**Johannes Keienburg** (0:05)
The type of access that companies that are moving quickly now and are adopting agents at scale, the type of access that they give agents is insane from a security perspective. It is literally wild west and insane, which is in the nature of things. The way I like to compare it is like, we just invented a real quick high-speed train, and we're driving it, and now we're realizing in fact there are no brakes. That's where we are essentially in terms of agentic adoption.
**Carlos Espinal** (0:38)
Welcome everyone. In today's episode, we have two long-standing friends of Seedcamp, both Seedcamp founders, David from Arcjet and Johannes from Cakewalk. I'll let them share what their companies do in a second, but I just want to introduce this episode because this episode is very much a timely one. There's so many companies out there chasing agentic workflows either as a sell or as a buy, and they're all struggling with the same things. How do I secure this? What does it mean to secure this? What should I allow? And a lot of the technology that's being released right now is super useful in terms of single user mode personal use, but when you start looking at in an organization or compounding it or having some sort of like stable enterprise solution, it starts getting really scary really quick. And so that's what this episode is about. So welcome, guys.
Hello.
I'd love for you guys to start. Maybe we'll start by alphabetical order, David. I'd love to just share a little bit who you are, what your background is. I mean, you definitely have to tell the server dead city story a little bit there. And then, you know, why you started Arcjet and then what is Arcjet? And then you go, Johannes.
**David Mytton** (1:52)
Yeah, thanks, Carlos. So I'm David. I'm the founder and CEO of Arcjet, which is runtime security policy enforcement at the application layer. So the web application getting public traffic and agentic applications taking actions behind the scenes, reading files, calling websites. When those actions are happening, you need to enforce certain controls like budgets for users. You need to check for plant injection detection both on the input from a user, but also when you're reading a sign or accessing a website. And that's what Arcjet can help you with. It lives inside of your code. It can be configured remotely by security teams, and developers can use it to build security into the application.
It started in 2023 and Seedcamp came in as one of our first investors. But this is not the first time I've been working with you. I started my first company, as you mentioned, Sabat Entity, back in 2009, which is one of the original Seedcamp companies.
Our investment was 50K, which these days is a little different model. But I built that company and sold it in 2018 to an edge security platform. So this is now technically my third company. Second one, console.dev, is a devtools newsletter. I've done a few angel investments through that, but just writing about devtools every week, still getting quite about 30,000 subscribers, mostly engineers, few investors as well, who use it to source deals. But the day job is Arcjet helping developers with agentic security.
Awesome. Johannes.
**Johannes Keienburg** (3:30)
Hey, to start with David, it's really cool to be in touch. We never met, even though both Seedcamp portfolio and solving adjacent related but different problems. So I'm Joe, and day in, day out, I'm working on helping companies to control access of their workforce. And that's really interesting. Coming back to what you just said, Carlos, we started Cakewalk also in 2023, and we built an access control platform for human identities. That's our existing product.
And end of last year, we went all in, and literally last week, launched an entirely new version, which is the sister product of the human access management. And guess what? It's controlling the access of the future workforce, which I believe is going to be a very agentic workforce. And that's what we do in short.
**Carlos Espinal** (4:21)
Nice. Well, with that, I think we warm up with a couple of really easy but insightful questions for the audience. Let's just start defining what it is. Like, when you guys think about agentic enterprise security, what is the real thing that people should be worried about? Is it the data access? Is it the bad actions? Is it the lack of accountability or is it something else?
**Johannes Keienburg** (4:43)
David, you go first.
**David Mytton** (4:45)
Yeah. So we think about this at the application layer. So that means understanding what the user is trying to do to which particular object and which workflow state with what input, and really try and connect that with the business rules. In the same contrast to Arcjet with something that sits on the network, like a firewall or a wasp, and we're complimentary to that. The network will see the packet, but it doesn't understand the intent. The network is a great place to deal with things like volumetric DDoS attacks, just huge volumes of traffic that might try to take your application down.
46 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000775028527