Traditional cybersecurity has been reactive, waiting for breaches to occur before responding, but modern AI-powered endpoint security agents can proactively prevent breaches by analyzing user behavior in real-time, understanding corporate policies, and stopping risky actions before they happen. These systems use embedding models to translate semantic context into actionable decisions, enabling sub-second intervention without requiring extensive backend infrastructure. The key advantage is that they can detect both human mistakes (like accidentally sending sensitive data) and AI agent misuse, providing a 'semantic substrate for security' that offers visibility into enterprise activities while maintaining user productivity.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
An AI that watches your every click may be the future of work | E2314
Added:Hello and welcome back to Twist. This is Alex and right now AI and cyber security are hot topics because the leading frontier models are increasingly capable of finding and exploiting software vulnerabilities. Precisely how to harden global software is an open question that we're all working on resolving. But there are startups working in the AI and cyber security domains that are not trying to build the next hacking tool.
One startup, fresh out of stealth, has a novel approach to securing human action inside of corporations using AI that could help prevent the breaches of tomorrow. So, please join me in welcoming to the show. It's Brandon Dixon, the co-founder and CTO of INT.
Brandon, how you doing?
>> I am doing phenomenal trying to stake pool in this uh hot weather in Virginia right now.
>> It's bad up here. I can't imagine how bad it is down in the sticky south. But before we get into anything important, uh I'm shocked that after all the mining we have done on Lord of the Rings, Arcana int was not taken yet. H how is that possible given that we've already gone deep into like the Sylmerelion to find startup names, >> you know? Uh I think it's just a happy coincidence like when we were building out the company brand and the name we >> we were thinking of uh you know enterprise as like kind of our core customer that we're going after and so like security for the enterprise uh was kind of the approach there and then of course being more technically inclined people there was a little bit of a nod to the to the kind of Lord of the Rings uh trees and the protection and as we were building out that brand it was important to me at least like I don't like the hoodies and hacker depiction of like, you know, the the the bad guys. I I like I like being outside. I like doing those sorts of things and I wanted to try and carry that through in the brand as well.
>> Yeah. Well, it works out well. It's very memorable. It was not hard to recall who I was talking to today. Now, let's dig into what you built because I don't think people are going to be as familiar with this tool, but uh to give people a quick summary from what I understand, you have built a ondevice agent for endpoints. So, you know, laptops, phones, and so forth that can essentially tell when someone's going to do something they shouldn't do or maybe risky and then stop them. Now, tell me what I got wrong and break it down for me why we need this. I'm really curious.
>> No, I mean, no, that's effectively it like um you know, when my co-founder and I formed, like the thesis to this was that we've largely given up uh prevention inside of security, right?
We're very reactive. We wait for the bad thing to occur. we have the the requisite information to troubleshoot, but it felt like there was we were just accepting that the adversary was going to compromise the the uh the infrastructure and a lot of the breaches occur because people are wellincclined trying to do their jobs, but they make a mistake. And so when we were looking at the current AI advances uh with some of these reasoning models and the ability to scale up understanding words and and representing that in in dimensional ways uh we wanted to apply that directly to where people worked. So we wanted to meet them in that moment, look at the work that was taking place and then make an assessment as to whether or not they were going to violate corporate policy or do something they shouldn't and effectively stop that from happening. So why do we need it now? Well, unfortunately like uh breaches still occur be from humans, right? Like people click things. They they want to do the job. If they were if they were otherwise security experts, we wouldn't be dealing with breaches, right? Everybody would do the right thing. But uh on top of that, we do have AI in the mix and it's a new technology and it just brings new risks.
So we we believe that that having that level of reasoning and and capability at the end point is an important advancement in the future. I want to get to the endpoint point and talk about models and such in a second. But the idea that uh people are doing more thanks to AI really resonated with me because up until when I had I mean frankly open claw codeex and cloud code I was not messing around in PowerShell or with the CLI and now I'm doing all sorts of insane things with my computers that I I'm absolutely not qualified to do. But that's the the homebrew side of this. So take me inside a corporation that's rolling out AI tools that give, you know, job functions more capacity capability than they would have had before and are now seeing these problems. I'm curious about like how it manifests and like which jobs are are really pushing the envelope, if you will, and getting into trouble.
>> I think it really depends on the maturity of organizations.
So a lot of the people that we're working with are are obviously uh adopting AI. They're kind of allin and they're looking to retool processes. Uh I've heard the term and I kind of like it citizen developers. So we run um into those people uh ones that don't have a technical background who are being encouraged by their leadership to you know solve problems with AI and like you know accelerate their workflows and in that case you know they run the risk of you know deleting artifacts off their system uh pulling in context uh that might be sensitive and then like accidentally leaking it outside of the corporation. On the flip side, you have your developers who of course are trying to take advantage of new technology and in that case they're they might have like 20 different agents running to go and perform uh various roles across the enterprise and there the same risks uh take place as well. But it's not even just innately tied to AI, right? Like there's still just mistakes that people do by accidentally sending an email uh you know with the financial information to the wrong person, right? or sharing credentials across uh you know chat ecosystems that otherwise could lead to to a compromise. So we see both sides of the house. We still look at the user behavior and we look at how they're working with agents and then we look at the agent behavior as well.
>> That's really interesting to me because it's a bit broader than I thought. Yeah.
>> How can you have enough context about a company, its individual job functions, what they are allowed and not allowed to do from the corporate perspective to determine in real time if person X with job Y in group Z responsibility, you know, Q is doing something that is suspect because to me that implies a level of specificity that's almost crazy. So I'm impressed that you managed to figure it out how. So for us like the setup of the product itself is predicated on like getting a corporate policy or getting something as simple as like what is the sanction software that you use across the enterprise. And you'd be surprised with that little bit of information and understanding the context that we're collecting. I can guarantee that there are policy violations that are occurring across the company. So people come to us and they say look um I'm I'm not going to restrict AI usage. I'm I'm going to let it happen. Uh but now my concern is I can't keep up with all the AI tools that are coming out and I've given people access to use these tools but I don't know how they're using them. So right away if I understand what like the allowed software is I can immediately tell you people that are using other software be it AI remote access or something else that is not sanctioned for them. So like that's like hour one sort of uh output for us and then over time and basically understands the operating aspects of the business because we're constantly forming baselines of what's normal for that user what's normal for that department what's normal for their cohorts and that allows us to essentially start to put the policy to use on the endpoint itself and stop bad things from happening. So we don't really require a lot of information. I think the the big advantage that you know or what makes this possible today and why it wasn't possible you know a couple years ago is the advantage that we have in in things like embeddings the ability to take semantic words like things that we understand have meaning and translate them into something that a computer can understand and make decisions on top of.
>> You're talking about uh vector databases and tensors more broadly.
>> Sure. Yes. Like it's Yeah. I mean in its essence it's basically you know words have meanings we know how to interpret those but it's been difficult to represent a lot of dimensionality uh for computers to understand but now because we have these large language models as part of like what makes them work really well is that extreme amount of dimensionality right that they understand like when these words are put together they have a more specific meaning uh than maybe when they're, you know, split apart from each other. And so that was an advantage that we were able to take um within building the product and that serves us well.
>> I mean, you're literally talking about why people are moving away from vectors because they want to have a a more multi-dimension way to represent data as numbers than sorry, words as numbers.
That all tracks with me and that makes good sense. But I'm curious about the learning loop because you said you can provide value right from the start with corporate policies, but then you keep learning. On the other hand, the way that I understand the way how it works is that there's a basically an ondevice agent which I think is doing local compute. So I presume there's kind of an SLM involved there. And then does it then federate information back to a centralized database to learn about Alex incorporated and then send that back to the ondevice agent? How does that process function?
>> Yeah. So quite simply when we were building out the architecture, we didn't want to have a back-end process and an endpoint process. We wanted to have one architecture that could work for either scenario because you might have some systems where they don't want to run anything at the endpoint itself because of you know regulatory compliance whatever. So the way that we've designed the system is it can run completely on the back end or it can run on the endpoint itself but it's the same architecture. So you asked about >> No, I'm just curious why. I mean, I feel like if you can centralize the compute, why not have uh I don't know, a more powerful model. You have more flops to play with.
>> As a founder, you've taken the time to become an expert in your niche and you fully understand the entire landscape.
But with so many regulations and rules that you need to follow from federal agencies and offices here in the US to the European Union and beyond, it's impossible for even the most diligent person to keep up with every exacting requirement. That's why you need to simplify compliance with a trusted partner like Vanta. All my startups use Vanta and they love Vant's AI powered platform that automates your entire compliance process. Whether you're preparing for a sock 2 or you're running an enterprise GRC program or you're doing an audit, Vant is going to worry about the security so your team can focus on building great products. That's why some of our favorite companies like Ramp and Writer are spending 82% less time on their audits by working with Vanta. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate. Vanta is here to help you automate your security and compliance and earn and prove trust. So get started today at vanta.com/twist.
That's van nta.com/twist.
>> So cost, you know, uh not everything requires like the most uh you know the the the greatest model or the frontier model. The way that that we use models, we use open uh models that have been published out there. We do rely like we'll make use of like the um the cloud service provider models or if a customer wants to bring a model. When it comes to embeddings, we control those um and we're using open models to dictate that those embedding models can run on the endpoint. They can also run on the back end. We've made uh changes to those models to optimize them to be very performant and to do particular use cases to solve like certain problems.
And so like we control that architecture. But if a customer otherwise wants to do deep investigations on all the data that we've collected, they have the capacity to do so. All right.
>> But the the effectively the way that the system works is we're building out a pipeline where we put this context in.
We start with the raw behavioral information and then we're decorating it with, you know, who's uh logged in, what is it that they appear to be doing and aligning that to whether or not it's a corporate violation or not. We have a single architecture that basically is built to run on the endpoint or it can run on the back end because of the way that embeddings operate. We want to control that process and we use embedding models. Embedding models are great because they're very performant.
They don't require like GPUs. They can operate on CPUs and when it comes to decision-m they can make decisions in sub-second time frames. Like we don't have to use a heavy amount of reasoning.
the the subsecond time frames thing is what the most interesting thing because the way that I think about int practice and you know it hasn't been rolled out at the company that I work at so I'm kind of theory crafting here but as I go to do something I shouldn't do it goes bing Alex don't do that that might be insecure is it that fast of a process or am I uh overestimating how quick technology is today >> no it it it has to be that fast to get prevention so the idea like the way that we roll out inside of a company is generally speaking if you ask like a siso who are your riskiest users and why they can't really tell you, right? They know the workflows that are taking place. They know roughly what people are doing throughout the day, but they don't emphatically know this. And so, typically the way that we roll out is we start in more of a baseline mode. We install ant across like the ecosystem.
It starts absorbing the information again. It has that corporate policy.
We're surfacing violations. The company is going to have more than enough thing to do based on what we're surfacing in that moment. We don't want to necessarily get in the way of anybody's workflow. We don't want to annoy people.
I don't want to run, you know, and like, you know, prompt them in some form unless I have information from the company. So, there's typically a burn-in period where you might have two weeks to establish baselines of what's normal, what's not, you know, where are the violations occurring that I actually care about? Because in your corporate policy, you might have something that stipulates um nobody should use social media, but you may not actually care to enforce it, but you might have on the other hand that AI use and sensitive data that goes into these models has to be done in this particular way. And so for that moment, like we're going to drudge up that behavior. We're going to say here's your unsanctioned AI usage.
By the way, here's what people are doing. This is the information they're sending in. This is the work that's taking place. And it allows us we we've built the product to basically isolate that workflow and then say well when I see this activity in the future now I want to intervene and that intervention can be customized. The way that I think about the product as this stop you before you do it thing is one portion of it because it can also do that for humans and apparently also for agents and it can provide a a bird's eye view into how a company is using software and in particular AI more broadly so people can learn from their own usage.
>> Correct. So the idea here is like you know I I've toyed around with like the lingo but it's like an organization work model. We we talk about world models.
>> Sure. Um, and world models were like super advantageous to cars, right?
Because prior to a world model existing that encapsulated the environment, we were trying to tell the car like when to stay in the lanes, when to apply the brake, when to like kind of, you know, change lanes, whatever. And the problem was is that you were overfitting to a particular set of environment variables.
When you had the world models, it allowed the car to essentially become more predictive, right? Oh, I'm anticipating that somebody's going to walk out in the crosswalk or there's a stop sign and I need to apply the brakes. It allowed the self-driving car movement to be more accurate. So, when I say that most sysos aren't aware of the behaviors that are taking place, step one is to make them aware from an observability perspective of you have some problems inside your environment that you probably didn't realize. And step two is to figure out which ones do you actually care about. And then step three is to determine how do you want to modify that user behavior if at all or your corporate policies and then enact those using ant.
>> So really I think that calling this a cyber security company almost feels too narrow. You are building kind of a work model in a sense. How far can you push that? Because once you have this information about how a company works, you could do all sorts of fun things like tell them where they're being inefficient or recommend different ways to go about stuff. It seems like if you can get wide adoption in a lot of information, this is a really potentially uh lucrative and useful tool that you're building with a lot of future applications that go outside of just cyber safety.
>> Absolutely. I I I think the you know, again toying around with like kind of lingo here. I don't know the best way to describe some of these things because they they feel new like we haven't had it at our disposal. One of the ones that I was playing around with was like the semantic substrate for security. So all of a sudden I have this like all of this information that's describing the work that people are doing inside of the business and that is a that is a massive uh you know set of context that we have at our disposal that can help accelerate closing out true positive benign tickets in the sock right it could give further context to DLP related events it could surface inside risk activity be it the 1% bad guy or the 99% mistakes that take place >> it could be choose to isolate and identify people that need training. So like there's a broad applicability in having context that describes what's taking place across the organization.
And you hit the nail on the head.
There's a productivity angle to this as well in which if I understand what people are doing throughout the day, then it becomes ripe to figure out what things might agents benefit, right? what is the mundane monotonous work that is occurring across different departments inside of the business or ones that like particularly risky across my enterprise that might benefit by having an AI agent do it and then once that AI agent is in place how do you ensure and keep it on the rails right how do you know that it's doing the right thing that it's aligned to the task and so for us we're concretely focused in security but we've we go and target big enterprises our our environments are global 2000 and above.
So think Fortune 500. And the thing that you articulated is what they're after as well. They say I can start with security. I can bring a level of visibility and stop problems from taking place. But then there's this downstream applicability that becomes really attractive like can we start mining out of that information ways to do process distillation ways to identify who are like who's using AI the most and how are they using it in ways that we can help others learn from that >> and this is why I'm terrified that one of the you know AI lab JV FTE private equity working groups are going to try to scoop you up and then take all the data you have and then apply it because it's going to be incredibly valuable.
But just listening to you on the lingo point, I work obs maybe. I mean, it does feel kind of like general work observability, lots of data. You can do different things with it.
>> We could we we like we've also used like um you know, I heard data lineage for a while, which is like looking at how data moves through the enterprise and I I think that that has merits and it's proven in the market. uh we've been toying around with behavioral lineage as well is like what are the behaviors that people do and how does that like then intersect with data lineage how does the behavior of an agent you know uh operate uh where we've settled on the marketing side is like the intent aware that's why you see that but you know I don't >> TBD and like how people respond to it so far that's been you know the the way that we've been pitching it >> most AI tools are adding friction not making your life simpler and it's another tab to switch to and maybe you forget to even do it. It's arduous. What you really want is one system that's going to make you more efficient and save you time every single time you do work. That's why I love Superhuman Go from the amazing team behind Grammarly, which I have insisted all my team members use since day one. Now, it's an AI chat that lives on the side of your browser. It's always there. Maybe you're drafting an email midmeating. It goes and helps you finish it without switching apps. Maybe you got a 40 email thread to get through before that call.
It's going to summarize it for you in seconds without losing your place. No new tabs, no starting from scratch, no context switching. Superhuman Go has the context of everything you're working on.
It works inside the tools and sites you already use. Your inbox, your docs, your browser. Maybe you're doing social media all day long like me. It's part of my job. You can try many of Superhum Go's features for free. Find out more.
Superhum.com. That's superhum.com.
I would say, you know, lineage and substrate are a bit too technical, but then again, I have to say the words agentic orchestration at least three times a day. So, what do I know about branding? Um, okay, let's talk about a couple of other things. One is just the the employee element of this. Now, uh, this computer that I'm on right now, because Twist is owned by Launch and Launch is a financial company, has all sorts of tracking software on it, right?
Just for this, you have to do that. I don't love it even though I don't actually care because no one cares what I do. But it still feels a little bit weird to me that, you know, there is a record somewhere of, you know, every tweet that I click on. Right. Right.
>> Now, in in what you're building, it is >> more granular. And so, I'm trying to kind of sort out how much do employees care because on one hand, I think it's becoming the norm to have your work observed to some degree. On the other hand, Meta just made a big push to really look at what their engineers were doing and that was very unpopular. So where's kind of like opinion and norms around this type of observation?
>> You know, I think it's TBD to some extent. Um, at least on the enterprises that we work with, a lot of them have corporate policies that stipulate the asset that you're using is subject to monitoring for the purposes of like it's their corporate asset, right? Like the intellectual property is there. So I think um you know most of the security software that has been deployed even in a traditional EDR sense is been historically collecting all of this information about the actions people are taking on their system. Right? And I I I do believe that we bring a new level of granularity to it and we have to determine you know what businesses are comfortable uh effectively deploying and I think it's just a matter of being straightforward with your employees.
>> Yeah. And so uh it's a matter of if it's in the corporate policy and you're able to collect it, then you know, okay, that's fine. Our our kind of general view is we when it comes to the the information that we collect, we don't want it coming back to a central authority. We can be the people that host that environment. So we can deploy as a SASbased uh as product and and host on behalf, give you a dedicated tenant, but more importantly, what we've heard from global 2000 and above is they want to own their data, right? they don't want it going to somebody else. So, Ant is deployed within the customer's boundary like we don't even get to see it. So, the limiting factors there are that's one way of kind of retaining that like it's only staying within the corporate environment. It's not being shared with other people. And then the secondary item is how much do you want to collect and centralize back to that you know uh that that corporate backend.
And so we've provided an ample amount of configurability that if you don't want to send something to the back end, you don't have to. You can keep it on the edge. Now obviously there's an operational um gain in putting everything in a central store, >> but there's more data to learn on. Yeah.
>> Yeah. But like a corporation may not want to do that. So for everything that we collect, there's toggles that basically allow the business to turn it on and off. We um support user groups, endpoint groups uh in terms of like you know you might want to collect more on your developers just because they have a higher risk uh pattern whereas your legal you may not really want to collect anything at all and then beyond that within the product there's rolebased access control and attribute based access control. So like if we're collecting something like screenshots for an investigation yeah >> I don't want the sock to necessarily see that. So we allow the business to basically hyper tune the information that's exposed uh to any given party.
>> I feel like you're nibbling around the edges of agentic identity and the issues and lack of maturity in that product world somewhat. Am I am I wrong? If I want to know what the agents are doing, I'm I'm going to want them to have a distinct permission set and a distinct identity and >> Well, it's the same thing with people too, right? I mean, I I like you could like I think part of the problem with like a corporate policy is that it it lacks teeth. It's only as good as its ability to put it into a control point.
And because corporate policy is written in natural language, there's some level of like interpretation that takes place by the employee. And I think that's sometimes what leads to, you know, mistakes being made is that the employee feels they're working within the boundaries of the corporate policy when they may in fact not be. And and the way that you get around this, right, is you have a draconian, you know, way of of stripping down the asset and removing the freedom and you're just saying like, "Thou shalt work this way." And and I don't think that's particularly uh uh fun to work in those businesses. I understand it, but like what I want to do is balance like being able to give a new control point layer to actually stop bad things from occurring while also not infringing on like privacy, right? And and so it's up to me as I design that product to put the controls in place to not build something that could otherwise be abused. And that's something that's very top of mind for us. I don't want to be nanny software. I don't want to, you know, police, you know, how many, you know, how much AI somebody used throughout the day. That's not what I care about. What I care about is stopping mistakes from taking place, removing adversaries from environments, making sure that people can adopt AI safely, and that requires some level of of observability and understanding what's happening.
>> Work obs. I'm telling you, it's going to be big. All right. Uh let's talk really quickly some business questions. So, you've mentioned how there's a SAS uh version of this and a self-hosted version of this. Now, when I usually see that breakdown, it tends to be open- source software. As far as I know, you guys are not pursuing the open source approach. So, uh, talk to me about the business decision there to allow for self-hosting and then also how do you charge for that?
>> Yeah, so self-hosting, um, the reason for it was when we were at Microsoft, we learned during this AI movement, people are really sensitive to their corporate data.
>> And I I think from a regulatory perspective, we're seeing more emphasis on data sovereignty. We're seeing like uh the intellectual property of a business wanting to be contained within its environment. they don't want it to go to, you know, third party supply chain. And so it was a it was a first principal decision for us. In the same way that we said we're not going to depend on any other security product to get our telemetry because that impedes our ability to be preventative and make decisions quickly, >> we also said we're going to make it out of the box oneclick deploy inside of whatever cloud you guys operate in. And we support the major ones. And so that was just an important decision for us.
If we host it, then effectively we take on the hosting cost and we pass that on in the licensing. If you host it, that becomes like a COG's implication that you have to effectively manage that that spend and we give you the predictability of what that looks like.
>> But I'm still paying you yearly, quarterly.
>> Yeah, there's a licensing. Yes, there's a licensing cost associated with the product. It just will change if you're hosting it because you're going to take on the uh the actual hosting.
>> Okay, that makes good sense. But it's still basically charge the same way.
Lower cost. Okay. Okay, that makes sense to me.
>> Uh, now you guys came out of Stealth and announced a $100 million round.
>> Mhm.
>> Uh, these happen more often than they used to, and I'm always curious why you need that much money. Uh, it's a lot.
That's that's an old seed fund from when I was younger. Um, so what are you going to do with $100 million?
>> So, the thing with Endpoint is it's a wellestablished market, right? It's it's something there's a lot of players and incumbents there and to be able to like penetrate inside of global global 2000, Fortune 500 and above. You need to like building that endpoint company takes a lot of effort, right? I have to build an agent that works across multiple different platforms. I have to like uh concern myself in the research and development of putting AI directly at the edge while also being able to run it on the back end. We talked about like you know hosting inside the customer's environment making sure that all of that infrastructure is supported be it uh if you're using AWS, Google um or uh uh Azure, right? Like all of that takes a significant amount of engineering to get it right to make sure that it's tested to not make those mistakes. And so there's a lot of uh money raised to basically go and do that. just expensive to build a product, but it's also expensive to then like get out in the market >> and land inside of these like big enterprise accounts. Like people come to us and they say, "Hey, look, are you going and competing with the traditional EDR?" And the short answer is no, right?
I don't want to go and compete with them on the same playing field. Why would I do that? From my perspective, EDR is a commodity at this point. Everybody's got something in place. They might be reasonably satisfied with what they're getting. My job is to augment where that EDR solution is not meeting the needs, where an inside risk solution is not meeting the needs or a DLP solution is not meeting the needs. So we talked about like the semantic substrate for security. My business is trying to build, you know, like the programmable endpoint. Can I solve a variety of different use cases using AI as my advantage across any platform in any cloud and give someone that level of visibility to understand what is happening inside their enterprise? It just takes money and capital to do it.
>> The team is pumped because you're about to close a massive deal, but then the client's lawyers get involved. What happens if you get hacked? How are we going to protect your data? There's no need to panic. This is why you brought in YC. Why security is staffed with over 40 experienced engineers who have actually worked security for world-class companies like Apple, Uber, Microsoft, Robin Hood, Brex, and so many others.
But the best part is you don't even need to hire Ysecurity. Your company can rent Ysecur's elite team by the hour. That means no massive salaries to pay, no costly consultants, just real experts embedded in your company helping you out with your Sock 2, ISO 4200, or any security or compliance challenge you're facing. You can even set a monthly cap so you know exactly how much you're spending. And your first 6 hours are completely free. Head to Ysecurity.io/twist and book your free 6-hour strategy call.
That's ysecurity.io/twist.
Given how many different endpoints, clouds, and services you have to make work to have this actually function at the speed you need it to. I'm never going to listen to a developer again. He tells me they can't launch on iOS and Android at the same time because it's too hard. I feel like you're taking on a much more difficult challenge. All right. Uh, last question for me is pretty simple. When you guys came out of stealth, you announced that in was generally available, which means your go to market, you know, starting gun was shot off.
>> Correct.
>> How has reaction been? How has uh the market responded? It's been like a floodgate even before that like we were like the reason why we we effectively like we've we've been in the the kind of market to some extent uh not like out of stealth but like kind of pseudo out of stealth for a couple of months and the reason why we just kept consistently holding it back is like I've retained a pretty healthy pipeline of like you know folks that are interested in what we're doing. So when Lou and I left Microsoft, they were like, "Man, you guys are going to do something crazy and I want to know what that is." And so like we've got a lot of goodwill in having multiple exits and startups that we just had a bunch of people that were like, "Tell me what you guys are doing." And the second that we were ready, we were entertaining, you know, uh, POVs and people that wanted to go and deploy the solution, test it out, because they're like, "We've never seen anything like it. This is exactly what we were expecting." And so beyond that, like typically you come out of stealth because you want help in hiring people.
>> And I I've hired well over, you know, 75 people now. Uh and I've not paid a single recruiting fee. And so like coming out of stealth was not lackluster. Like we've got a lot of like for us like it didn't feel like any material difference. Like we've retained a healthy pipeline of people that are interested. I've got more people now asking me like, "Dude, I want to see this thing in action. Uh, this is what I was waiting for." And so for us, it's just a healthy amount of demand beyond what we already had.
>> Do you have enough GTM infrastructure in place, sales teams, etc. to handle all the new inbound?
>> That's exactly where we're hiring right now. So, we've got uh several sales reps. We're hiring for sales engineering. Um, you know, we got folks on like the forward deployed engineering side that's been staffed out. And so like we're we're getting our pieces there. I feel pretty comfortable. But like, you know, now it's just a matter of like going through the motion and executing, right? You know, having multiple deals uh in tandem, managing the POV process, making sure that we're delivering success and outcomes. That's the biggest focus that we have right now. So early beginnings of it. Uh we're hiring and then it's a matter of just like continuing to turn the crank here.
>> Well, we are looking forward to when you start announcing a ar milestones, but in the meantime, it's int.ai AI Brandon, congrats on the Brown. Congrats on coming out of fake pseudo stealth and uh come back on in six months and tell us how it's going.
>> Appreciate it. Thanks, Alex.
>> All right, everybody. Next up on today's twist, >> you remember David Im. He was previously on our show. He had Claraara, the open claw AI girlfriend. Do you remember this Jason from February? Yes, I do. I do.
So, he's back. He's got a new product from his company, Sume Labs. It's an agent orchestration layer utilizing multiple video generation models. The goal is generating high quality video outputs in just one attempt. Jason, the the idea you could finally oneshot your AI videos instead of multiple gorounds to get it exactly the way you want it.
David, thank you for coming back to the show.
>> Yeah, it's good to have you back.
>> I mean, when you make video, it is literally like a slot machine. You put in your prompt. I did it the other day.
Pull up my Yoda uh one. And I did it in gro.
>> It was it was relatively good. It got it right. I said I want Yoda from the Clone Wars style to say Frontier Model Wars begun.
>> I see. Yes. Here. I >> Frontier Model Wars begun. They have.
Which is a favorites line. The Clone Wars begun.
>> They have.
>> There we go.
>> And I honestly got to be honest. I give it like a nine out of 10, eight and a half out of ten. It knows what it's doing.
>> It's pretty good.
>> The voice is off, but I mean I'm not paying a royalty to Disney here, so I don't get in trouble with Disney. But David, why don't you show us what you built because I do think there is something here to taking when you get rid of the slot machine nature of these LLMs, um, it becomes more predictable and your utilization goes up.
>> Yeah. Yeah. The slot machine is not fun when you're making videos and images and they take 30 seconds. It's incredibly frustrating >> right now. You know, deboling right now is um like prompting the videos again and again to get the right results because it's unpredictable because you know video generation models are still castic. So what we're trying to do is make an API that is basically unwrapper of like let's say five or six models to get the production ready result. So our belief is that once we make these one piece piece piece let's say production lab production ready like API primit primitives then once we got the APIs then we could make our agent one shot a marketing video very easily.
>> Okay I'm guessing you have a killer demo to show us.
>> Yeah, >> there it is.
>> Can you see a screen?
>> We we can see it looks like your your X feed.
>> Yeah. So yeah, this is kind of like our UDC API. It's our operator API and then >> you could do kind of like >> so this is basically the same prompt. So it's a basic prompt with Gemini Omni Cance and Sum Avatar and basically what we did is we are basically basically on a router of multiple models not only video but image video audio and clipping and everything. and we were a rapper around all these models and this is what we got with the same problems.
>> You're seeing on the left Je Gemini Omni and it looks like um a young adult maybe a 25year-old or younger in their apartment in a city uh or maybe they're in high school in the second one and um they're doing the classic looks like selfie marketing like I'm making a Tik Tok video about this product. Yeah. So same prompt you see three different results then what happens what's next >> so what we're trying to make at the end goal let's see like after six months is a video agent that wants marketing videos so our users are brands or marketers want to promote their product and make video ads for them and right now our first model was for UGC so as you know like if you want to make UGC videos with AI right now you have to combine a lot of different models let's say like sea advance or like touch up the image or grog and everything and then after that you have to combine those videos to make along because you know video generation models only like support up to 15 seconds it's like 30 seconds for our like CDS like next model like it's only 30 seconds so what we did is we made a router of video generation models and image models and audio to like get the like audio persistent to like make this kind of videos and then finally you could generate up to 60 seconds of consistent afterare videos right now.
>> Okay.
>> So, you put in a script. Hey, I want to promote my new uh app. It's called Uber.
And you open your phone. It's rain. You go outside. It's raining. You You can't walk home. You want to get a ride. And you write the script for this.
>> And then it goes and makes you a bunch of different scenes. Do you tell it what scenes to make in your >> No, actually it's only So for the user, it's basically just picking an avatar and then writing the script.
>> Got it.
>> That's it.
>> The user writes the script or the LLM writes the script.
>> The user writes the script.
>> Got it. So after I write the script, >> then each scene gets done three times and then it's up to me to stitch them together. So I might say, "Oh, I like this one where it shows the car, you know, in the pouring rain. And I like this one when it shows the guy getting out with his umbrella or putting his jack, one of them has him put his coat over his head to walk to his front door and I and I just get to essentially vibe code my way around a longer form video.
Yeah, >> 100%.
>> Okay, cool. Do you have any outputs like that that we can see? I would love to see like where you where you got to with this.
>> Okay, so I could show you the video.
Yeah.
>> So this is like 16 seconds. So you you could see that it's up like more than 15 seconds. But yeah, you can make these kind of videos with 60 seconds.
>> So it's using multiple ones and then it stitches together with one clean audio file across it. So a little bit of a hack there. Um >> Yeah. Yeah. Yeah.
>> And if you go to >> Yeah. So around now Yeah.
>> It's also consistent the the her face remains totally consistent throughout. A big problem when you're generating these kinds of like video clips I find is that it'll for the first like seven seconds of the video it'll look like the person's face and then it sometimes gets like distorted towards the end. Like that's a big problem with >> Yeah.
>> Yeah. It's like the keeping that facial consistency the whole time.
>> What is the website? Do you have a website for this that we can see?
>> Yeah, you can search sum.com.
>> Ah >> su.com.
>> Cool. Oh my god, you got a good domain name. How much did that cost you? Four letter.
>> Yeah, we got it cheap.
>> Really? That's a $100,000 domain name.
>> 70% discount on the initial price on GoDaddy.
>> Love it. All right. Well, this is like a great start. And uh who's it for? Who's the customer? You think startups making uh uh marketing videos or just general DTOC marketers? Who who who is your customer base currently?
>> Yeah. So, right now we have 20K users and the main customers espe especially about 90% of the paid customers are brands.
>> Got it. our main audience >> is not on Twitter, but they're on Instagram and Tik Tok.
>> Got it. Yeah. People are trying to flood those space. I can't even tell what's AI anymore unless like you're paying attention. I got a lot of shark videos because one of my daughters loves sharks and I'll do like shark videos with her and now I'm starting to get AI slop sharks and you know they start out and it's like a person on a boat and they're pulling in a fish and you're like, "Oh my god, there's going to be a shark."
And then like this ridiculous shark jumps up, eats the fish, the person falls in the water, the shark is jumping in the water. I'm like, sharks don't interact for 90 seconds with a human.
This is getting a little ridiculous here. Uh, all right. Well, great job with the startup. Uh, keep grinding and we'll see you when you uh have your next update.
>> Awesome. Thanks.
Related Videos

Expanding Stikbot thumbnails
leopoldshorts
2K views•2023-09-24

Digital Discrimination: Cognitive Bias in Machine Learning
redmonktechevents2974
4K views•2019-12-18

Evolutionary Approach to Clustering by Ujjwal Maulik
ICTStalks
279 views•2019-06-26

Rose Yu "Learning from Large-Scale Spatiotemporal Data"
networkscienceinstitute
2K views•2019-03-04

Stanford Seminar - Generalization through Task Representations with Foundation Models
stanfordonline
4K views•2025-07-14

Satellite-Based Wheat Yield Forecasting using GEE & Transformer Neural Network
gisrsinstitute
634 views•2025-06-15

Paradigm Shifts in Data Processing for the Generative AI Era: Robert Nishihara of Anyscale & Ray.io
GradientFlow
2K views•2025-01-02

How to Build Your Own GenAI-Based Knowledge Management System
2150GmbH
360 views•2025-06-03
Trending

WOW! Judge TURNS THE TABLES on Trump in His OWN $10B LAWSUIT!!!
MeidasTouch
197K views•2026-07-23

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23