This Week in Startups - An AI that watches your every click may be the future of work | E2314

Episode Date: July 20, 2026

This Week In Startups is made possible by: Vanta https://www.vanta.com/twist Superhuman https://superhuman.com YSecurity https://YSecurity.io/TWIST Today's show: *Cybersecurity has long focused on c...leaning up a system AFTER a breach but Ent founder Brandon Dixon says that's backwards. He just raised a $100M seed round to put an AI agent on everyone's company laptops that catches the risky clicks, leaked files, or rogue agents BEFORE they wreck havoc. PLUS Clawra creator David Im return swith his new project, Sume's Avatar, a multi-model orchestration layer that generates 60-second UGC videos from a single prompt… and gets it right on the first try, rather than falling back on trial and error. Guests: Brandon Dixon on LinkedIn: https://www.linkedin.com/in/brandonsdixon/ Ent: ****https://ent.ai/ David Im on X: https://x.com/davidim Sume: https://www.sume.com/ Relevant Links: WSJ: "Cyber Security Startup Ent Raises $100 Million in Seed Funding": https://www.wsj.com/pro/cybersecurity/cyber-startup-ent-raises-100-million-in-seed-funding-a3e9b6c6 Microsoft Security Copilot: https://www.microsoft.com/en-us/security/business/ai-machine-learning/microsoft-security-copilot Engadget: "Meta 'pausing' employee tracking program…": https://www.engadget.com/2199458/meta-is-pausing-employee-tracking-program-after-it-let-the-whole-company-see-sensitive-data/ Seedance 2.0: https://seedance2.ai/ Timestamps: 0:00 Intro: Why AI + cybersecurity is the hot combo right now 2:29 How INT stops breaches before they happen 4:56 AI is giving non-technical employees dangerous new powers 10:26 Vanta - Compliance and security shouldn't be a deal-breaker for startups to win new business. Vanta makes it easy for companies to get a SOC 2 report fast. Get $1,000 off for a limited time at https://www.vanta.com/twist 13:54 Why on-device AI beats cloud-based security 20:08 Superhuman - Get AI that works where you work. Unlock your Superhuman potential at https://superhuman.com 25:18 INT's business model and go-to-market 30:26 YSecurity - The on-demand security team for startups. Need enterprise-grade security without hiring a $400k CISO? YSecurity gives you 40+ expert engineers, matched to exactly what you need, by the hour, with your first six hours completely free. Go to https://YSecurity.io/TWIST 34:18 David M. of Sumi Labs: one-shotting AI video 36:10 Live demo: Sumi's video orchestration API 40:05 Consistent faces, 60-second videos, and who's buying Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.com Check out the TWIST500: https://www.twist500.com Subscribe to This Week in Startups on Apple: https://rb.gy/v19fcp   Follow Lon: X: https://x.com/lons   Follow Alex: X: https://x.com/alex LinkedIn: ⁠https://www.linkedin.com/in/alexwilhelm   Follow Jason: X: https://twitter.com/Jason LinkedIn: https://www.linkedin.com/in/jasoncalacanis   Check out all our partner offers: https://partners.launch.co/   Great TWIST interviews: Will Guidara, Eoghan McCabe, Steve Huffman, Brian Chesky, Bob Moesta, Aaron Levie, Sophia Amoruso, Reid Hoffman, Frank Slootman, Billy McFarland   Check out Jason's suite of newsletters: https://substack.com/@calacanis   Follow TWiST: Twitter: https://twitter.com/TWiStartups YouTube: https://www.youtube.com/thisweekin Instagram: https://www.instagram.com/thisweekinstartups TikTok: https://www.tiktok.com/@thisweekinstartups Substack: https://twistartups.substack.com

Transcript
Discussion (0)
Starting point is 00:00:00 Hello and welcome back to Twist. This is Alex, and right now, AI and cybersecurity are hot topics, because the leading frontier models are increasingly capable of finding and exploiting software vulnerabilities. Precisely how to harden global software is an open question that we're all working on resolving. But there are startups working in the AI and cybersecurity domains that are not trying to build the next hacking tool. One startup, fresh out of stealth, has a novel approach to securing human action inside of corporations using AI that could help prevent the breaches of tomorrow. So please join me in welcoming to the show. It's Brandon Dixon, the co-founder and CTO of Ent. This Weekend Startups is brought to you by YSecurity, the on-demand security team for startups. Need enterprise grade security without hiring a $400,000 C-So? Why Security gives you 40 plus
Starting point is 00:00:47 expert engineers matched to exactly what you need by the hour with your first six hours completely free. Go to y-security.io slash twist. Superhuman. Get the AI that works where you work. Find out more. at superhuman.com. And Vanta. Compliance and security shouldn't be a deal breaker for startups to win new business. Vanta makes it easy
Starting point is 00:01:07 for companies to get a sock to report fast. Get $1,000 off for a limited time at vanta.com slash twist. Brandon, how are you doing? I'm doing phenomenal. Trying to stay cool in this hot weather in Virginia right now.
Starting point is 00:01:21 It's bad up here. I can't imagine how bad it is down in the sticky south. But before we get into anything important, I'm shocked that after all the mining we have done, on Lord of the Rings Arcana, ENT was not taken yet.
Starting point is 00:01:34 How is that possible, given that we've already gone deep into like the Silmarillion to find startup names? You know, I think it's just a happy coincidence. Like when we were building out the company brand and the name, we were thinking of, you know, enterprise as like kind of our core customer that we're going after. And so like, and like security for the enterprise was kind of the approach there.
Starting point is 00:01:55 And then, of course, being more technically inclined people, there was a little bit of a nod to the kind of Lord of the Rings trees and the protection. And as we were building out that brand, it was important to me at least. Like, I don't like the hoodies and hacker depiction of like, you know, the bad guys. I like being outside. I like doing those sorts of things. And I wanted to try and carry that through in the brand as well. Oh, well, it works out well.
Starting point is 00:02:21 It's very memorable. It was not hard to recall who I was talking to today. Now, let's dig into what you built because I don't think people are going to be as familiar. with this tool. But to get people a quick summary from what I understand, you have built a on-device agent for endpoints, so, you know, laptops, phones, and so forth, that can essentially tell when someone's going to do something they shouldn't do or maybe risky and then stop them. Now, tell me what I got wrong and break it down for me why we need this. I'm really curious. No, I mean, no, that's effectively it. Like, you know, when my co-founder and I formed N, like the thesis to this was that we've largely
Starting point is 00:02:56 given up prevention inside of security, right? We're very reactive. We wait for the bad thing to occur. We have the requisite information to troubleshoot, but it felt like there was, we were just accepting that the adversary was going to compromise the infrastructure. And a lot of the breaches occur because people are well inclined trying to do their jobs, but they make a mistake. And so when we were looking at the current AI advances with some of these reasoning models and the ability to scale up understanding words and representing that in dimensional ways. We wanted to apply that directly to where people worked. So we wanted to meet them in that moment, look at the work that was taking place, and then make an assessment as to whether or not they were going to
Starting point is 00:03:42 violate corporate policy or do something they shouldn't and effectively stop that from happening. So why do we need it now? Well, unfortunately, like breaches still occur, be from humans, right? Like, people click things. They want to do the job. If they were. If they were otherwise security experts, we wouldn't be dealing with breaches, right? Everybody would do the right thing. But on top of that, we do have AI in the mix, and it's a new technology, and it just brings new risks. So we believe that having that level of reasoning and capability at the endpoints and important advancement in the future. I want to get to the endpoint point and talk about models in such a second, but the idea that people are doing more thanks to AI really resonant to me. Because up until when I have, had, I mean, frankly, open claw codex and cloud code. I was not messing around in PowerShell or with a CLI. And now I'm doing all sorts of insane things with my computers that I'm absolutely not qualified to do.
Starting point is 00:04:39 But that's the home brew side of this. So take me inside a corporation that's rolling out AI tools that give, you know, job functions more capacity capability than they would have had before and are now seeing these problems. I'm curious about like how it manifests and like which jobs are really pushing the envelope, if you will and getting into trouble. I think it really depends on the maturity of organizations. So a lot of the people that we're working with are obviously adopting AI. They're kind of all in and they're looking to retool processes.
Starting point is 00:05:08 I've heard the term and I kind of like it, citizen developers. So we run into those people, ones that don't have a technical background who are being encouraged by their leadership to solve problems with AI and like, you know, accelerate their workflows. And in that case, you know, they run the risk of, you know, deleting artifacts off their system, pulling in context that might be sensitive and then like accidentally leaking it outside of the corporation. On the flip side, you have your developers who, of course, are trying to take advantage of new technology. And in that case, they might have like 20 different agents running to go and perform various roles across the enterprise. And they're the same risks take place as well.
Starting point is 00:05:51 But it's not even just innately tied to AI, right? Like there's still just mistakes that people do by accidentally sending an email, you know, with the financial information to the wrong person, right? Or sharing credentials across, you know, chat ecosystems that otherwise could lead to a compromise. So we see both sides of the house. We still look at the user behavior and we look at how they're working with agents and then we look at the agent behavior as well. that's really interesting to me because it's a bit broader than I thought.
Starting point is 00:06:24 How can you have enough context about a company, its individual job functions, what they are allowed and not allowed to do from the corporate perspective to determine in real time if person X with job Y and group Z responsibility, you know, Q is doing something that is suspect. Because to me, that implies a level of specificity that's almost crazy. So I'm impressed that you managed to figure it out how. So for us, like the setup of the product itself is predicated on like getting a corporate policy or getting something as simple as like, what is the sanctioned software that you use across the enterprise? And you'd be surprised with that little bit of information in understanding the context that we're collecting, I can guarantee that there are policy violations that are occurring across the company. So people come to us and they say, look, I'm not going to restrict AI usage. I'm going to let it happen.
Starting point is 00:07:17 But now my concern is I can't keep up with all the AI tools that are coming out. And I've given people access to use these tools, but I don't know how they're using them. So right away, if I understand what like the allowed software is, I can immediately tell you people that are using other software, be it AI remote access or something else, that is not sanctioned for them. So like that's like hour one sort of output for us. And then over time, and basically understands the operating aspects of the business, because we're constantly forming baselines of what's normal for that user, what's normal for that department, what's normal for their cohorts, and that allows us to essentially start to put the policy to use on the endpoint itself and stop bad things from happening.
Starting point is 00:08:04 So we don't really require a lot of information. I think the big advantage that, you know, or what makes this possible today and why it wasn't possible, you know, a couple years ago is the advantage that we have in things like embeddings. The ability to take semantic words, like things that we understand have meaning, and translate them into something that a computer can understand and make decisions on top of. You're talking about vector databases and tensor is more broadly. Sure. Yeah.
Starting point is 00:08:32 Like it's, yeah, I mean, in its essence, it's basically, you know, words have meanings. We know how to interpret those, but it's been difficult to represent. present a lot of dimensionality for computers to understand. But now because we have these large language models, as part of what makes them work really well, is that extreme amount of dimensionality, right? That they understand, like, when these words are put together, they have a more specific meaning than maybe when they're, you know, split apart from each other. And so that was an advantage that we were able to take within building the product. And that serves us well. I mean, you're literally talking about why people are moving away from vectors because they want to have a more multi-dimensional way to represent data as numbers than, I'm sorry, words as numbers.
Starting point is 00:09:20 That all tracks with me and that makes good sense. But I'm curious with the learning loop because you said you can provide value right from the start with some corporate policies, but then you keep learning. On the other hand, the way that I understand the way how it works is that there's basically an on-device agent, which I think is doing local compute. So I presume there's kind of an SLM involved there. And then does it then federate information back to a centralized database to learn about Alex Incorporated and then send that back to the on-device agent? How does that process function? Yeah. So quite simply, when we were building out the architecture, we didn't want to have a back-end process and an endpoint process.
Starting point is 00:09:57 We wanted to have one architecture that could work for either scenario. Because you might have some systems where they don't want to run anything at the endpoint itself because of, you know, regulatory, compliance, whatever. So the way that we've designed the system is it can run completely on the back end end point itself, but it's the same architecture. So you asked about... No, I'm just curious why. I mean, I feel like if you can centralize the compute, why not have a more powerful model? You have more flops to play with. As a founder, you've taken the time to become an expert in your niche and you fully understand the entire landscape, but with so many regulations and rules that you need to follow from federal agencies and offices here in the U.S. to the European Union and beyond.
Starting point is 00:10:41 It's impossible for even the most diligent person to keep up with every exacting requirement. That's why you need to simplify compliance with a trusted partner like Vanta. All my startups use Vanta. And they love Vantas AI-powered platform that automates your entire compliance process. Whether you're preparing for a SOC 2 or you're running an enterprise GRC program or you're doing an audit, Vant is going to worry about the security. so your team can focus on building great products. That's why some of our favorite companies like Ramp and Ryder are spending 82% less time on their audits by working with Vanta.
Starting point is 00:11:15 Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate. Vanta is here to help you automate your security and compliance and earn and prove trust. So get started today at vanta.com slash twist. That's V-A-N-T-A-com slash twist. So cost, you know, not everything we're... requires like the most, you know, the greatest model or the frontier model. The way that we use models, we use open models that have been published out there, we do rely, like, we'll make use of like the cloud service provider models or if a customer
Starting point is 00:11:49 wants to bring a model. When it comes to embeddings, we control those and we're using open models to dictate that. Those embedding models can run on the endpoint. They can also run on the back end. We've made changes to those models to optimize them to be very performance. and to do particular use cases to solve like certain problems. And so like we control that architecture. But if a customer otherwise wants to do deep investigations on all the data that we've collected,
Starting point is 00:12:16 they have the capacity to do so. All right. Effectively, the way that the system works is we're building out a pipeline where we put this context in. We start with a raw behavioral information. And then we're decorating it with, you know, who's logged in. what is it that they appear to be doing and aligning that to whether or not
Starting point is 00:12:36 it's a corporate violation or not. We have a single architecture that basically is built to run on the endpoint or can run on the back end. Because of the way that embeddings operate, we want to control that process and we use embedding models. Embedding models are great
Starting point is 00:12:51 because they're very performant. They don't require like GPUs. They can operate on CPUs. And when it comes to decision making, they can make decisions in sub-second timeframes. Like we don't have to use a heavy amount of reasoning. The subsecond time frames thing is what the most interesting thing, because the way that I think about in practice, and it hasn't been rolled out at the company that I work at, some kind of theory crafting here. But as I go to do something I shouldn't do, it goes, Alex, don't do that.
Starting point is 00:13:15 That might be insecure. Is it that fast of a process, or am I overestimating how quick technology is today? No, it has to be that fast to get prevention. So the idea, like the way that we roll out inside of a company is generally speaking, if you ask like a CISO, who are your riskiest users and why? they can't really tell you, right? They know the workflows that are taking place. They know roughly what people are doing throughout the day, but they don't emphatically know this. And so typically, the way that we roll out is we start in more of a baseline mode. We install ENT across like the ecosystem. It starts absorbing the information. Again, it has that corporate policy. We're
Starting point is 00:13:53 surfacing violations. The company is going to have more than enough thing to do based on what we're surfacing in that moment. We don't want to necessarily get in the way of anybody's workflow. We don't want to annoy people. I don't want to run, you know, and like, you know, prompt them in some form unless I have information from the company. So there's typically a burning period where you might have two weeks to establish baselines of what's normal, what's not, you know, where are the violations occurring that I actually care about? Because in your corporate policy, you might have something that stipulates nobody should use social media. But you may not actually care to enforce it. But you might have, on the other hand, that, you might have, on the other hand,
Starting point is 00:14:33 that AI use and sensitive data that goes into these models has to be done in this particular way. And so for that moment, like, we're going to drudge up that behavior. We're going to say, here's your unsanctioned AI usage. By the way, here's what people are doing. This is the information they're sending in. This is the work that's taking place. And it allows us, we've built the product to basically isolate that workflow and then say, well, when I see this activity in the future, now I want to intervene.
Starting point is 00:15:00 And an intervention can be customized. The way that I think about the product as this stop-y-before-you-do-it thing is one portion of it, because it can also do that for humans and apparently also for agents, and it can provide a bird's-eye view into how a company is using software and in particular AI more broadly so people can learn from their own usage? Correct. So the idea here is like, yeah, I've toyed around with like the lingo, but it's like an organization work model.
Starting point is 00:15:29 We talk about world models. Sure. And world models were like super advantageous to cars, right? Because prior to a world model existing that encapsulated the environment, we were trying to tell the car like when to stay in the lanes, when to apply the brake, when to like kind of, you know, change lanes, whatever. And the problem was is that you were overfitting to a particular set of environment variables. When you had the world models, it allowed the car to essentially become more predictive, right? Oh, I'm anticipating that somebody's going to walk out in the crosswalk or there's a stop sign and I need to apply the brakes. It allowed the self-driving car movement to be more accurate. So when I say that most sisters aren't aware of the behaviors that are taking place, step one is to make them aware from an observability perspective of you have some problems inside your environment that you probably didn't realize. And step two is to figure out which ones do you actually care about. And then step three is to determine how do you want to modify that user behavior, if at all, or your corporate policies, and then enact those using
Starting point is 00:16:33 end. So really, I think that calling this a cybersecurity company almost feels too narrow. You are building kind of a work model in a sense. How far can you push that? Because once you have this information about how a company works, you could do all sorts of fun things like tell them where they're being inefficient or recommend different ways to go about stuff. It seems like if you can get wide adoption and a lot of information, this is a really
Starting point is 00:16:55 potentially lucrative. and useful tool that you're building with a lot of future applications that go outside of just cyber safety. Absolutely. I think the, you know, again, toying around with like kind of lingo here, I don't know the best way to describe some of these things because they feel new. Like we haven't had it at our disposal. One of the ones that I was playing around with was like the semantic substrate for security. So all of a sudden I have this like all of this information that's describing the work that people are doing inside of the business. And that is a, that is a massive, uh, set of context that we have at our disposal that can help accelerate closing out true positive
Starting point is 00:17:33 benign tickets in the sock, right? It could give further context to DLP-related events. It could surface inside risk activity, be it the 1% bad guy or the 99% mistakes that take place. It could be used to isolate and identify people that need training. So like there's a broad applicability in having context that describes what's taking place across the organization. And you hit the nail on the head. There's a productivity angle to this as well in which if I understand what people are doing throughout the day, then it becomes ripe to figure out what things might agents benefit, right? What is the mundane, monotonous work that is occurring across different departments inside of the business or ones that, like, particularly risky across my enterprise that might benefit by having an AI
Starting point is 00:18:21 agent do it? And then once that AI agent is in place, how do you ensure and keep it on the rails, right? How do you know that it's doing the right thing, that it's aligned to the task? And so for us, we're concretely focused in security, but we go and target big enterprises. Our environments are global 2000 and above, so think Fortune 500. And the thing that you articulated is what they're after as well. They say, I can start with security. I can bring a level of visibility and stop problems from taking place. But then there's this downstream applicability that becomes really attractive. Like, can we start mining out of that information
Starting point is 00:19:00 ways to do process distillation? Ways to identify who are like, who's using AI the most and how are they using it in ways that we can help others learn from that? And this is why I'm terrified that one of the, you know, AI Lab, JV, FDE, private equity working groups
Starting point is 00:19:18 are going to try to scoop you up and then take all the data you have and then apply it because it's going to be incredibly valuable. But just listening to you on the list, single point. Work obbs, maybe? I mean, it does feel kind of like general work observability, lots of data. You can do different things with it. We could, we, like, we've also used, like, you know, I heard data lineage for a while, which is like looking at how data moves through the enterprise. And I think that that has merits and it's proven in the market. We've been towing
Starting point is 00:19:45 around with behavioral lineage as well. It's like, what are the behaviors that people do? And how How does that like then intersect with data lineage? How does the behavior of an agent, you know, operate? Where we've settled on the marketing side is like the intent aware. That's why you see that. But you know, I don't TVD and like how people respond to it. So far that's been, you know, the way that we've been pitching it. Most AI tools are adding friction, not making your life simpler.
Starting point is 00:20:12 And it's another tab to switch to. And maybe you forget to even do it. It's arduous. What you really want is one system that's going to make you more efficient and save your time every single time you do work. That's why I love superhuman go from the amazing team behind Grammarly, which I have insisted all my team members use since day one. Now it's an AI chat that lives on the side of your browser. It's always there. Maybe you're drafting an email mid-meeting. It goes and helps you finish it without switching apps. Maybe you got a 40 email thread to get through
Starting point is 00:20:43 before that call. It's going to summarize it for you in seconds without losing your place. No new tabs, no starting from scratch, no context switching. Superhuman Go has the context of everything you're working on. It works inside the tools and sites you already use. Your inbox, your docs, your browser. Maybe you're doing social media all day long like me. It's part of my job. You can try many of Superhuman Go's features for free.
Starting point is 00:21:06 Find out more. Superhuman.com. That's superhuman.com. I would say, you know, lineage and substrate are a bit too technical. But then again, I have to say the words, agentic orchestration at least three times a day. So what do I know about branding? Okay, let's talk about a couple of other things. One is just the employee element of this.
Starting point is 00:21:24 Now, this computer that I'm on right now, because Twist is owned by launch and launches a financial company has all sorts of tracking software on it, right? Just for this, you have to do that. I don't love it, even though I don't actually care because no one cares what I do, but it still feels a little bit weird to me
Starting point is 00:21:40 that there is a record somewhere of, you know, every tweet that I click on, right? Right. Now, in what you're building, it is more granular. And so I'm trying to kind of sort out how much do employees care? Because on one hand, I think it's becoming the norm to have your work observed to some degree. On the other hand, meta just made a big push to really look at what their engineers were doing.
Starting point is 00:22:01 And that was very unpopular. So where's kind of like opinion and norms around this type of observation? You know, I think it's TBD to some extent. At least on the enterprises that we work with, a lot of them have corporate policies that stipulate the asset that you're using. is subject to monitoring for the purposes of like, it's their corporate asset, right? Like, the intellectual property is there. So I think, you know, most of the security software that has been deployed, even in a traditional EDR sense, has been historically collecting all of this information about the actions people
Starting point is 00:22:37 are taking on their system, right? And I do believe that we bring a new level of granularity to it. And we have to determine, you know, what businesses are comfortable, effectively deploying. And I think it's just a matter of being straightforward with your employees. Yeah. And so it's a matter of if it's in the corporate policy and you're able to collect it, then, you know, okay, that's fine. Our kind of general view is we, when it comes to the information that we collect, we don't want it coming back to a central authority. We can be the people that host that environment. So we can deploy as a SaaS based as product and hosts on behalf,
Starting point is 00:23:16 give you a dedicated tenant. But more importantly, what we've heard from Global 2000 and above is they want to own their data, right? They don't want it going to somebody else. So ENT is deployed within the customer's boundary. Like, we don't even get to see it. So the limiting factors there are, that's one way of kind of retaining that. Like, it's only staying within the corporate environments, not being shared with other people. And then the secondary item is, how much do you want to collect and centralize back to that, you know, that corporate back end? And so we've provided an ample amount of configurability that if you don't want to send something to the back end, you don't have to. You can keep it on the edge.
Starting point is 00:23:55 Now, obviously, there's an operational gain in putting everything in a central store. But there's more data to learn on. Yeah. Yeah. But like a corporation may not want to do that. So for everything that we collect, there's toggles that basically allow the business to turn it on and off. We support user groups, endpoint groups. in terms of like, you know, you might want to collect more on your developers just because they have a higher risk pattern,
Starting point is 00:24:23 where as you're legal, you may not really want to collect anything at all. And then beyond that, within the product, there's role-based access control and attribute-based access control. So like if we're collecting something like screenshots for an investigation, I don't want the sock to necessarily see that. So we allow the business to basically hyper-tune the information that's exposed to any given part. I feel like you're nibbling around the edges of agentic identity and the issues and lack of maturity in that product world somewhat. Am I wrong? If I want to know what the agents are doing, I'm going to want them to have a distinct permission set and a distinct identity. Well, it's the same thing with people, too, right?
Starting point is 00:25:04 I mean, I think part of the problem with like a corporate policy is that it lacks teeth. It's only as good as its ability to put it into a control point. And because corporate policy is written in natural language, there's some level of like interpretation that takes place by the employee. And I think that's sometimes what leads to, you know, mistakes being made is that the employee feels they're working within the boundaries of the corporate policy when they may in fact not be. And the way that you get around this, right, is you have a draconian, you know, way of stripping down the asset and removing the freedom and you're just saying like, thou shall work this way. And I don't think that's particularly fun to work in those businesses. I understand it. But like what I want to do is balance like being able to give a new control point layer to actually stop bad things from occurring while also not infringing on like privacy.
Starting point is 00:25:59 Right. And so it's up to me as I design that product to put the controls in place to not build something that could otherwise be abused. And that's something that's very top of mind for us. I don't want to be nanny software. I don't want to, you know, police, you know, how many, you know, how much AI somebody used throughout the day. That's not what I care about. What I care about is stopping mistakes from taking place, removing adversaries from environments,
Starting point is 00:26:24 making sure that people can adopt AI safely. And that requires some level of observability in understanding what's happening. Work jobs. I'm telling you, it's going to be big. All right. Let's talk about really quickly some business questions. So you've mentioned how there's a SaaS version. of this and a self-hosted version of this.
Starting point is 00:26:41 Now, when I usually see that breakdown, it tends to be open-source software. As far as I know, you guys are not pursuing the open-source approach. So talk to me about the business decision there to allow for self-hosting, and then also, how do you charge for that? Yeah. So self-hosting, the reason for it was when we were at Microsoft, we learned during this AI movement, people are really sensitive to their corporate data. And I think from a regulatory perspective, we're seeing more emphasis on data sovereignty.
Starting point is 00:27:09 We're seeing like the intellectual property of a business wanting to be contained within its environment. They don't want it to go to, you know, third-party supply chain. And so it was a first principle decision for us. In the same way that we said, we're not going to depend on any other security product to get our telemetry because that impedes our ability to be preventative and make decisions quickly. We also said we're going to make it out of the box, one-click, deploy inside of whatever cloud you guys operate in. and we support the major ones. And so that was just an important decision for us. If we host it, then effectively we take on the hosting costs and we pass that on in the licensing.
Starting point is 00:27:48 If you host it, that it becomes like a COGS implication that you have to effectively manage that spend. And we give you the predictability of what that looks like. But I'm still paying you yearly, quarterly. Yeah, there's a licensing cost. Yes, there's a licensing cost associated with the product. It just will change if you're hosting it because you're going to take on the, uh, the actual hosting. Okay, that makes good sense. But it's still basically charged the same way, lower cost. Okay, that makes sense to me. Yeah. Now, you guys came out of stealth and announced a $100 million
Starting point is 00:28:16 round. Mm-hmm. These happen more often than they used to, and I'm always curious why you need that much money. It's a lot. That's, that's an old seat fund from when I was younger. Um, so what are you going to do with $100 million? So the thing with endpoint is it's a well-established market, right? It's something there's a lot of players and incumbents there. And to be able to penetrate inside of global 2,000, Fortune 500 and above, you need to, like, building that endpoint company takes a lot of effort, right? I have to build an agent that works across multiple different platforms. I have to, like, concern myself in the research and development of putting AI directly at the
Starting point is 00:28:56 edge, while also being able to run it on the back end. We talked about, like, you know, hosting inside the customer's environment, making sure that all of that infrastructure is supported, be if you're using AWS, Google, or Azure, right? Like, all of that takes a significant amount of engineering to get it right to make sure that it's tested, to not make those mistakes. And so there's a lot of money raised to basically go and do that. It's just expensive to build a product. But it's also expensive to then, like, get out in the market and land inside of these, like, big enterprise accounts. Like, people come to us and they say, hey, look, are you going and competing with the traditional EDR?
Starting point is 00:29:36 And the short answer is no, right? I don't want to go and compete with them on the same playing field. Why would I do that? From my perspective, EDR is a commodity at this point. Everybody's got something in place. They might be reasonably satisfied with what they're getting. My job is to augment where that EDR solution is not meeting the needs, where an inside risk solution is not meeting the needs,
Starting point is 00:29:58 or a DLP solution is not meeting the needs. So we talked about like this semantics. semantic substrate for security, my business is trying to build, you know, like the programmable endpoint. Can I solve a variety of different use cases using AI as my advantage across any platform and any cloud and give someone that level of visibility to understand what is happening inside their enterprise? It just takes money and capital to do it. The team is pumped because you're about to close a massive deal, but then the client's lawyers get involved. What happens if you get hacked? to protect your data. There's no need to panic. This is why you brought in Y security. Why
Starting point is 00:30:37 Security is staffed with over 40 experienced engineers who have actually worked security for world-class companies like Apple, Uber, Microsoft, Robin Hood, Brex, and so many others. But the best part is, you don't even need to hire Y security. Your company can rent Y security's elite team by the hour. That means no massive salaries to pay, no costly consultants, just real experts embedded in your company, helping you out with your company. your SOC-2, ISO-4200, or any security or compliance challenge you're facing. You can even set a monthly cap so you know exactly how much you're spending. And your first six hours are completely free. Head to Y-security.io slash twist and book your free six-hour strategy call. That's Y-security.io-S-T-W-I-S-T.
Starting point is 00:31:25 Given how many different endpoints, clouds and services you have to make work to have this actually functioning at the speed you needed to, I'm never going to listen to a development. again, he tells me they can't launch on iOS and Android at the same time because it's too hard. I feel like you're taking out a much more difficult challenge. All right. Last question for me is pretty simple. When you guys came out of stealth, you announced that int was generally available, which means your go-to-market, you know, starting gun was shot off. Correct.
Starting point is 00:31:50 How has reaction been? How was the market responded? It's been like a floodgate. Even before that, like, we were like, the reason why we effectively, like, we've, we've been in the kind of market to some extent, not like out of stealth, but like kind of pseudo out of stealth for a couple of months. And the reason why we just kept consistently holding it back is like, I've retained a pretty healthy pipeline of like, you know, folks that are interested in what we're doing. So when Lou and I left Microsoft, they were like, man, you guys are going to do something crazy and I want to know what
Starting point is 00:32:23 that is. And so like, we've got a lot of goodwill and having multiple exits and startups that we just had a bench of people that were like, tell me what you guys are doing. And the second that we were ready, we were entertaining, you know, uh, POVs and people that wanted to go and deploy the solution, tested out because they're like, we've never seen anything like it. This is exactly what we were expecting. And so beyond that, like typically you come out of stealth because you want help in hiring people. And I, I've hired well over, you know, 75 people now. And I've not paid a single recruiting fee. And so like coming out of stealth was not lackluster. Like, we've got a lot of like for us like it didn't feel like any material difference like we've retained a healthy
Starting point is 00:33:07 pipeline of people that are interested. I've got more people now asking me like dude I want to see this thing in action. This is what I was waiting for. And so for us it's just a healthy amount of demand beyond what we already had. Do you have enough GTM infrastructure in place sales teams, et cetera, to handle all the new roundbound? That's exactly where we're hiring right now. So we've got several sales reps. We're hiring for sales engineering. you know, we got folks on like the forward deployed engineering side that's been staffed out. And so like we're getting our pieces there. I feel pretty comfortable. But like, you know, now it's just a matter of like going through the motion and executing, right? You know, having multiple deals in tandem managing the POV process, making sure that we're delivering success and outcomes. That's the biggest focus that we have right now. So early beginnings of it, we're hiring. And then it's a matter of just like continuing to turn the crank here. Well, we are looking forward to when you start announcing AORR milestones.
Starting point is 00:34:05 But in the meantime, it's int.a.I. Branding, congrats on the round. Congrats on coming out of fake pseudo-stealth. And come back on in six months and tell us how's going. Appreciate it. Thanks, Alex. All right, everybody. Next up on today's twist.
Starting point is 00:34:18 You remember David M. He was previously on our show. He had Clara, the OpenClaw AI girlfriend. Do you remember this, Jason, from February? Yes, I do. So he's back. He's got a new product from his company, Sumet Labs. It's an agent orchestration layer utilizing multiple video generation models. The goal
Starting point is 00:34:38 is generating high quality video outputs in just one attempt, Jason. The idea you could finally one shot your AI videos instead of multiple go rounds to get it exactly the way you want it. David, thank you for coming back to the show. Yeah, it's good to have you back. I mean, when you make video, it is literally like a slot machine. You put in your prompt. I did it the other day. pull up my Yoda one. I did it in rock. I'll take a look. It was, it was relatively good. It got it right. I said, I want Yoda from the Clone War style to say, Frontier Model Wars begun. Oh, I see. Yes. Here I feel.
Starting point is 00:35:18 Frontier Model Wars begun, they have, which is a favorite's line. The Clone Wars begun. There have. There we go. And I understand. I have to be honest, I give it like a nine out of 10, 8.5 out of 10. It's pretty good. It knows what it's doing. It's pretty good. The voice is off, but I mean, I'm not paying a royalty to Disney here, so I don't know, I'm going to get in trouble with Disney. But David, why did you show us what you built? Because I do think there is something here to taking, when you get rid of the slot machine nature of these LLMs, it becomes more predictable and your utilization goes up.
Starting point is 00:35:56 Yeah, yeah. The slot machine is not fun when you're making video. in images and they take 30 seconds. It's incredibly frustrating. Right now, you know, the bowling right now is like prompting the videos again and again to get the right results because it's unpredictable, because, you know, video generation models are stochastic. So what we're trying to do is make an API. That is basically a wrapper of like, let's say, five or six models to get the production
Starting point is 00:36:23 result. So our belief is that once we make these one piece, piece, piece, let's say, production lab, production ready, like API print of it, primitives, then once we got the APIs, and we could make our agent
Starting point is 00:36:38 one shot a marketing video very easily. Okay. I'm guessing you have a killer demo to show us. Yeah. There it is. And you see a screen. Yeah, we could see. It looks like your,
Starting point is 00:36:49 your X feed. Yeah. So, yeah, this is kind of like our UDC API. It's our operator API. And then you could do kind of like, So this is basically the same prompt.
Starting point is 00:37:02 So it's a basic prompt with Gemini, Omni, Seedance, and Summa Avatar. And basically what we did is we are basically on a router of multiple models, not only video, but image, video, audio, and clipping and everything, we were a wrapper around all these models. And this is what we got with the same prompts. You're seeing on the left, Gemini Omni, and it looks like a young adult, maybe a 25-year-old or younger, in their apartment, in a city. or maybe they're in high school in the second one.
Starting point is 00:37:33 Yeah, yeah. They're doing the classic selfie marketing. Like I'm making a TikTok video about this product. Yeah. So same prompt. You see three different results. Then what happens? What's next?
Starting point is 00:37:46 So what we're trying to make at the end goal, let's see like after six months, is a video agent that wants us marketing videos. So our users, our brands or marketers, want to promote their product and make video ads. for them. And right now, our first model was for UGC. So as you know, like if you want to make UGC videos with AI right now, you have to combine a lot of different models, let's say like C-dance or like touch the image or grog and everything. And then after that, you have to combine those videos
Starting point is 00:38:16 to make along because, you know, video generation models only like support up to 15 seconds. It's like 30 seconds for our like C-dance's like next model. Like it's only 30 seconds. So what we did is we made a router of video, theater generation models and image models and audio to get the audio persistent to make this kind of videos. And then finally, you could generate up to 60 seconds
Starting point is 00:38:41 of consistent after videos right now. Okay. So you put in a script, hey, I want to promote my new app. It's called Uber. And you open your phone. You go outside, it's raining. You can't walk home.
Starting point is 00:38:56 You want to get a ride. And you write the script for this, and then it goes and makes you a bunch of different scenes. Do you tell it what scenes to make in your? No, actually. It's only so for the user, it's basically just picking on AvTor and then writing the script. Got it. That's it.
Starting point is 00:39:15 The user writes the script or the LLM writes the script. The user writes to script. So after I write the script, then each scene gets done three times, and then it's up to me to stitch them together. So I might say, oh, I like this one where it shows the car. you know, in the pouring rain. I like this one when it shows the guy getting out with his umbrella or putting his jack.
Starting point is 00:39:35 One of them has him put his coat over his head to walk to his front door. And I just get to essentially vibe code my way around a longer form video, yeah? 100%. Okay, cool. Did you have any outputs like that that we can see? I would love to see like where you got to with this.
Starting point is 00:39:52 Okay, so I could show you the video. Yeah. So this is like 16 seconds. So you could see that it's up, like more than, than 15 seconds. But yeah, you can make these kind of videos with 60 seconds. So it's using multiple ones and then it stitches together with one clean audio file across it. So a little bit of a hack there.
Starting point is 00:40:13 Yeah, yeah, yeah. And if you go to you. Yeah, so round now. Yeah. It's also consistent. Her face remains totally consistent throughout. A big problem when you're generating these kinds of like video clips I find is that it'll, for the first like seven seconds of the video at a little.
Starting point is 00:40:29 like the person's face, and then it sometimes gets like distorted towards the end. Like that's a big problem with, yeah. It's like the keeping that facial consistency the whole time. What is the website? Do you have a website for this? That way you can see? Yeah, you can search zoom.com. Ah.
Starting point is 00:40:44 S-U-M-E-D-com. Cool. Oh my God. You got a good domain name. How much of that cost? Your four-letter domain? Yeah, we got it cheap. Really?
Starting point is 00:40:51 That's a $100,000 domain name. 70% discount from the initial price. I'll go daddy. Love it. All right. Well, this is like a great start. And who's it for? Who's the customer?
Starting point is 00:41:01 You think startups making marketing videos or just general D2C marketers? Who is your customer base currently? Yeah. So right now we have 20K users and the main customers, especially about 90% of the paid customers are brands. Got it. Our main audience is not on Twitter, but they're on Instagram and TikTok. Got it. Yeah, people are trying to flood those base.
Starting point is 00:41:24 I can't even tell what's AI anymore unless you're paying attention. I got a lot of shark videos because one of my daughters love sharks, and I'll do like shark videos with her. And now I'm starting to get AI slop sharks. And, you know, they start out and it's like a person on a boat and they're pulling in a fish and you're like, oh my God, there's going to be a shark. And then like this ridiculous shark jumps up, eats the fish. The person falls in the water. The shark is jumping in the water. I'm like, sharks don't interact for 90 seconds with the human.
Starting point is 00:41:51 This is getting a little ridiculous here. All right. Well, great job with the startup. Keep grinding. And we'll see you when you have your next update. Awesome. Thanks, David.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.