Every argument clarity score on this site is built from rows on this page. Each
question and answer was assessed with names hidden, the host's own answers included, on
four things from 1 to 5:
directness (does it answer the question asked), coherence (do the ideas follow),
precision (concrete details and clear references), compression (says a lot per word). The weighted
mix (30/30/25/15) is the exchange score. A person's published score averages their exchange
scores on raw tape only, at least 8 of them, shrunk toward the cohort mean.
Full method →
Answered raw tape
D 5 · C 5 · P 5 · Cm 4 4.85
Q Okay. Thank you. Um, so let, let's jump into the product. Um, so when you guys started initially, I believe the initial product was focused on, uh, helping secure open source projects, right? Is that, is that, was, was that the origin from a product standpoint?
A It's a, it's a, there was an interesting kind of, um, uh, ambiguity with our name, which I think might've even kind of served us, uh, well, which is we were open source security. So on one hand you feel like it's securing open source. It's the, it's security that is open source. In practice, it was securing your use of open source. So you're consuming open source libraries and there's an ownership paradigm problem there, which is you download this stuff from the internet. Nobody's really got your back. You know, you need to know what you are using. You need to make sure it's vulnerability free and maintain that over time. Um, so That's what we started with. Uh, I think the, when I think about reusable lessons here, you know, uh, what was interesting for us is we set up to build a developer tooling company following the developer tooling playbook, but we're attacking the security industry. So when we started, we started with a, uh, very much the dev tooling playbook, which was pick a stack and deliver, you know, pick, pick something fairly narrow and deliver a great developer experience on that stack win over that community. And so we build open source security or securing Uh, open source usage in Node.js. So mostly NPM packages, uh, which we felt was a, uh, a niche that was big enough and small enough, big enough to care, to sort of have some commercial viability, but also smal…
AI assessment note: “In practice, it was securing your use of open source. So you're consuming open source”
Answered raw tape
D 5 · C 5 · P 5 · Cm 4 4.85
Q Very interesting. Um, The vulnerability, uh, database also sounds super interesting. And that's something you guys have been doing for, for a while, or is that, is that more recent? What is it? What does that do?
A Yeah. From the beginning. So I've kept harping on the developer first angle, but in practice we combine developer first and security expertise. Uh, in the context of open source vulnerabilities, I can have an amazing system that tells you which libraries you're using, but I need to tell you whether they're vulnerable. I need to know which vulnerabilities are known. Uh, and what happens is, uh, in, in the world of open source dependencies, uh, open source projects, uh, an open source maintainer would fix a vulnerability would save much in the release notes. And that would sort of disappear into the ether of GitHub. And so we built actually from day one, uh, a threat Intel system, uh, that listen. So we have a team now about 25 odd people that have a system that, that reads a source of information, just like these like social feed torrents and things like that. We actually also technically read those social feeds. We read. Uh, open source projects like Apache Jira projects and GitHub and many other sources. Uh, and we identify candidate vulnerabilities. That system has gotten very sophisticated over the years and it uses machine learning to identify, uh, uh, candidates. So some of it is simple, straightforward, like bring the NVD database in, uh, and we'll, uh, we'll identify. And, uh, and some of it is, is much more, uh, natural language processing and other sort of combination …
AI assessment note: “Yeah. From the beginning.”
Answered raw tape
D 5 · C 5 · P 4 · Cm 4 4.60
Q Amazing. Well, congrats on all of that. So, um, maybe as a jump off point, what is, what is sneak?
A Um, so sneak is a developer first security company. And what we mean by that is, you know, the company was created on the belief that security has to be built into the development process because nothing else scales. Um, and especially as you talk about DevOps and cloud and kind of the modernized surrounding and that to achieve that, you need to build a developer tooling company, not a security company. And that was really like our light bulb moment is to build a company that, uh, put the needs of the developers and, you know, how do we delight the developer first, um, versus the, despite the fact that the person signing the checks is oftentimes the, uh, the security buyer. Um, so that's really like the core of us. We're about five and a half. Years old. Uh, uh, and, uh, we started, started on sort of more of a sneak open source. We can talk about sort of the different product evolutions. And I talked about the two products we launched, but you know, we, we started off with this dev first mentality, tackling open source security, secure the open source components that we use, uh, and have grown to what we call today, cloud native application security, which is in a cloud native context in which developers are more and more empowered and they manage. Uh, increasingly parts of the infrastructure, you know, in this sort of cloud setup, everything becomes an API. Uh, so basically w…
AI assessment note: “sneak is a developer first security company”
Answered raw tape
D 5 · C 5 · P 4 · Cm 4 4.60
Q Sneak is part of a, an emerging category that, uh, you guys have actually helped define called, uh, DevSecOps. Do you want to talk about what that is and maybe contrast it, uh, with DevOps?
A Yeah, DevSecOps is, uh, the gist of it, it's about sort of putting security into, uh, uh, in the middle of, uh, of DevOps, but it's about adapting security to the DevOps motion. Uh, so generally DevOps has predicated on breaking the barriers between developers and operations, uh, about independent teams that can kind of Take the ball at one end of court and run with it, you know, all the way to the other and do that repeatedly, uh, without external dependencies and kind of continuously. Security hasn't gotten the memo, uh, as an industry, it's still operating as, you know, a separate entity. So teams are not independent. Oftentimes they get dictated to, so they don't really control their destiny. It's oftentimes not continuous. It's not automated enough, a lot of manual reviews and manual processes. And so at a high level, DevSecOps is about, Changing that it's about building a security model that allows you to ship continuously and through independent teams, but still be secure in the process. And that's just been dropping the security controls. Um, and then there's just like DevOps, you kind of ask five experts, you get 10 opinions about the exact definition of DevSecOps. Uh, but, uh, but fundamentally it's about bringing security into the DevOps fold. Uh, and that requires transforming the security industry. Uh, and the, uh, uh, underlying kind of security, uh, um, uh, metho…
AI assessment note: “building a security model that allows you to ship continuously and through independent teams”
Answered raw tape
D 5 · C 5 · P 4 · Cm 4 4.60
Q um, who's, who's building, um, a comparable company in terms of, um, in terms of motion. So, uh, as you said at the beginning, like you, you, you guys initially started with open source. Security for open source, but you're actually not an open source company, right? You're, you have a freemium model, not an open source. Can you talk to the thinking behind being freemium and not open source?
A Uh, yeah, for sure. So, um, we, so to me, I have lots of thoughts about freemium, but To me, fundamentally to me, freemium is about, uh, a use case. So what you want to do is you want to satisfy the needs of someone to do something. Uh, in our case, we defined our freemium tier as, uh, we want to, is, is twofold. One is we want to help open source projects secure their projects. And so we made sneak free for open source. So open source project can use sneak, you know, at no charge. We can scale substantially. And that's, uh, I heard someone refer to it as cheaper than free. You know, it's, it's not only is it, it's not open source, but it is actually even better for them because we also operate it and run it for them. And we do all of that. Um, and then subsequently, and for those people, they helped us amplify the business. They help us, uh, you know, basically get awareness in the ecosystem. Uh, and some of those people work at companies and then for companies, we built a more classic freemium model, uh, which is at a certain volume and it's smaller teams. You can use things for free. And at some point we'd like you to talk to a salesperson and maybe, uh, uh, and maybe move up. So this bottom up motion was very, very focused on developers, developers succeeding, uh, like having successful, uh, uh, uh, delightful use of the product started, you know, really lower the bar, but …
AI assessment note: “we defined our freemium tier as, uh, we want to, is, is twofold.”
Answered raw tape
D 5 · C 5 · P 4 · Cm 4 4.60
Q way is, is like super interesting. Like, you know, you, you spend your first few years just marketing to, uh, developers, you know, um, sometimes open source, sometimes freemium, uh, As you get to your stage, what does that look like? Do you have like one centralized marketing function and like one part does like dev rail, uh, the other part does like buyer marketing. What does that look like?
A Yeah. So it's a good question. I think in general, as the organization scales, you go from, uh, generalist to specialist. And so Uh, so as the company grew at the beginning, it was a bit all hands on deck and that division didn't matter as much. Everybody was, was very connected to it. So the, the, the same product leads and marketing leads cared about both the freemium motion and the top-down motion, both the user and the buyer. As we grew, we have more and more specialization. Uh, today, when you look at where we stand, we have A dedicated product led growth, uh, um, uh, motion, which manifests as a, as a subgroup within product, a subgroup within marketing. Uh, and the subgroup within marketing has a, has a dev rel, uh, view to it, which is more community minded and such, and has a growth component to it, which is a bit more funnel management, a bit more, uh, understanding how many users that we get, how many, how well, what percentage of them activated and became successful users of them. How well are we monetizing those users? Uh, and so it's, it's mostly led between product and marketing, but there are dedicated leaders and dedicated people under them because it is true. And we've seen this, uh, as we, as we went through that, it became hard for someone leading both the product that growth aside and, and the enterprise motion to say, no, no, no, I will put aside this like…
AI assessment note: “As we grew, we have more and more specialization.”
Answered raw tape
D 5 · C 4 · P 4 · Cm 4 4.30
Q And the fundamental reason for this and the fundamental premise is that, uh, security, all the, a lot of the security tools were invented for a different world, right? Whether that's firewalls or endpoint security that was invented for the sort of the previous generation, but in a world where you have cloud and microservices and containers that has been breaking, is that the idea?
A Yeah. There's kind of two things being mixed. There's DevOps and cloud. So DevOps drives the need that I mentioned before about dev first security. It's the idea that the decisions around, uh, security are being made, uh, by, by developers and that you want the security control to be near the decision maker. Uh, and so, and it's, it's not a new need. It's maybe just a growing, it's grew in kind of importance over time. Um, alongside sort of the debt, the That first security solution to the DevOps change, the cloud change happened. And what cloud did is it changed. It turned it into app. So pre-cloud applications were mostly some code and some libraries sitting on top of this sort of hefty central IT stack, uh, which might've been your, your like central IT apps and like databases and such. Uh, you had, you know, the team manager, your data center, your infrastructure, your sort of the ends. And those IT teams are fairly security minded and they had IT security solutions. And now a lot of those layers have become APIs and those APIs are now managed out of the repo as part of a development process, right? Containers versus VMs is a good sort of way to think about it. And so they no longer require an IT security solution. They require an application security solution. Um, and, and so really that's the, that's the, the different transition where you could have done that first secur…
AI assessment note: “Yeah. There's kind of two things being mixed. There's DevOps and cloud.”
Answered raw tape
D 3 · C 4 · P 4 · Cm 3 3.55
Q And what about sneak code? What does that do?
A So sneak code is, uh, is interesting to an extent it, it, it, uh, it expands a little bit more into the, into the history. Uh, so, uh, the, in the world of, of, uh, vulnerabilities, actually the majority of the industry today is focused on not these open source components or all that, but rather on custom vulnerabilities in your own code. You write code, you write bugs, some of them are vulnerabilities. And so there's, there's a plethora of like an alphabet soup here of SAS, DAS, IS, all sorts of like static analysis, dynamic analysis. Uh, interactive, which is instrumentation based, all sorts of solutions trying to uncover in different ways, vulnerabilities in your own custom code. Um, and, uh, the, the, the one that has the most promise and the most anguish in it is, is SAST, which is, uh, theoretically scanning your code, doing program analysis. So just inspecting your code automatically and figuring out whether there is a security mistake here. Can I identify a path that an attacker might take from, In, injecting some data into a form field and going all the way into your database and stealing some data out of it. Um, and SAST is a great promise because you connect to the source code and it has full visibility and practice. It's a very, very mathematically hard problem. And it resulted in a decade's worth of tools. I'm responsible for one of them. I built an AppScan source,…
AI assessment note: “what we've done with, with SNCC code is we figured we will not enter”