In a typical security team, engineers write one-off scripts to track a particular problem on a cloud provider such as an unauthorized user on your GitHub account and while engineers are able to write those scripts, it's not exactly an efficient way or scalable to handle the range of security issues these professionals need to track.
Vectrix, a member of the Y Combinator Summer 2020 cohort initiated by three security veterans, wants to solve this problem. It has created a security market where fellow security professionals write forms to automate these types of fixes and other security professionals can take advantage of it without reinventing the scripting wheel every time.
Alex Dunbrack, the company's co-founder and COO, says that he and his co-founders, CTO Matthew Lewis and CEO Corey Mahan, have seen this problem firsthand in their previous jobs at PlanGrid, Vimeo and Uber. Like many founders of YC companies, they decided to build a solution.
"It is a market for automated security tools that monitor technology and have the ability to respond to any security concerns that a company may have within its cloud providers," explained Dunbrack. He says it could be on GitHub, AWS, G Suite, potentially on any cloud service.
The idea is to make security professionals build these modules, then give them a "royalty" and boast of finding a workable solution. Dunbrack says it is no different from the HackerOne model, which provides financial incentive and community recognition for finding vulnerabilities in the code.
Users don't download anything. They simply select a module, enter their cloud service credentials, and provide output like Slack or Jira for all the alerts generated by the module.
The startup checks the modules and developers before allowing them on the market. While this is a manual process at the moment, it says they are working on bringing more automation to it. For now, every person who wishes to contribute with modules, does an interview, a reference check, a check of working conditions and similar types of investigation.
Once this is done, and the security officer writes the form, he has to go through a further review. "Basically we mean exactly what they're going to build and the types of alerts that will result. And then from there, we have an extremely modeled logic scheme on the side of the code where they're just writing logic to go crawl," he said.
Form authors cannot see any user information about the service and Vectrix makes sure there are no problems like outgoing requests for data. They currently have 10 modules with plans to add more soon. While they are working on the pricing model, customers are now paying a flat rate for access to the entire marketplace, rather than paying per module.
The company is currently only the three co-founders, but they hope to expand and when they do, they have already reflected a lot on how to build a diverse and inclusive company. He says they are not affected by the effect of the Silicon Valley network to begin with.
"Many people will say 'we just want the best people', but our interpretation of the best people is really a set of different thoughts and experiences that make someone's perspective truly unique. This comes from the diversity in the way we see it, so in many senses involving the best people means carrying the widest range of thought processes, and that involves diversity and being inclusive, and in a sense taking all these factors into account, "he said.
Regarding the experience of YC, Dunbrack says he was looking forward to learning from the network of companies that preceded him, and says that even the company has practically managed to give him that experience.
So far, the company has started the bootstrap and has used Y Combinator's money, but intends to do a fundraising tour soon. "We are aware of what we are bringing to the industry and the value there. So attracting strategic partners is really the way we are approaching this," he said.
