
I've heard, So I've done the security Bloggers be good. Yeah, it's, we, well, we renamed security bloggers, meet up, security creators meet up. So if you do security content b, we'd love to see you there.
I Know you course, so get ready To Go to Allen's event and then come to the after of event after The hero party. I might, you might see me there too then. Yes, we hope so.
If I stay up that late, I'll, I'll try. Um, Hey, Peyton, it's great seeing you. I will see, I, we will also of course be live at, uh, broadcast alley all week, so come say hello to me and, um, of course, good luck with this, uh, a I PPI Integrations Program.
Thanks so much. Have a great one. Thank You.
Peyton O'Neill, head of Marketing and a piro here on Text Drunk tv. We're gonna take a break. We'll be right back.