back to guests archive

transcript · reviewed SEPTEMBER 1, 2026

#episode 131 transcript

Shikhil Sharma

Shikhil Sharma

Astra Security | AUGUST 27

Continuous pentesting and vulnerability management platform helping companies find and fix security issues before attackers, with automated scanning and human-led assessments.

Timour Kosters

Timour Kosters

Edge City | AUGUST 27

Runs temporary, month-long villages where people from tech, science and public life stay side by side, experimenting with how communities coordinate and self-govern.

transcript

9,888 words

Full Transcript

Utsav Somani: Alright. Listen. Stream 131. If you're celebrating today, happy Raksha Bandhan. We're gonna get right to it. I have my guest, Timour. He's dialing in from SF. He's the founder and CEO of Edge City. Timour, welcome to the show.

Timour Kosters (Edge City): Thank you so much for having me, Utsav. Alright.

Utsav Somani: I'm very, very curious. It took you nine villages to get to India. You've been doing this for three years, but how do you describe Edge City now to anyone who's hearing about it for the first time?

Timour Kosters (Edge City): Yes. So Edge City is a society incubator, and what that means is that we've built a global network of people at the frontiers of tech, science, and culture. And we gather twice a year in an event that we call a pop up village, which is a month long container for anywhere between 500 to a thousand people from multidisciplinary fields like technology, science, art, policy making. We get movie creators coming as well. And we call it a society incubator because it gives people a real, context and a real community in which to test new technologies, new institutions, and new ways of living.

Utsav Somani: And how do you come up with the timeline? Like, I mean, how do you decide that it's gotta be three weeks or one month?

Timour Kosters (Edge City): Yeah. So the key innovation here is that when you do something for a month or sometimes we've even done two month long events, it goes from being a break in your life, like a conference, to actually becoming part of your life. And that gives us much more surface area to have new innovations, new ideas, new startups. We've had new academic fields come out of Edge. There have been hundreds of projects born in this incubator. And I think that's happening because when you gather people who are curious and high agency and building and thinking about the future, but in a context where we're not just talking about it, we're actually starting to ship things. We're actually starting to create. A lot of amazing things happen when those people intersect. So we have found the month to be a sweet spot, but it was an empirical study. We've done different, ranges of events, and we've really nailed down that this month is almost like a perfect almost like a semester on a university campus.

Utsav Somani: And was it, I mean, I remember that it takes twenty one days to build a habit. Is that correct? Like, I mean,

Timour Kosters (Edge City): there's there's Exactly. And I've seen this I've seen this many times. Some people are like, well, why why do you do this all around the world? Why not just do it in San Francisco or in New York? And for us, there's two key reasons. One is what you're saying where we actually want people to remove themselves from their usual silos and go somewhere new so that they can actually start to think about a new way of living, a new, habit formation. They have new ideas. We've had people come from SF and meet other people in SF that they wouldn't have otherwise met for they've even started startups together. And I think there's something about being in this, you know, just different environment for an extended period of time. You can actually form new habits, form new ideas. And the second thing is that we want people to be thinking in a global perspective. Right? We want ideas from India to inform the things that are happening in Silicon Valley and vice versa. We've done events in South America, in Patagonia, in Argentina. We've done Thailand, done South Africa. We've even done something in Bhutan. So we're excited to keep this going and bring folks from the US and from Europe to these interesting places and create a context where local founders, local investors can meet with international ones as well.

Utsav Somani: And how do you pick these venues? All of these are, like, phenomenal places.

Timour Kosters (Edge City): Yeah. So it varies. There has to be a very, interesting combination. The Venn diagram crosses in the middle of a strategic location, so an interesting ecosystem where there are many founders, startups. There's a lot of kind of dynamism and energy. We, look for amazing local partners. So, in India, we'll be partnering with Build3 and a project called Startup Eco Ashram and and Localhost and a few other amazing local organizations. And then, also, it has to be a place that people, kind of our international community want to go to and want to be kind of in in that environment and actually get to know. And for us, India is a very interesting dynamic ecosystem. We read a lot about what's happening in the startup ecosystem there. I've personally spent a lot of time in India, so I'm really excited to bring our community. And we have people coming from New York, from San Francisco, from all over the world who maybe haven't spent time in India and haven't known how to get involved, and this gives them the perfect way to land into that, community.

Utsav Somani: And it's fascinating because you've done this nine times over. So there must be some learnings. How did you think about and ideate the first one, and what are the learnings that you're transferring across these nine, pop up villages to now when you do the tenth one, like, what will you improve? What will change?

Timour Kosters (Edge City): Yeah. So it's it's changed a lot, and it's helpful maybe to give a little bit of context of how this started. The first event like this was called Zuzalu, and it was started by Vitalik Buterin and my now cofounder on Edge, Janine Leger. And this was two months in Montenegro, and this was purely an experimental thing. What happens when you get hundreds of people to live together for two months? People from a wide range of fields, kind of Vitalik's network and and the people adjacent to that. And what we learned was that there is something very potent there, but it's it's a it's a process that can be improved. We were kind of just figuring it out at the time. And over time, what what Edge has become and Edge came out of that ecosystem, we've really, perfected the art of gathering folks in a way that allows them to have their focus area but really benefit from being surrounded by hundreds of other amazing people. So a a specific example is that we now host residencies, meaning residencies are kind of smaller groups anywhere from five to 50 people, and they are, they have their own thing going on. They either have a theme or we do a lot of founder residencies. So if you go on our website, edgecity.live/india26, you'll see, the plan for Edge City India. There's already almost a dozen residencies. There are some just focused specifically for founders. So if you're a founder and you're listening to this, you can apply and you can spend three weeks with us surrounded by brilliant people. There are some residencies focused on specific themes like AI or consciousness or robotics, things like that. And there's also, the the aspects of building, something interesting like a startup that don't just relate to the active building but also relate to the well-being of the founder, well-being of the builder. So we have well-being residencies, and everyone who's at the village gets to benefit from all of the residencies. But if you're in one, you also have a bit of your own focus with that smaller group. That's been a really big innovation from the start where now Edge is becoming a collection of concurrent groups that are there benefiting from the overlaps of each other's, focus areas, but still having their own focus lane.

Utsav Somani: And all of this is so real. Like, I mean, in the world of AI, like, I think they say that touch grass. Like, I mean, you gotta be real and actually doing, like, real stuff, making stuff with your own hands, and connecting with people behind I mean, away from screens. And I think this is sort of a step in that direction. And I think I mean, have you heard of this festival called Burning Man in SF?

Timour Kosters (Edge City): You know what

Utsav Somani: I mean?

Timour Kosters (Edge City): I've been to Burning Man many times. Yes. And there is there is a there is a lineage of inspiration there.

Utsav Somani: Yeah. So that's what I'm gonna bring up. Like, I mean, they are very strong about their principles. And when you start a movement like Edge City or Burning Man, you need to have the core principles and the pillars very, very strongly defined. So I would help you with your your, philosophy on that and, I mean, mention all the core key pillars of this.

Timour Kosters (Edge City): Yes. Yes. So what's interesting about Burning Man, it's been around for forty years now, and do they actually only introduce their principles, I think, in year 10 or 15? So it took them a while for the for the culture to really emerge and solidify, and we're approaching it in the same way. Everything we do at Edge is cocreated by the people who come, and we're letting the natural community emerge and be influenced by the communities and the places where we're going. So Edge right now will be very different to Edge three months from now when we've had the influence of the amazing, founder and builder community in India, and I'm so excited to see what that's like. But we do have a semblance of design principles, and I'll give you four key examples. One is that we focus on cocreation and building, meaning you don't come to Edge for passive learning. You come to have a posture of creation. We want people to ship while they're there. We want them to share what they're doing with the community. We want them to actually make progress and accelerate their projects. So that's a key one for us. We're also very multidisciplinary from the beginning, meaning we're very interested in what happens when you have a material scientist spend time with an AI researcher who spends time with a, you know, a spiritual leader. And, you know, these kinds of intersections are very interesting to us. And I think as the world moves into a very dynamic kind of, you know, we're moving through a transition, society and culture science and especially technology, I think these intersections are very important because we're dealing with very complex issues, and we need complex solutions. So that's a second key pillar. We are also, what we call default healthy, meaning we don't just want people to come and burn out. We want people to feel their best. So they're eating good food, spending time outside, connecting with people. It can feel like, it's very productive, but it's also kind of like a breath of fresh air. And I feel like founders are often just in their caves and in their silos, and they're not going outside. And to your point, they're not touching grass. Or, you know, in Goa, it's going to be touching sand. And that's just such an important part of building something that has longevity. Right? If you're building, your life work for the next decade or two, you need to find a way of tapping into well-being for yourself. And then the fourth one is that the events are multigenerational, meaning if you have a family, if you have kids, you are very welcome to come. Bring them. We've had hundreds of kids at our events, and that just creates a really fun and interesting vibe. Because even for the people that don't have children, it's so cool to have the next generation around, especially as we're talking about these big, heady ideas about how the world is going to change. You know? We see the generation there that's going to inherit that. So it's, it feels like a real village environment, and that's just been a a really, really wonderful thing. And I'll just finish by saying that the the Burning Man example is quite apt. Some people call Edge learning man because it has less of the, less of the hedonistic side of the burn, which, you know, is great, but it still has that emergent quality to it where the thing is cocreated by the people who are there.

Utsav Somani: I have actually some of my friends and ex colleagues going to Burning Man. They said it's apparently, what, fortieth anniversary or some they're celebrating some, milestones.

Timour Kosters (Edge City): Yeah. Forty years. Yeah. Yeah. Yeah.

Utsav Somani: Yep. But, another thing, like, so who's I mean, you mentioned passive learning is not a thing that you look for. Are there other things that you wanna highlight on air, for people to know that, hey. This is not for me?

Timour Kosters (Edge City): Yeah. I would say, generally, we look for yeah. We we look for people who are curious, kind, and high agency. And so what I would say is that, in terms of what it who it's not for, I would say if people are, you know, just focused on, yeah, I guess, like, passively learning but don't want to kind of create something. It's it's maybe not the right fit. We generally want people who are kind of have momentum, are in action, or they are thinking about what's next. This is a common archetype of people that come to Edge. If you have exited your company or you're between roles or you've just graduated with your degree or your PhD and you're not quite sure that you want to do the default path that, society has laid out in front of you, maybe you want to be a founder but you don't quite know which idea, you know, you're choosing between a few, Edge is the perfect place because it gives you tons of surface area and tons of conversations that you can have that help you train your mental model of what you want to be doing. So it's really perfect for that. It's also perfect if you're building a startup and you want to get it in front of people. So we're very excited about people who have a product, and they want feedback, and they want to iterate on it and make it better. And, also, just if you're, like, a talented builder, maybe you have a a normal job, and you can work remotely for a couple of weeks, we'd love to have you as well.

Utsav Somani: And, I mean, so my show lead at TON, our show lead, Yashvi, is, at is gonna be at Edge City as well. So what does a day for Yashvi look like at Edge City?

Timour Kosters (Edge City): Yes. So every day is different, and everyone's experience is different. It's actually been amazing the last couple of edges where people have now come for four or five of them, and people start to say, oh, this edge was different for me in this way, or I I did my edge differently this time, which is kind of cool for me as a founder to hear about this. Yeah. It's like, oh, it's actually becoming a part of people's lives in a way that they can compare the different experiences they're having. So that's just wonderful. But if we were to choose a prototypical day, I'd say, generally, moo mornings can begin with movement or nature. So, you know, we go outside, people host meditations, host runs, host workout classes, maybe some yoga. Then, you might, meet someone interesting over breakfast and kind of continue that conversation. Generally, in the early afternoons and kind of lunchtime and into the, into the later afternoon, there's space for deep work. So So there'll be some programming, but, generally, folks like to have a bit of time to get you know, we use Pomodoros as a social technology, so people just get a ton of work done very quickly. And then as we get more into the evening, there's more lectures and programming and opportunities to learn. So yeah. And we have a shared coworking space. That's really the hub. That's where the workshops and the talks will be. There'll be demos. There'll be dinners. There'll be more resident curated programming. And then, you know, we have the residencies like I mentioned. So the Forge folks will be making a residency for early founders. There's also a residency called Ground Floor that's going to be working with local businesses and upskilling them on the latest AI tools and then sharing the stories of that because, you know, I work with a lot of AI people. I hang out with a lot of people at the labs. They are all thinking about how do we tell interesting, optimistic stories about how this technology is actually improving people's lives. And I think we have a really cool opportunity to showcase some of that on the ground as well.

Utsav Somani: And that's fascinating. So, I mean, just for me to paint a picture and for our listeners to know, how does it look and sound and feel physically? Like, what area do you cover? Like, is it just, I mean, called I mean, a pop up village, but has, like, I mean, different nodes running within Goa or area that you choose in or it's more concentrated and has a physical boundary of sorts?

Timour Kosters (Edge City): Yeah. That's a really good question. So, generally, we will find about a dozen venues within ideally a ten minute walk, but potentially within, like, a ten to fifteen minute bike ride. And in Goa specifically, we'll have a couple of kind of core locations, like the coworking space and the main hotel where people stay, and then people are finding places to live in that neighborhood. And what's really nice about this, and we designed for this specifically, is that it starts to feel like a campus where you have your coworking, you have your, cafe, you have the place where you're staying. And as you're walking between them, you're running into people on the street. It feels very serendipitous. It feels like, oh, yes. You know, good to see you. Good to meet you. Do you wanna go to the beach? Or do you wanna are you going to that talk? Oh, yeah. I'm going to that as well. Let's walk together kind of thing. So it's a very kind of open and, fun environment, and it's just a perfect way to connect with other people.

Utsav Somani: And, I mean, what's the mix of audience? Like, the people who are at the village? Like, I mean, is it mostly young people? You mentioned some families as well. What's the split between, domestic versus international?

Timour Kosters (Edge City): Yeah. So it's it will probably be around fifty fifty in terms of domestic and international, which I think will be a really cool mix. And, age wise, it really varies. But if we were to plot a normal distribution, it would probably median at around or mean at around, maybe 30 or, like, late twenties. So there's, I mean, there's people of all ages, but, yeah, there's there's probably a kind of a core average around that age. And in terms of what people are up to, it really varies. Like I mentioned, it's, you know, extremely multidisciplinary. People are doing a lot of different things, but we get a good mix of founders, general technologists, people working at startups. I should also mention, by the way, you don't have to come the whole time. I should have maybe said that earlier. You don't have to come for the full three weeks. I've had a lot of amazing Indian founders reaching out to me saying, hey. I would love to come, but I can only make it for a weekend. Is that okay? It's totally fine. Come for a weekend. Come for a week. You get to, you know, show off what you're building. And, and yeah. And so it's gonna be it's gonna be a really cool chance to, get together.

Utsav Somani: And you mentioned the word network city as well and, sort of this physical experiment. So why not have a permanent one? You've heard of network states, I believe, by Balaji? Mhmm. Yeah. Of course. Why not choose a permanent setup at one permanent place?

Timour Kosters (Edge City): Yeah. That's a really good question and something we think about a lot internally. We collaborate with permanent places. So we're actually helping to build a new town in California called Esmeralda, which will be an amazing future node in the network. We're also working with the, government in Bhutan on their new city project, and we get a lot of new cities, new towns reaching out to us saying, hey. We're building this thing. Can you do an event with us? Because they want the energy and the momentum and the ideas that come with hosting a full Edge Village in their place. And it makes sense, right, because they're building on ten plus year timelines, and we get to, for one month, showcase what it could be like to live in that environment, and get people actually excited. And instead of just looking at a deck, they get to really experience what it might actually feel like. Why are we taking our time with that? Why not just go all in on finding one place? Couple of reasons. One, like I mentioned, we do want to be a global ecosystem from day one. So we're not just trying to recreate San Francisco somewhere else. We really want there to be it's a fundamentally new thing. It takes longer to build, I think, something that's truly global. But over time, I think it will pay dividends in the ideas and the network that we're creating. And two, it's it's hard to find a permanent place that works. You know, the the people that have gone all in on that have, have had difficulties. It's it's difficult to explain what this is. These ideas are very new. Local government, state government sometimes don't fully, you know, jive with what's happening. And so, you know, we're not in a rush. This is life work for us. I think this is kind of a fundamentally important thing to be happening, and we're living through, you know, many different transitions at once. And I think this network state, lens is another one that we can look at things through. So, yeah, we're not in a rush as as the as the TLDR summary, but I think it's inevitable that we will have kind of a collection of permanent nodes around the world over time.

Utsav Somani: Fascinating. And it's the Balaji thesis playing out in reality because network states, is what he wrote about, in his book as well. And what's the economic engine? I believe you run as a nonprofit. Right?

Timour Kosters (Edge City): Yeah. So a couple of things. One is the, the events, and the grant making and things like that. We are doing through a nonprofit, and the key insight there is that we are not an events company. We're not trying to get rich rich off the events. We're using the events as a way to bootstrap this community of technologists and scientists and culture folks. And then over time, how do we find sustainability in that? Well, there is a lot of value being created in this network, and so we are already thinking about, you know, how do we invest behind that? You know, is there a venture model? Is there a real estate model given the work that we do with new towns? And that's, going to be the engine that actually keeps this sustainable. So that's the that's the general layout. But the events themselves are breakeven. They're profitable. They you know, through a mix of ticket sales and sponsorships, we try to keep the events as reasonably priced as possible. And we, you know, literally take the amount that it costs to organize it, divide it, you know, subtract the amount of sponsorship we're gonna raise, and then divide that by the number of tickets we sell, and that's how we generally arrive at the price. So, yeah, that's that's how we approach the financials.

Utsav Somani: And since your community is growing, I I believe, like, what, more than 15,000 people now?

Timour Kosters (Edge City): Yeah. Well, we've had 12 and a half thousand people at the events themselves, but the broader network in terms of our reach, it's it's hard to measure, but it's somewhere north of twenty, thirty thousand. Yeah.

Utsav Somani: Wow. So apart from the principles that we discussed early on, how do you think about governance? Because, I mean, given the scale, and I can see this growing and, I mean, becoming into, like, millions and millions of people across the world in a few years. Like, how do you think about governance?

Timour Kosters (Edge City): So it's a really good question. We have spent a lot of time in various governance related fields, and the general feeling that we have is that it's very important early on to essentially be a benevolent dictatorship or, you know, whatever you want to call it, but to have a core team that really drives the vision forward and to not, you know, progressively decentralize too early in terms of, other, you know, other forms of governance. That said, I think that the Edge City philosophy is is a is a generalizable culture that can scale through other people doing similar things, and we very much encourage it. And so we're actually running experiments where we pick people that we really trust to run their own Edge style events, and we actually even lend them the name of Edge. It's slightly branded slightly differently. It's not kind of an official Edge City, event, but those are some of the seeds that we're planting now to see how that goes. And if that's a good experience, I could imagine scaling that quite a bit. There are a couple of examples of this. Right? There's, like, TED and TEDx. There's obviously franchise models that have been around for a long time, been successful in business. So we're, again, taking our time with that. But, yeah, in in terms of governance, I think, again, I've seen this happen so many times where people, you know, decentralize far too early. They are aiming for something like a direct direct democracy in their community, and that becomes quite difficult over time. Yeah. I also am personally, I've been writing a lot about, agents as a new surface area for governance and for cooperation and coordination. And I think that that's you know, we have just shaken that snow globe, and we haven't seen where things land yet. So I think in the next twelve months, there will be amazing new technologies and norms around how do you actually engage in collective action with groups. This is my personal you know, what I'm nerdiest about, I would say. So I think I I will be applying those learnings to Edge as well. But, again, I think it's we need to, take it slowly and make sure it actually all makes sense.

Utsav Somani: I love it. I'm gonna look it up, after the show. I mean, and this was phenomenal. I mean, this is, fascinating what you've built. I think it's a movement, and I think it's exciting. Like, I might actually spend a few days there, myself. Like I

Timour Kosters (Edge City): would love to have you.

Utsav Somani: Do we have a discount code, for TON listeners or our community?

Timour Kosters (Edge City): Yes. Yes. So you can use, TON20, so TON20, at the checkout. There is an application, so you can find it at edgecity.live/india26. And when you apply and get accepted, you can use that code for a, 20% discount. And I should mention that, folks who are local, Indian citizens, will already get 50% off the ticket. So we do want to encourage people who are local to attend. And, yeah, that this will be, it will be great to have you there.

Utsav Somani: Alright, folks. Go check it out, Timour. Thank you so much for coming on our show. Wishing you the best.

Timour Kosters (Edge City): Thank you so much, Take care.

Utsav Somani: Bye bye. Alright, listeners. Moving on to our next guest, we've got Shikhil from Astra Security. Shikhil, welcome to the show.

Shikhil Sharma (Astra Security): Hey, Utsav. Good to be here. Thank you so much.

Utsav Somani: Are you dialing in from SF as well?

Shikhil Sharma (Astra Security): No. I'm actually driving, dialing in from Canada.

Utsav Somani: Oh, nice. Must be I mean, how's the weather right now?

Shikhil Sharma (Astra Security): It's it's not too bad. Yeah. I mean, what you do you generally think of Canada? Not that bad.

Utsav Somani: That even that comes to my mind is, like, typically super snowy and everything is, like, just Yeah. Cold enough.

Shikhil Sharma (Astra Security): It's surprisingly better right now. So, yeah, I'm I'm taking in on the sun.

Utsav Somani: Alright. I love it. And so let's introduce Astra Security to our listeners. What does it do? It's super technical Absolutely. Technical explanation, and then maybe we do a one, two minute nontechnical, ten year old, explanation.

Shikhil Sharma (Astra Security): Absolutely. I'll actually start, with with the second one first.

Utsav Somani: So Alright.

Shikhil Sharma (Astra Security): I'm sure everyone right now knows that every company is becoming a software company. Right? And most of them, I I can confirm, are shipping security vulnerabilities, way faster than shipping features. So that's something that I've seen firsthand happen. So, at Astra Security, we are a continuous and autonomous pen testing solution, which means that we discover, we exploit, we validate, and even now fix vulnerabilities for our customers across their web apps, APIs, cloud network, you just name it. So we've got about 1,200 plus customers in 70 above countries. Last year, and this is the part that I'm super proud of, that last year we discovered 7,000,000 plus vulnerabilities for our customers, and we were discovering one critical vulnerability every forty seconds. So this is a vulnerability which could have actually caused a breach or data loss of millions of records or, dollar value. So every forty seconds last year, we were discovering, one's critic such critical vulnerability for our customer, for our customers. And this year, this number, I feel, is already doubled. So by the end of the year, let's see where it will go. And since the name here is, has the word network in it, I feel security itself is a huge, community. We also run our side community called the 403 Circle. It has a nerdy name to it. Four zero three is a forbidden status code. So, it's it's it's a community where security leaders, practitioners come in. They talk about, my joke is that they sometimes bitch about tech teams because security team and tech teams often have a have a tussle between them because security teams want everything logged in, and engineering team usually deprioritize or there's always a tussle. So that's a joke I say, but they've started playing, really well with each other. So this is the community of a few 100 people that we, run and it's and and we do a ton of offline events, as a part of the community too.

Utsav Somani: Boom. Off line events. That's what I'm stressed. Intense. I'm actually quite happy. So the explanation that you gave I mean, it's good for a 25 year old because some of the words even I couldn't understand. Like, so you mentioned pen test. What does pen test mean?

Shikhil Sharma (Astra Security): Absolutely. So pen test is a, is a process of discovering vulnerabilities just like a hacker would in any system, but being a good guy. So that's basically what an ethical hacker

Utsav Somani: would do. White hat.

Shikhil Sharma (Astra Security): You actually exactly. So you you go there, and I feel it's no more just manual work right now. It is a lot about, doing that autonomously using AI agents, because, I feel AI, you would have I'm sure everyone, even I feel a 10 year old child would have, learned about my thoughts in the last few weeks. So Mythos has become a big thing, the new model that came in from Claude. So the idea is, like, to help companies discover vulnerabilities, but being the good guys, do the exact same work that bad guys would do and exploit. But just we just the only difference is we just go there and report the vulnerabilities ethically. And, that's exactly what, pen testing is. It's like simulation of a attack.

Utsav Somani: And this is by being the good guy, the white hat hacker. And you do this automatically. Your agents are now able to crack into systems and actually point this thing. But when did you get the confidence? Because you launched this in June, I believe June 4. And, I mean, how did you get the confidence and how do your customers actually get the confidence that, hey. I'm gonna, like, let an autonomous agent, like, hack into my systems. Because we've all read those stories where OpenAI and Anthropic, agents are, like, breaking out of their cages and those border lines, harnesses and all of that stuff that's created for them. So how do you trust an agent, with live data and live systems?

Shikhil Sharma (Astra Security): Sure. So two things. First is, also, I'm gonna, like, use this platform and say, I've been dilly dally if I should be posting on LinkedIn about this or not, but I'm gonna just go ahead and say it. But I do feel that a lot of this hacking and a lot of OpenAI and Anthropic of the world, I respect these companies massively. Some of these models we are still

Utsav Somani: when I were having this discussion, my colleague, Dude, I feel key like, I mean, like, there were memes which are going around that, hey. Go I mean, there's this Google meme as Sundar Pichai is telling his Gemini team that he has, like, post something about it as a bank hack or something.

Shikhil Sharma (Astra Security): Yeah. I I wouldn't say it's planted, but I see definitely it's one way of using this as a marketing tactic that, oh, our model is so amazing that we cannot release it to the public. It'll create a havoc. Or by the way, it went crazy on its own and it discovered this vulnerability in some software, which was mission critical. All of this is happening. It's true. But now it's gotten so much that, that every company seems to be doing this, every few weeks in a way that it's become a marketing tactic that we are not launching it publicly because our model is so great that it'll do the that it did this and that. And over the next one month, suddenly, that model is generally available to everyone. So

Utsav Somani: Under a different name, we don't expensive tokens, basically. My thoughts become Exactly.

Shikhil Sharma (Astra Security): Same with exactly.

Utsav Somani: And so tell me about this OWASP standard. The category Yep. Is judged on that standard, and your team helped write it. So how did this happen?

Shikhil Sharma (Astra Security): So absolutely. OWASP is something, online online web application security standards is something that has been the backbone of security community because it's it's one of the largest nonprofit organization which, where security professionals come in. They're collectively without their personal interest, try to write standards of how a web app is supposed to be tested, how a mobile app. If now AI is coming in, they write something known as OWASP top 10, which is like top 10 threats or top 10 vulnerabilities in a web app, in a AI, in a LLM, whatever. So they they maintain this top 10 vulnerabilities, which anyone who's testing or even anyone who's actually creating a LLM or a AI application, they should look for these top 10 vulnerabilities. The I entire idea is to set these standards which are rigorous and convert them into a understandable way where someone who's not in security, they are also able to work with them. So for this, we had been, so while we launch our autonomous pen testing, a cup a quarter or so ago, but we've been in pen testing space for eight plus years. That's from where we've got, like, 1,200 or so customers and all these millions of vulnerabilities we're discovering. So we realized that since we've done over the years about 8,000 plus pen tests for our customers, real world, right, from, you know, small startups to, to, like, some Fortune 100 companies who are our customers, we realized that we understand a few things about pen testing and these standards. So how about, and now since AI is the one which is also going to be hacking, it is going to be a white hat hacker also or a hacker, and then it's on us to decide how do we want to use it. So why not write a standard which, and and collaborate with OWASP in writing this where it defines how autonomous pen testing would work, how these autonomous ethical hackers would go about hacking and ensuring exactly what you're saying, like, what are the guardrails, what are the areas that they are allowed to play into, what are the areas they are not allowed to play into, and kind of have a governing standard for it. So that's the thing that we did, and it's been received really well. And, of course, there are around the globe who are now contributing to it.

Utsav Somani: You didn't take outside money until last year, and you've been building this for five, six years. Were you like, I mean, mean, I can see a scenario where if your agent or the platform is that good, that you're writing standards and you're, of course, working with so many different clients, over a thousand clients and some top names as well, you can actually be a bun a bounty hunter. Right?

Shikhil Sharma (Astra Security): Absolutely. So, I mean, that's from, where I started, the journey. Right? So I've been, I mean, a bug bounty hunter myself, a pen tester myself. One of the, like, I I've discovered vulnerabilities in, you know, top companies via Yahoo, Microsoft, Adobe, AT&T, name it. But that those are the not ones that I'm proud of. The one I'm proud of is the one that actually got me some real value out of it is that, I had to this is, like, a few years ago. I had to before starting Astra, actually, that I had to I was a, like, broke student, but I had to travel to the US and a couple of places. So I discovered, vulnerabilities in an airline company, reported it to them. And as a result, they gave us, me and my cofounder, they gave between us, they gave us, I think 1.1 or 1,200,000 miles for their airline. And this company was part of a very famous top tier, program of miles where, like, ten, fifteen airlines are a part of. It's one of the top programs. So and I have some of those miles with me right now also. So a million miles, like, is something that people usually flyers who are you you know it, like, ten, twenty years they're traveling. That's how they accumulate a million miles. So that was fun, and I realized that, you know, if vulnerabilities in these giants are possible, then there's so much possibility of, in startups to all size of com com companies where vulnerabilities would be existing, and that's how Astra began. And now I do not do bug bounty, but we've created an agent that tests application just like how a bug bounty hunter tests. So we've kind of the idea is to, like, put all the knowledge that we've gained over the years pen testing, doing bug bounty into these AI agents and, you know, just have these I'd say, I I hate to say the word minions, but because they are so much more than minions, but have these mini versions of yourself who are equally intelligent and thousands of numbers and doing the same work that you could do.

Utsav Somani: And what's the play in India? Like, I mean, RBI compliances, DPDP Act coming in, the Yep. Consent manager. Like, so many different regulations are coming in. Like, in in Europe, we have GDPR and bunch of other regulations sort of make testing or being compliant actually, much more necessary. Is that playing in your favor?

Shikhil Sharma (Astra Security): Oh, yes. Absolutely. In a big way because, see, first of all, like, security, community, CISOs always have been super security conscious. But the thing is that when a compliance get attached to it, it just tells that there are either national interests in the case of DPDP and GDPR or there are organizational interests like there's a SOC 2 compliance, ISO compliance in play where they have to get compliant to these standards. And as a result, usually, it's highly recommended or in some compliances or standards even mandatory to have a what we do a pen test as a part of it because that's where real defenses get tested in real time. Right? So definitely, it's been working, in our favor in a big way. And I I think you mentioned about the funding. We we did raise a couple of years ago, but since we've we've been lucky with traction, customers, and we've been very good with marketing also. So that has never like, money's never been a problem, so that's why we've not raised since then, because we are customers trapped since that race.

Utsav Somani: Nice. And I'm gonna zoom out a little bit to understand the industry a little bit. So there is I mean, Leafix self funded, Snipe, then there's Verizon three, and a bunch of other players. Like, what is I mean, it's becoming I mean, security is now not just a buzzword. Like, maybe it was five, ten years ago. And And we bought Nikesh and Rudan, super active, as well. Oh, yes. Twitter. Yeah. So, what's happening in the world of security and cybersecurity? Like, how does a team from Delhi make their mark globally and get 1,200 customers?

Shikhil Sharma (Astra Security): Sure. So, I'd say, like, cyber is a industry like no other. It you might be building a SaaS in cyber, but you'll be defying all the principles of a SaaS. You might be building a b to c in a security company, but you would not look like any traditional b to c company because SaaS runs its own game. If you would see even public companies in I I've actually was seeing some, Indian influencers who've been, recommending international, including Palo Alto and other cyber stock to a lot of people. So that's been a tray I mean, one of the trends because and thanks. Because because the thing is simple, also, the white coding is like giving someone a sports car who's just gotten their learner's permit. So, yes, they will go fast, but the the, sadly, the crash also would be equally spectacular. So with wipe coding, everyone in the company is a developer. People brag about it, including myself, that, you know, hey. I wipe coded this on link and I'll tell about this on LinkedIn. Hey. Earlier, I I used to require a designer to do this or this, designer thing that I used to used to need a developer to do something. And now all of these things are being done by one person themselves. Product managers are, like, actually writing features now. That's great, but until you start thinking about consequences on security. Because now if you were generating a million lines of code a year ago a month, now you're actually at five, ten million, which means attack surface is increasing massively, which means security companies are becoming increasingly more important. And, fun fact, like, LLMs were trained on publicly available data, which also included vulnerable libraries, vulnerable GitHub repos. Right? And that's exactly what they are actually doing right now. AI has been finding, like, literally landmines that we had buried twenty years ago. It's like a post World War two site.

Utsav Somani: Yeah. Even my thoughts, like, what they've discovered, like, browser and OS level vulnerabilities. Yeah.

Shikhil Sharma (Astra Security): Exactly. Which were, like, twenty seven year old, OpenBSD vulnerability got discovered, which is a 27 year old vulnerability. It survived to, like, lifetime of people, and now it's certainly getting discovered. So imagine you are writing ten, twenty x more code, more infrastructure right now, And there is a huge backlog in the past where you've not done that quality of testing, and all of this is coming together right now. So as a consequence, attack surface is increasing. It's largely vulnerable. There's another angle of which I feel is going to become a big big one where state sponsored attacks, on on countries where grids would start getting targeted. Because when you start seeing vulnerabilities, like you were saying on in OpenBSD and other low level systems, it means that your grids and all of these things are powered by these low level things. If finding vulnerabilities in those is becoming easier, I feel even a national security becomes a very important piece with security. So in general, in security, like, everything is, like, there's an outburst of vulnerabilities. There's an outburst of solutions who are actually promising to cater to that. And, yeah, I feel, being in the trenches, it feels super stressed, but I feel customers or growth or those are not the challenge, but serving that and the fact that, you know, you're when you're actually in the middle of building a security company, it's a lot like you are in a nine one one center or in a hospital. A hospital never feels happy when a patient comes to them. They want to serve them better. In security, a very similar situation where you, like you don't see our customers as, just customers. You want to serve them better. You want to make sure that they come out secure more secure. And, the only problem then remains is that how I'm able to do that at scale. Thankfully, with AI, now you're able to do that a lot. So, yeah, I mean, security is exploding, and it's going to continue happening that way.

Utsav Somani: Oh, Oh, thank you for painting a good picture. And tell me a little, about the business and the moats. Like, so at thousand customers, you have different advantages. At 5,000, you will have uniquely different advantages. What are those advantages or moats?

Shikhil Sharma (Astra Security): The biggest one, also remains data because, at thousand customers, you would have done pen tests on about seven, eight thousand of assets. Assets is a web app can be an asset, a network device, a mobile app can be an asset. So on these assets, we've done a pen test on each asset. We would have discovered a few dozen to a few 100 vulnerabilities. These are super unique data that we have, which no one else would have. And we can even if we do not use this data, which we do not, we can derive insights on unique ways pen testers went about discovering vulnerabilities humanly on these. And then the idea is that we can actually augment that using AI that now agents can actually have insights on those unique vulnerabilities because this is not kind of data that is publicly available. And that becomes a huge mode where you are sitting on these millions and millions of vulnerabilities that you've discovered, and it keeps snowballing. It keeps it's it becomes a fly ball eventually where you are able to discover vulnerabilities, correlate a web app vulnerability with a mobile app vulnerability and say that it could cause a breach if these two vulnerabilities are combined. So those kind of analysis that you can do at and then that you you start becoming your solutions start becoming a lot more sophisticated for larger odds. In an in a huge bank, it's not just their five mobile apps. They've got a huge network. They've got internal applications. How an internal application vulnerability can lead to a public facing breach, those kind of connections, is something that are called attack paths in security industry. And those attack paths, you're able to make, using this data that you unique data that you have. So it it only the flywheel, as you get more customers, becomes even more sophisticated, and the mode increases because anyone who's starting this at a thousand oh, sorry. At a 100 customers or first 10 customers, they'll not have unique set of vulnerabilities. They'll largely rely on rely on publicly available vulnerability data. So that's how it usually flows.

Utsav Somani: Can we spend the next two minutes closing the segment out with the story? You mentioned nine one one call. So any I mean, you don't have to mention exact names of customers, but anything that you remember from the last few months or maybe earlier this year distinctly?

Shikhil Sharma (Astra Security): Yes. Actually, I'll give you two. One is shorter one, and a bigger one. The shorter one is, a customer came in, a large platform here in North America. They used to have this solution which, Airbnb owners and even private rentals are big here. Right? Because small, rental management property management companies using their software. So they had a software which was being used by hundreds of these things to manage thousands of properties. They came in with a very restricted budget, and we said that fine. You just use an autonomous pen testing piece that we have, and our human pen testers won't come in. So they ran it within, like, first hour, of, this thing testing. We have an agent called bounty hunter agents. So so that agent, RB, actually discovered a vulnerability where they had an API endpoint, where everything that is uploaded to the platform was publicly available. Now that included pictures which property managers have uploaded of the property, which is fine. It got scarier because then it included all the guests that had uploaded their identity cards, their, before signing into the property, they used to upload them. That was being exposed. Then properties had their lease agreements and their, their their agreements with the loan loaning company or whatever they had. Those kind of agreements were uploaded. All of that data was publicly available. Anyone could have scraped that, and that is massive because it includes data of properties. There behind them, what their cost is, what their loan terms are to all the guests who've ever stayed there. So, basically, that's the way where that company can actually go bust, like, if they if this could have been exposed, in front of hackers. Right? So that's something which possibly would have taken weeks and weeks of five pen testers previously, and now is a couple of hours play, which means that for hackers, also, it's the it's a level playing field. And one interesting one is that, we used to work with an ecommerce store. I think it's a European ecommerce store where they mentioned that they are spotting some unusual activity in their application, so they wanted us to run a scan and see what's happening. We did that, in the first go, nothing. Second go, nothing. Third go, we actually tried deep in the scan ourselves, went and saw, and saw something super interesting that they had a checkout option in their, ecommerce store of PayPal. And hackers are actually Russian hackers, interestingly, had put us code there where any customer, out of five options, whenever they chose PayPal, x amount of transaction data, which was, like, up to under a dollar kind of a data, few cents to a dollar, random numbers, used to instead of going to our customer's PayPal account, used to go to random, PayPal account, which was controlled by hacker. And this had been continuing for three years, and about 2 to $300,000 is something they had siphoned off. And for them, it was a huge store. It was a rounding of error in their ecommerce store. And their accounts team thought that something

Utsav Somani: What is that thing called? Like, it's called penny I mean, penny dropping is when checking a bank account when adding details. Like, this this shaving off, like, pennies in a transaction, it's called something. Right? There's a technical term for it?

Shikhil Sharma (Astra Security): Yeah. I I'm I I even I wouldn't be sure because in from security side of things, what we call it is price manipulation vulnerabilities. So when you're testing, this comes under price manipulation vulnerabilities, and it's a business logic attack. So I'm sure there's a other term also for it, but, yeah, penny rounding or something similar.

Utsav Somani: Alright, Shikhil. This was phenomenal and, informative. Thank you so much for coming on our show.

Shikhil Sharma (Astra Security): Thank you so much for having me, also. And, yeah, best of luck.

Utsav Somani: Cheers.

Shikhil Sharma (Astra Security): Thank you. Bye bye.

Utsav Somani: Alright, listeners. We're just about a few minutes, from the weekend. I wanna show you a couple of things. So ED Startup Awards, the winners were announced. There's, some names that you'll recognize. Start up of the year, they've had a phenomenal run. Grow has listed. Lalit is now a billionaire. You've got Midas touch, with Manu Chandra. I mean, he's basically pretty much anything that he's touched in the consumer space has turned to gold. Mokovar, the whole growth and so many others, Hocko, the ice cream brand and many other things that he's done, I think I've really shown tremendous scale in the consumer businesses. And he started off with a small fund. And now he has a growth fund. And he's, I mean, pretty much the king of consumer brand businesses in India right now. And interestingly, come back here. We hosted somebody from the team, Emergent, the head of education at Emergent. And we're hoping to have Mokun on the show very, very soon because his learnings while building done so and then building literally, I think the unicorn that is, I think, maybe the fastest unicorn in India emergent. I think that's a fascinating case study. They've got capital from Khosla Ventures and so many others that I just wanna hear them out. Western campus, Armintrix, is building a robotic arm. So I think that'll be fascinating as well. I think we should get some of these founders, on the show as well, just to hear their stories because Moonstruck Champ, top innovator, all of the women ahead, social enterprise will make for fascinating stories. Then we've got something that's happening in AI. And surprisingly, NVIDIA was supposed to announce their earnings, and OpenAI went and announced their chip just before that. OpenAI had announced the intent to build something with, .com. But now that chip, what they're calling the project is called Yalapeno, dropped just around, NVIDIA earnings. And NVIDIA also announced, they've not actually announced. They've actually I mean, the news is leaked that they're gonna acquire Hugging Face. Hugging Face is where open models basically sit. It's the platform. It's the shelf where open models come and display their strength and people can use them. They're buying this for 12,900,000,000. They have $150,000,000 in ARR. So this is a pretty hefty multiple that they're paying. So now players in AI and NVIDIA has a lot riding on OpenAI success because they are a big customer and they've promised, buying from them for a very long time. And now they're stepping into each other's territories. OpenAI is, of course, a closed model and on basis where open models sit and display what is happening. And, yeah, you know, is fascinating. I what I read is, I mean, it's putting I mean, the first they put out the first benchmark results for Yelp, you know, it's on an inference chip this week, and they're saying they're getting more intelligence from every bot and faster responses at the same time, which is normally a trade off. And the claim numbers are really, really large, one and a half to nearly two times the throughput per kilowatt and 1.7 to 3.6 times lower end to end latency against NVIDIA's GB 200 and GB 300 track systems. And, I mean, semi analysis, which is by default the biggest newsletter or the website or the platform that you go to to actually read anything to do in the world of chips and semiconductors and inference chips. They visited the labs, and they said they found the chip to beat Blackwell on performance for what in nearly every scenario tested. So there is third party, data as well to go, for this. And there's a new fund down and some awesome names backing it. We've got Biri Bansal, Vidit, Avisho, Deep, Kalra, Make My Trip, Hari, Big Basket. It's a $2.50 crowd fund, launched by the Nudge Foundation, and it's called, launched by the Nudge Nudge Foundation. It's called the TILT. They'll invest, two to 16 girls in c to c, and it'll focus on areas in agriculture, climate, employment, and financial inclusion. And with that, we end this Friday show. We will see you on Monday, 4PM. Dhruv will be back, and I cannot wait for him to be back. And, have a wonderful, safe, fun weekend. Thank you again, and happy Raksha Bandhan

Shikhil Sharma - Episode 131 Transcript - The Offline Network