Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Anshu Sharma, Skyflow

Transcript

All right, here we are, another episode of Breaking Changes. My name is Kin Lane. I’m your host of Breaking Changes. I’m also the chief evangelist of Postman, and I run our open technologies program, which focuses on open APIs, AsyncAPI, JSON Schema, and the standards and tooling that are built around those API specifications. For Breaking Changes, what we’re trying to accomplish is to reach business leadership and help make them more aware of the importance of APIs and how they can help you be more competitive, be more agile, and achieve the velocity that you’re looking for across your teams.

So I’m always reaching out, looking for folks on LinkedIn, on Twitter, everywhere I can, who are doing interesting things at startups all the way up to large enterprises and government agencies. Today I was playing around on LinkedIn looking for some interesting stories, and I came across Anshu Sharma, who is the CEO of Skyflow. They’re focused on data privacy and sensitive data, which is an important topic today with the value and importance of data. We’ll dive in and I’ll let Anshu talk more about it specifically. But welcome, welcome to Breaking Changes.

Thank you, Kin. I’m really glad to be here. I didn’t expect in my lifetime there’d be a business podcast focused on APIs. But it’s kind of like 2010, when everybody figured out what an app was, and I had this slogan on my homepage everywhere which said, “Your company is an app now.” I think we’re about to hit a stage where you can replace that word by saying your company is an API now. And the punchline is, if you don’t build that API, someone else will.

Yes, I like that. I so agree, and I want to get to the point with APIs where it’s like apps, where I shouldn’t be an API evangelist or anything API focused. It’s just part of doing business. It’s in our DNA. That’s really a big part of the show, to help leadership understand that APIs aren’t the next vendor solution or the next trend. It’s just the next iteration of the web. We went from web to mobile. APIs are just about that multi-channel approach. So let’s start with the basics. I like to start with the basics. What is Skyflow?

Skyflow is a very simple idea. Lots of companies every day have data breaches, and you find out, oh, they didn’t know how to protect my social security number. They didn’t know how to protect my credit card number. And you always ask the question, why is it so hard? The answer is, it’s hard because that’s not their job. Just like if you kept gold at home, it’d be very difficult to protect it all the time. That’s why we have banks. We basically built a data vault as a service where you can store, protect, and still use all of your sensitive data without it ever getting decrypted. It’s kind of amazing that nobody had built it. We just decided there should be such a thing. And here we are two and a half years later, and we just love what we’re doing.

I like it. My next question that I have written on the list here is pretty basic, and I feel silly asking it, but why do we need an API for privacy? How do APIs help us out with privacy?

Sure. Again, as you said earlier, API is just a word. I think what it means to us is that someone who’s building an application, whether it’s a stockbroker application or an order-your-food application or a bank application, frankly anything that has to do with user data, shouldn’t have to worry about user data. You have all of these requirements these days, starting out with privacy, which is not just the compliant thing to do but also the right thing to do. Then there are laws like data residency laws and compliance laws. I’m just trying to build my app so you can send me a package or let me use a doctor online. I’m not an expert in figuring out how HIPAA decides what data should be encrypted and not encrypted. How does PCI decide what credit card numbers I can show or not show? So we’re like, look, it should be as easy as Twilio or Stripe. Just give us an API call, and we will take that sensitive data field and give you a token back, and you can just reference this token going forward and you don’t have to worry about compliance, security, and privacy, because we take care of it.

We are a team of 50-plus people now. Most startups you go to, you’ll see half and half sales and marketing. We had 40 engineers before we hired our first salesperson. It’s just a hard problem. Everybody understands the problem, and nobody has a team of 40 people working on it. I jokingly always say, I don’t care who you are in this world, it’s pretty insane for a CTO to say I’m going to put 40 people on encrypting social security numbers. It just doesn’t make any business sense. But the beauty of the API world we are building together is essentially it’s a specialization world. Since this is a business podcast, I’ll drop a name, Clayton Christensen. He wrote a book before he died, among many other famous ones, called Jobs to Be Done. If you read the Jobs to Be Done book, it basically says we should view the world not from the perspective of functionality. Nike is not a shoe sole company or a plastics company or a rubber company. The job to be done is really running. So in a similar way, the job to be done is data security, protection, and compliance, and you shouldn’t have to worry about it. With a simple API interface, we take care of everything in the background. That’s basically what Skyflow does and how we built it.

So I, as an application developer, my specialty is building a specific type of mobile application. I know my users, I know my market fit, but I can rely on the Stripe API to abstract away all the payments and stuff. I don’t have to get to know the payments industry. I can use Twilio to abstract away all the SMS and telephony, the whole phone industry. I don’t have to be an expert there. And Skyflow allows me to not have to build my own security vault, understand encryption, understand all of this. I abstract that away, and it’s not just the technology. It’s, as you said, the people, the company behind it, the entire Skyflow business.

Yeah. I always jokingly said software as a service is 10% about software and 90% about as a service. If you think about it, API basically means as a service. And the job to be done here, back to Clayton, is to meaningfully understand that our job that we’re doing for our customers is to protect, govern, but also make it available for use. Anybody can take your social security number and put it in a vault and not give it back to you, but it’s useless. And that’s what people do. They encrypt the data at rest and then they decrypt it when they need it. Well, that defeats the whole purpose. There are modern breakthroughs that have happened in cryptography and other technologies over the last 10 to 20 years where we can do something called zero-knowledge proofs, something called homomorphic encryption, something called confidential computing. Again, these are just technologies that you don’t need to know, just like you don’t know what a PSTN network is. Someone at Twilio does. You don’t need to know what a PBX is, someone at Twilio does. So you don’t need to understand the difference between confidential computing, key rotation, key management, homomorphic encryption, order-preserving encryption. We do all of that behind a clean, simple API. All you’re doing is, “Hey, here’s my social security number, keep it and let me run identity verification against it. Here’s my phone number, help me secure it and let me run analytics on area code.”

That really was our insight, and it’s frankly an idea that I did not come up with myself. It was a problem that I saw our customers face when I was an EVP at Salesforce. I was like, “Who’s doing this?” And we found out that companies like Netflix and Apple and Google and Goldman Sachs, they all isolate their most sensitive data. That’s why you don’t see them on the front page of the newspaper as much as you see Target and Equifax. So there’s a pattern here that the leading technology companies were adopting by themselves, but that tech and that knowledge was not available, and was definitely not available as a product and a service.

So why did it become a priority? Why did security become such a priority for these leaders that they realized they need to invest in that vault technology on their own, versus why aren’t other leaders investing at that level, would you say?

There’s a longer answer, but I’ll start with the shortest answer: $5 billion. Facebook got fined $5 billion three years ago. That fine was actually going to be $20 billion. They negotiated it down, using tons of friends and lobbies they have, down to $5 billion. That pretty much told business leaders, it’s not some compliance checkbox thing that’s going on. Then we hauled all the CEOs of leading tech companies in front of the congressmen, senators. Then the EU passed all these laws like GDPR and data residency. And then India and Australia passed their own laws. Essentially what happened was, for about 20 years, we were telling a lie. The technology-enabled companies were essentially telling a lie to consumers. The big lie was, “For me to sell you shoes, I need to know your date of birth. For me to sell you slightly better prescription glasses, I need to know your entire medical history.” Intuitively we all knew, like, something is off. And it’s even worse when that knowledge of my prescription glass background, which contains my entire medical record for some reason, also ends up resulting in me seeing ads for cancer therapy when I go to a search engine.

I think what happened was people bought into the lie because we were told there is a trade-off here. Give up your privacy because you want personalization. Give up your privacy because you want to buy things online. And I think people just revolted at some point, saying this is too big of a trade-off. The government started cracking down. The market response was to try and sort of salvage this. Our response was to start this company and say, look, the fundamental lie that you need to know everything about me at all times to service me is just a lie. It’s a false dichotomy. You don’t have to choose. You can actually do my taxes in their entirety without knowing my social security number. If you’re an online tax company, you don’t need my SSN. You’re just filling up a form. Once the form is filled and you need to send it to the IRS, you could pick up the social security number on the route and send it to the IRS. You can do that using encryption, tokenization, homomorphic encryption, and all kinds of techniques. If you think about it, it’s very intuitive. If you went to a tax preparer, you’d say, “Why don’t you fill up the form for me and I will add my social security number to it and mail it myself.” It’s the same thing.

So there’s a core idea here, which is very simple. You can do things for me without knowing everything about me. The simplest way to think about it is you walk into a 7-Eleven store and you ask for a pack of cigarettes. I don’t need to know your date of birth to know whether you’re 21. You can actually just tell me that you’re above 21, and I can guess based on your age. Worst case scenario, I need to know the year of your birth. But in the paper-based world we live in, I can’t prove my date of birth without showing you my entire date of birth. That’s where technology is wonderful. I can actually create data masking and just show you the year. I can go one step further and sign a certificate that authorizes you to sell me cigarettes or whatever it is, because someone else has asserted that this guy is above 21, or that my doctor has signed this prescription. You don’t need to know my doctor’s license ID number and date of birth to know that they’re a doctor. We’ve used these technologies in other areas like DNS, and almost all of the internet works on all of this tech. But again, it was convenient, easy, and very, very profitable to have this big lie that I need to know everything to customize your homepage.

I think what we can do together as a technology industry is basically break through this lie. It’s not just Skyflow, there’s a whole bunch of companies that are trying to do this. There’s a search engine company called Neeva that’s trying to do search without knowing who you are. There are other companies that are trying to do identity that’s on your phone only. A lot of stuff Apple has done over the years on not storing your credit card number, for example. They don’t store your credit card number. Apple is the only payment processor that doesn’t actually store your credit card number. They store it on your phone in a secure enclave. Basically, it’s an on-phone encrypted vault. We’ve taken basically the same concept and moved it to the cloud for everybody else.

So the way we’re talking about APIs is, Twilio allows us to abstract away all the complexities of the telco. Stripe, same with payments. Skyflow, privacy and security. That allows us as app developers to do one thing, do what we do best. Is that one value we’re adding by giving end users this app? But you kind of just painted another dimension to that, that we can ensure those developers are only doing the thing they say they’re building that for. I shouldn’t be able to say, “Oh, I’m selling you eyeglasses or doing an eye exam by your iPhone,” and then get your social security number and get your entire medical history. So it actually has a potential to keep app developers honest. And when they do need access to a portion of your medical history, that can be tokenized, that can have a granular level of approach, and they can have access to what they need to make a decision or pass it along, but nothing more. So it’s an API-driven, a whole other kind of dimension to specialization, but just for security and privacy.

Yes. So privacy is one aspect of it, and you can’t really buy privacy. You can’t buy attributes. So privacy, we think, is our number one value. Security is number two value. And as I said, you have to break the false dichotomy. You can’t just have privacy and security. Usability, the ability to share data, not just within your application or within your company. Recently, when COVID-19 happened last year, our company was literally just getting launched. We got a phone call from the Department of Health and Human Services that basically manages this data around COVID-19. They had a fundamental problem. They were not able to convince the testing labs, the employers, the people who are testing; they didn’t want to share the data because of security and privacy concerns. Some of them didn’t want to share it because they wanted to profit off of it. And unlike governments in other countries where they have a single payer, single vendor kind of a thing, in the US you can’t just declare, “Hey, everybody’s data goes to a single database.”

So we participated in the Department of Health and Human Services program to enable sharing that’s granular. You could run a test on Kin for COVID-19 and then share the information as he’s boarding a cruise without revealing who Kin is. We can make an assertion that 100% of people have a negative result, so they’re all good. Or I can say seven of your employees have tested positive. You as employer don’t need to know who. Would you like to notify their health provider so they can get in touch with them and ask them not to go to work? Again, separation of concerns. It’s a very old principle in the world of service-oriented architecture and APIs, and you can apply that mindset to our data. So what we were able to do was build a COVID-19 solution on which people built some of these COVID-19 vaccine passports and data sharing applications. But the core of it is the same. Secure the data, ensure privacy, ensure data protection, ensure it’s stored in the right country in the right geo at the right time, make sure only the right people can see the right parts of the data, and then make sure that the right people get the assertions or workflows get the assertions from it.

All of that has to be done in a consolidated way. You can’t have one application platform that takes care of access control, another that takes care of data masking, because the rule has to be applied. When Kin logs in to an application as a customer support representative, there are certain rights and privileges and responsibilities that come with it. Skyflow enforces all of that. So behind the scenes, we are a data governance engine, a policy engine. Again, it sounds fancy, but it’s very simple. You’re basically building a database layer with a governance engine that enforces the rule when you call that API.

So it’s much more than just PII versus non-PII data. You could get very granular and create specific domains of any type of data and really enforce and govern to ensure that only that slice of data is being applied or not. And people don’t actually have to ever have access to the PII or non-PII data.

Yeah. There’s a program that one of the car ride-sharing companies wanted to do with one of the leading hospitals, saying, “Hey, if you’re old or if you don’t have enough money, if you want to show up for immunization like the COVID-19 vaccine or for a regular checkup, a lot of old people don’t show up because they don’t really know how to call Uber and Lyft.” Now, the problem is, an insurance company like Anthem or an employer like Walmart can’t just give their employee database to Uber or Lyft. That would be an invasion of privacy. Now imagine I could actually do a join across these data sets in a privacy-preserving manner, and you get a text saying, “Hey, your employer has authorized a free ride for a vaccine shot.” Neither the employer knows that the text went to you, nor does Uber really know until you accept and say yes. So you can actually enable some amazing workflows across companies, across supply chain, across collaboration boundaries that look like magic.

And we know this in our personal lives. Forget that cross-company collaboration. A few years ago, if my girlfriend called Uber, the Uber driver could basically harass her later. Then Uber spent a few years actually solving that problem and they wrote papers about it. All they were doing was privacy-preserving reporting. They basically added a layer of redirection, anonymization, tokenization to the phone number, so that when you call them now, your phone number is not displayed. It’s just a pointer to a pointer, in our API language. And it shouldn’t take Uber two years and dozens of engineers and papers and articles to basically implement something simple like that. If you build that today, you could get that done in one day using Skyflow.

So the incentive models for this. You admitted, and you and I both know, it’s a lot of money to be made off of the backdoor partnerships to a lot of this data. The more data you can aggregate, the more PII you can associate, there’s a lot of revenue to be made aside from whatever your core business model is. So other than that regulatory stick of government suing you, why would leaders want to be able to do this? Is it those workflows that it enables? Is it that seamless access and operability? Because they’re giving up this pretty lucrative layer of their reality.

So, multiple things, but you raised several good questions in there. Let me start with the simplest one. Not everybody is afraid of fines or cares about them, and it shouldn’t drive the right thing to do. Some companies like Apple have some values where they try to be respectful of privacy. Some others do it for brand. When I asked Jitendra Aswani, who was the head of privacy and security at Netflix, “Why did you build an API for privacy inside your company with a vault?” his answer was, “Well, we didn’t build it because we wanted to. We built it because we had a management offsite and one of the questions that came up was, we should never be on the homepage of the New York Times for any other reason other than a new show.” So we call it the New York Times test of privacy.

A lot of businesses understand now that when people say data is the new oil, they probably didn’t mean it, but the worst aspect of data is the new oil is truer than they thought, and you don’t want an oil spill on your hands. In regulated industries, people have to do the right thing. But here’s the amazing thing. If you’re a company like 23andMe and you have information about lots of people, you can go two ways. You can either try to do semi-legal things or shady things and try to monetize it, which is horrible for your brand if it comes out. Or you just sit on the data, which actually could help people. We could actually identify clinical trial participants who have a certain gene modification and ask their permission, “Would you like to join a clinical trial?” The right way to do that would be to do it through anonymization and opt-in principles. To do something like that, companies like 23andMe and others have spent years building that technology, and they can barely get it to work. And we think that should be available to everybody.

If you could take away the downside of sharing data, enable monetization with controls in the hands of the end user, enable collaboration in the hands of the people, then how many of us would have signed up for a COVID-19 vaccine if someone asked us through an opt-in process? I am from the Indian community, and there are other Asian people. There are a lot of minorities, Black people in this country who don’t really get to participate in clinical trials, for example. And it’s hard because they don’t usually form a certain community. You could actually have a more inclusive society. You could have more inclusive clinical trials if we could share data responsibly and with privacy intact.

I think that’s the big promise. The false dichotomy says the only way to monetize your data is to actually do these backhanded things on social networks. The liberated, educated, modern, enlightened way to think about it is, oh my god, if I really put in place controls on privacy, anonymization, data sharing, I can enable new kinds of collaborations and workflows while respecting your privacy. Think about it. Apple enables payments and has unlocked hundreds of billions of dollars in value for itself without knowing your credit card number. Now they could have done it in a bad manner with bad faith by trying to collect information. They didn’t. And because they did it in a privacy-preserving manner, they have an edge. I think every company could be like Apple. In fact, sometimes we say Skyflow helps you be more like Apple or Netflix. I think that’s the spirit. This is a false dichotomy, and we just have to break it using technology.

So the model that we’ve learned about selling data and generating revenue off of people’s privacy, that’s really yesterday’s business model way of making money. It’s not creative. And the next iteration, how you’re actually going to compete and stay ahead, is by innovating around these new policy, tokenize, secure, privacy-respecting ways. There are actually entirely new ways of making money and monetizing partnerships and relationships in this new environment. Is that what you’re saying?

Yes. Yes. As a consumer, my parents are old. If they go from Kaiser Permanente in California to Kaiser Permanente in Virginia to a pharmacy in Florida because they’re on vacation, we want the Walgreens pharmacy in Florida to know that they cross-react to a certain medication and they shouldn’t be taking Tylenol. It’s in my best interest that my hotel knows that the guest in 734 has a dust mite allergy. We want people to know these things so they can serve us, but do it in a manner that can be privacy-preserving. So if you do it the right way, we can actually save lives. We can literally save lives. We can enroll people in clinical trials. We can have high-quality service. If you think about the whole TSA Pre kind of thing, it enables convenience because they take measures to protect your data. I don’t have to show you everything about me on every trip. Once they’ve essentially generated a token, your TSA Pre is nothing but an assertion that’s been signed by the TSA, except they’ve done it using 40-year-old technology sitting in some mainframe, and half the time they can’t look up my entry. But there is no reason it can’t behave more like a Visa network where it’s just a signed assertion.

So the concepts of zero-knowledge proof, homomorphic encryption, confidential computing, they are going to be mainstream. And they were going to be mainstream not by your application developer or database engineer learning everything there is about key rotation and homomorphic encryption. It’s going to be enabled by someone like us figuring that stuff out and giving you an API, just like Twilio. Without Twilio, we wouldn’t be able to dial into a Zoom conversation using a phone. We don’t think about these things because they become second nature. Even just 10 years ago, I’ve always been saying the last couple of years, if COVID-19 happened 10 years ago, we would be in much worse shape because some of these APIs didn’t exist. If the Stripe API doesn’t exist, then you can’t shop on the internet for everything that we did last year. If Uber can’t figure out where I am using a GPS location API, then they can’t actually come pick me up. My doctor can’t quite figure out whether I have COVID-19 or not because Quest Diagnostics literally didn’t have APIs 10 years ago. The only way you could access that data was actually logging into your portal. We all remember that. Now, if you log into your iPhone or Android phone, you can get all of your test results. It’s all happening behind the scenes through privacy-preserving, respectful APIs in most cases. I think our view is, you shouldn’t have to be Apple to do it in a privacy-preserving way. Everybody should be able to do it, except not everybody can have 40 engineers working on it.

Yeah. And so back to your original example of our parents traveling from state to state and healthcare interoperability. Apple is like the credit card. They have the health pass info, so you can have it on your iPhone. But what if one parent uses an iPhone, one uses an Android, but they both have the Walgreens app? So now in that case, Walgreens needs to be the vault, right, to have both your parents. So what you’re saying is that an API-driven vault will make this type of vault and privacy storage and then tokenization on top of it much more ubiquitous, and work across any platform, any app, anywhere we need it.

Exactly, and it’s just based on a concept. As I said, we won the Health and Human Services contract. We have several states right now using Skyflow for that purpose, on the digital health side. And then on the payment side, we have several customers who are using us to store identity verification data before they do KYC. If you think about KYC, it’s something that an app has to do before they let you use a service. But after you’ve been KYC’d, they don’t have any use for your passport number or your driver’s license number except for compliance purposes. And it’s rather unfortunate in this country that every time I go to my tax accountant, to my doctor’s office, I’m just giving them my social security number and date of birth. Unfortunately, they use it both as data and metadata, and as a way of asserting that they have prior authorization from me, which is sort of a signed certificate, and they use it as a way of using it like a password if you can give them this. We basically overload the interface called social security number with four different interfaces when it was designed for just being an identifier.

So I think we can break that now. If you were building social security number today, it would look much more like a credit card tokenization API and much less like a credit card number that’s fixed for the rest of your life.

Yeah. And a lot of folks talk about, we need a more secure, a new version of the social security number, but we don’t need the social security number to change. We need that tokenization wrapper around it. And then, that granularity that you spoke of before, to that token. We talked about multiple states within the US, but if I’m traveling to other countries, there’s, say you’re Canadian and you’re coming to an event in the US, an educational event, and if you’re storing students’ information from Canada, it has to remain in Canada. If you’re an American tech company…

Exactly. So in an ideal world, only your university knows your student ID number and your date of birth. It makes an assertion which gets signed, ideally by the government of Canada in some manner, and it’s respected by the airport in Washington, D.C. and by the bar in San Francisco. That’s the ideal world. I think at the very least we can do this today for every application that we use, whether it’s a portal or a phone application. There’s a lot of low-hanging fruit here. If companies like Equifax were using a zero-trust vault like Skyflow and they lost all their data, all we would find out is that the credit scores of Americans follow a bell curve and some people have really bad credit scores, which is really useless information. It’s like, enumerating all 16-digit numbers doesn’t give you a credit card number. What makes a credit card number a credit card number is a 16-digit number that’s associated with a name and a zip code. It’s the association between the PII data fields that makes it PII. If I say Kin, there’s no PII in Kin. There’s no PII in Lane. There’s no PII in Postman. It’s when you join these things together. And we join these things all the time for no good reason, when sometimes all I need to know is you are working at Postman. Sometimes all I need to know is that your last name is Lane.

So we can make those assertions, we can have those API calls, and it can all be set up through a very simple policy which looks like English language: allow customer success that’s not resident in EU to only see redacted data. You set a policy like that in Skyflow, it will be globally implemented. Doesn’t matter whether it’s a customer success application, a marketing email going out, whichever department it is, that policy will be followed, and you can rest assured as the CTO of Netflix or CISO that you’re not relying on the application developer. Essentially what we’re doing, Kin, is we’re moving the problem of data privacy, security, governance, and data residency to the left. Way left, even before you build the application. People talk about left as in, while I’m building my app. We’re pre-building it. Once the vault is in place, when you’re building an application, that problem is pre-solved. All you have to do, when you connect to the system and we create a service account for your application, someone has to just say, “I’m associating this policy with this application,” and you’re done.

Yeah. See, I avoid building certain things. I have startup ideas, things I want to do on the side, and because of GDPR and CCPA and other regulatory things, I just know the overhead and the risk. I really don’t want your email address. I don’t want any of your PII. I just want you to be able to use my cool little game or my cool thing that I wanted to build. And because of that friction, I don’t even build these apps. I don’t even do those things, because I don’t want to get into that game.

Exactly. A few years ago, nobody was using two-factor auth because, I don’t know how to connect to a PBX. Then people were building these badly written username-password applications because they didn’t know how to write good auth. And now auth is taken care of, telephony is taken care of, payments is taken care of. Nobody wanted to go to a bank, get a merchant ID, and then accept payments. People were like, “Screw it, I’ll just run ads.” The transformation from an ad-based economy to a subscription-based economy was not enabled through some magic. It was enabled through privacy. If you actually read some of the things Patrick Collison has written, he openly talks about the fact that Stripe is a security company that happens to be processing your payments. Because the hard part is not processing the payment. You can call Authorize.Net. It’s existed for 30 years. It’s a bad API. And they’ve asked you to store the credit card numbers in your local database, and nobody wants to do that. And what Stripe did can be done for all PII. That’s really our mission and vision for the company. The idea is very simple. You should be able to just write the app, and you set policies, and you’re ready to go.

That ability, because I’ve done payments or e-commerce apps since ‘98, ‘99. I’ve used Authorize.Net, CyberSource, all of those. And that moment that I could embed the thing on my site, have one of my customers enter their credit card number, and know that I don’t have to store that, I don’t have to go through PCI compliance, that it goes straight to Stripe, and then I get that token back, if I could do that for everything else…

If you just wrote the PRD and MRD for Skyflow, that’s literally the PRD and MRD for Skyflow. I’ve had this idea for like 10-plus years. The hard part was, okay, it’s easy to say that. It’s like saying, I wish electric cars existed. What is it that makes it possible today? The great startup question is always, why now? And what’s possible today is, compute and storage are so cheap and data platforms are in the cloud that I can actually do things like polymorphic data encryption in real time so that you can actually have your cake and eat it too. You can build an application that needs and uses PII without touching the PII.

When I started the company two and a half years ago, before I wrote a single line of code, I went and talked to some of the largest companies in the US that have the biggest amount of PII. I won’t name the company now, but the largest online pharmacy, which also has the largest number of pharmacy stores physically, the CIO said to me, “Anshu, I wanted all the data forever stored in my data lakes. I don’t want that anymore. In fact, every social security number, every patient ID is a liability for me. So in an ideal world, someone else would solve that problem for me and I would just use an API,” which is what Skyflow does. “But in a bigger world, what would happen is, I don’t even take ownership of that data. The consumer authorizes me access for very limited amounts of time.” As I said, TurboTax uses your social security number for one second a year, but they have to protect it for the other 365 days, 24 hours, and 59 minutes, and 59 seconds. Why? What do they gain from it? You can’t even sell social security numbers. It’s just all toxic stuff. So if we could just do this with a simple API, we enable commerce, we enable health, we enable payments, we enable logistics, and we actually enable companies to work with each other directly without having social networks be the intermediary.

The reason Uber advertises on a social network to get an Amex user to use them is because Uber and Amex can’t work together. If you really think about social networks, they don’t connect me to you. They connect Uber to Amex in the context of you and me. And if these companies could partner with each other without revealing any data, with prior authorization and respecting my privacy because we are the paying customers and we can sue them, then we can enable a world where social networks don’t have to be the intermediary. The cookie is a badly written, uncontrolled way of tokenizing data about you that you don’t control and your companies don’t control.

And it’s being used to exploit us and track us and surveil us.

Exactly. The beauty is, thanks to leading companies now trying to shut that down, governments making it illegal, that spigot is off. People are slightly more enlightened. And what I’m saying to these CTOs and CEOs is, look, you can actually make even more money if you respect my privacy. I want you to sell me a CPAP machine. I just want you to sell me the CPAP machine when I have told you that my father has sleep apnea and I’m asking for the information. And then take it away. I’m not going to buy a CPAP machine every day. You’re kind of wasting your dollars advertising a CPAP machine to me every day. So I think if we do it with thoughtfulness and meaning, these online technologies, which all of us love every day, can entertain us, they can get us work. We can work with each other anonymously, too, by the way, in certain contexts. In certain times, all I need is someone to go out and do a certain chore. They don’t need to know everything about me, and I don’t need to know everything about them. We can do all of that stuff if we have a privacy-preserving API for enabling these workflows.

And it’s much more resilient and reliable, as you said. We use the phrase API economy a lot in the sector, and I remember 2010 through, still I’m explaining it this way to a lot of folks. When I say, “Well, the API economy,” they think I mean, “Well, if they build the next Twilio, that’s the API economy. There’s a huge opportunity.” And it’s not that. It’s what you said, that it enabled, what Twilio and Stripe enabled, for the gig economy, for us to order our groceries, order our restaurant food. It’s that level of enablement. That’s what I hear you saying about privacy, that if we tokenize privacy in this way and our PII that we’re handling, that we’re actually able to enable and light the fire under this entirely new way of doing business. And there’s actually even more money for folks to make, and it’s more resilient, and it’ll deal with down economies, pandemics, other things like that, global climate change, other things that are going to come our way.

Yeah, so we need to move from an API economy to a privacy-preserving API economy.

I like that. Yeah, that makes a lot of sense. So, okay, this is great. Skyflow can do this for me. Doesn’t this just make you guys a target? Doesn’t Skyflow become a target? Doesn’t that keep you up at night as a CEO sometimes?

That’s an amazing question. It would if we just did it like the old times. People know that when you go and use something like Auth0 or Snowflake, all the data doesn’t go into one single thing. We’ve actually evolved from a single centralized SaaS architecture to a modern SaaS architecture where we’re able to actually deploy a single-purpose dedicated VPC with a private link just to your VPC so it can’t even be seen on the internet by ordinary traffic. So it’s really your vault running in your VPC connected to your systems. It’s fully managed at the control plane and code level by us. You bring your own key management system. You can bring your own master keys. You can bring even your keys down to the single column level. So we give full control to the customer on both deployment architecture and on key management, which basically means it’s really your vault running in a very, very distributed architecture with no single point of failure.

Impressive. Yeah, no, I can see that would alleviate a lot of my concerns if I was running the show within an enterprise.

It’s like Cloudflare. Cloudflare is not a single point of failure because they don’t have a single point of failure. They have a lava lamp that decides how traffic gets routed. If you’ve been to their lobby, they have a randomizer that is run using a lava lamp. So a lot of these companies that have to think about these problems for a living, we don’t have someone just winging it on a weekend. The guy who built Oracle’s database encryption is our database encryption guy. The guy who built Salesforce’s encryption and governance layer is our application layer governance architect. The guy who built MuleSoft’s integration platform is our PM for APIs. So we’ve collected, I call it the Ocean’s 11. Sometimes it takes 11 to rob a casino, sometimes it takes 11 to protect a vault in a casino. You need people who have very, very different experiences, and that’s why nobody’s done it. I was at Oracle, we couldn’t do it because we didn’t know how to run cloud in those days. Salesforce couldn’t do it because we didn’t have our own database, we were using Oracle. We needed to control all layers of the stack and build it off with a very simple, singular purpose. Just like the Auth0 guys did auth, they’re not a single point of failure. So that’s how we thought about the problem. We assembled a team of 40-plus engineers before hiring a single marketing person or salesperson, and we’ve just recently gone to market over the last year.

Impressive. So you think about this a lot when it comes to just doing business globally today. What’s your biggest concern? What do you think is the biggest threat out there right now?

As a businessperson, of course all of us care about people suffering from COVID-19, and hopefully that gets resolved as we get everybody immunized. But beyond that, I think the biggest business risk, frankly, is whenever people try to do something good, in the past it was protecting your borders, sometimes it’s health, people will take common good and something that’s great like protecting data privacy and turn it into a way of profiting, rent seeking. So right now there’s a bunch of laws getting passed in a lot of countries that really don’t do anything to protect the data. The fact that something sits in a physical server in Hyderabad versus Taipei doesn’t really protect anybody’s data. It just helps someone that owns a data center get some rent. It’s literally rent seeking in that case. We need to be sure that when we are solving problems like data protection, privacy, consent, we don’t do it because Europe hates American companies and vice versa. We do it because technology today allows us to actually facilitate cross-border payments and taxes and cross-border commerce and movement and working with each other. Can we enable the global economy without using these data protection and privacy laws to impede global commerce? That’s what I think about a lot. And I think if our global GDP goes up 2x over the next 20-30 years, everybody’s better off.

Yeah. I think that rent-seeking mentality of corporations, and kind of data nationalism when it comes to government regulation and thinking, “Oh, if we just come up with our own set of regulations, we’re going to be better off.” But you want to actually still do business with the rest of the world, and let the rest of the world do business within your country as well. So there’s a balance and a trade-off that you have to strike there when it comes to how you do business. And for me, that’s what APIs are about, finding that balance between access and control over your digital resources and capabilities, but while still allowing access and, in this case, privacy and security to exist.

You know, when we started the company, we initially thought of naming it Skymote for protection, or Skyvault. And someone said, “You know, vault is how you do it. What you’re really enabling is the flow of commerce and data without compromising privacy. So you’re enabling flow by building a vault.” And I was like, “That’s great. Maybe we should call it Skyflow.”

Yeah. Oh, I support that. Because that’s ultimately what we want, and that’s the enablement for that next-generation economy. We want to keep things secure and private and give control to people, and we all want to generate revenue running these companies, and governments want to protect their interests, but it’s about the flow that’s actually going to benefit us all. I really like that name. So, you seem to know a lot about the security space. You seem to be fairly in tune with global business and how things are regulatory. How do you stay aware of what’s happening in technology and the world? How do you get your information, stay on top of things?

Before Skyflow, I started another company that’s in the healthcare AI space. When it was in stealth, I always name my companies in stealth with something funny or interesting. I called it Learning Motors. It’s kind of like a play on machine learning, learning machine. I think all founders, all leaders, people like you who are enabling thought leadership, or just thought leadership is a bad word for just thinking things through. People have canned it and turned it into Campbell’s soup, when the original meaning of the word is simply, dude, think about things. I wish there was a better word for that. So I’m in the dude-think-about-things category, and I’ve always been that way since I was a kid. And to me, entrepreneurship is exactly like being a physicist or a real computer scientist. You build something, then you optimize it, you find things, you explore things. In fact, when I started Skyflow, if you came to our homepage, we redirected you to a slide deck that I created called “Things I Learned Starting a Company and How You Could Do the Same Thing.”

I think it’s curiosity that drives me personally. I kind of had a good career at both Oracle and Salesforce and became an investor for many years, and I could retire and not do any of this stuff. So to me, the motivation for building this company is, it’s an important problem. It’s nerdy enough that I can really get into things. We have really invented some new ways of using existing technologies. And I think it’s fun. It’s a lot of fun learning about things. You can’t really build an electric car if you don’t know how to sell it. You can’t commercialize space without commercializing it. SpaceX and Tesla can’t exist without figuring out the business model, which to me is a scientific mindset question. You can’t really build Moderna as a company, you can’t just sit around in a lab and say, “Hey, we’ll keep doing RNA stuff.” They had a hypothesis: well, if you had RNA, we could solve a lot of diseases. One of them is actually vaccinations. And it turns out they were right. That’s part of the job of not just a founder or a business leader. If you go look at the leading labs in universities, they have to get grants. Everybody has to figure out how to sustain something. The leading universities in this world all have large endowments, and they have to worry about how do I get that money? If you can make the business model be in sync with your purpose, then you don’t have to do a fundraiser. If I can charge you a flat fee every year for using my vault, that’s great. For another company, if they can charge you 4 cents per API call to send text messages, problem is solved. We don’t have to have this whole business-people thing.

And frankly, I think that’s another fascinating part. You increasingly see product people and engineers run companies. If you think about it, 30 years ago all the big company CEOs were like Larry Ellison. They gave talks, they did keynotes, and you kind of sort of didn’t believe them but they got headlines. Then we moved from sales-type leaders to what I would call marketing leaders like Marc Benioff. Amazing, right? He can hold your attention for hours. But then we got these product and engineer nerds like Stewart Butterfield and Jeff Lawson and Todd McKinnon at Okta. All of these people, and I consider myself in that category of just engineers trying to build things. And we didn’t have to hand over the reins of our company to some guy in a suit who can do a keynote and look better. So as I say, we have a lot of ugly people now giving keynotes, and I’m proud to be one of them.

Yeah, and I think you, so I’m going to give a shout-out to my CEO Abhinav Asthana, who’s a developer and had the Postman vision, and he’s still leading and really changing my views on marketing. Because I’m not a big fan of marketing departments, and what he’s doing as far as Postman from a marketing-your-tech-company standpoint is pretty impressive. But for me, like, I’m also seeing the API space. I’m a database guy. Since the ’80s database was always my game, and APIs for me struck that balance of access to these kind of power centers within a lot. I mean, you come from Oracle, you know the power center that’s around the database. And I really was like, “Oh man, APIs are democratizing this.” But it was still very technical in 2008, 2009. Now I see more business users getting involved in the API lifecycle and actually designing and defining and being part of it. They’re not delivering and deploying and developing the API, but they’re involved in the entire process from end to end. That’s our fastest-growing persona base at Postman, those types of users, because they get the importance of APIs, and they’re able to get much more hands-on in the fine-tuning of the business using these APIs.

Yeah. I love open source. We built some amazing open source technology at Salesforce on the database side, actually, SQL on Hadoop kind of things before Snowflake existed. But there was a problem with open source, which is you can’t quite monetize it. The only way you can really work on open source is if your day job is at Salesforce or Oracle, and at weekends you’re working on it. APIs have the beautiful thing that the business model is embedded into the sharing architecture in some ways. So someone can build a tool like Postman and charge people for it, and we all use it, we all benefit. There are some free API calls, and there’s some free usage, and there’s some enterprise features. We figured out how to grow businesses while giving access to everybody. You don’t have to buy a $200,000 PBX machine to send your first text message. And none of us mind paying .001 cent for sending a text message if the other alternative is buying a PBX machine at $250,000.

I think it’s the same with us. We have so many startups right now in the fintech space and digital health space who are able to launch internationally because of us, or able to launch in the US GA from day one because they have their PCI and SOC 2 and HIPAA taken care of. It used to be you would build something and then you show it to the customer, and they say, “Well, I would love to use it, but go figure out all these things and come back to me in two years.” We basically said, “Look, tell your customer we use Auth0 to do username-passwords, we use Twilio to send you text messages, we use Stripe for storing credit card data processing, and we use Skyflow for all PII. You don’t have to trust me.” And we make available our CTO for conversations with customers of our customers. Sometimes it’s about helping our companies build business. Back to my favorite Clayton Christensen, who passed away recently. The job to be done is for me to enable a digital health company to sell a solution to end consumers, or to a hospital, or to the National Health Service. To do that, we have to provide privacy protection, data residency, security, compliance. But then I have to give them the peace of mind and the brand and the technical know-how so that when they go in the meeting, either one of us is there or they can pick up the phone and say, “This question you just asked about, if I used your application for wealth management, let me ask my partner, and they can tell you in gory detail how, using private link and homomorphic encryption, your data is handled.” And it’s really a CISO as a service. Essentially, we’re acting, in a very, very narrow sense of the word, of course, as a CISO as a service for PII data protection. If you had a CISO who was only worried every morning about data protection, that would be embodied as Skyflow.

Yeah, so you just beat me to my second-to-last question, which was, how do you change, get someone, if I’m in an Equifax or one of these companies that has a culture that doesn’t support security, how do I change that culture? And you just pretty much answered it for me, by, you guys don’t just start using Skyflow and thinking about this tokenization and this vault approach, but really it’s also that knowledge and awareness that comes with the industry, the horror stories. Let folks come in and help you not make the same painful mistakes.

One of our customers was selling to a large pharma company in France, and they were doing a clinical trial using their software, and they shut down the clinical trial because of this data residency Schrems II act. And we literally took the paper by the European authority, it’s called ENISA, and we showed them section 3.4 says, if data protection company and data processor company implement this pattern, then you’re compliant. Using a vault, this is how your data gets anonymized before it comes into this clinical trial SaaS application. That one-pager basically is the core of what they really need to share with their pharma customer, and then their engineer basically uses our API to actually just use it.

Yeah. Well, I’m, this is definitely the future I envision, an API-driven one, but one that respects security and privacy. So one last question, taking it more to a personal note. You seem pretty engaged with your business. How do you prevent yourself from burning out, especially in these times during a pandemic?

I think it comes down first and foremost to the very core principle: people. As a founder, you have a privilege to pick your first five co-founders and co-workers. When I hire people, we are about 50-plus people now, 53 I think now, as of today. When I interview them, and I talk to everybody before we hire them if possible, I always say two things. I’m like, I’m sure you’re great at your job because our VP of engineering Pradeep picked you, or CPO Amrita picked you. But you really have two jobs coming in. The two jobs are the job that you’ve been signed up for, and the second job is to help build this company. And building this company part of the job really is about culture. It’s your job to keep jerks away from this company. Make the culture that you would want to have here for the next 10 years as we grow into an amazing public company. I can’t do it by myself. I will do it for the first 10 to 50. Your job here is to help me do that for the next 10 to 50. And there are many bad multi-level marketing schemes, but this is a good pyramid scheme. If you can get the pyramid scheme going where we have a high-trust culture, where we avoid hiring people who are toxic, or if you do hire, you make amends.

Many years ago at one of my two employers, someone very senior, he was the president of the company, said, “Let’s do a culture committee thing.” He read some Reed Hastings stuff, and we had this big meeting with a lot of people, and I was a VP there. The meeting went on for 45 minutes, and then he turned to me and said, “Hey Anshu, what do you think we should do to improve our culture?” And I said, “Well, there’s only one question. Everybody in this room knows three VPs who nobody wants to talk to or work for, and they are still here. So you can fix this problem tomorrow morning.” But it’s a hard business decision. These people, some are good at shipping things, some of them are good at selling things, and culture is not about giving speeches. We don’t have posters saying, “Be nice to each other.” It’s about not hiring the wrong people, and it’s about, unfortunately, people who are going to destroy your culture, letting them go. We’ve done that a couple of times in our history, and it’s really hard, but that’s really what the job is. So that’s my hard job. I do that. I make sure people that work with me, I enjoy working with them, they enjoy working with me. You can check out our Glassdoor rating. We’re only 53 people. About half of them have left a note there. We have a 100% rating on the company and the CEO. I’m sure we’re going to eventually drop down to like 90% as we scale, maybe worse. But it’s not an accident.

I must credit Marc Benioff. For the stage of the company that I joined, he was so far ahead of where his old company, Oracle, was, and he took the best of Oracle and made sure the worst was not repeated. I’m trying to do the same, and I think that’s how you actually prevent burnout. I take vacations. When I take vacations, we have a channel on Slack called Veer Now where people post their vacations. We cheer people on when they have vacations, we have a photo journal Slack channel, you’re welcome to post your vacation photos there. We have a culture of making it okay to take time off to recharge and do great work. Again, there’s no policy that says you have to recharge, but once you know your CEO is doing it, you know your CPO is doing it, you know your execs are doing it, it becomes okay. It’s okay at Skyflow to have a down day or take a week off for a vacation.

Yeah, this definitely sets a good foundation internally for the company, but I can tell that’s reflected in how you all do business, because your respect for privacy and security and just a straightforward, straight-up way of doing business. So I appreciate that. And I really appreciate you entertaining my offer, because I just kind of solicited randomly on Facebook. We hadn’t met before today, and I really appreciate you joining me for this conversation.

Well, Marc Benioff said to me, when life opens doors to you, you can either keep going or you can actually walk through the doors that life is opening for you. And I think to do that, we have to be mindful. Mindfulness applies to privacy, mindfulness applies to the quality of code, mindfulness applies to someone pinging you on LinkedIn or Twitter and asking you a question. I was in that state of mind that day, and it felt like a great opportunity. So thank you so much. I really appreciate you reaching out. We are all fortunate to be part of this new revolution. And these things happen only once every 20 years, by the way. The last big one was SaaS. And the API thing, people who are in the middle of it may think they’ve always existed and it’ll always be the thing. It’s not true. Secular shifts are amazing, and you can ride them for decades. So with that thought in mind, again, I want to thank you for inviting me here.

Yes, thank you. Well, enjoy the rest of your week, and I look forward to talking again in the future.

Thank you, Kin.