About Graphiant NaaS with Arsalan Khan
As enterprises accelerate AI adoption, data governance and network security have become inseparable. In Graphiant’s Networking Field Day presentation titled, “Why Data Governance Demands a Unified and Secure Approach to AI Networking,” Graphiant explores how a secure, compliant, and unified networking infrastructure is essential to enable responsible AI at scale.
Arsalan Khan framed the core problem: enterprises are investing heavily in AI, but their data is siloed across on-prem data centers, multiple clouds, and emerging neocloud providers. This creates massive infrastructure headaches, high costs, and significant security risks. The challenge is compounded by complex data governance regulations, especially for sensitive PII in finance and healthcare. Khan noted that while traditional networking struggles to “catch up” to new technologies, AI demands moving the “whole haystack,” not just finding needles, making network-level control and compliance essential from the start.
Graphiant’s solution is a Network-as-a-Service (NaaS) built on a stateless core, which functions as an overlay/underlay network operated by Graphiant using leased fiber. This provides a single, ubiquitous fabric for any-to-any connectivity with SLA guarantees. The key, Khan emphasized, is simplifying the “plumbing” so businesses can focus on their AI goals. The platform provides centralized visibility and control over metadata, allowing enterprises to see traffic paths and applications (without decrypting payloads) and enforce granular policies, such as guaranteeing that specific data never leaves a geographical boundary. This approach aims to provide the auditability, security, and cost-effectiveness required to manage modern AI data flows.
Presented by Arsalan Khan, Chief Security Officer. Recorded live at Networking Field Day 39 in Silicon Valley on November 5, 2025. Watch the entire presentation at https://techfieldday.com/appearance/graphiant-presents-at-networking-field-day-39/ or visit https://techfieldday.com/event/nfd39/ or https://Graphiant.com for more information.
Transcript
My name is Alan th I am the Chief Security Officer at Grapht. This is my second time presenting here at Networking Field Day. Third time overall for Grapht.
Uh, there's quite a few folks on the panel here who have been there at our previous sessions, so nice to see a lot of familiar base. Today, we'll talk a lot about what we've been up to over the last year, year and a half since we last presented. Now, before we jump into those details today, the presenters are going to be myself as well as Vinne bu, who is our Chief Product Officer.
So we'll go into the details of the technology that we've built, the focus that we've had in the AI space, and the problems we're looking to solve, and what role the network plays in this kind of new evolution that we're going through. Now, before we jump into the new fun stuff, I want to do a quick recap of what graphene is, what we've built, and what kind of capabilities we provide. At a high level, graphene is a network.
As a service company, that term means a lot of different things to a lot of different people. What it means to us is we focus on providing an agile on demand network. This network is meant to scale and grow as your needs grow, and it gives you certain fundamental capabilities built into the network itself with a big focus on security as well as reliability.
Now, the key things that we tend to focus on are the service that we offer needs to be cost effective. This means whether you're looking to deploy, whether you're looking to expand your network or you're simply operating your network. How do we simplify that experience for you and make it cost effective so that it's possible for you to continue to grow your network without having to worry about exorbitant infrastructure costs and delays?
Additionally, it is extremely important to make sure security and governance are covered as part of the solution. With the focus on moving a lot of data through networks, it is extremely important, especially looking at all the data breaches that have happened. We need to make sure that at every layer of the infrastructure, we are accounting for security and govern.
Now, using all of these capabilities, our fundamental focus remains, how do we enable you and your business to solve more problems without having to worry about how will I set my infrastructure up? A fundamental piece of this solution, this is something we've talked about a lot in the past, is the graph and stateless core. The idea behind this is fairly straightforward.
We want to provide a reliable SLA based network that gives you any to any connectivity, whether you have on-premises, locations, data centers, branches, edges, cloud locations, multiple clouds, different regions. You want to be able to connect all of them using a single ubiquitous network fabric. You shouldn't have to worry about the connectivity piece, where a cloud region now needs to be treated as a separate entity.
When it's added to your network, a new cloud provider becomes a whole different headache for a networking perspective, you should be able to consume all of this in one simple fabric, and all of this needs to give you SLA guarantees. So this stateless core is a multi-tenant system. It's something that's operated by grapht.
For you to consume it, you simply connect into this stateless core, and then you can start consuming bandwidth out of our core itself. So looking beyond those fundamental capabilities, what have we been focused on over the last year, year and a half, just like everyone else, we're focused in the AI space. Now, what is critical here is there is a proliferation of AI going on.
Enterprises are investing heavily. All sorts of businesses are investing heavily in AI tools. This may be for internal purposes, it's for features that they are rolling out to their customers.
Regardless of what scope it is, regardless of what sector your business is in, everyone's investing in ai. But the key thing for them is they want this AI to be built on their data. You don't want to use generic AI because you want this AI to solve your company's problems to help people use your products.
This is also very relevant because the focus for AI is efficiency and a big push as you roll out AI capabilities is how do you do this quickly? How do you adapt to the evolution that's happening in this space? Now, this creates a whole set of problems regarding infrastructure, data, mobility.
It's very easy to say, I would like to use all of my enterprise data to train my AI models, but if you look at the problems that exist, data is going to exist in a lot of different locations. You have data living on the edges, on premises, data centers, different cloud providers. Plus, while you're looking to build out this AI infrastructure, there's neo clouds that are showing up which allow you to train your models at a much more cost effective solution.
You want to be able to extend to consume those new services. Now, to top it all off, you have to deal with security and governance. The big problems that start to show up are, well, my data is siloed even though my data exists regarding everything I need to know, it exists in a lot of different places and there is no central place for me to consume it from.
The other problem that exists is infrastructure is expensive. If I am looking to extend to a neo cloud, a lot of times it's going to be I need high bandwidth connectivity. I wanna make sure it's secure and I wanna make sure it's performant.
It's low latency, but then I have to show up, get private connectivity into these neo clouds, so I have to be present in an Equinix Co. How am I going to build these connections? If my data's at the edge, now I have to backhaul it to this colo.
I have to connect it into this cloud provider, these cost issues, the deployment effort that's involved. And then to top it all off, you still have to deal with complicated governance. Now, governance is not necessarily a complex problem to solve from a technical point of view, but there is so much that you have to focus on based on the regions that you're present in based on the jurisdictions that you're working in.
There's a lot of different rules that you have to account for, and it's just a fairly complicated process problem to solve. Now, as we've been thinking about these set of problems, our focus has been a lot on what's the role of the network in trying to address these issues. If you look at the evolution of technologies over the last decade, the internet has had to deal with the cloud.
After multiple cloud providers, different regions showed up. We've had to deal deal with blockchain technologies. We had ar VR technologies show up.
Now in the case of ar vr, you're dealing with low latency connections. People build separate gaming networks to try and deal with these kind of problems. Now, AI has shown up.
The consistent problem that we've seen is the network is always having to catch up as new technologies come out. Network is the last to know about these technologies because everyone builds out an application and pushes it out and then comes talk to their infrastructure folks and says, oh, can you support this for me? Infrastructure is time consuming, and it is not cheap.
It's imperative for us to start thinking about these problems differently. From an AI perspective, AI is the future. Now, regardless of how you see it playing out, the technology is transformative.
It is here to stay, and it is impacting every single business out there. How do we from a networking perspective impact this revolution? What is our part to play and, and the way we've been looking at it from a graphene point of view is we no longer want to play catch up.
This is not about finding out after the fact and spending years trying to address the problems that come with these technologies. We don't just want to stay on par. We want to make sure we are enabling these capabilities.
How do we take the network from being simple connectivity to something that helps you drive your AI business goals, your AI business vision in order to achieve this? There's a few fundamental capabilities that we believe the network needs to have. Now, something we've already talked about is just any to any connectivity that is table stakes, bare minimum that you need in this kind of dynamic use case environment, your solution app needs to be able to adapt to the requirements.
Going beyond that, our focus is on visibility and control. Now, what this means, like I mentioned, the grapht core is something that's multi-tenant. It's operated by grapht, but we don't want you to experience it as a black box where you put in packets on one side and packets pop out the other side.
It's not what the core is about. We provide you visibility into your traffic running over our core, what path it's taking, what kind of assurances it's gotten, as well as what applications are communicating, what sources, what destinations are being consumed. This gives you monitoring capabilities from an operational perspective.
What this also gives you is auditability. If you need to do inspections after the fact to be able to go back and we're going to go through a demo of this to see how we track all of this information, how do you visualize it? The focus is I want to be able to audit actions that have happened.
I also want to be able to control things happening in the future. How do I centrally enforce a policy across the graph network to say, I do not want this particular traffic to leave the geographical boundaries of North America because that is a compliance requirement that I have. In addition to visibility, it's also important to be able to exchange data with partners.
This may be data for financial purposes, healthcare, AI applications. All of this data needs to be exchanged securely, and you have to make sure you have control over who you share it with. When you choose to revoke that sharing, as well as tracking what has been consumed by whom, when, where a key thing to call out is when I talk about visibility, I'm not talking about visibility into your payloads.
We do not look at customer traffic going through our core. What we do provide you is visibility into the path that it's taking, the applications, the sources, the destinations, what kind of SLA it's gotten. So you have visibility at a metadata layer, but there is no decryption of your traffic in this entire environment going beyond this secure exchange.
So we'll also go through a demo for the secure exchange because we have this ability where different customers either both using graphene or one of them on graphene. The other not, how do you simplify exchange of data. If you look at current technologies, there's a lot of effort that goes into being able to connect to networks together with overlapping IP address space, simplifying that problem, giving you the ability to not focus on plumbing, but instead focus on the business cases that you are looking to solve.
Now, in addition to this, I've mentioned governance a few times and by the end of the presentation, I'm sure you will be sick of hearing me talk about it, but it is fundamentally important to what we are building. The key aspect of this visibility of this control is how do we allow you to be compliant with your governance regulations in the regions where you operate? How do we give you security?
And then as we're looking at more and more critical data that is making it into the AI ecosystem, there is sovereign data, there is financial data, healthcare data for all of this. How do we give you the ability to control this data to make sure it stays within your confines and you are not subject to losing this data beyond the technical aspects. There's also one other very critical business aspect to the proliferation of ai.
Whole focus is on efficiency. The whole focus is how do we get things done quickly? A key aspect for us there is time to market and return on investment.
While there are a lot of big budget AI projects out there, AI adoption is still in its very early stages. A lot of companies are looking to try it out. They're running POCs.
They're evaluating the different use cases that they have. In some cases, they learn their use case doesn't work. In other cases, it works and they need to expand it.
Having to deal with a lot of effort underneath of building infrastructure, expanding your network capabilities to be able to deploy these things is time consuming. But more importantly, what we're focused on is how do we drive these applications and provide them capabilities that they would have to build themselves otherwise. So if you look at the visibility, if you look at the governance, the entire focus is network will take care of these problems for you.
Your application needs to work with the network, but you are no longer bound by these limitations. You don't have to worry about collating data from all your different databases into one place so that your AI models can access it. You have connectivity across your network.
You don't have to worry about is why traffic going the wrong way. All of that gets done by the network itself. Hi, this is uh, Steve.
I was, I wonder if I could ask a, a little bit of a clarification here. This absolutely, this is all very logical and it's flowing through, but I'm not seeing the part of this yet that's different to ai. Everything you've talked about here in this control of the flow and the security and the, and the monitoring and the governance, that applies to a lot of other data besides AI as you mentioned, like healthcare and financial and all.
So what's the, what's the difference in the AI data that we're sending to these custom clouds or or applications on the network as opposed to what we're already doing with the partners in finance or the et cetera? Absolutely. Uh, that's a very good question.
Some of it we will touch on later, but at a high level, the biggest difference that you'll see is around the amount of data that we're dealing with and the kind of data flows that we're looking at. If you're looking fundamentally at healthcare data or you're looking at financial data, there's a lot that you have to focus on as it relates to PII. So we wanna make sure that this is sensitive information that shouldn't go out.
It's like looking for a needle, a bunch of needles in a haystack. With ai, you're moving the whole a haystack. Now you need to start looking at, well, okay, I guess my haystack's moving.
Is it going to a place that's allowed to go? Is it going to a different place? That combined with just the fact that it's so much data means your demands keep growing.
You need to quickly roll out more bandwidth capabilities. You want to make sure it's low latency connections and you want to make sure it's reliable. If a new neo cloud provider shows up and you wanna make sure your costs stay in check, you might wanna switch.
Traditionally, the problem there is are they providing me the right application ais and can I even get to them? If you don't have to worry about the infrastructure, it makes you so much more flexible in trying to solve these problems. And AI is in its early stages.
We don't know all of the requirements that exist. We just have to make sure we are quick and adaptable to solve them as they come along. Okay.
And the existing systems already have the, the data sources correctly labeled so that we know how they apply to our, uh, policies and our governance policies in place? In certain cases, yes. In certain cases, no.
So we will talk a little bit about the role that applications have to play because it's not possible for the network to purely solve all of these problems on its own. If you look at other technologies like Kubernetes, you can't just drop an application into Kubernetes and expect it to work. You need to make sure the application supports integrates with Kubernetes of, okay, am I sending it my information?
Am I using service discovered? All those capabilities are there. They're built out for an application to consume.
This is very simple, but you still have to do a little bit of work to make sure the entire ecosystem works. Thanks. I have a question for you.
This is a Kevin Myers, and I may be skipping ahead to your technical presentation a little bit, but you know, as I understand it, you know, this is an overlay underlay solution that can operate over a, you know, private network or a public network like mm-hmm. The internet. How do you ensure that you're remaining within national boundaries when you don't control the path of the underlay?
So for the underlay itself is simply the last mile where we are tried to sit as close as possible to our customers. Mm-hmm. So even if they're using an overlay, we're looking to get them onto our network.
Within the network we have full visibility. Gotcha. So once it enters your network, you control the paths of the paths that it's taking so that you don't, you know, someone's traffic engineering route doesn't suddenly take you from LA to London and back.
Exactly. Gotcha. Okay.
And in cases where it's even more important for you to be able to control the path, you can have private connectivity into our environment. Okay. In which case, you know what the last mile is, we know what the rest of the path Is.
Okay, gotcha. Thank You. You saying your network as in graph, you guys have built out your own, uh, owned fiber and that kind of thing?
Or are you right on top of a cloud service provider or? We don't own the fiber, but we have leased fiber. Okay.
But it's, but it is your Yes. Grapht owns these. Yes.
Not owns, but as you, we Are not running, RAF is a carrier as well as the, as a product, not A shared network. It's it's true network. Exactly.
Well, Because there's some providers that they'll say, yeah, we write on top of a cloud service provider where we use AWS and GCP and so on. You, you're not that. You have your own, uh, I keep saying that word.
We're with you. We got it. Okay.
Okay. I have the same question too. Yeah.
Yeah. So, uh, Denise Donahue. Um, so yeah, so you have your own data centers, things consolidate to there.
I know we're probably leaping way ahead to the technical part of your presentation, But So most of our presence is in existing Equinix, digital, digital realty facilities, and then we have our own, uh, fiber connections. Now, a key thing to call out, we are a software company that has to build this network out to prove that our technology works. Our long-term goal is not to be a carrier ourselves.
Our focus is technology, building software that runs on top of this physical layer, giving you the ability to do things dynamically. We have to prove what we have built, but we don't think of ourselves as a traditional carrier.