The Exchanges

Every argument clarity score on this site is built from rows on this page. Each question and answer was assessed with names hidden, the host's own answers included, on four things from 1 to 5: directness (does it answer the question asked), coherence (do the ideas follow), precision (concrete details and clear references), compression (says a lot per word). The weighted mix (30/30/25/15) is the exchange score. A person's published score averages their exchange scores on raw tape only, at least 8 of them, shrunk toward the cohort mean. Full method →

Dimitri Sirota no published score: only 7 usable exchanges on raw tape, and a fair score needs 8+ · coarse estimate ≈4.0/5 from 7 raw tape exchanges record → ← everyone

Every exchange below was scored with names hidden, four dimensions each from 1 to 5. An exchange's score is 0.30·directness + 0.30·coherence + 0.25·precision + 0.15·compression. The published score averages the raw tape exchange scores and shrinks small samples toward the cohort mean, so five great answers can't beat twenty good ones. Produced feed rows count only toward coarse estimates, never toward a full score.

clear all ✕
7exchanges match
7on raw tape
0redirected or not addressed
Answered raw tape D 5 · C 4 · P 4 · Cm 4 4.30

Q So it's the scanner layer. Uh, on top of it, you have the graph database layer, which establishes a relationship between the different parts. And then on top of that, you have machine learning to extract patterns. Is that?

A Yeah, that's kind of a simplified. So we have the scanners, uh, the back end, we have a graph, uh, uh, the scanners don't do this. Scanners kind of do parsing. They're kind of like dumb, uh, endpoints. Um, most of the orchestration is in the back, in the back end. Uh, that's also where we store the graph, uh, information. Um, so we have a graph database, uh, embedded in the system. Um, and, uh, we don't, we try, we don't, we try not to keep data for reasons, regulatory reasons, privacy reasons. So we essentially keep, uh, almost like a GPS. We keep pointers that are tokenized and salted And then we have a little bit of encrypted metadata to make it searchable. So think of it as this kind of virtualized inventory of the data. It's searchable, um, but the data still stays in Snowflake, and Databricks, and in Hadoop, and SMB, NFS, CIFS, whatever that is.

AI assessment note: “Yeah, that's kind of a simplified. So we have the scanners”

Answered raw tape D 5 · C 4 · P 4 · Cm 4 4.30

Q VCs for what it's worth, like a lot of people are gonna say, well, you know, uh, if your tiny company is selling to the Nikes of the world, it's super hard, don't do it, sell instead to, you know, startups or early adopters. Well, how were you able to pull it off, and any lessons learned for, you know, people in the audience who might be early stage entrepreneurs?

A Yeah. So look, there's a couple of things here. So I'm going to be very, very honest. Um, one is the reality was the people that cared about our problem that we, you know, we built this beautiful mouse trap. Well, we gotta, we gotta look for the people with the mice, right? So the ones that had the problem most acutely and had the biggest penalty, like, um, you know, the regulators in the UK or France, like Canil, they're not going after Joe's auto body. They don't care about Joe's auto body. They're going after the multinationals. So they had the problem. Secondly, it's also a matter of comfort zone, right? Um, I was starting this company in my late forties. I'm 52 right now. I'm sure you guys all think I'm 35. Um, so I kind of had sold to enterprises, and on top of that, I didn't know a lot of, like, the CTOs at a lot of these, you know, your startups are 25 years old. I don't know them, right? I know the people that are CTOs at the bigger institutions. They're more my age. So I think there is also just a comfort zone in terms of Who I was comfortable selling. So today we do sell to SMB, not, we sell to mid-market. I would not say SMBs, uh, but obviously I don't do the selling, and we have a bunch of young people doing, like, doing the talking to the younger, but I do think there needs to be a compatibility, and I do, you know, I may, it may sound terrible, but I do think the…

AI assessment note: “the ones that had the problem most acutely and had the biggest penalty”

Answered raw tape D 4 · C 4 · P 5 · Cm 4 4.25

Q So I'd love to, um, double click on what you started talking about and, um, understand the use cases. So privacy, what is the scenario for privacy, uh, and how does BigID help and then maybe move to, uh, the other areas governance?

A Yeah, sure. So I'll kind of describe our evolution in kind of, uh, three steps. So the first, so I would still look at our, our tagline if you go to our website is know your data, control your data. So Kind of very similar to what I described around data visibility and, um, uh, control. What we focused on for the first kind of three, four years of our history is really just knowing your data and looking for applications of where do you need to know your data? Why did, why was it important? So first we settled on privacy, right? So I think we were six people when we sold our first enterprise customer, Nike, and I sold it from like the backyard in Mamaronek in Orienta. Uh, by the pool. I didn't even, I didn't even have a shirt on. Um, and, ah, our second deal was Intel. Um, and these were like meaty, meaty first deals, and it was like literally dialing for dollars. We didn't have any relationships. We didn't even have investors that had connections in these firms. But we looked for, ah, kind of a repeatable use case, and we, the GDPR one was appealing because, A, the old technologies couldn't solve the problem. Um, there was obviously a regulation over the horizon. Um, it impacted large companies. They would have liability both in terms of the, um, the country regulators, the DPAs, uh, potentially individuals. Um, and so we focused on that use case. Um, and so privacy, and in par…

AI assessment note: “privacy, and in particular, just this data access, data deletion use case”

Answered raw tape D 4 · C 4 · P 4 · Cm 3 3.85

Q And is a part of the complexity of GDPR that you need to be able to find all the data that relates to one individual in particular, as opposed to other forms of data privacy?

A Yeah, so, so GDPR, and you know, now today there's multiple, there's regulations in most countries. Canada has a new regulation. Obviously California had CCPA, not obviously, but some of you may know California had CCPA, which was replaced by CPRA. Uh, Virginia has a new law. Colorado has a new law. I think Washington State has a new law. Michigan, Ohio, Florida, Texas have new laws and committees. So again, it's getting more of a, uh, a minefield. So under these regulations, consumers have a right to control their data, and that means being able to access their data. It also means being able to delete their data. Technically, under these regulations, the definition of what is personal is very broad. Historically, when you look at, kind of, breach regulations at a state level, the definition of personal data is, is very well defined. Typically, 13 or 12 attributes, like address, name. Under GDPR, it could be anything, right? So my shopping preferences on Shopify could be personal data. My GPS coordinates. So right here, we all share a GPS coordinate, right? We're all in the same location. That could be personal. What makes the problem hard of being able to locate, um, all of a person's data, um, is that obviously there could be a lot of things that define what is personal. In fact, instead of saying, and I'll talk about what we did that's innovated there in a second, but that's…

AI assessment note: “What makes the problem hard of being able to locate, um, all of a person's data”

Answered raw tape D 4 · C 4 · P 4 · Cm 3 3.85

Q Yes, let, let's get into that. Um, so I'd love to understand sort of the architecture of the product. I mean, presumably you have a bunch of Crawlers or connectors or whatever, like ways to get into the data?

A Sure. So yeah, so we started as a pure SAS product. Uh, however, what we discovered early on is most of the companies that had this problem or cared about this problem, um, were large enterprises. And back when we were started selling, so we started selling at the beginning of 2018, the large enterprises were still a little bit schizophrenic around cloud. They didn't mind some of their, uh, ML kind of workloads in the cloud, but they didn't have their primary workloads in the cloud. And so we kind of split the product, the same product, but we essentially made it available, accessible, uh, on-prem or through kind of even a hybrid deployment. So one thing to understand is while we started cloud native and AWS, we very quickly kind of realized that we needed to make the cloud runnable in GCP and Azure and in a private cloud, but also even in a, in a, uh, legacy data center. So that's one thing we did. Um, the rest of the stack, basically we, we didn't want to go, uh, with agents because agents have Complexity around instrumentation. There's some companies that have been successful with it, with agents and sidecars, but we didn't want to do any of that. We want to leverage the native protocol. What we do have is scanners. So we have kind of a two-tier architecture. We have a backhand server essentially. Um, think of it as kind of an, uh, in the plain old telephone system for those…

AI assessment note: “We have kind of a two-tier architecture. We have a backhand server essentially... And then there's scanners.”

Answered raw tape D 3 · C 4 · P 4 · Cm 3 3.55

Q How far along were you when you started that marketplace?

A Uh, look, we were, uh, you know, like it was a couple years ago, so, Look, we were, we had revenue, but I, I still think it was probably under 30. Um, um, we had a little bit, you know, we benefited, you know, I think we decided to do it after the tiger, uh, money came in, so we had to kind of spend the money on something. Um, and back then you just, you know, hired a lot of people, so, um, you don't do that anymore. Um, but, um, but yeah, and we, but, you know, I think it basically came because we realized data is a massive problem, right? And historically people kind of ignored it. You had, You had vendors that specialized in pockets of it, like Varonis, for those of you, uh, that are familiar with it, that focused just on unstructured data, so things in your SMB. You had, um, Proofpoint that just focused on email. Um, you had Symantec that did a little bit of unstructured, but mostly structured. Uh, you had, you know, Collibre or their, um, antecedents that focused on just extracting metadata from SQL databases. So it was kind of a hodgepodge. There was nobody that provided you universal Visibility across the data. And we think that's important to have a consistent set of rules, uh, controls for again, uh, reporting on that data, uh, whether it's to regulators or whether it's to, uh, board members, um, or controls just around access. So that was kind of what we embarked on. …

AI assessment note: “we had revenue, but I, I still think it was probably under 30.”

Answered raw tape D 3 · C 3 · P 4 · Cm 3 3.25

Q At 35? Yeah. Uh, I'd love to hear, like, anything you, you, you can share, you know, things that, uh, you wish you knew then, that you know now that you wish you knew then.

A I thought black swans, I remember, so I started my first company right around two, 2000. Um, so we had the full kind of, uh, hurricane, uh, impact from, um, uh, from the first kind of, uh, black swan event, and they told me this was gonna be kind of once a career, and I think I'm on my fourth now. Um, so, um, look, I think that's cha, that's challenging. I do think so much of this is situational, right? There are times when I thought, oh, wouldn't it be great to just sell to other startups, right? The computer just describing. Some of those companies are able to just get huge amount of traction really early by selling to friends, selling to connections to the VCs. But then when something like this happens, like good luck selling to another startup today, they're trying to like rationalize all of their tools. We are doing it. And it's much better to be selling to enterprises and selling to security. So again, you know, depending on my mood and day, I'd say, oh, wouldn't it be great to sell to small companies? Today I'm pretty happy we're selling enterprises, right? The sales cycle may be a bit longer, there's more complexity, um, but at least there's more stability in those buyers, especially when you have, uh, this kind of, my fourth, uh, um, uh, black swan if you include, 2020, and then 2008, and then, uh, 2001. Um, so, so there's that. Um, look, I, I wish I knew then what I k…

AI assessment note: “I wish I knew then what I know now in terms of raising money”

page 1
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 400 conversations transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.