← BACK TO PROFILES

Alankrit Chona

Co-Founder & CTO·Simbian·San Francisco Bay Area, California·

Swinging the pendulum back to defense

In this interview

In this interview, Alankrit Chona, co-founder and CTO of Simbian, explains why reinforcement learning has made AI far better at attacking than defending, and what it will take to close that gap. He argues that detection is largely a solved problem and the real failure is capacity, with analysts drowning in alerts that are mostly benign, and describes how Simbian's AI SOC, pentest, and threat hunting agents check everything so nothing gets missed. He also traces his path from Twitter and Afterpay to founding a company, and shares his north star of swinging the pendulum back in favor of defense.

Alankrit Chona
Alankrit Chona

Alankrit Chona is the co-founder and CTO of Simbian, a Bay Area startup building AI agents for the defensive side of cybersecurity. Simbian's suite includes an AI SOC agent that triages and investigates alerts, an AI pentest agent that attacks a customer's own applications the way an adversary would, and a threat hunting agent that turns fresh threat intelligence into searches across the infrastructure. The company sells to enterprises and to managed security service providers that must close each investigation inside tight SLAs, and it works across OpenAI, Anthropic, and open source models, tuning every agent for cost, performance, and latency. Alankrit describes the mission plainly: help defenders adopt AI fast enough to keep up with the AI attacks already coming at them.

Alankrit came to Silicon Valley to work at Twitter, where he spent more than four years as a senior software engineer on notifications infrastructure and Android onboarding. When the director of engineering who had managed him at Twitter became CTO of Afterpay's US business, Alankrit followed him and became one of the founding engineers behind the company's US launch. He went on to be a founding engineer at Spotnana and Kanmon, discovering along the way that his real strength was platform and data infrastructure. A graduate of IIT Delhi who grew up in a conservative family, where his father held the same job for more than 30 years, he raised his appetite for risk one role at a time. The release of ChatGPT at the end of 2022 told him the moment had come, and he co-founded Simbian.

“Being able to detect that you are under attack is a solved problem for the most part. The alerts are firing. Organizations just don't have the human capacity to actually investigate all of them, and it becomes death by entropy.”

His thinking starts with an uncomfortable asymmetry. Frontier models improve through reinforcement learning, and offense is easy to reward: plant a flag in a database, and a model that extracts it has provably pulled off a SQL injection. Defense has no such clean signal, because it depends on each organization's budget, telemetry, and crown jewels. Alankrit argues that detection is largely solved and the real failure is capacity. Detectors cast a wide net, roughly 95 percent of what fires is benign, and analysts drown in the noise until they miss the real attack, a condition he calls death by entropy. His answer is to let AI agents check everything, since true pattern recognition only comes from examining every alert, then let customers encode their risk policies and widen the agent's authority as trust builds.

Simbian has published what Alankrit calls the first defensive benchmark in cybersecurity, a cyber defense benchmark and reinforcement learning environment modeled on the problems defenders actually face, and research labs around the world have taken it up. With about 60 people and a seed round behind it, the company is scaling sales and R&D, planning one quarter at a time while holding a longer north star. He is cautiously optimistic about AI, expecting a period of transition that gives way to real abundance, and he believes the attention now flowing to defense will help organizations put the right controls in place. His measure of success is ambitious and specific: train AI to be as good at defense as it already is at offense, and swing the pendulum back in the defender's favor.

The conversation

In this conversation: Josh Rubin (Host, CTO Studio) and Alankrit Chona (Co-Founder & CTO, Simbian).

Recorded in San Francisco for the CTO Studio interview series. Interview recorded on 09/03/26.

This interview was recorded by CTO Studio, a media brand owned by Howdy (howdy.com). Transcript lightly edited for clarity.

Josh Rubin

So I start these conversations exactly the same way. If you could tell me your name and how you spell it.

Alankrit Chona

I'm Alankrit. I spell it A-L-A-N-K-R-I-T.

Josh Rubin

And last name?

Alankrit Chona

Chona, C-H-O-N-A.

Josh Rubin

And I ask these questions to make sure that whenever it gets edited, we don't screw up everyone's title, everything. So, Alankrit, what do you do?

Alankrit Chona

I'm the co-founder and CTO at a company called Simbian. We are basically building AI agents for the defensive side. So we help defenders adopt AI and keep up with the AI attacks that are coming up these days.

Josh Rubin

Okay, well, that's obviously a hot topic and we're going to get deep into that, but let's start by going into your background a little bit. How long have you been working in cybersecurity?

Alankrit Chona

So this was my first official stint working on a product in cybersecurity. I have done security implementations at my biggest companies. I implemented authentication, authorization, and made vendor choices. But this is the first time building a product in cybersecurity. And yeah, it's a very interesting time. Things are changing very fast, and we are on the cutting edge of what's happening with AI, and especially on the offensive side, we keep up with all the progress over there. So it's been exciting from that point of view.

Josh Rubin

All right, so let's trip back in time a little bit. What brought you to the Valley to begin with?

Alankrit Chona

So I got a job working at Twitter, now known as X, obviously. It'll always be Twitter to me. I still call it Twitter, you know? And I worked on data infrastructure over there, and I worked on the client side as well. And over time, that's how my career started. And then eventually I moved into a few other companies. I worked at Afterpay as an early engineer in the US office. And then I was also part of the founding journey at a couple of other startups as a founding engineer. That's how I kind of got the knack of working in early-stage companies and startups. And that's how my journey kind of started.

Josh Rubin

So what was it about... I mean, Twitter's not early stage at the point that you're joining it, but you're dealing, I imagine, very deeply with complex user data layers and also security on that side. You jump over to Afterpay, which is obviously as much a fintech product as anything else. So on that journey, what specific problems were you solving in those experiences? And what did you enjoy about that?

Alankrit Chona

Yeah, good question. So early on in my career, some of the decisions I made between these companies were more around the people who had worked with me and who trusted my work, right? So they kind of took me along. The director of engineering who had had me at Twitter joined as the CTO of Afterpay US, and he was building a new team. And I was fascinated by the opportunity. This was a fast-growing company. And I went in with an open mind: okay, this is an early-stage company, you have to kind of do whatever is required. I was more backend focused, but problem-space-wise, I didn't have any affinity to, okay, data engineering or backend engineering. I kind of learned almost everything there. And I ended up working more on the consumer side at Afterpay, and then later on focusing more on the platform infrastructure side when I worked at Kanmon and Spotnana, the startups that I joined as a founding engineer. And you kind of figure out, I was naturally good at platform and infrastructure stuff, and I ended up focusing my attention there. But at early-stage companies, you kind of do whatever is needed to make them successful.

Josh Rubin

So your path was basically going... it sounds like trust and loyalty played a role in that. You work for the guy, he brought you in, brings you to the next place, you work there, you do what's necessary to get things done. Now that you've kind of flashed forward, you're not a founding engineer anymore, you're a founder. What was that transition like for you? When did you decide, you know what, it's time for me to start something?

Alankrit Chona

Yeah, yeah. So as I was telling you, in my career journey, I was kind of gradually increasing the scope of risk I was taking. I grew up in a conservative family, right? My father worked the same job for 30-plus years. So it didn't come naturally to me to start a company. I know there's a lot of founders who do it very young these days.

Josh Rubin

Did he want you to be a doctor, and he was just disappointed that you ended up in software engineering?

Alankrit Chona

Engineering was good for him. Engineering was okay. It meets the bar. But I gradually worked up my risk appetite, if you will, right? I worked very closely with founders in these founding engineering roles. And it kind of unmasked it a little bit: okay, these are people similar to me in their thinking and how they approach problems. They just have a better ability to handle risk and put themselves in situations to make a bigger impact. So I just need to do the same for myself, is how I came to the conclusion. The end of 2022 is when I kind of took the leap into starting a company. And the trigger for me was obviously ChatGPT being released, right? There are naturally new opportunities that get created when such large platform shifts occur. And AI was obviously a new platform shift where I felt like, "Oh, this is the moment to take a plunge, if you will." So that's how I decided, okay, I need to figure out what to do and start my own company.

Josh Rubin

And were you very specifically focused on, "This is a security nightmare and that's where I want to play"? Or were you looking around at all of the different opportunities? Why did you decide that this was the layer you wanted to attack?

Alankrit Chona

Yeah, so I was open-ended from that point of view. I knew from a personal point of view I would be a better fit as a co-founder CTO at that stage. And I met my current co-founder, who was leading the go-to-market side, and he has a good background in security and networking. And we talked to lots of people, figured out what people are experimenting with in AI. How do we accelerate AI adoption? And we started with the problem of alert triage and investigation. That's a big problem. It has been for several years in security. There's lots of telemetry and detections and alerts people deploy to keep infrastructure and services secure, but there's not enough people to be able to handle these at scale. So we ended up narrowing down on that problem. Some of the cyber risk attacks that we're talking about are starting to be more emergent over the last year or so, right? So that's somewhat new, but the initial focus was a bit more on, okay, how can we help businesses and enterprises on the AI automation side, on the security side?

Josh Rubin

But it wasn't really the recognition that these tools are going to attack us. Like, these are going to be used as hacker enablement tools, and the only way that we can fight against them is by building a defensive net on top of it.

Alankrit Chona

Right. So those realizations, I would say the middle of last year is when I started seeing some early signs around reward hacking. We built our own offensive security product as well. It's called the Pentest Agent, right? It's basically a mini attacker, and it tries to attack web applications and perform various kinds of exploits against them. So that's when I saw early signs of how capable these models are getting.

Josh Rubin

So you started by building your own white hat hacking system to start attacking companies where the vulnerabilities were?

Alankrit Chona

Yes, yes.

Josh Rubin

I assume with their permission? Or was this a sales technique? "Hey, I just hacked your company. You might want to close this down."

Alankrit Chona

That's good marketing. That's good marketing, but we were doing it as white hat activity, as you say, right? We were working with organizations. We actually had a design partner who we built this out with. And we started seeing early signs when modern harnesses were coupled with, I would say, the Sonnet and then Opus models. Those were the first ones that we saw were really good, combined with a good harness. And we started seeing models chaining together vulnerabilities and creating exploit payloads very effectively. You were able to basically utilize the progress they had made on software engineering and just point it towards attacking web applications. And the problems turned out to be very analogous to each other, right? So all the progress you got for free on software engineering, you kind of need the same set of skills to be able to exploit web applications.

Josh Rubin

Well, it's also, once you know how to build something, you know how to break it. And as soon as all of these platforms get good, oh, I can create any kind of website, any kind of product, any kind of way. Well, that also by necessity means that I can attack. I know where the vulnerabilities are.

Alankrit Chona

Right, so there's actually something interesting. Most of these models progress through a process called reinforcement learning, right? And what we found out was that it's much easier to build these environments to conduct reinforcement learning for hacking and attacking. So it's happening somewhat deliberately from the lab side, right? A lot of people feel that, oh, it's just kind of accidental, models are discovering how to do this, but it's pretty deliberate, these kinds of environments. The way these things are built, you plant these kinds of synthetic flags: hey, if you are able to see this particular page on my web application, then it means that you have bypassed my authorization controls. If you're able to extract this flag from a database, then it means you have conducted a SQL injection. So you kind of create these mini environments, and then you roll out the agents and see which ones are able to achieve it. And then at scale, once you train the model with these reinforced trajectories, you get a model that's really good at attacking. But such a thing doesn't exist for defense. It's not easy to build these reinforcement learning environments to improve on defense. That's an active area of research that we as a company are also progressing on, on our side.

Josh Rubin

You know, is it not two sides of the same coin? If you're training something to attack, is it not also learning how to defend? Or is it simply, no, it doesn't think about that. It's only thinking about how to penetrate, to take on the problem. It's not thinking about how I would prevent that.

Alankrit Chona

Right, so they're very different kinds of skills. I think Andrej Karpathy was the one who coined the term jagged frontier, right? So AI is progressing in weird ways. They've gotten really, really good at software programming, but content writing is really bad, right? So even though you might feel that, hey, software writing used to be considered a very high-skill thing, why is it that it seems like it's moving so fast, but there are other areas that aren't? It's the same with cybersecurity, right? It's just the way reinforcement learning works. It's just much easier to build environments with verifiable rewards for attacking. On the defensive side, it's a multi-layered problem. It often deals with an organization's budget and how much you can actually query a SIEM, a security events management system. How much can you query that at scale? How do you prioritize the various alerts? What are your crown jewels? It's a very multi-layered problem. It's not easy to build these simple, verifiable environments to kind of coach how to defend better, right? It ends up being a very custom problem for each environment, whereas with attacking, you can centralize that knowledge very easily into the model's weights, and that's how we're seeing the progress. So it's definitely something a little bit concerning, but there are ways forward.

Josh Rubin

So what is your way forward? What does your product specifically enter into the market to do?

Alankrit Chona

Yeah, so the ways forward are on the hygiene side, right? Obviously people will now have to proactively attack their own infrastructure, right? That's why we built the pentest agent. And the red teaming side of the product that we're building is to be able to give you the same view of what an attacker would see when they encounter your organization. So looking at your attack surface and looking at your deployed applications, figuring out if there are any exploitable vulnerabilities, right? And you marry that with the organizational context of: is this high priority for you? What is the data that you're dealing with in this application? Is there a risk of exfiltration? What is the risk level of that particular exposure to you? So all these contexts kind of go into setting this up in a way where the organization can handle this. And on the research side, we published the first defensive benchmark in cyberspace. Most of the benchmarks so far focus on the offensive side. We built a cyber defense benchmark and an RL environment on how to actually create this data set, so that the same progress we can also train into the models, on how to strategize better for defense, by modeling problems that defenders actually face.

Josh Rubin

But what are you selling? Who are your customers, and what are you selling these customers right now? What is the product you're giving them?

Alankrit Chona

Yeah, so we have a suite of agents that we sell on the defensive side. We have this AI pentesting agent that I was talking about. We have what we call the AI SOC agent, which basically helps you keep up with triage and investigation. And we have a threat hunting agent as well. So whenever there's any new kind of threat intel or awareness about a new kind of attacker out there, you can take that threat intelligence and convert it into searching the infrastructure, making sure you have the right telemetry to support those kinds of queries.

Josh Rubin

Okay, so that's two sides of one. On the one hand, you have a triage agent that's out there that has best practices, knows what's coming in, has observability into, I imagine, whatever the technology stack is, where things are coming from. That's pre-programmed, that's trained on a particular stack, the particular company, unique, I imagine, to any individual company, but with best practices involved. And then that secondary thing is your intelligence layer. This is the agent that is constantly being updated with, this just happened to this company over here. I imagine that that is connected to your own data and resources. You're constantly feeding it new attack vectors that are out there, new things that are happening, a mixture of news and internal intelligence: on this company over here, we got this new attack. Just as back in the day, an antivirus company said, "There's a new virus out here," and we update all of our virus definitions and patch it. This agent is operating almost as a real-time patch as new intelligence comes in, to say, "This is a new problem. Let's make sure that we've trained our new defensive tech on this," and it's feeding it that way. Am I understanding all of that correctly?

Alankrit Chona

Yeah, that's right. So threat intelligence is already a big industry in cyber, and we integrate with most of the popular sources of threat intelligence, and we also curate specific sources for our threat hunting program as well. But to be honest, I feel the most... So even this OpenAI Hugging Face incident that was trending, right? If you go through the Hugging Face side of the story, that's the defensive side of the story: okay, what did they see? So they had, in my opinion, detection, right? Being able to detect that you are under attack is a solved problem for the most part. There is enough telemetry that you can deploy that will catch it. There are UEBA kinds of detections, which will track, "Okay, is this something that is deviating from baseline?" Then there is signature-based detection that you can deploy. So in the case of Hugging Face as well, over the course of four days when all this intrusion was going on, they had alerts that were firing, right? But they just didn't have the human capacity to actually investigate all of these. So what happens in a large organization, it's just death by entropy, right? You have tons of these detections that are firing, and a lot of them end up being what's called false positives, right? They're just benign behavior, but they've not been tuned, or there's not enough human workforce to triage these things. So it's just a very high ROI thing. That's why I built this AI SOC agent: to be able to actually go through all this backlog of alerts and detect and respond in time to all this activity that's going on.

Josh Rubin

I mean, humans are terrible at checking. When the check engine light comes on, we'll leave it on forever. It's not telling us exactly what's wrong, it's just saying something's wrong. I imagine when your product or company, like Hugging Face, is under attack, a thousand, a million different things are being alerted, and they know, well, something's happening, but an individual human doesn't even know where to begin. So how would your triage agent operate in that environment?

Alankrit Chona

Right. So the interesting thing is that even when they're not under attack, this is happening, right? There's a lot of analyst burnout in this space. You have these detectors going off, and the reason for that is that the detectors, by design, try to cast a wide net. You're trying to not be very specific; you're trying to be able to catch a wide variety of activity, right? And on average, I would say 95% of activity is actually benign whenever a detector fires. So what ends up happening is, even when nothing is going on, these things are firing all the time, and analysts have to prioritize which ones to focus on, and they often end up missing the real ones as a result, right? It just ends up being too noisy for them to deal with. And the way we help is actually: okay, you don't need to evaluate everything, let the AI agent do it, right? Go through everything. And we have the platform and the capability built to be able to do this in a cost-effective way, right? So depending on what kind of asset that particular alert is involved in, how severe that particular alert is, we can prioritize and make sure that nothing gets missed. So that's where the opportunity is.

Josh Rubin

So a human being is great at two things, albeit slowly: pattern detection, or checking out an individual thing and running down an individual problem. Pattern detection is a matter of wisdom. They look at something, and through experience they know, "Okay, something's happening here, and I think I know what it is," versus checking everything individually, which is a linear process. The time it takes is what it takes. Your AI agents can actually do both, but the thing is that they can do the individual checks at such incredible speed that it operates almost in the same way that pattern detection would, because ultimately that's what it's doing. It's checking everything, and it can see the pattern at the same time.

Alankrit Chona

Exactly, exactly. And the pattern recognition only comes when you check everything in the first place, right? If you have some learning from these individual checks at scale, only then will you see the patterns. And most orgs are just not staffed at scale enough to be able to see through all of this.

Josh Rubin

As opposed to sample pattern detection. You're doing actual pattern detection. Like, "Okay, we've seen everything. This is what the pattern is," not "I have the time to check every hundredth, every thousandth thing and detect a pattern from that." So you're getting the actual real-time, real resolution or definition of what the problem actually is.

Alankrit Chona

Exactly, exactly, yeah. And this is how you kind of scale up your defensive side. In my opinion, prevent, detect, respond: the three pillars of defense, right? So what will happen is that you'll have AI agents periodically scanning, right? So preventative: looking at all your controls, running them in loops, and making sure of that. And then you'll also have your AI-based, friendly white hat attackers, like our pentest agent, trying to see, "Is this actually exploitable? Do I need to actually worry about this on the detection side?" Making sure that your coverage is complete. And then on the response side, any of the signals that your machine is generating, don't let them just sit there. That's not very useful.

Josh Rubin

That's a hard problem to solve. To your point, detection is solved. We can detect it all. But outcome, that's the thing. All of the activity in the world, if it doesn't lead to a negative outcome or a problem, it doesn't matter as far as you're concerned. So are your triage agents there to then insert the human, "Hey, this looks like a real thing"? Or are they empowered to say, "Oh, this is a real thing. Shut it down"?

Alankrit Chona

Yeah, so every organization has a different risk policy, right? So that's where encoding organization preferences is also very important: analyst feedback, organization preferences. The platform itself and our AI agents are capable of taking response and taking remediation actions themselves. But some organizations prefer, "Hey, you escalate to a human before you do anything." Okay, maybe they might be okay with resetting some user's password or killing a process on a host, but they may not want us to block something on the firewall, which can kill a lot of traffic, right? So there are risk-based decisions people place around these things. And oftentimes there are IT policies around taking response, and we try to meet them where they are. And then as they slowly start trusting the agent's judgment, once they have encoded more of their policies inside the product, they can start to give the agent more room to operate, let it take more actions on their behalf, and you kind of gradually unveil the trust.

Josh Rubin

Okay, there was that cybersecurity proclamation that was signed by all of the frontier labs and major companies a couple of weeks ago at this point, essentially encouraging everyone: "You need to do something. You can work with us. You can work with somebody. You need to work with somebody." Where do you fit in with this? I mean, OpenAI would like for everyone to work with them to build this out, enterprise to enterprise. What's your moat? Or do you work alongside them? Or are you model agnostic? How do you fit in with this? And how do you prevent yourself from being eaten by these guys?

Alankrit Chona

Yeah, that's a good question. So awareness definitely is good, right? This OpenAI Hugging Face incident brought a lot of attention to this topic. And as a result, we are getting lots of inbound from customers as well who want to adopt something with AI. And I think it's good for the ecosystem. So we have a lot of people having this awareness, and we have our own place in it, right? We work with various different model providers. We optimize our own agents based on cost and performance and latency. There's a lot of factors that go into it. And we work with OpenAI, Anthropic, even a lot of open source models in our stack. And on the moat side, that's an interesting question, right? My sense is that in domains where, you know, we have a reliable problem, including the problem that we work on in the defensive side of security operations, your relationships with your customers matter a lot, right? Because they like to customize the agent a lot to their risk and organization policies. And through several years, we have worked with our customers, and they learn to trust our judgment on picking the right models and infrastructure and guiding them through the change that we're seeing in the world.

Josh Rubin

Right, so it goes back to what we talked about originally, trust and loyalty. It seems like AI and these attack vectors have disrupted many things, but above all things, trust. And so direct relationships. You need something to trust, because there's so much data, there's so much speed, there's so much of everything at this point that at a certain point you have to say, okay, I trust you to fix this for me. I trust you to handle this for me. And I'm going to blame you if it goes wrong. And is that ultimately what you're stepping in here to do? They need that layer to come in and say, we will protect you, trust me to do this. It's my fault if we don't.

Alankrit Chona

Absolutely. And we also sell to MSSPs, which are managed service providers, and they have their own clients, right? And these people have extremely tight SLAs, right? So it's not just trust on keeping you secure, it's also just meeting your SLAs. They need to finish their triage and investigation at scale within five minutes per investigation. So having a platform with the maturity to do all of that, making sure that they're able to deliver service to their customers, is also something that's very important. And we take pride in setting this up in the right way possible.

Josh Rubin

Okay, so shifting gears a little bit. You're spending a bunch of time in the AI space, you're living in the Valley, and you are operating in a sphere that is frankly one of the scariest in the world. It's out there. Outside of the Terminator and Matrix world, we're in the Sneakers, Hackers world of disruption, of theft, of deepfakes, of everything that's there, of security. How concerned are you with the way things are going? Because the Valley is the Valley. Everybody's kind of gung-ho and moving forward. Outside, in the rest of the country, we're seeing a lot of pushback on where some of this tech is going. How are you feeling right now?

Alankrit Chona

Yeah, I'm cautiously optimistic. I like to think that, in general, the progress that we're seeing is going to create a lot of abundance over time. There will be a period of transition, and different people have different opinions on how fast some of these things will take off. And I feel humanity will always have a role to play, and we'll find what is the next level of development and how to spend our time, even if, let's say, AI ends up doing a lot of the core jobs that we take pride in today. We keep reinventing ourselves. And I think there will be enough focus on the cyber side specifically, right? There is enough attention right now being placed on the defensive side. So I'm cautiously optimistic that we'll band together and figure out how to put the right controls in place, and how organizations can adopt the right security policies on their side to be able to cope with any of these AI attacks.

Josh Rubin

How big is your team?

Alankrit Chona

Overall, the company is around 60 people.

Josh Rubin

And what stage are you guys in? Are you out there raising? Are you in a growth phase? Where are you at?

Alankrit Chona

We are in a growth phase. We raised a sizable seed round a couple of years ago, and we are seeing good traction overall, both with managed service providers as well as enterprises. So at this point we are scaling our sales as well as the R&D org.

Josh Rubin

So sales and R&D is where you're putting most of your stuff, where you're expanding right now. So how do you get more into market, and how do you stay on top of all the changes that are happening at the same time? Where do you see your business, and frankly cybersecurity, going? Can you predict longer than six months? Or can you make bets right now? I know you'd love to have a five-year plan. Can you have a five-year plan right now, or are you kind of operating quarter to quarter at this point?

Alankrit Chona

Yeah, so I like to think of it as: you need to have a north star of where the company wants to go, what's the right thing to do long term. But more tactically speaking, I think one quarter is good, both for the stage of company we are in right now, since we're still early in our journey, and because the world is changing so fast. Planning beyond a quarter is, I think, futile. The rate of development in AI, as well as the security aspects of it, is so fast that thinking beyond a quarter is probably not useful. And the north star for me is if we can demonstrate the defensive side being able to achieve the same rate of progress that the attacking side is, right? We have some unique insight into the problem that I was sharing with you around reinforcement learning, and our place in the world, I think, is that now that we have this understanding, can we actually deliver on this promise? Can we train an AI model to be as good on the defensive side? Can we swing the pendulum back in the favor of defense? And we'll know we would have done well if we can place a claim like that in the world.

Josh Rubin

Do you have a timeline in your own head to say, like, we've done this, or we haven't done this and we need to find something else?

Alankrit Chona

So on this particular defensive model training, I'm expecting to see significant traction for us in the next couple of quarters. So we are working with that timeline. We published our benchmark last quarter, and we've had significant uptake from lots of research labs around the world on that one, and we have more planned on that front. So I'm very excited about that direction. But we'll adapt based on how the world is shaking out. There might be some new innovation from the labs that we'll have to change our strategy around, but we're a small, agile team, and we take pride in being able to adapt well to what's out there.

GET INVOLVED

Be part of the
conversation.

Whether you're a CTO who wants to be featured, a company looking to sponsor, or an engineering leader wanting a seat in the room — there's a place for you here.