Securing the Full Data and AI Lifecycle with Noma’s Niv Braun
Noma has emerged from stealth, announcing $32 million in funding along with the launch of its application security platform designed to secure the entire data and AI lifecycle.
Transcript
This is Textron tv. Hey everyone. Welcome back here to techron tv.
I've got a new company to, and a new CEO, a new company to introduce you to. They've recently come outta stealth with a funding announcement. I'd like to introduce you to NIV Braun.
NIV is the co-founder and CEO of Noma. That's NOMA. niv.
Welcome to Tech Trunk tv. It's great to have you on. Thank you very much, Alan.
Thanks for having me. Absolutely. Hey, we're gonna jump into Noma here in a minute, but before we do, look, I've been interviewing and not only interviewing, I've only been doing that 10 years, but I've been meeting with CEOs and founders for 30 plus years.
I founded a few companies myself and, you know, I always liked to see what was the passion, where did they get their passion for founding a particular company? So, niv, I'm gonna put it to you. Where, where does your pa, where did you get your passion for this?
Tell us a little bit about your journey. For sure. So like, uh, eventually I think it's the, the, the, our journey is like, not only like mine, it's through like, uh, me and my, my partner, uh, launch run the cts.
Uh, we basically, we are both like tech guys. They are like from childhood, like we served together in a 200 as well, the Israeli technological unit. And there we kind of like, uh, did like each, each one of us like did a bit a different role.
Like I came from the cybersecurity side and during the old career also, like manage like groups, build products, like in cybersecurity areas, and a lot actually brought from the, from the data science and the machine learning thing. And one of the things that, like what in, in my last role in, uh, like in different company like American corporate that I worked with, I managed a big, like big, relatively big group of 100, uh, 100 people. And, uh, part of this 100 people were also the data scientists and the machine learning and the data engineers of the team.
And one of the things that I truly saw is that while in my group I had great observability and security for all the software developers and all the applications start from the pre-run time up to the run time itself. I saw that, like in the data, the AI teams, I'm completely blind. Like we have no tools, we have no visibility to what happens there.
We have no any tool that help them to work more securely. And then me and alone, we started like to consult about it a lot and alone, like manage like a big group of data scientists. And he told me, Neil, I am like raving it to my CTO every week that like, I'm sure that we have like total vulnerabilities and issues like under my group, but I have no tool like to like to, to, to be able to like, to control it and govern it and help my data teams to work securely.
And then start like to, like, to get into the differences between the classic application security and the software lifecycle to the data and AI lifecycle, which is completely new one. Uh, and then we start like to, to say, okay, we, we, we truly like need, like to make sure that, uh, this, uh, this gap is breached. Uh, also after like, uh, in, in one of the other comp in other groups in my company, they actually got like breached, uh, through one of this, uh, vulnerabilities in the data and AI lifecycle.
And then it was just like for us, like the perfect storm and like their, their perfect reason to say, let's do it like right now. And we started the journey. Excellent.
You know, I, uh, one of the companies I co-founded, we had a vulnerability man access and management, uh, product back in 2003, right? Today there are so many vulnerability scanners out there, right? Big and small.
What is it about the AI data lake and the AI data stack that the existing vulnerability scanners are inadequate to find these vulnerabilities? Yeah, so I think there are three main differences between the classic software life cycle and the data and AI life cycle. The first thing is just like the workflow, the data and AI teams, they truly like work differently from many reasons, from the software developers.
One of the main reason is that unlike software developers that can wait to the real data until they get to production, they can code their code locally and then like to go through the CICD and to meet the real data only in production, the data and the items. They cannot work this way most times because they truly need the data in order already to develop. Like the data analyst cannot work, cannot manage their analysis without the data.
And the data scientists cannot train the model without the data. So they work in a lot of different like areas. One of the area, for example, is Jupyter Notebooks, uh, which is like, uh, the, the kind of like the, the IDE, let's call it for the data and machine learning teams and the, the, these Jupyter notebooks, they work like real differently.
They don't go through the CICD. This is where like the data scientist also like share their code with each other and maintain their code. It can be Jupyter app, it can be on Databricks, on Snowflake or Domino AI platforms.
It can be also on cloud like in services like a w SageMaker, Azure Mail, Google collab, uh, ver ai, et cetera. Uh, and therefore we have kind of like completely like we are completely blinded to, to all the code that they write because the workflow is differently. They true, like don't go through the CICD.
The second is, although exactly like you said actually Alan, like the stack, the stack is that is just different. Like if we look on the classic SDLC stack, so we look on CICD and we look on SCM and if we look on open source or we look on open source dependency. But when we go to the data and AI teams, what stuck like helped them to build their application, their data pipelines and models, it's just different.
One, they work with all these model registries and lops and data bricks, airflow, Argo, like tens of different like systems. Most time they open source is even like open source models from hack face and open source data sets completely different. One, nobody checks all the configuration, nobody scans all these open source, again, completely like light area.
And the third one is actually eventually the, um, the, the tech, the technical characteristics of the technology that they build models are different than classic software model, are statistical are not deterministic. Because of that, there is also new kind of what we call vulnerabilities by design of this technology. Like for example, all the new kind of like, uh, threats that we keep hearing about all the time, uh, like prompt injection and model jailbreak and model denial of service and mold denial of wallet.
That can eventually because the model is statistical, not deterministic. Uh, so I think that like when we look at this all life cycle, start from the workflow and how the data scientist and the machine learning and the data engineers work continue with all the stack and the open source and the different elements that help them to build. And eventually also the technical characteristic of the technology that they build into our production.
We see that like these differences are like, so, so impact. This is why they truly like work differently. This is why you have lops and not only like DevOps, it is truly like practically technically different process tools and technology.
Agreed. Very cool. So I I, so we hear your passion right now, it's come out.
So you've, you found Noma with your co-founder. Um, when did this happen? Give us kind of the NOMA story now, if you will, right.
How you recently launched and announced funding. Yeah. Uh, so we started, uh, on the October, September, October of, uh, 2023.
And since, uh, like a before that we, like, we truly took some time to build our thesis to speak with a lot, a lot, a lot of prospects. We already had a lot of customers even like before we established like officially the company, like a lot of like, uh, prospects that were like, like were waiting for us to build the product so they will be able like to start and use it. And then we started, we started in October and things ran like, uh, gladly very, very well.
Uh, up until now. Uh, we very quickly started like to work with big enterprises, including Fortune 500. Uh, we released more and more products, uh, very quickly.
Uh, we actually didn't even like, uh, we haven't launched, uh, officially the, the company, uh, because the bottleneck until now was still like more like the r and d, like we had like more like a potential like a POC and prospects and customer to start to work with than we could true, like handle. And for us it was very important to start already day one to build a platform. I think that like in the classic application security, one of the things that we see that like organization today really struggle with is the fact that in order to cover the whole AppSec start from the scanners to the CICD, to the, to the runtime, you need four different far different like product.
And it's, uh, it, it's, it's difficult for us, it was very important that once we cover for the organization, for our partners, the data AI lifecycle, we truly cover it end to end from the pre-run time after to the runtime from the classic data pipelines in the machine learning up to gen ai. And it took us a while to like, to build like this critical mass. Uh, and as I said, like we gained like more and more and more amazing customers and partners that they also pass through like to, to also like to, to pave this path.
Uh, and now after like, uh, like on August, on September, uh, after like, uh, also like people around like, so the, the great traction and the great, uh, uh, references, uh, that we get, most of our customers actually got from other customers of us that like referred like on us and recommended to users. And for us, this the Best kind, Exactly the biggest compliment that we can get. Um, and therefore some amazing, uh, business approach just to, to, to start like also like an A round.
It came for us in perfect timing because we want to accelerate and we want to run, uh, big and fast. And now we partnered also with, uh, with ballistic, uh, amazing partners. And we're, uh, we're running fast.
So Ballistics is the strategic investor. Yeah. So the, the seed round was led by a lot capital together with Cyber BA of London and a lot of amazing, amazing, amazing, uh, angels that, uh, help us a lot, uh, mainly because they are like really like very experienced seesaws and security executives that like understand the need, like so deeply.
And we love these kind of partners to consult with all the time and to get their perspective. Um, and the A Round was led by, uh, by ballistic and together with, uh, again, OT more angels that, uh, that, uh, got on board and soon we're going actually like to, to release and to publish, uh, some more, uh, amazing partners that, uh, that joined this, uh, this journey. Fantastic.
Um, so is the product in GA now or it's still sort of in limited Total n ga total n ga and ga. Yeah, and like all the different products of the platform, by the way, like the platform, because as we said, we truly like provide the holistic view start from the pre-run time up to the runtime. So the platform is actually built from three main products.
The data and AI supply chain security, the AI security posture management that checks all your model, build inventory of all your models, tests all your models to make sure that they're secured. And then also the runtime side, the AI runtime protection. All the three products are already, like GA are fully used.
They're daily used by our customers, big enterprises on daily base. And so yeah, 100%. Very cool.
Very cool. Um, you know, I didn't even ask, what's the website? security.
Do security. Anything behind the name Noma is always some reason you picked that name. Yeah, so, uh, actually it was like several reasons, but it started from, uh, NOMA was, uh, one like the most amazing restaurants, uh, considered like the, the best restaurant in the world, but it was actually like more than a restaurant.
And this is what we loved about it. Like Noma officially it's like the the restaurant, the restaurant for us it's like the, the business. But the real thing, like the real cool thing about NOMA is what is that?
It was like, at the background, it was truly more like a kind of like a research institution of like food and how we truly like works in behind, like they truly like drilled to what, like in our case, it like true, like the te the technology. Like we truly love the technology. We truly love ai.
For us, like we, we, one of the most important things for us is that we kind of like bridge the gap between the language gap between the data teams and the AI teams and the security teams. We don't want just to secure the organization. We truly want to make this common language to work together and to push forward the data and AI operations inside the organization.
And this is where the original, like it came from that like NOMA is not only, okay, it's a business, it's a company, it's a platform we like, like we, we, we work with like external like, uh, of course like, uh, uh, customers that we see as our partners. But in our core, we truly like researchers. Like this is what we do.
We, we, we, we love food, we love technology. So this is where it came from. Got it.
I love it. I love it. Um, nif, I wish you ton of luck.
You and the whole team there with Noma. Um, we'll be looking for big things coming forward, right? This is yet another, a new, a new, uh, frontier or a a, a new well could also be a new attack surface, unfortunately.
Right. I come together. All right.
Best of luck, man. Thank you. Thank you very much, Alan.
Alright. NIV Broad co-founder, CEO of Noma here on Tech Drunk tv. Check him out, Noma Security.
We're gonna take a break. We'll be back in a minute here on Tech Drunk tv.