How to solve AI's security problem | Anshu Sharma, Co-founder & CEO, Skyflow

Posted

0 MIN READ
0 MIN READ

Show Outline

AI raises the stakes for security. Protecting data privacy against other humans or predictable software is one thing; with non-deterministic agents in the mix, the challenge grows exponentially.

Anshu Sharma, founder and CEO of Skyflow, joins me to talk about securing sensitive customer data across data stores, models, and agents, as well as some of his biggest lessons as a three-time founder. 

Today, raw enterprise data can't simply be fed into a model: it's full of personal information that has to be transformed so it protects privacy while preserving meaning. Skyflow controls what data reaches a model, enforces policy on what an agent is allowed to do with it, and manages data sovereignty across borders.

Anshu has been chasing this problem for over two decades.

At Salesforce, he had to convince early enterprise customers like JPMorgan and Cisco to trust the cloud with their most sensitive data; work that led him to help build Salesforce's identity and app-exchange infrastructure from scratch. 

That same trust problem kept resurfacing across two more startups before he founded Skyflow in 2019. “At some point you realize, you know what? There's probably a $100B company to be built just protecting the most sensitive data for customers at all these companies,” he explains.

As a founder, Anshu draws lessons from leaders like Marc Benioff, noting the way companies position themselves against rivals and partners can shape their success in the market. He also argues that enduring companies start with a meaningful problem and leaders who can build a culture around the shared mission to solve it.

We close with his advice for technical founders: learn to respect marketing as a craft. The best sales and marketing comes from understanding your audience so well that it doesn’t feel like sales or marketing at all.

What we covered:

  • 0:00 – Cold open: Anshu on the biggest misconception in AI security

  • 1:00 – What Skyflow does

  • 2:35 – Why AI agents raise the stakes on data privacy

  • 3:55 – Anshu’s story: from Salesforce to Skyflow

  • 8:05 – How AI is reshaping SaaS and infrastructure

  • 10:44 – Skyflow's role in the token economy

  • 15:59 – The biggest misconception about AI security

  • 18:22 – Is cybersecurity a failed industry?

  • 19:08 – How Skyflow's product and go-to-market evolved with the AI shift

  • 20:57 – Building culture in a company competing with OpenAI and Anthropic for talent

  • 22:40 – Lessons from Marc Benioff: beginner's mind and breaking the rules

  • 26:12 – The open-weights debate: trust vs. transparency

  • 30:16 – Advice for technical founders: respect the art of marketing

  • 31:18 – Closing thoughts

Read the transcript:

Ashu: What's a common misconception people have about the security issues in AI?

Anshu: The first misconception is the word "security." Think about thousands of models and literally millions of agents running. None of the security, none of the privacy systems, none of our platforms were built around this idea that an arbitrary model or agent can do things that we can't predict, because the agent and the model are non-deterministic. You can't actually isolate the security problems down to one thing. What you have to do is invert the problem and say: what do I need to do to have a secure, privacy-preserving, controllable infrastructure in place? At some point you realize, you know what? There's probably a $100 billion company to be built just protecting the most sensitive data for customers, from two-person startups all the way to Fortune 10 companies.

Ashu: We're here today with Anshu Sharma, the founder and CEO of Skyflow. Skyflow is an AI security company that is focused on securing sensitive customer data across data stores, models, and agents. Welcome to the B2BaCEO podcast, Anshu. It's good to have you today.

Anshu: Great to be on the cast.

Ashu: Well, why don't you tell us a little bit about what Skyflow does and why it matters?

Anshu: Skyflow is built on a very simple premise, which is that when we go about our day-to-day lives, we have no choice but to give our personal information to the governments we interact with. If you've tried filing taxes, you give them Social Security numbers, addresses.

Even a coffee company — if you go to Starbucks, they know more about your location, have multiple credit and debit cards on you, know where you travel, where you live half the time. As a result, we live in a society where customers are constantly sharing information with these companies, and that forms the foundation of our society.

Now, with AI, this just goes to the next level, and none of this will work if we can't trust the entities we're sharing this information with. So how can I trust my personal information with the AI chatbot, with the hardware device in your ear, or the bank, if I can't be sure that information isn't going to end up in the wrong hands — inside their company, outside their company, or frankly, be sold on the internet?

So that's the problem we set out to solve, and we solve it with our platform.

Ashu: Makes sense. And that problem has always been true, as you rightly said, as long as there have been business relationships between consumers and enterprise, especially with the internet. But with agents, the problem has become 10x more.

I was talking to one of my partners, and she was telling me how she's given an AI assistant access to her bank accounts so that it can wire money to her landlord every month. And I was like, "Oh my God."

Anshu: Every time we delegate an important task to another person, another business entity, or an agent, we're essentially trusting them with both information and workflow, and that cannot be done without deterministic controls.

We live in a world where agents and models are non-deterministic, which means they can arbitrarily do random things sometimes. And if we want to use those things, we must have very, very deterministic, fine-grained controls in place. And none of the security, none of the privacy systems, none of our platforms were built around this idea that an arbitrary model or agent can do things we can't predict.

So we must somehow secure this information without the systems being deterministic. And that's a hard, fun problem to have, and that's what all of us are trying to build.

Ashu: And you've been working on this problem for many years. You started Skyflow six, seven years ago now; you and I were brainstorming the idea for several years before that, and you worked on products in the same general zip code for many years before that. Tell us a little bit about the founding story.

Anshu: If you actually think through the founding story, it has two or three points of pivot. One is when I was at Salesforce — people don't remember this, but most of Salesforce's early customers were actually small companies willing to trust the cloud.

My first problem was, okay, how do I convince the JPMorgan Chases and Ciscos of the world to give us their most important data? Turns out it's a trust problem. So we essentially had to rewrite a lot of Salesforce's data stack, security stack, identity stack. We had to literally invent things like the ability to log into one application through another application — that's called an app store, or app exchange. We were the first company in the world to do that. So things like that had to be solved from first principles. And as I was solving them, I would go talk to these customers and say, "Hey, you're asking me to jump through all these hoops before you give me your data. What exactly are you doing to protect the data inside your company?" And they'd say, "Don't worry about it, it's all secured in a data center, because I have a building." Two things happened: the building disappeared because they all moved to the cloud, and the building was never really a data protection layer to begin with.

So I left Salesforce. I started a couple of other companies — one in email/AI security, another in healthcare AI. (We could spend a whole hour just on healthcare and AI.) But as I was doing those things, the same questions kept coming up: how do you convince the world's largest health system to give you their patients' data? I had to tell them we'd make sure it was secure and safe. Through that process, I kept bumping into the same problem again and again, and at some point you realize: there's probably a $100 billion company to be built just protecting the most sensitive data for customers, from two-person startups all the way to Fortune 10 companies.

Ashu: I think it was spring of 2020 — a little over six years ago — when we ended up leading your seed round. As we were talking, I was reminded of a conversation we had leading up to that seed round, where you told me the story of your early days at Salesforce, when you worked with Marc and with VMware to create the first co-branded product for Salesforce, which was VMforce. How does it feel today, now that they've launched CloudForce?

Anshu: It was completely déjà vu for me. As you know, Marc is a marketing genius. When I initiated the idea of building a cloud platform together, one that could run any arbitrary programming language, between VMware and Salesforce,we just thought it would be called something like Java Cloud, Internet Cloud, or Programming Cloud.

Marc said, "No, if you're going to be peer-positioned with VMware, it should be called VMforce." Marc has a very true, innate sense of when to peer-position against another company. At that time, VMware was about our size, maybe even slightly bigger. Today, Anthropic is, by most measures, maybe two to five times larger in market value, and peer-positioning against — or with — Anthropic is beneficial to both entities.

Marc has three phases for companies: companies he ignores and never talks about; companies ten times his size, which he peer-positions against; and companies three to ten times larger, which he picks as his enemy. For a long time, that was SAP, and then Microsoft, for Salesforce. I don't know who the new enemy is, but we all know the new partner is Anthropic.

Ashu: CloudForce definitely caught the market's attention, especially the public markets. We've seen how Salesforce stock reacted. But what's the broader trend you see in the AI landscape, especially at the intersection of infrastructure, applications, and models?

Anshu: There's a famous quote: "I know the answer, but what is the question?" If you think about CloudForce, that's the answer, but what's the question? I think that's where Marc's true genius is. The question is all the questions everybody has about SaaS companies: are they still relevant? Can they transition to AI? Will AI companies compete directly with them? Will AI kill them? All of those questions are floating around, and then, pop, comes a one-word answer: CloudForce. It doesn't come with a written letter of intent saying those things won't happen, but sometimes a one-word answer answers all the questions. So I think that's what's going on. SaaS companies, and the broader market, are figuring out that we now have a new category of technology.

We tend to think of model companies as technology companies, but I think that's a mistake, because they're unlike everything else. The biggest thing is that they're inherently stateless, and that creates a lot of questions and challenges in the broader market. Everybody's trying to figure out which layers are sticky and which aren't, and collectively the market is trying to figure out what a stable equilibrium looks like.

So the market dynamics are changing. What we're seeing on the other side is what I call the new "token factory": how does the data — the conversations you and I are having — get turned into knowledge, which turns into models? Models process tokens at runtime. Those tokens generate traces or logs, which then become tokens fed back into reinforcement learning—

Ashu: —which creates the context graph.

Anshu: —which creates a context graph, and then you fine-tune it further, and so on. In that "water cycle" of tokens, how do companies like Salesforce, ServiceNow, Databricks, and Snowflake play a role? How do they evolve? I think that's an open question for those big companies, and for all infrastructure and data companies.

Insights for technical founders on the path to CEO.

Learn how to build and scale an enduring company from Ashu and leading founder-CEOs.

Ashu: It's clear that data has value, and it's also clear that data has gravity. You're both protecting data stores and are yourself a data store for sensitive customer data. Tell me, what is Skyflow's role in this new AI and token-factory economy?

Anshu: If you read the news recently, Spirit Airlines went bankrupt and tried to auction off their data. If I gave you all the email messages, all the Slack messages, all the databases, all the CRM records of Spirit Airlines, unless you're a madman, you don't just take that data and feed it into a model. There's so much personal information embedded in those internal CRM databases, ticketing systems, and conversations. So what does that mean? That data was getting sold for $10 million because people think they can extract value from it.

The first thing you have to do is make sure the data is correctly anonymized, but you can't just throw away the information either. If you removed everything, you'd be left with essentially a random conversation. So you have to keep the meaning — we call this "meaning preserving." You have to keep the entities intact — "entity preserving." You have to keep the privacy of the people involved — "privacy preserving." That transformation makes the new data you create from something like the Spirit Airlines database still 100% usable, but with 0% risk. That's the first job to be done.

Now you want to use these models, say, to send a request to book an airline ticket, because that's what AI chatbots do. Well, to do that, I can't really help you if I don't know who you're flying with, the names and ages of your kids and your wife, I need their dates of birth. And if I really want to book the flight for you, not just be a chatbot (gen one), but gen two, with computer use, now I'm touching your passport information, your credit card information: pretty much everything. And that's just to book a ticket, not even to plan a will or do a wire transfer. Just to plan a trip, I need all of that information.

So where Skyflow comes in: zero data retention has become a problem. Companies like Anthropic and OpenAI, for good reasons, have to say, "We can't be completely stateless, because if something terrible happens tomorrow, we have to be held accountable — so we're going to retain the data for some period of time." So you, as a consumer or an enterprise, like an airline, need a layer in place.

Just like Open Router helps you figure out which model to use at runtime for the cheapest option, Skyflow sits in the middle and helps you figure out what data should and shouldn't go to the models in plain text. In some ways, our job is simply to keep plain text out of the wrong hands, the wrong logs, and the wrong compute.

Once you do that and get your information back, the agent has to take action: maybe making an API call to Stripe, or sending a text message. Now, again, you have to enforce policies: should this agent really be able to use your credit card number versus your wife's? Should it be allowed to use a customer's corporate credit card? So controls have to be put in place. We call this "policy." All of this requires security controls, privacy controls, and policy controls, many of which have to operate at a global level, since you're talking about multinational companies.

You're an airline. You can't transmit someone's date of birth from India to Germany, or an American customer's Social Security number to someone in the Philippines. All of these laws and rules essentially come down to keeping plain text data out of certain regions, countries, models, agents, logs, traces, databases, data warehouses, Box, Salesforce, ServiceNow.

That air-traffic-control system, if you will, is Skyflow. We're the platform used by financial processing systems for the biggest banks in the world, all the way to Visa and Walmart. All of these companies are customers of Skyflow.

Ashu: So every agent call should ultimately be a call to a Skyflow server.

Anshu: It's funny, some people ask, "Are you in the token flow or not?" If you think about it mathematically, we may be in the token flow three to five times over: when the token gets created, we're in the flow; when the model generates logs, we're in the flow; when you make the call to the model, we're in the flow; when the response comes back, sometimes you have to anonymize that data; then the agent makes a call. So it's the same token, as it flows across systems again and again, passing through Skyflow each time.

Ashu: Got it. Anshu, I'm going to zoom out from Skyflow specifically and talk a bit about what's going on in the world of AI security. What's a common misconception people have about the security issues in AI?

Anshu: I think the first misconception is the word "security" itself. A lot of people, including our friend Nikesh Arora at Palo Alto Networks, and really every cybersecurity CEO, think of this as a security problem. In the old world, that was true: you had security companies, identity companies, log-management companies, database companies. That works when you have deterministic flows: you do one thing, and I can secure it, like a firewall for network traffic. But when the business process itself is evolving and changing because the agent and the model are non-deterministic — and that's just one model with one agent. Think about thousands of models and literally millions of agents running. You're talking about swarms. As that happens, you can't isolate the security problem down to one thing. What you have to do is invert the problem and ask: what do I need to do to have a secure, privacy-preserving, controllable infrastructure in place?

The control layer, which in the old days was meant to control whether employee A or employee B saw certain information; security meant whether a bad actor from outside got into your system; governance meant whether you could prove to auditors you did the right thing; sovereignty meant whether a government like Saudi Arabia's or India's would come and shut you down or ask for data. These questions are no longer independent. If everything is a non-deterministic flow of data, you have to think from the principle of how you secure the data at all times, and what securing data even means. Sometimes it means security, i.e., the bad guy can't get access to it. But 80% of the time, it means controlling it.

Ashu: So are you saying all security companies are dead in a world of AI, or merely irrelevant?

Anshu: Even before AI, cybersecurity was a failing industry. After AI, I think it's a failed industry.

Ashu: A failed industry with a couple of trillion dollars in market cap. I think Nikesh is doing pretty well at Palo Alto — 350 billion, last I saw.

Anshu: American healthcare is another such industry, where we spend more money every year with not that many more outcomes. Cybersecurity is as poorly run, as poorly implemented, and as wasteful as the American healthcare industry. And the answer is very simple: you need to think about the problem from a different perspective.

Ashu: Let's talk a little about that. You started Skyflow when machine learning was definitely a thing, but LLMs were still in their infancy, back in spring of 2020. As the environment around you has changed completely, you've had to make changes to the company, the product, and your go-to-market. Can you talk about that process?

Anshu: Our old problem statement was "sensitive data is a problem for enterprises." The new problem is "agents break data security." You have to align the company around the existential problem you're trying to solve. Why are you still relevant? Sometimes the answer is you're no longer relevant, in which case you should sell the company. The second question is: in this new world, what assets do we have that are still important and uniquely applicable, and what new things do we have to build?

In our case, we did a fabulous job with structured data, because that's where we started. But it turns out a lot of AI is about unstructured data. So we had to build a whole set of capabilities — engineering, product, sales, marketing — around understanding what it takes to protect data when tools like Glean and Claude are accessing PDFs inside your company.

That's the second change. The third thing you have to do is find a new ecosystem. What we did was reach out to all the companies active in the space and find early design partners and customers, learning to speak their language, so that by the time the market really matures, you've already fully transformed. I think those are the things that come to mind.

Ashu: That's super helpful, Anshu. As you pointed out, transforming the culture and employee base of the company is as important as product, technology, and strategy. And the culture question is even more important in a world where every company, in some shape or form, is competing with OpenAI and Anthropic for talent. Talk about how you think about culture at Skyflow.

Anshu: We've had a strong belief from the beginning that you can only build a great company if you're solving an important problem. What's important may be different for you, but whatever it is, you and the core leadership team truly have to believe that what you're doing matters. Second, you have to make sure people understand that what you're doing can lead to very large outcomes, and the only way your company achieves large outcomes is if it stays relevant in the new world.

Weirdly enough, the answer always comes back to the same question: what is the fundamental reason for your company to exist? That's always a great founding question, and when times change, you have to ask it anew. Then it comes down to practical steps. Step one: hiring. I'd even say it's 70% hiring and 30% firing, and everything else takes care of itself.

Ashu: That's true. I always remind myself that, as a leader, especially as a manager of managers, every problem is first and foremost a hiring or firing problem, and strategy and execution follow from that. But building on what you just said: given that you worked with one of the all-time great entrepreneurs, Marc Benioff, before starting any of the companies you've gone on to build so successfully, what did you learn from Marc, and what advice would you give founders about lessons worth carrying over?

Anshu: I think there are two lessons. One is the meta lesson: beginner's mind. Marc was essentially an understudy for Larry Ellison. He worked directly for him, one of the most successful executives ever. But when he started Salesforce, he did everything opposite of what Larry Ellison had done. You're supposed to charge a lot of money for software: Salesforce was $10 a user. You're supposed to sign multi-year deals: they sold software month to month. You're supposed to build something that runs on particular hardware and locks people in: you could cancel subscriptions monthly in those days. He broke all the rules and still succeeded.

I think that's the first lesson. In Zen Buddhism they say, "Read all the books, burn all the books." Reading the books is important, but burning them is sometimes the most important step. In practical terms, that means you can't say, "I'm going to become as successful as Marc Benioff, Sam Altman, or Elon Musk by doing what they did." Look at Elon Musk: each of his companies follows a completely different set of rules, and people get confused because he's not even trying to repeat his own rules. He's just trying to solve the problem at hand.

The second thing I learned from Marc is that the most important thing a company has is relevance and reputation. In the world we live in — and the world our customers are moving toward — are you relevant? If not, why would they talk to you? How do they know you're relevant? By your reputation. How do you create a reputation? Either by forecasting the future and branding products like CloudForce, or by earning customer trust. If you have customers' trust, you're showing them the direction of the future, and you're top of mind, then you'll have an engaged community of customers and partners you get to co-build the future with.

The reality is, go read the emails between Dario and his investors, and Sam Altman, and Elon Musk — nobody knows exactly where the world is going. But if you're in the right place at the right time, you get to figure it out, and you have to earn your place at the table. The way you earn that place, the way we've focused on at Skyflow, is by earning customers' trust. Second, you have to be relevant. And third is top of mind, which is marketing.

Ashu: Got it. I'm going to start to wrap up now — two final questions, Anshu. First: there's a lot of talk right now about "own your intelligence," moving to open weights, "proprietary data is your moat," and there's truth to all of those phrases, but also a lot of nuance. What's your take on the open-models debate, both from a "what should founders do" perspective and, more specifically, from a security and privacy perspective?

Anshu: We believe open weights are net good for the ecosystem, but they're not a panacea. Unlike open source, you can't tell how an open-weight model was actually created, or what went into it, or what's been modified. So open weights are good in that you can take the weights and do something interesting with them openly, but they're not the same as open source. That means two things.

One: you can't trust a model just because it's open weights. You have no idea where it came from or what rules have been embedded. I could easily train a model to wake up on September 17th, 2031, and start sending bank account information to a new IP address, and there's almost no way to pre-test for that. So open weight doesn't equal trust. If you're going to use open-weight models, we'll have to build a trust layer around them collectively, as an ecosystem. I think that's where the market is headed.

More broadly, the idea that we're going to run our businesses on Wikipedia-and-Reddit-trained models is fundamentally broken, and a lot of us could see that three to five years ago. We're going to have to train models on more realistic data and workloads. A model can't be trained on Reddit data and then suddenly know how to conduct a diagnostic study for a root canal. There's a specific set of data that has to go into that. So we're going to live through a new economy of data, through reinforcement learning and new techniques, and as a result it's a unique new world, not dominated by just one or two model companies.

Ashu: What do you think about open weights, especially in the context of China?

Anshu: If I call them Chinese models and ask you to run your insurance company or bank on them, how do you feel? Now, if I call the same thing an open-weight model, how do you feel? Turns out open-weight models are Chinese models in many cases, and Chinese models are open weights. Just by using a different word, you can completely change the buyer's preference and trust level. That's the power of words in marketing.

I believe we shouldn't be talking about open-weight versus closed-weight models, and we shouldn't be talking just about Chinese versus non-Chinese models. We should be talking about trusted models running in trusted environments, versus untrusted models running in untrusted environments. And the way to do that is through runtime controls across models, data, weights, and runtimes. I think that's where the industry will eventually land.

Ashu: So it's a race for trust.

Anshu: In a world where models are fungible and vaguely similar, the most important question becomes: who do I trust? Who do I trust with my data? Who do I trust to have the best model three years from now? Who do I trust to still be around in five years? The questions that used to be about "who has a one-trillion-parameter model versus a seven-trillion-parameter model" have become: which company do you trust to bet your life's personal data, or your enterprise's future, on?

Ashu: One last question. Anshu, as you've admitted a couple of times, you're truly a nerd — a technical founder who's learned marketing from one of the best in the business. What advice do you have for other technical, first-time founders thinking about starting a company?

Anshu: The first thing to learn is to respect the art of marketing. The word "marketing" itself carries such negative connotations. People say, "This person is too salesy," and when they say that, they typically mean bad marketing and bad sales. Because the best sales and marketing, as you know, Ashu, doesn't feel like sales or marketing, it feels like sharing knowledge, sharing what you've learned. So: learn to respect the art of finding customers by learning from the greats, and treat it as one of the most important functions of the company.

Ashu: Anshu, thank you so much for joining us on B2B as CEO. This has been such a fun conversation, and ultimately it seems like the best AI apps will all be using Skyflow.

Anshu: They will be — or they'll lack trust.

Ashu: Once again, thank you so much.

Posted

0 MIN READ

Show Outline

AI raises the stakes for security. Protecting data privacy against other humans or predictable software is one thing; with non-deterministic agents in the mix, the challenge grows exponentially.

Anshu Sharma, founder and CEO of Skyflow, joins me to talk about securing sensitive customer data across data stores, models, and agents, as well as some of his biggest lessons as a three-time founder. 

Today, raw enterprise data can't simply be fed into a model: it's full of personal information that has to be transformed so it protects privacy while preserving meaning. Skyflow controls what data reaches a model, enforces policy on what an agent is allowed to do with it, and manages data sovereignty across borders.

Anshu has been chasing this problem for over two decades.

At Salesforce, he had to convince early enterprise customers like JPMorgan and Cisco to trust the cloud with their most sensitive data; work that led him to help build Salesforce's identity and app-exchange infrastructure from scratch. 

That same trust problem kept resurfacing across two more startups before he founded Skyflow in 2019. “At some point you realize, you know what? There's probably a $100B company to be built just protecting the most sensitive data for customers at all these companies,” he explains.

As a founder, Anshu draws lessons from leaders like Marc Benioff, noting the way companies position themselves against rivals and partners can shape their success in the market. He also argues that enduring companies start with a meaningful problem and leaders who can build a culture around the shared mission to solve it.

We close with his advice for technical founders: learn to respect marketing as a craft. The best sales and marketing comes from understanding your audience so well that it doesn’t feel like sales or marketing at all.

What we covered:

  • 0:00 – Cold open: Anshu on the biggest misconception in AI security

  • 1:00 – What Skyflow does

  • 2:35 – Why AI agents raise the stakes on data privacy

  • 3:55 – Anshu’s story: from Salesforce to Skyflow

  • 8:05 – How AI is reshaping SaaS and infrastructure

  • 10:44 – Skyflow's role in the token economy

  • 15:59 – The biggest misconception about AI security

  • 18:22 – Is cybersecurity a failed industry?

  • 19:08 – How Skyflow's product and go-to-market evolved with the AI shift

  • 20:57 – Building culture in a company competing with OpenAI and Anthropic for talent

  • 22:40 – Lessons from Marc Benioff: beginner's mind and breaking the rules

  • 26:12 – The open-weights debate: trust vs. transparency

  • 30:16 – Advice for technical founders: respect the art of marketing

  • 31:18 – Closing thoughts

Read the transcript:

Ashu: What's a common misconception people have about the security issues in AI?

Anshu: The first misconception is the word "security." Think about thousands of models and literally millions of agents running. None of the security, none of the privacy systems, none of our platforms were built around this idea that an arbitrary model or agent can do things that we can't predict, because the agent and the model are non-deterministic. You can't actually isolate the security problems down to one thing. What you have to do is invert the problem and say: what do I need to do to have a secure, privacy-preserving, controllable infrastructure in place? At some point you realize, you know what? There's probably a $100 billion company to be built just protecting the most sensitive data for customers, from two-person startups all the way to Fortune 10 companies.

Ashu: We're here today with Anshu Sharma, the founder and CEO of Skyflow. Skyflow is an AI security company that is focused on securing sensitive customer data across data stores, models, and agents. Welcome to the B2BaCEO podcast, Anshu. It's good to have you today.

Anshu: Great to be on the cast.

Ashu: Well, why don't you tell us a little bit about what Skyflow does and why it matters?

Anshu: Skyflow is built on a very simple premise, which is that when we go about our day-to-day lives, we have no choice but to give our personal information to the governments we interact with. If you've tried filing taxes, you give them Social Security numbers, addresses.

Even a coffee company — if you go to Starbucks, they know more about your location, have multiple credit and debit cards on you, know where you travel, where you live half the time. As a result, we live in a society where customers are constantly sharing information with these companies, and that forms the foundation of our society.

Now, with AI, this just goes to the next level, and none of this will work if we can't trust the entities we're sharing this information with. So how can I trust my personal information with the AI chatbot, with the hardware device in your ear, or the bank, if I can't be sure that information isn't going to end up in the wrong hands — inside their company, outside their company, or frankly, be sold on the internet?

So that's the problem we set out to solve, and we solve it with our platform.

Ashu: Makes sense. And that problem has always been true, as you rightly said, as long as there have been business relationships between consumers and enterprise, especially with the internet. But with agents, the problem has become 10x more.

I was talking to one of my partners, and she was telling me how she's given an AI assistant access to her bank accounts so that it can wire money to her landlord every month. And I was like, "Oh my God."

Anshu: Every time we delegate an important task to another person, another business entity, or an agent, we're essentially trusting them with both information and workflow, and that cannot be done without deterministic controls.

We live in a world where agents and models are non-deterministic, which means they can arbitrarily do random things sometimes. And if we want to use those things, we must have very, very deterministic, fine-grained controls in place. And none of the security, none of the privacy systems, none of our platforms were built around this idea that an arbitrary model or agent can do things we can't predict.

So we must somehow secure this information without the systems being deterministic. And that's a hard, fun problem to have, and that's what all of us are trying to build.

Ashu: And you've been working on this problem for many years. You started Skyflow six, seven years ago now; you and I were brainstorming the idea for several years before that, and you worked on products in the same general zip code for many years before that. Tell us a little bit about the founding story.

Anshu: If you actually think through the founding story, it has two or three points of pivot. One is when I was at Salesforce — people don't remember this, but most of Salesforce's early customers were actually small companies willing to trust the cloud.

My first problem was, okay, how do I convince the JPMorgan Chases and Ciscos of the world to give us their most important data? Turns out it's a trust problem. So we essentially had to rewrite a lot of Salesforce's data stack, security stack, identity stack. We had to literally invent things like the ability to log into one application through another application — that's called an app store, or app exchange. We were the first company in the world to do that. So things like that had to be solved from first principles. And as I was solving them, I would go talk to these customers and say, "Hey, you're asking me to jump through all these hoops before you give me your data. What exactly are you doing to protect the data inside your company?" And they'd say, "Don't worry about it, it's all secured in a data center, because I have a building." Two things happened: the building disappeared because they all moved to the cloud, and the building was never really a data protection layer to begin with.

So I left Salesforce. I started a couple of other companies — one in email/AI security, another in healthcare AI. (We could spend a whole hour just on healthcare and AI.) But as I was doing those things, the same questions kept coming up: how do you convince the world's largest health system to give you their patients' data? I had to tell them we'd make sure it was secure and safe. Through that process, I kept bumping into the same problem again and again, and at some point you realize: there's probably a $100 billion company to be built just protecting the most sensitive data for customers, from two-person startups all the way to Fortune 10 companies.

Ashu: I think it was spring of 2020 — a little over six years ago — when we ended up leading your seed round. As we were talking, I was reminded of a conversation we had leading up to that seed round, where you told me the story of your early days at Salesforce, when you worked with Marc and with VMware to create the first co-branded product for Salesforce, which was VMforce. How does it feel today, now that they've launched CloudForce?

Anshu: It was completely déjà vu for me. As you know, Marc is a marketing genius. When I initiated the idea of building a cloud platform together, one that could run any arbitrary programming language, between VMware and Salesforce,we just thought it would be called something like Java Cloud, Internet Cloud, or Programming Cloud.

Marc said, "No, if you're going to be peer-positioned with VMware, it should be called VMforce." Marc has a very true, innate sense of when to peer-position against another company. At that time, VMware was about our size, maybe even slightly bigger. Today, Anthropic is, by most measures, maybe two to five times larger in market value, and peer-positioning against — or with — Anthropic is beneficial to both entities.

Marc has three phases for companies: companies he ignores and never talks about; companies ten times his size, which he peer-positions against; and companies three to ten times larger, which he picks as his enemy. For a long time, that was SAP, and then Microsoft, for Salesforce. I don't know who the new enemy is, but we all know the new partner is Anthropic.

Ashu: CloudForce definitely caught the market's attention, especially the public markets. We've seen how Salesforce stock reacted. But what's the broader trend you see in the AI landscape, especially at the intersection of infrastructure, applications, and models?

Anshu: There's a famous quote: "I know the answer, but what is the question?" If you think about CloudForce, that's the answer, but what's the question? I think that's where Marc's true genius is. The question is all the questions everybody has about SaaS companies: are they still relevant? Can they transition to AI? Will AI companies compete directly with them? Will AI kill them? All of those questions are floating around, and then, pop, comes a one-word answer: CloudForce. It doesn't come with a written letter of intent saying those things won't happen, but sometimes a one-word answer answers all the questions. So I think that's what's going on. SaaS companies, and the broader market, are figuring out that we now have a new category of technology.

We tend to think of model companies as technology companies, but I think that's a mistake, because they're unlike everything else. The biggest thing is that they're inherently stateless, and that creates a lot of questions and challenges in the broader market. Everybody's trying to figure out which layers are sticky and which aren't, and collectively the market is trying to figure out what a stable equilibrium looks like.

So the market dynamics are changing. What we're seeing on the other side is what I call the new "token factory": how does the data — the conversations you and I are having — get turned into knowledge, which turns into models? Models process tokens at runtime. Those tokens generate traces or logs, which then become tokens fed back into reinforcement learning—

Ashu: —which creates the context graph.

Anshu: —which creates a context graph, and then you fine-tune it further, and so on. In that "water cycle" of tokens, how do companies like Salesforce, ServiceNow, Databricks, and Snowflake play a role? How do they evolve? I think that's an open question for those big companies, and for all infrastructure and data companies.

Insights for technical founders on the path to CEO.

Learn how to build and scale an enduring company from Ashu and leading founder-CEOs.

Ashu: It's clear that data has value, and it's also clear that data has gravity. You're both protecting data stores and are yourself a data store for sensitive customer data. Tell me, what is Skyflow's role in this new AI and token-factory economy?

Anshu: If you read the news recently, Spirit Airlines went bankrupt and tried to auction off their data. If I gave you all the email messages, all the Slack messages, all the databases, all the CRM records of Spirit Airlines, unless you're a madman, you don't just take that data and feed it into a model. There's so much personal information embedded in those internal CRM databases, ticketing systems, and conversations. So what does that mean? That data was getting sold for $10 million because people think they can extract value from it.

The first thing you have to do is make sure the data is correctly anonymized, but you can't just throw away the information either. If you removed everything, you'd be left with essentially a random conversation. So you have to keep the meaning — we call this "meaning preserving." You have to keep the entities intact — "entity preserving." You have to keep the privacy of the people involved — "privacy preserving." That transformation makes the new data you create from something like the Spirit Airlines database still 100% usable, but with 0% risk. That's the first job to be done.

Now you want to use these models, say, to send a request to book an airline ticket, because that's what AI chatbots do. Well, to do that, I can't really help you if I don't know who you're flying with, the names and ages of your kids and your wife, I need their dates of birth. And if I really want to book the flight for you, not just be a chatbot (gen one), but gen two, with computer use, now I'm touching your passport information, your credit card information: pretty much everything. And that's just to book a ticket, not even to plan a will or do a wire transfer. Just to plan a trip, I need all of that information.

So where Skyflow comes in: zero data retention has become a problem. Companies like Anthropic and OpenAI, for good reasons, have to say, "We can't be completely stateless, because if something terrible happens tomorrow, we have to be held accountable — so we're going to retain the data for some period of time." So you, as a consumer or an enterprise, like an airline, need a layer in place.

Just like Open Router helps you figure out which model to use at runtime for the cheapest option, Skyflow sits in the middle and helps you figure out what data should and shouldn't go to the models in plain text. In some ways, our job is simply to keep plain text out of the wrong hands, the wrong logs, and the wrong compute.

Once you do that and get your information back, the agent has to take action: maybe making an API call to Stripe, or sending a text message. Now, again, you have to enforce policies: should this agent really be able to use your credit card number versus your wife's? Should it be allowed to use a customer's corporate credit card? So controls have to be put in place. We call this "policy." All of this requires security controls, privacy controls, and policy controls, many of which have to operate at a global level, since you're talking about multinational companies.

You're an airline. You can't transmit someone's date of birth from India to Germany, or an American customer's Social Security number to someone in the Philippines. All of these laws and rules essentially come down to keeping plain text data out of certain regions, countries, models, agents, logs, traces, databases, data warehouses, Box, Salesforce, ServiceNow.

That air-traffic-control system, if you will, is Skyflow. We're the platform used by financial processing systems for the biggest banks in the world, all the way to Visa and Walmart. All of these companies are customers of Skyflow.

Ashu: So every agent call should ultimately be a call to a Skyflow server.

Anshu: It's funny, some people ask, "Are you in the token flow or not?" If you think about it mathematically, we may be in the token flow three to five times over: when the token gets created, we're in the flow; when the model generates logs, we're in the flow; when you make the call to the model, we're in the flow; when the response comes back, sometimes you have to anonymize that data; then the agent makes a call. So it's the same token, as it flows across systems again and again, passing through Skyflow each time.

Ashu: Got it. Anshu, I'm going to zoom out from Skyflow specifically and talk a bit about what's going on in the world of AI security. What's a common misconception people have about the security issues in AI?

Anshu: I think the first misconception is the word "security" itself. A lot of people, including our friend Nikesh Arora at Palo Alto Networks, and really every cybersecurity CEO, think of this as a security problem. In the old world, that was true: you had security companies, identity companies, log-management companies, database companies. That works when you have deterministic flows: you do one thing, and I can secure it, like a firewall for network traffic. But when the business process itself is evolving and changing because the agent and the model are non-deterministic — and that's just one model with one agent. Think about thousands of models and literally millions of agents running. You're talking about swarms. As that happens, you can't isolate the security problem down to one thing. What you have to do is invert the problem and ask: what do I need to do to have a secure, privacy-preserving, controllable infrastructure in place?

The control layer, which in the old days was meant to control whether employee A or employee B saw certain information; security meant whether a bad actor from outside got into your system; governance meant whether you could prove to auditors you did the right thing; sovereignty meant whether a government like Saudi Arabia's or India's would come and shut you down or ask for data. These questions are no longer independent. If everything is a non-deterministic flow of data, you have to think from the principle of how you secure the data at all times, and what securing data even means. Sometimes it means security, i.e., the bad guy can't get access to it. But 80% of the time, it means controlling it.

Ashu: So are you saying all security companies are dead in a world of AI, or merely irrelevant?

Anshu: Even before AI, cybersecurity was a failing industry. After AI, I think it's a failed industry.

Ashu: A failed industry with a couple of trillion dollars in market cap. I think Nikesh is doing pretty well at Palo Alto — 350 billion, last I saw.

Anshu: American healthcare is another such industry, where we spend more money every year with not that many more outcomes. Cybersecurity is as poorly run, as poorly implemented, and as wasteful as the American healthcare industry. And the answer is very simple: you need to think about the problem from a different perspective.

Ashu: Let's talk a little about that. You started Skyflow when machine learning was definitely a thing, but LLMs were still in their infancy, back in spring of 2020. As the environment around you has changed completely, you've had to make changes to the company, the product, and your go-to-market. Can you talk about that process?

Anshu: Our old problem statement was "sensitive data is a problem for enterprises." The new problem is "agents break data security." You have to align the company around the existential problem you're trying to solve. Why are you still relevant? Sometimes the answer is you're no longer relevant, in which case you should sell the company. The second question is: in this new world, what assets do we have that are still important and uniquely applicable, and what new things do we have to build?

In our case, we did a fabulous job with structured data, because that's where we started. But it turns out a lot of AI is about unstructured data. So we had to build a whole set of capabilities — engineering, product, sales, marketing — around understanding what it takes to protect data when tools like Glean and Claude are accessing PDFs inside your company.

That's the second change. The third thing you have to do is find a new ecosystem. What we did was reach out to all the companies active in the space and find early design partners and customers, learning to speak their language, so that by the time the market really matures, you've already fully transformed. I think those are the things that come to mind.

Ashu: That's super helpful, Anshu. As you pointed out, transforming the culture and employee base of the company is as important as product, technology, and strategy. And the culture question is even more important in a world where every company, in some shape or form, is competing with OpenAI and Anthropic for talent. Talk about how you think about culture at Skyflow.

Anshu: We've had a strong belief from the beginning that you can only build a great company if you're solving an important problem. What's important may be different for you, but whatever it is, you and the core leadership team truly have to believe that what you're doing matters. Second, you have to make sure people understand that what you're doing can lead to very large outcomes, and the only way your company achieves large outcomes is if it stays relevant in the new world.

Weirdly enough, the answer always comes back to the same question: what is the fundamental reason for your company to exist? That's always a great founding question, and when times change, you have to ask it anew. Then it comes down to practical steps. Step one: hiring. I'd even say it's 70% hiring and 30% firing, and everything else takes care of itself.

Ashu: That's true. I always remind myself that, as a leader, especially as a manager of managers, every problem is first and foremost a hiring or firing problem, and strategy and execution follow from that. But building on what you just said: given that you worked with one of the all-time great entrepreneurs, Marc Benioff, before starting any of the companies you've gone on to build so successfully, what did you learn from Marc, and what advice would you give founders about lessons worth carrying over?

Anshu: I think there are two lessons. One is the meta lesson: beginner's mind. Marc was essentially an understudy for Larry Ellison. He worked directly for him, one of the most successful executives ever. But when he started Salesforce, he did everything opposite of what Larry Ellison had done. You're supposed to charge a lot of money for software: Salesforce was $10 a user. You're supposed to sign multi-year deals: they sold software month to month. You're supposed to build something that runs on particular hardware and locks people in: you could cancel subscriptions monthly in those days. He broke all the rules and still succeeded.

I think that's the first lesson. In Zen Buddhism they say, "Read all the books, burn all the books." Reading the books is important, but burning them is sometimes the most important step. In practical terms, that means you can't say, "I'm going to become as successful as Marc Benioff, Sam Altman, or Elon Musk by doing what they did." Look at Elon Musk: each of his companies follows a completely different set of rules, and people get confused because he's not even trying to repeat his own rules. He's just trying to solve the problem at hand.

The second thing I learned from Marc is that the most important thing a company has is relevance and reputation. In the world we live in — and the world our customers are moving toward — are you relevant? If not, why would they talk to you? How do they know you're relevant? By your reputation. How do you create a reputation? Either by forecasting the future and branding products like CloudForce, or by earning customer trust. If you have customers' trust, you're showing them the direction of the future, and you're top of mind, then you'll have an engaged community of customers and partners you get to co-build the future with.

The reality is, go read the emails between Dario and his investors, and Sam Altman, and Elon Musk — nobody knows exactly where the world is going. But if you're in the right place at the right time, you get to figure it out, and you have to earn your place at the table. The way you earn that place, the way we've focused on at Skyflow, is by earning customers' trust. Second, you have to be relevant. And third is top of mind, which is marketing.

Ashu: Got it. I'm going to start to wrap up now — two final questions, Anshu. First: there's a lot of talk right now about "own your intelligence," moving to open weights, "proprietary data is your moat," and there's truth to all of those phrases, but also a lot of nuance. What's your take on the open-models debate, both from a "what should founders do" perspective and, more specifically, from a security and privacy perspective?

Anshu: We believe open weights are net good for the ecosystem, but they're not a panacea. Unlike open source, you can't tell how an open-weight model was actually created, or what went into it, or what's been modified. So open weights are good in that you can take the weights and do something interesting with them openly, but they're not the same as open source. That means two things.

One: you can't trust a model just because it's open weights. You have no idea where it came from or what rules have been embedded. I could easily train a model to wake up on September 17th, 2031, and start sending bank account information to a new IP address, and there's almost no way to pre-test for that. So open weight doesn't equal trust. If you're going to use open-weight models, we'll have to build a trust layer around them collectively, as an ecosystem. I think that's where the market is headed.

More broadly, the idea that we're going to run our businesses on Wikipedia-and-Reddit-trained models is fundamentally broken, and a lot of us could see that three to five years ago. We're going to have to train models on more realistic data and workloads. A model can't be trained on Reddit data and then suddenly know how to conduct a diagnostic study for a root canal. There's a specific set of data that has to go into that. So we're going to live through a new economy of data, through reinforcement learning and new techniques, and as a result it's a unique new world, not dominated by just one or two model companies.

Ashu: What do you think about open weights, especially in the context of China?

Anshu: If I call them Chinese models and ask you to run your insurance company or bank on them, how do you feel? Now, if I call the same thing an open-weight model, how do you feel? Turns out open-weight models are Chinese models in many cases, and Chinese models are open weights. Just by using a different word, you can completely change the buyer's preference and trust level. That's the power of words in marketing.

I believe we shouldn't be talking about open-weight versus closed-weight models, and we shouldn't be talking just about Chinese versus non-Chinese models. We should be talking about trusted models running in trusted environments, versus untrusted models running in untrusted environments. And the way to do that is through runtime controls across models, data, weights, and runtimes. I think that's where the industry will eventually land.

Ashu: So it's a race for trust.

Anshu: In a world where models are fungible and vaguely similar, the most important question becomes: who do I trust? Who do I trust with my data? Who do I trust to have the best model three years from now? Who do I trust to still be around in five years? The questions that used to be about "who has a one-trillion-parameter model versus a seven-trillion-parameter model" have become: which company do you trust to bet your life's personal data, or your enterprise's future, on?

Ashu: One last question. Anshu, as you've admitted a couple of times, you're truly a nerd — a technical founder who's learned marketing from one of the best in the business. What advice do you have for other technical, first-time founders thinking about starting a company?

Anshu: The first thing to learn is to respect the art of marketing. The word "marketing" itself carries such negative connotations. People say, "This person is too salesy," and when they say that, they typically mean bad marketing and bad sales. Because the best sales and marketing, as you know, Ashu, doesn't feel like sales or marketing, it feels like sharing knowledge, sharing what you've learned. So: learn to respect the art of finding customers by learning from the greats, and treat it as one of the most important functions of the company.

Ashu: Anshu, thank you so much for joining us on B2B as CEO. This has been such a fun conversation, and ultimately it seems like the best AI apps will all be using Skyflow.

Anshu: They will be — or they'll lack trust.

Ashu: Once again, thank you so much.

Get insights directly to your inbox.

Subscribe to The Foundation for our thinking on what comes next, firsthand lessons from our founders, and guidance on building from day zero.

Subscribe to The Foundation for our thinking on what comes next, firsthand lessons from our founders, and guidance on building from day zero.