**Grace Gong** (0:02)
We are live. Hi Guy, welcome to Venture with Grace.
**Guy Arazi** (0:06)
Hello, nice to meet you.
**Grace Gong** (0:07)
So obviously, you're an investor. I want to shout out to Itamar. He is the best.
He's your investor. So yeah, recursive ventures. And he is the best and he intro'd as a while ago. And obviously, you guys stressed at the fundraising announcement yesterday. Tell us more. Maybe we could start from the background. So obviously, you have been a security expert at Microsoft, among other top security department and all the top tech companies. Maybe we could talk about what were some core lessons that you've learned early on in your career shaping to who you are today.
**Guy Arazi** (0:42)
Sure. So I started with security when I was six or seven years old. I was always into securities. That's kind of like my escape.
And then I was doing some stuff that relates to encryption in the Army and also the intelligence.
**Grace Gong** (1:00)
Is that the 8200?
**Guy Arazi** (1:01)
No.
**Grace Gong** (1:02)
No, okay.
**Guy Arazi** (1:03)
There are other teams for you.
**Grace Gong** (1:04)
Okay, there are other teams? I feel like...
**Guy Arazi** (1:07)
So when I left the Army, my first role in security was a CISO of an investment company. And after a while I left and I went to lead all the application security in one of the biggest companies in the world, the American company Israel. And then I got a proposal from Microsoft to join Microsoft Defender. And I was there for a few years. I found the SolarWinds attack, one of the biggest supply and joint attack probably in history.
And I got to do some awesome things like stopping ransomware infections in enterprises. Then I spent two years in Palo Alto Networks. I built a cloud product called XCloud. All the way from scratch, I was in the founding team. And then I got another offer from Microsoft to come back. And I missed the culture.
And then I was like a vulnerability researcher for Azure for a few years, like I think two years roughly. And then I moved to the UK. And with that transition, I also moved to MSRC, which is, MSRC is a frontier research team that deals with the entire ecosystem of Microsoft around product security. So all the vulnerabilities reports, mitigations, everything was handed by our team. It's called V&M, Versibilities and Mitigation.
And a year and a half ago, I left Microsoft and started the company.
**Grace Gong** (2:24)
I want to start with like, since I feel like serving clients right now versus like, you know, working for Microsoft. I think if you're working at one company, the vulnerability is predictable. Well, it's like semi-predictable. But I guess like from nowadays, like with all the different like AI companies, there must be like different kind of threats. Maybe we could talk about like, you know, what kind of threats is there? And then how do you guys think about like, you know, building for the AI company to keep AI company secure, but also using AI to build security company as well.
**Guy Arazi** (3:03)
So, different threats exist for different companies, right? Like not every company builds the same software, the same features, the same business. Like they're not even offering the same business, right?
And we get to see everything from everything. Our customers or travel companies, insurance, some of them are Frontier AI Labs. So, the threats and the vulnerabilities, like they're different from company to company. But at the end of the day, like companies are using AI to generate code, right? They're building with like Cloud, Codecs, whatever it is. But it's very hard for those agents to really kind of conceptualize and understand all the ecosystem that goes in there, in that specific company. And it's kind of like the foundation of, how can you define security boundary in a proper manner before you're even writing any line of code? So, that's exactly our intersection on how can we help them build things better, which is obviously why we built Pi.
**Grace Gong** (4:11)
For sure. Let's talk about Pi Security in general. So, obviously, I'm currently sitting in the office at SF right now. Since you guys just did the announcement of 35 million raised and maybe we could talk about how did you ensemble the first team and what was the first product that you guys have launched?
**Guy Arazi** (4:30)
Sure. So, when I left Microsoft, so in MSRC we used to get hundreds of reports on a daily basis. I felt like I was extremely overwhelmed. Yeah, it's exciting. You get to see live exploits and things that can demolish our reputation in a few seconds, and you also get a chance to remediate those. But you see the same issues over and over, and that also made me get into realization that it doesn't make sense that we're using AI to brilliantly develop features and applications very fast, but it's almost impossible for us to secure it at the same time. So as much as velocity grew by 10 or 15x at that time where I was in Microsoft, the security was stuck on the same traditional path or the same trajectory.
47 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000773096202