E195: Taking on the New AI Attack Surface With Manifold: Runtime, Skills & Supply Chains
45m 18s
Neil and Alex, co-founders of Manifold Security, discuss their journey from early AI security work at Protect AI (acquired by Palo Alto) to founding Manifold. They highlight a major shift: AI has moved from chatbots delivering responses to agents taking autonomous actions, which breaks traditional security models focused on model output. This change creates new risks, especially from agent supply chains—skills, plugins, and servers that are often unknown and unmonitored. Manifold addresses this by providing a runtime security platform that begins with discovery and inventory of all agents and their assets, then scans for threats to help organizations govern adoption. The founders note that while engineers rapidly adopt tools like Copilot, security teams lack visibility, leading to imbalanced access and risks. Their open-source project, Manifest, tackles the lack of common standards in scanning agent artifacts. Existing scanners produce high false-positive rates (e.g., claiming 40% of skills are malicious), while Manifest uses lineage and trust-based analysis to deliver accurate findings. Manifold positions itself as an enabler, helping companies safely expand AI tool access beyond engineering to other functions.
Welcome to the open-source startup podcast. This is Tim from SNVC and our lovely awesome co-host, Robby from Modern Technical Fund. (upbeat music) So we are super stoked to have Neil and Alex from Manifold Security. Manifold is securing all AI on all endpoints. So welcome guys. - Thanks, let's be here. - So really excited to get into the Manifold story and talk about Manifest, the new open project that you all released. But I think maybe let's start by talking a bit about both of your backgrounds, 'cause you've been in the AI security space for as long as it's basically existed, which is unique for this space, 'cause that hasn't been around too long. So why don't you talk a little bit about your background, be it protect AI, and then we'll get into what Manifold is. - Yeah, 100%. I mean, the way we look at AI securities kind of have the moment of the AI security before Cheshire T came around and it kind of pulls Cheshire T era. And so it's really around the time that Alex and I kind of start to work together for the first time. But yeah, maybe before that, I can tell you a little bit more about myself, originally from Belgium, start out in finance, realize I didn't wanna wear a suit for rest of my life, even though nowadays I heard they pretty much modernize that to retain people. But you know, went into product management quite early on, always left technology and then kind of combine it in the same way that you folks are doing finance and tech as an VC. That's that for some time. And really kind of in my last year in VC, I got to look at a lot of AI security companies at a time when they were in the pre-Cheshire T era as in trying to secure vision models, you know, making sure that your Tesla doesn't go off the road when somebody slaps a stick around the traffic sign. But then Cheshire T came around and it kind of changed the whole equation and we really got hooked on it. So all of a sudden, myself, we were neighbors in Berlin. At the time, I was living above him. He was the apartment below me. And we're still neighbors in a different part of town and we always talked about different things that I was looking at, he was looking at. And AI security was really pivotal because everyone was building in the space, but nobody really grok'd, you know, what security really meant. And if you were to boil it down, it was all about securing the model response. And so we went out and we built a Lengard, which is what we're most known for, actually open source. And very quickly, we had like an amazing trajectory in downloads usage, both of the models that we open source to do detection, as well as the library itself. And so we had millions of downloads. In fact, actually, some of our models are still in the top 20, 30 classification models on how we face it over like 300,000 downloads a month. And then we got to meet the nominal team at Protecti, who many of the people in AI security obviously know. And we saw a big opportunity go join them and effectively go lead runtime security within Protecti, which is what we did. And yeah, it was just an amazing journey into your time. We then got acquired by Palo Alto, where we still got to lead a lot of stuff around the agent security and runtime. But we saw the riding on the wall, kind of, you know, beyond that, just also unfinished business. You know, we had a lot of energies still left to go. And that's why we started manifold security. We saw a massive shift from securing the model response to security action. And yeah, in December we left Palo Alto and now we're five months in growing the team, deploying. And so lots of good things going. But Alex, I mean, we kind of had crossing paths for the past two years. So I might have told you a story too. Yeah, but it's much covered. But before that, 15 years in engineering, I love building, I'm always hands on, like building all types of projects, including open source, but also love building teams and just hiring, talent and working with great people. That's very cool. So giving your history, AI has really been around for so long, but LLM's has really boomed the last two, three years. And I feel like every single quarter feels like a year or five years, no matter how it feels like. And so we've very curious, like, since you've gone through almost like two phases of it, and different company contexts, what is the motivation? You said, unfinished business. We can talk a little more about what this unfinished business is. Why couldn't you stay around and just do continuation of AI security into places you were either a founder or a place you were acquired? Why do you have to come out and do another company, manifold security? Is it a totally different philosophy? Is it a different entry point? Like what's the big motivation around doing this? Unfinished business, to me, is like twofold. Like one, we did see the riding on the wall in terms of what a lot of people are saying today, which is every now and then I see competitor and you kind of see the same LinkedIn polls for the say. In the past few years, models were giving you the response. And now models are effectively enabling you to go and act on your behalf. And we saw that riding on the wall. And then in terms of unfinished business, we've been apart of the space since the earliest days. And we had a lot of energy left to go do this zero to one yet again. And obviously Palo Alto is a great place to be with a lot of great people, amazing distribution power. But there's something different in going at it alone at a time when everyone still questions the fact that there is a change happening in the market. Now we're seeing it, now it's here. And we're just riding the right time really to go and execute on that new belief that security of what we've built in the past years no longer holds up and something new is required. - Yeah, on my side, I think when we started, like we were always looking at hats, like even when building our commercial product at Protect the Eye, we were looking at like some automation that might happen and like trying to architect it around it. But then even like, you know, after two years of building this, you realized the agents are completely different. Like when Cloud Code started to be like even popular Palo internally, realized that even their textures that we built, they're not really scalable. But then we saw like a kind of massive adoption, massive scale of like events, like telemetry that we are getting. And we're like, this is gonna be different than whatever we had before. And it's like maybe like a, you know, unique opportunity for us to leave and like use all this knowledge from like how to build a startup, how to build like a product in the eye security and maybe build something like even bigger than we had to protect the eye. - So I think it'd be really interesting to talk a bit about how this space has changed because the initial set of security products for AI were very guard real based. And you both as well as a team had this insight that with agents, Neil, you'd mentioned just like the action portion of it, it just kind of breaks a lot of the security paradigms. So maybe talk a bit about why you needed something that was a runtime security platform, like how old security products break and then we can get into specifically what manifold does from there. - Yeah, 100%. I mean, look, like the past two years are really kind of dominated around the model, right? Effectively a linear relationship from user, something the model getting a response, then they added some flavor with retrieval and then the generation as well. And it was effectively kind of the dream of perfect enterprise search that was being realized at scale. Nowadays, even a year ago, we talk about it all the time, plot code existed, but it's nowhere near to what it is today. And the reason for that is just that it just augments the level of productivity that an engineer can achieve in a very short amount of time and we see it every day as well. When we are building our own security products, we're applying it to ourselves. And what we're seeing is just as massive untapped supply chain as well that is propelling these agents forward. And so when we talk to customers, why is this so radically different than anything that we've done two years ago, the endpoint is really the battleground because again, plot code, codecs, and all these other tools are seeing a major inflection point over the past few months for the engineers. And with it, we see with our customers that they don't even know what their engineers are using, let alone the artifacts, the assets that are driving those agents to go do what they're doing. And so what I mean by that specifically is skills, servers that are pretty much aware of, extensions, plugins as well. So when we talk to those ceaseless, they don't know what agents that are being used. They don't know the assets that are underpinning them. And then they also don't even know whether these things are good or bad because ultimately they're being pulled in from external sources. And so beyond that, if that is not by itself a big alarm bell to many organizations, we see that most of these attacks are coming through that supply chain as a vector, a new vector. And besides that, nobody's monitoring what is happening within these agents at runtime. And ultimately, it happens at runtime. So it's a really untapped space and the pace at which it's moving, the pace at which the adoption is happening across organizations is unlike anything we've seen before. And just to put it in perspective, what we've seen in the past two years, when you're looking at chatbots, the volume that you had in a customer facing chatbot is not even anywhere close to what we're seeing on a week-by-week basis within our own engineering team. And so it's really quite incredible to see kind of the explosion of the supply chain, but also the adoption across these organizations.
Yeah, also, AI security, one point I was started mostly by people, not from cyber security space. It was a lot of ML, machine learning, engineers, AI people that had a belief that it needs completely different approach. They had a lot of AI researchers training different classification models. But then you have an issue of cost accuracy latency because you need to use smaller models, then smaller models are not trained on code. So it's not really scalable for a code at all because it will flag so many false positives. Also, we are talking about different modalities, languages, and so on. So this is what we realized. We took a completely different approach when we started without having any background and cyber. And now we are seeing this message shift that people from actually cyber was a lot of experience, entering the space to apply some techniques that from the past, from the supply chain, from detection response, to make another attempt of securing agents, how they have been securing this for people, applications, and so on. So that makes us really excited because we are basically taking the learnings, but also doing it completely different, because the space completely changed. So I guess we're really curious about how you guys approach when it comes to the product positioning and even the problem you're solving, because oftentimes we just say AI security, such a vague term. And most part, you say endpoints, we kind of understand what it is. But I'm sure AI agents is changing the way people should think about how you should actually secure not just your endpoints, but all the agents going in and doing the changes. But frankly, also feel like most enterprises are so early on this adoption curve, right? They're not having it really everywhere yet. But we all know it at writings on a wall. So I feel like being a startup selling in this space is a very tricky and interesting time, because there's so much chatter with early but growing adoption, and the pain is just kind of there. I'm curious like how you guys decided what the position should be. Like, are we selling a very big platform sort of speech from top down, or are we going to try to work through with some individual engineers on getting some particular use cases? Have you found anything that you learned so far? Like, hey, I think we should definitely come into this sort of problem set and talk about our product this way or that way? Like, is there any early learnings already? Absolutely. I think ultimately, it always boils down to you have to do a runtime detection response. And that's where we started. That's where we really build out the most muscle in the platform. The very interesting learning that we have is, and this was under the assumption that we would be way more ahead than where we actually were at the time, that companies already had a good understanding of what agents there are, and what assets that are propelling those agents forward, like skills, servers, you name it. And every single conversation we had with the customer, we started realizing they have no idea of those things. And if you don't even know what you have, then you also don't know whether what you have is good or bad, whether you're pulling an empty malicious. And so that was really a big a harm on the trust, where we understood it's not just a very isolated focus solution that we're building around detecting at runtime within the sequence of events, suspicious activity at a minimum, but also at a broader level like actual attacks. But it's much more than that it's actually going to discovery kind of fulfilling the true promise of ASBM, if you will, not in just your first party environment, but also your endpoints itself. So when we serve our customers today, we actually always start at like the discovery, giving them an understanding of what they have, not only the agents, but the full supply chain. And then we go about scanning those assets, so they can effectively control their inventory and go approve and deny anything that might be deep malicious. And you mentioned that something interesting, which I will challenge is, you know, I don't think we're early at all. I think we are seeing some really impressive stuff at companies where there's been a really big shift happening over the past three months where there's an immense amount of pressure from the sea level, board level, to go and enable the business from the security side, that there was a lack time on the security tooling available in the market to go and enable the business. And that's what we're seeing. We have a lot of imbalance. And then consistently we see that table stakes stuff are completely missing. And that is for us like a major validation point that we're in a greenfield space that that it's such an urgent problem. Yeah, I mean, on my side, it's not much to add, but yeah, like we started like a very optimistic that like, threat detection is what it's needed. We built like a very advanced engine for that, like that could detect like really impressive stuff. And then I think just yeah, I realized like the discovery of inventory, the whole supply change is more important for now. And so like people want to just first understand what they have was the risk like assess it. And then from there, like start adoption of different AI tools. Like example is that we're seeing that Cloud Code is usually quite like, I mean, the permissions are quite relaxed. Like every engineer gets quite a lot of access because they like usually companies trust there. But like you have all the other functions that have no access to those tools, like marketing design, product. And so like we are basically like becoming certain fanabler for these companies to give access to like, co-work, cloud design. And like all these other tools to other functions to also augment them. Because right now like it's basically, it's just a blocker for security teams to have like a bigger adoption. So maybe that like this is where like it's maybe early. Because security teams are like trying to understand all the risks. But for engineers, it's definitely not like we're seeing like all companies, Cloud Code or like similar tools are enabled for every employee. Yeah, the piece of it's really interesting because I think versus the last wave of like first gen AI security tools, this is just getting adopted in a plated way. That's just really hard for companies to manage. And then you coupled out with the fact that even though these weren't all AI related, there've been a ton of supply chain intact lately, which kind of brings us to manifest. So maybe talk a bit about what manifest is, like what the goals are for it. And how it helps our customers and users when it comes to like securing their agents. Yeah, for sure. I mean, I think I actually forgot to mention a pretty important point which got us to supply chain as well. And the fact that we're seeing so much urgency from the pop level down to the security team, as you see so right at the sea level. And the reason for that has been pretty much open to the clock. Right? I think a lot of people start to understand the true power of agents in a non-technical way, whereas engineers already understood the kind of massive uplift and productivity they can get from agents already. And with the open client reduction which kind of showed the true power to any non-technical user, you also start to see a lot of the supply chain attacks unfold. Right? I remember many people kind of flagged to us that week when OpenCloud was kind of in the peak hype where they were asking, okay, have you seen this skill? That was like the most downloaded and it was like somewhere involved and all that. And it made us realize that the supply chain again is such a major component that enabled the agent to go do. Things that are more tailored to your own specific focus, whether it's as an engineer or even just within co-work as a non-technical user. And so we started to dig in because you start to see like multiple registries and inventories if you will marketplaces rather kind of pop up where there was no understanding whether those artifacts have any kind of security implications attached with. And then the interesting thing happened. A lot of vendors, Cisco and a bunch of others, they started to roll out their old scanners. But the thing that we saw when we started digging in is that among 30,000 skills that each of those vendors started scanning, they had a common verdict on only 0.32%. And so all these scanners were kind of throwing a lot of headlines forward where they said, hey, 40% of the entire skill ecosystem is malicious. And that is not a solution, right? Because it definitely wasn't 40 plus percent. It was closer to less than 1%. And so we realized that a lot of these scanners are driving a lot of noise. And it's not a good thing for the industry. If you cannot use those scanners to go control that inventory and govern it effectively for your organization. So we took an open approach there where we understood like a common foundation for the industry is completely missing. That is not just grounded in like, hey, let's send the skill file to like an alum and let's see what it kind of conjures up in terms of risk. But we started to look at a lot of the learnings you have from supply chain security in the past, where you look at lineage and you look at the author, trust core and all that, to effectively come up with true security findings, which we couldn't find anywhere else. Is that the only thing that we're doing? We're doing a lot more than just that. But it's one of the things that we were doing at the time when we released it that others don't have.
So we started that skills because it's kind of the newest artifact, the most commonly, and exponentially growing asset out there. But we're extending it to any kind of AI asset that is propelling agents forward. And we're keeping it entirely open, and it's also directly integrated with our products. But all of us should talk more about like, you know, the actual stuff that we're doing that does maybe more interesting technically. Yeah, I mean, we started also with skills because the adoption is so much easier. So like, I'm CPU servers are really for technical people that know like how to like do NpX install and put it in some JSON file in some right place. Skill is so much easier like to just install it just like one command or even like you don't even need command you just like upload a MD file. So it just become like even more risky to put them. And we see like how security teams are struggling to like verify them the way they do it. They put it in like some sandbox, they try to like read entire like MD file, they try like I don't know some comments like it's probably takes like a lot of time to even do this. So what we have done we start with how would you choose like a library on open source? You would look at the order, you would look at the commits, you would look at popularity of this like trans of like updates, we started there from there like we built a sort of like an execution graph which extracts different potential paths that this skill can take like for example there's some serial execution, there's some I don't know like it wants to write to some file something we basically mapped it on the graph to show what is actually happening. And then when we were building this part of this and like trying to make like different rules on top of that graph, we realized there's a bigger issue. When we flag something to user, we want also to give them an alternative that we don't want to only say to them, hey this is like bad and like don't use it because they still need to have some skill for this maybe like it's a I know some PDF help or like writing document. And maybe this is malicious but like they need to find something that is safe. So we created ecosystem graph showing like is there like a system something that is similar maybe by content maybe by name maybe by like author that is not flagged and you can actually just turn to that and like download that skill instead of this one because that one is a lot of like so basically making it easier for security teams when they look at the skills to look at different parts of it and not need to read every skill and like every file that this like now skills have like even like this bar scripts. So it's becoming even more complicated. So it's really cool to see you guys able to provide such a valuable thing for that's open access to everybody to directly use and it reminds you a little bit of a socket security sort of feel to it. And I guess my question here given that your last startup did LM guard right which is open source freely available for folks and have a lot of visibility and and wedge into the space. I'm very curious that what did you learn doing that maybe some lessons things did well or you wanted to change that's transferable learning to what you're doing in the manifest kind of world even though they're not exactly the same but feel like spiritually it is trying to gain a lot of people a way to get value much quicker right without having to buy your product right away. What are the things you learn doing to LM guard that you are a playing here? Yeah I would boil down to like two really simple things like one open source security is really really hard and two, arguably and this might be controversial take don't do open source and green field security domain because ultimately he has so many different competitors that are trying to fight for the same mind share and if you truly are not active and you have a very strong open core companies will just build on top of it and you know even at the time when you were building I would argue we were pretty much ahead of the curve and like the way we were pushing you know new features within the library that one of the biggest mistakes you made is like you need to have a lot of smarts and important things early on around licensing around like what is through the your open core and it's very hard to kind of define that in a space that is greenfield right. Who knows what is going to be important like you obviously know like a few core features that it's a lot of experimentation and more than not you don't have time to experiment in a new domain and you just hit the customer to write features at the right time and so we did see a lot of companies that were effectively replicating a lot of our features early on and so you lose that edge of open source with that in fact so. If this was like one year later after LMGART I would be much easier probably because there is already like established players and then you could build like an open source alternative and get like adoption and like usage based on that and probably would not be worried that competition wrapping your product to sell that much but at the beginning it was quite tough because like obviously like we didn't have money for like massive marketing and paying also like it was so early that like there was no budget even for even buying these solutions but I think like what was positive and we were a bit lucky there because we joined Protect the I was like you know resources of Protect the I that we knew exactly when we joined which are the scanners that people care about how they're adopting them was the scale of usage we knew all of that we didn't need to like go through like POC processes and many conversations because we had conversations with like enterprises like big companies and like because open source was like our door opener for like many C-sauce that they were just like wanted to talk to us because they saw open source so that is positive side but like I would say being like a soul to people team building open source at the time would be really hard but like because of the you know events and we got lucky we basically used all this learning so our commercial product was completely different and we planned it like just I think even once we planned entire like scope because we knew exactly what needs to be done. Yeah and you'd mentioned before how manifest is integrated and used by manifold customers and users but can you talk a little bit about how it fits in with the bigger company mission and who kind of like the main users are is it more of a developer user or security teams using it and is it mostly to build trust or is it for distribution or a combination of things right now? It's a combination of things I mean ultimately it has like a dual mission right like one is we do see a need for like a common ground truth for the industry that is not going after a headline that is actually a useful artifact let's say to go and figure out hey what are the skills that I am using and are any of them malicious enough because it's really a table-stakes question that every single customer we talk to cannot answer and so we do have a lot of like network effects for that where you know for one we have folks reaching out on skills that might be like by us that they deem to not be malicious and so we get to learn about that but we are also putting real resources behind manifest to go and improve it over time and so that's like the one mission the way it plugs into the product is very simple right like like a lot of the customers don't know what they have like that's still a truth that is consistent from our point of view but again like when they do know what they have they need to have a really good low noise product that can tell them what they need to prioritize in their inventory to govern and effectively deny across the organization and those are table stakes stuff that don't exist today that we're kind of building that network effect around and so it really fits nicely to have like dual use and dual mission products in a way that does drive major value and we see that in every conversation we have because a lot of people know it and a lot of people are organically coming inbound to us through manifest as well yeah I wanted to add like we chose intentionally to like make it open for everybody also to use just basically this network effect that Neil mentioned like we could build in just you know closed and then it would be only like valuable for like our customers but we could get so much more by like having feedback from like the whole community outside what they like about this what they find like as a noisy so there's much more feedback I mean again like kind of example of a film guard because you're making it's open if you like thinking strategic about like what you make open and how you make it you could actually have like a massive thing that like we'll drive like a lot of feedback to you not just from your customers but also like from anybody that is using it so this is what we are seeing today like we see a lot of positive feedback some things that we could improve and then like our customers benefit from this like from the manifest and also brother community benefits from it yeah we'd also add like one one more thing like because it's full table stakes because it's the entry point the fact that we have that network effect just makes us all the more appealing to go work with because we have that coverage and we can be way more granular in our findings compared to others that again are more than often just sending it to an LLM for evaluation and then with that they get the scary headline but they also get the scary useless product that just drives a lot of noise and alerts and effectively makes the security team repelt the product at the end so that's also like the strategic thinking that we have around it so maybe talking about the similar your LMGAR learnings here I think one big part of actually just creating any sort of bottom up sort of service or products is really driving the
awareness and the funnel and the community, right? In fact, the community, they should talk about you more, because that's how the world of mouth really got going. And I'm just curious because I think at this time and space, everybody's talking about open-cloth skills. I get such a hot and crazily contested topic. So oftentimes, you have many, many people, plus vendors, all pretty much talking around the same points, the claw swarms and all these things. So I'm curious, what have you learned so far when it comes to such a hot space with such a hot topic? What are things that was really memorable for folks? How does word of mouth actually kick in for any examples where people really gravitated towards what you've offered or even your messaging way more than potentially some others by just talking something similar in this space? Yeah, I mean, word of mouth ultimately comes through great content, right? And you cannot see two different things in security. And I think it's changing a little bit where in the past five years or not even the past five, maybe a year ago, five years before that, along with it was like Firdram. And I see a lot more messaging that is, you know, cartoonish on the website, but also like all about like enabling the business and all that. So it's all more happy and fun. But ultimately, the way we look at it in terms of our content is to be really focused on things that matter. And not just seek out like a nice headline that scares people for clicks. So it's not just on like the content of the articles and research that we make, but it's also in a way we position the company, right? And ultimately what you will see in AI security is that every vendor out there, they think they will win or they will get into a PSC because they can solve your clouds, AI, they can solve your third party AI and also your endpoint AI. But ultimately what we are seeing because we are truly positioning ourselves as like a platform for the endpoint and the AI that lives there, we actually see that play in our benefit. It helps us be more focused on attacks that are relevant there, the kind of usage pattern, the way security teams think about endpoint as well because that's a pretty important thing, right? Like you have cloud security teams, you have IT security slash corporate enterprise security, then you have IT kind of mixed in between that and then you have detection engineers and if you kind of blurred a messaging at the top that you solve everything, then how do you reach the right audience with your content too? And so that really helped us drive a lot of good content. It helped us get a lot of roles with people in the room early on in the initial conversations. And so that's really how we think about that. They are all like, you're kind of driving a lot of the research as well with the team. Yeah, I mean, as you mentioned, conduct is important, timely content actually, even really going deep and like explaining what is reality and like also driving different research, like open source findings. But I think another point what is changing is that it used to be that like you had a landing page full of like some headlines, but now a lot of buyers they expected to see some product. They want to see like some screenshots, more information what is actually doing and not doing and just not like some fluff. And we see this even what changed in like a buyer persona used to be that you could pitch a product like sort of like an MVP of the product and then like tell about the roadmap and then basically they would buy the vision of the founders, the roadmap, like, you know, all these factors. Now with Cloud Code it's becoming like a sort of a decision like should be by coded or self or should be like buy it like a solution and then you need to be more feature complete. You need to show like faster pace. You need to show like more breads in coverage. So this is like something that we learned was like all this hype of like, you know, open cloud code and like everything was going on. Yes, you need to go like in one specific area, for example, endpoint, make it right messaging. But then in that specific area, you need to have some certain brands and not just like tell that yes, we have it's like in like three months from now we will build it for you. A lot of times like they expected like, you know, soon because otherwise they have like a security team that can also open code code and like maybe do something similar. Yeah, it's interesting because there's so many vendors now that are saying similar things like we have like, you know, so many competitors out there saying something similar, but at the end of the day, it comes down to like, yeah, how valuable it ends up being and how much value you can show in a demo environment and going through this now with L. M. Gart and Paul also and protect the eye, you've now kind of seen this play out. I want to make sure that we had a chance to talk about andthropic and how the model players are going to kind of like your view on their role in security. So obviously there's been a lot of hype around cloud security andthropic security scanning capabilities. But I think for folks who are in the space like you like seeing the difference between where they can help and where they can scan and find vulnerabilities versus the context and breadth that you'll have. Maybe just talk about like where you see them positioning over time versus independent players when it comes to Asian security or also security scanning in general. Pretty important positions for sure. I think to all its point, cloud codes, codex, all these tools, they allow teams to move so much faster and what we use to see were a lot of wrappers that are very soft specific, you know, consumer focused or kind of B2B copycats. But I think just the ability to reason through a backlog of alerts or a massive set of events and drive signals from that is ultimately one of the things that alums do so well. And so it's kind of inevitable that it will play a more and more important role. I guess like the bigger question, which I'm not to need to or can answers like will they effectively start rolling out their own products? I mean, we've seen it within traffic around cold scanning that whether that is just a show of force of what you can achieve with cloud as opposed to them going out and building out an entire team to sell them to the market is the question. I think with Mito's a lot of the kind of conversation shifted around, you know, are, you know, these AI models going to break security solutions that have been there for 10 years or not. I think it comes with a lot of caveats that we've kind of seen unfold over the past week. And I know that all of us have a lot of time looking into this. So maybe you want to talk about. Yeah, my take is like, it's not just the model. Like that will change it. It's also the registration piece around it because we see currently like based on bench for our first for like each, you check the bench works of each model like whenever it's released. And then you see like it's always like at the top. And then when you try it, like it's not performing well, for example, maybe just in isolation. And then maybe you try it like in specific like agent according to like open source or like, I don't know some close source and then it's performing much better because the orchestration is also like doing a lot of work for us. Like that's why maybe like cloud code is like, you know, for some people much better for than codex, maybe codex is better like for some other does because just orchestration pieces around it. It's like optimized to do some specific task well because this is how engineers planted. So I think this is the same with meters like it's not just the model that was like really well trained in like on specific use cases, but it's also that they created like a very advanced pipeline of like fine vulnerabilities very fine them then creating patches for this. And I mean so far we've seen that the cost of this is quite high, maybe like not really acceptable by all companies. That's why maybe like access was also given to like only players that could afford this, but I think like over time it's going to be not just the model, but like how you can properly like create tools like optimize like search for different functions, write code and so on. So maybe shifting to your users and buyers a little bit too, what is the most common misconception that you have to educate or teach them around AI or even security? Like what is like the number one thing you always feel like, okay, here's Gary goes again, I need really to let them know what would that be? >> Yeah. That's a tool like LM guards or any kind of classification of prompt output or what it just atomic events within an agents cannot like secure the overall agents at runtime. So I guess it's like a byproduct of what we saw in the past the years as I mentioned, you know, we secured the model response. So it was like low volume prompt in prompt out. You could classify that with a really good signal to noise ratio, but now we're looking at invocation chains with a lot of contacts that ultimately unfold as the chain unfolds in our resource access tool calling skill use you name it and looking at each event within the context of that entire chain and saying because I saw this one tool call now your entire agent is malicious, which is drives a lot of noise. And I think a lot of the buyers, they're kind of trying to wrap their head around how that shifts from response to action happens. And they're also suddenly trying to wrap their head around like those tools that used to work okay-ish for model response no longer holds up to what is next and here already today. So it's almost like they didn't the time.
to figure out what's next and it just came at them very quickly. And that's why they're trying to frame their worldview around this new problem that's with what they just bought a few months ago. Yeah, also, like, a lot, many times the original AI security was handled by product security teams. So it was mostly focused on chat boards that companies are building. So, and those product security teams, they bought probably procured some of solutions that are on the market. So they have certain biases. So it depends really like who is like entry point for our conversation. And if it's like product security team, it's going to be 100% conversation about that solution that they procured. Can it work for agents or not? Because I mean, they procured it. It's still there. They put it like already like in their LM gateway. They put it like in bunch of tools that they have. And obviously they will be interested to learn why like they need something else. We have it many times. This conversation like why LM firewalls won't solve it. Why need a different approach to that? I mean, the other thing is that more than often after they bought it, they were told that this works for agents. So you have to go and explain why, you know, the vendor they just bought from. We're not completely honest with that, you know, belief. So I think that's kind of the side effect of like super quick velocity and how technology moves forward. And I think the other thing is also around the belief that discovery is like pretty much done. Right? I mean, to all of this point, we're usually talking to first party teams and the product security teams that are securing their internal builds. AISDM is a big topic that a lot of people talk about. But what we saw in the industry is that runtime preempted posture management. And so to go and explain what that looks like is an entirely new topic for many people. Yeah, it's interesting how much I would say like buyers also just don't know what they need either. And so figuring out how to explain it to them where they are. But then also kind of like provide that full platform. It'll all over time shake out as they kind of see what's working. See what's not. But we're at kind of an interesting point of the market where no one really knows what they need. We're obviously still very early in the manifold and manifest journeys. But are there a couple of kind of big things that you each learned or like advice you would have for other founders that are thinking of releasing part of their product or something open source that you can kind of leave our audience with? The focus is really on table stakes stuff. I mean, I think we kind of alluded to this, right? We were building a really amazing, and we are still building to be clear, detection engine around the runtime threats. It's critical. But you need to look a little earlier in the journey for those teams, right? They care about that. But as they don't know, the inventory, what they have across endpoints and whether it's secure or not, you're kind of running ahead of what they really care about. And I also think the other thing is the timeline completely shifted, right? So to all of these points, like in the past, we would be selling vision. Now more than nothing, we see that the buyers, they care more about like enterprise readiness. Not just like, what do you detect, but how do I operationalize the detections? And the only way you can show them that is by having some of the more enterprise features that we would, a year or two ago, would push out a year from starting a company or maybe like six to seven months from having your first customer. So the kind of timeline is really crunched down because of the tools that we're trying to secure as well, which makes the pace so much more important. Yeah. And one thing that we are not just saying, don't rush open source like anything because we are seeing so much like so many new projects open source for like security for like open close security. And it's all like coded like kind of very quickly, just really something massive scope that like you cannot really like in this small project, you can really understand like what is doing and like what it's not doing. Don't rush it. Like ensure that you understand well, the problem you're trying to solve the scope, like we know that you can achieve a lot with code code, but like it needs to be a solution that looks mature and it can be easily installed. And like as Nino mentioned, it needs to be like enterprise ready that it will be easily like deployed installed. There's like a good documentation, not also like coded documentation. And we're seeing many times like everyone is rushing, like just want, I don't know, like in the next day or three days after some article comes out to like build something, but then like it doesn't really maybe they're frustrated because there's like no adoption. And there's like another thing maybe like two, three weeks later that just properly executed and maybe like even much smaller scope and it has more adoption. So yeah, I would say that would be probably advice like from building like a garden also like manifest. Awesome. This is a great conversation. We're both pumped to follow the manifest journey and trajectory. So thank you both so much for doing it with us. Yeah, it was so much fun. Thanks, well, thank you.
Podcast Summary
Key Points:
Manifold Security was founded by Neil and Alex, who have extensive experience in AI security from their work at Protect AI (acquired by Palo Alto Networks). They saw a shift from securing model responses to securing agent actions.
The "unfinished business" driving Manifold is the need for a new security approach as AI agents (e.g., Cursor, Copilot) act autonomously, breaking old guardrail-based paradigms. The focus is on runtime security and supply chain risks.
The space has evolved from securing chatbots (model responses) to securing agents that execute actions, with a massive explosion in agent supply chains (skills, plugins, servers) that organizations cannot track.
Manifold’s product starts with discovery and inventory of agents and their assets, then scans for risks, enabling security teams to govern adoption. This is crucial as companies face pressure to enable AI tools across functions.
The open-source project "Manifest" addresses the lack of common standards for scanning agent supply chains (e.g., skills). It uses lineage and trust-based analysis to reduce false positives, unlike existing scanners that flag 40% as malicious when the real rate is under 1%.
Summary:
Neil and Alex, co-founders of Manifold Security, discuss their journey from early AI security work at Protect AI (acquired by Palo Alto) to founding Manifold. They highlight a major shift: AI has moved from chatbots delivering responses to agents taking autonomous actions, which breaks traditional security models focused on model output. This change creates new risks, especially from agent supply chains—skills, plugins, and servers that are often unknown and unmonitored.
Manifold addresses this by providing a runtime security platform that begins with discovery and inventory of all agents and their assets, then scans for threats to help organizations govern adoption. The founders note that while engineers rapidly adopt tools like Copilot, security teams lack visibility, leading to imbalanced access and risks. Their open-source project, Manifest, tackles the lack of common standards in scanning agent artifacts.
, claiming 40% of skills are malicious), while Manifest uses lineage and trust-based analysis to deliver accurate findings. Manifold positions itself as an enabler, helping companies safely expand AI tool access beyond engineering to other functions.
FAQs
Manifold Security secures all AI on all endpoints, focusing on runtime security for AI agents. It addresses the shift from securing model responses to securing the actions agents take, including their supply chain of skills, servers, and plugins.
Neil started in finance, moved to product management and VC, focusing on AI security pre-ChatGPT. Alex has 15 years in engineering, building teams and open-source projects. They co-founded Lengard, joined Protect AI, then Palo Alto Networks, and left to start Manifold Security.
They saw a market shift from securing model responses to securing agent actions, and felt they had unfinished business to build a new solution from scratch. They believed the old security paradigms no longer held up for the new agent-driven landscape.
Traditional AI security focused on the model and its responses, like guardrails. Agent security involves monitoring actions, supply chain assets like skills and plugins, and runtime behavior, which breaks old paradigms due to the scale and complexity of autonomous agents.
Manifest is an open project that provides a common foundation for scanning and governing AI agent supply chain assets, like skills. It uses lineage, author trust, and other factors to identify true security risks, reducing noise from traditional scanners.
Agents rely on external skills, servers, and plugins that are often unknown to organizations. Many of these assets can be malicious, and traditional scanners have low agreement on what is risky, making it hard to manage inventory and prevent attacks.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.