← All episodes

Jad Boutros: Cut Risk Reviews From 33 Days to 4

Jad Boutros · Founder & CEO · TerraTrue
· Hosted by

About this episode

Jad Boutros is the founder and CEO of TerraTrue, and he argues that security and privacy review should not sit as a last gate before launch. It should live inside the tools teams already use. TerraTrue connects to Notion, Jira, and Ironclad so a new contract or feature can trigger a risk review automatically, before a line of code is written.

Boutros brings 25 years in the field. He was one of the first 10 security engineers at Google and the first security hire at Snap, where he built the function to more than 100 developers through the IPO. The idea for TerraTrue came from one hard question at Snap: what user data does the company hold, and what does it do with it. Answering it meant searching thousands of systems. Boutros says TerraTrue cuts risk reviews from 33 days to 4, and points to Jam City running 10 times more reviews without adding headcount.

In this conversation

Watch the full episode on YouTube →

Full transcript

Welcome back to the podcast guys. Today we're joined by special guest, Jad Boutros, from TerraTrue. Jad, it's great to have you here.

The pleasure is all mine, Mikulas, thank you.

So to get us going, Jad, for anyone hearing you about the first time or the company, can you give us the quick version of what you do and what kind of problem do you solve?

Absolutely. So, you know, as you said, I've been the founder and CEO of TerraTrue for the past seven and a half years. we built TerraTrue as a very unique risk management platform. We specialize in privacy, security, and AI risks. And it's really born out of almost 25 years of being in the security and privacy space.

And learning about the challenges to build strong risk programs in those organizations. So, very, very briefly, I worked at Google for almost 10 years in security. I was one of their first 10 engineers in security and got the chance to build a risk review program from the ground up. And then fast forward 10 years later, same thing happened. I joined Snap or Snapchat at the time as their very first hire in.

security, privacy, and trust and safety, tasked with building programs for all of these three. Over four years built that to over 100 developers. We went through an IPO, learned a lot about sort of the process of what it takes to collaborate with the business to reduce risk effectively. And decided it's time to start TerraTrue in a way that can return that

knowledge and that experience and enable equip companies to do things that I struggled I struggled doing because of the lack of tools.

Interesting. Yeah, it's it's interesting that you've actually built this whole security function at Snap and then what actually made you l leave and go on your own?

honestly, Snap again, both I've been very lucky to work at companies that care very deeply about security. Google and Snap were perfect examples of that. And and so it was extremely stimulating type of work under a lot of high pressure, but also we felt we accomplished a lot and built a lot of defenses that are sort of state of the art in the industry and

And managed to support a business that was in hypergrowth in a way that was positive, that didn't slow the business down, which is one of the key challenges. And we one of the reasons I started TerraTrue is that one time we received this question: what is all the user data that Snap has and what does it do with it? And it was a very easy question to ask, but a very difficult one to

to answer. Snap had thousands of different systems where it could store data. And I remember it was a very challenging task to come up with the right answers. And so as I thought about this, I wanted a way to bring privacy and security better into everything the company does so that these answers are c can be given automatically.

Without that soul searching, without that thinking, just as a byproduct of the risk program that is there. And so that was, to me, an impetus to say we can do better. There is no tooling. We struggle to do a lot of these things at Snap. And there has to be a way to bring in improvements to the way teams deal with privacy and security.

It's interesting because TerraTrue actually sits inside Notion, Jira, and Ironclad. So it's it's inside of the existing tools rather than actually replacing them.

Yes.

Yeah. Y a absolutely. Sorry, go ahead, go ahead.

So

Yeah, I I wanted to ask like most security teams I think still treat privacy review as kind of a launch gate. you as an expert, why do you think that's the wrong model?

yeah, you you're absolutely right that it is a the wrong model. And it's not that companies don't realize this, they do. It's just that they can't do much about it absent spending considerable resources. And that's where it starts to get very, very difficult. Because when companies want to do the right thing and meaningfully conduct

Risk reviews against what they're new features they're launching, new products, maybe new vendors, maybe new internal tools, marketing campaigns, even HR tools and and sales functionality. Everything that they're doing new generally requires a review from privacy and security to make sure the risks are understood, the risks are mitigated. but to do this in practice is extremely hard. And to do this at scale.

Mm-hmm.

in today's world is even much more so. And there are a few reasons for that. one, risk in general is exploding. So, as excited as we all are to embrace AI as an extremely disruptive and powerful technology, it also brings in a lot of risks. and it's like that with every new sort of innovation in the world. As you embrace it, you add more risks. It's very rare that you eliminate.

risks that used to be there before. So it's always additive in in a lot of ways. But also companies are launching and innovating at a much higher rate than they ever did, which brings the question how can you do all of that and still work in lockstep with security and privacy? so you don't have these bad situations where you launch something new and then you have to withdraw it from the market because it had some serious

Mm-hmm.

Vulnerabilities or causes an incident or or these kinds of things. And also, the unfortunate reality of today's lean market dictates that innovation needs to move forward at all costs without being slowed down by teams like privacy and security. So these teams, subject matter experts, are having

To constantly struggle internally, what can we do that is meaningful to reduce risk, but not slow down the business? And so for us at TerraTrue, we're really about equipping those teams to scale without the dread of scaling. So that they can achieve more, they can do it with the resources that they have, and they're more and more business friendly. They're not slowing down the business. On the contrary, they are

Mm.

growth accelerant for the business. And and so this brings me yeah, sorry, go ahead.

Are there?

are there any like specific tips that you could give to to viewers if they would like to implement AI but still be on the safer side and have a you know secure space?

Absolutely. So there are a few sort of, if you will, basic principles that apply all the time, particularly with new technology. And those are essentially as follows. the business today, so think of it as developers or product teams or HR or sales, when they need review from privacy and security, they don't want to

Have a lot of friction in that process. So you asked me about why integrations are powerful. They're very, very, very powerful and very beneficial. And the reason is it bridges the business with privacy and security. So, for example, as you think about a tool like Ironclad, which is a contract lifecycle management tool, we built an integration with Ironclad so that anything that comes in to Ironclad.

A new contract for a new potential vendor that is being evaluated can automatically trigger privacy and security reviews in TerraTrue without any manual reaching out to privacy and security. It's all automated. So it gives you that ability to have discovery and understand what does the business, what is the business doing, what does it need from you without adding friction to their process.

And it also gives the advantage that you get looped in earlier in the process because the minute something happens that warrants a review, you're notified through those integrations. So the same way with Jira as developers and product teams use it. And and so, in terms of advice, there are quite a few, but first always speak proactively.

With privacy and security. Don't assume that work you're doing, particularly in the AI space, is going to be an easy ride that you can just let them know one day ahead of your launch that you're doing it and expect that they will rubber stamp it and you can continue. So always, always work very closely early on with your privacy and security team. Give them the heads up.

If they need to build new countermeasures to the risk that you may be introducing, they have more time to do it without impeding your ability to execute and innovate. So have that dialogue, collaborate well with them. And also to the to the security teams, all of them right now are completely overwhelmed with AI risk. We're seeing it everywhere, with our customers, with the market in general. And

Mm.

And so it comes it comes down to is the security team equipped to handle these risks? Or are they starved for resources so much so that they're saying no to everything? And that's deadly today, right? If you say no and you're standing against you know improvements in AI and use of AI, it's it's going to be very career limiting. The organization will not tolerate that for too long. So my advice to security teams is to

Mm-hmm.

Proactively work and collaborate with the CTO, the head of HR, privacy teams, even the CEO and others to build a governance strategy. What is okay, what is acceptable risk, and what is not. And be very clear about it so you can evangelize it to the business and help them make sure that they follow it. That gives them a direction. That gives the business and engineers in particular.

a sense of direction. What do they need to do? How they should be thinking about things, and what could be very challenging and require a lot more review and work with the security team to achieve those goals. So guidelines and proper governance are the best thing. Saying no repetitively, burning bridges are probably not the best situation.

Got it. Mm-hmm. I've seen that you have a Databricks partnership. what what made that the right fit and is is there something that you've learned from closing it?

Yes.

Look, it's a great question. I think one of the items or the properties that make TerraTrue unique today is that we're extremely proactive. So for us, as we equip teams to build a risk program, we want them to do it as early in the life cycle of work as possible. This is why we build these integrations with document systems. So even before a single line of code is written.

Your reviews can start. And I'll share a quick anecdote about that actually. When I was at Snap, there were a few cases where we as a security team had to tell the CEO, look, we can't launch your engineers, can't launch this feature as it is today because it needs some work from the security team to address risks. And obviously, you can imagine that's never well received.

Right. If you're telling the business slow down and don't innovate, it's not a good story. So the way we made it work is that the CEO invited me to join these ideation meetings, where before any document or design doc or any concrete work on any new feature is done, those meetings happen to throw out some ideas to say for the CEO to indicate what they would like to pursue.

And me being in those meetings led to two really important things. One, most of the work I would automatically give a heads up, a thumbs up to, like, no problem, you won't encounter resistance from the security team. Don't worry about it, just work on it. And then for the very few that are actually introducing something novel that the security or privacy team needs to build defenses for, the CEO would get an immediate heads up.

And so they're not left g guessing and thinking about what could be the potential delay. And we get to work with the engineers in a lockstep way from the very, very, very beginning. And that was extremely powerful. Now, our pitch is start those risk reviews early. Databricks is a little bit of the opposite. It's almost a validation layer or a compliance layer built into the proactive engine.

And the understanding there is did we miss anything? Did privacy or security miss a review that is important? And as a result of that, some information now surfaces in your Databricks environment that you didn't expect and you didn't approve, and could become consequential to an incident, a breach, a violation of a regulation. So TerraTrue connects to your Databricks instance, understands what you're storing there.

Classifies it, understands if you've reviewed that use case for the data. And if you haven't, and we've really found some discrepancy, then we can surface automatically a review for the business to address it. And that means they could then delete the information that they've stored, undo a certain feature, rethink it, or approve it and say, yes, that's okay, that's intended, and then constantly strengthen their program.

So it's a little bit like tackling a problem from two sides that complement each other.

Hmm. How do you approach go to market strategy? Because I can imagine that integrating and mitigating risk and security must be very hard kind of pitch because it's you know it's one of those things that when if there is no you know no no hackers or no bad experience, then most people

like they are not actively looking for that solution. Or is that is that on only my assumption?

No, no. you're absolutely right. There is a little bit of sort of educating the market because there is no platform like ours that can handle privacy, security, AI risks, even product counseling risks, trust and safety, compliance and others all in one umbrella. But where the conversation typically starts is, we're drowning. We're not able to effectively scale our risk program.

The risk reviews are taking thirty-three days, and with TerraTrue, you can do them in four. That's an extremely compelling story for the business because that's 29 days. Faster they can innovate and execute and launch stories. we just released this morning a case study from Jam City, which is a a wonderful gaming platform. And they said thanks to TerraTrue.

Wow.

We're able to do 10 times more reviews at 10 times more depth without any increase to the headcount. So it's enabling them to have that discoverability to make sure they have a beat on the risk of the business, but do that efficiently and intelligently. And that's what we're here to support. So we work with our customers, we understand where their process is breaking down and how we can remove these obstacles.

One of the things you know organizations don't want, and this has happened at Meta recently. It was in the news. the privacy team was slowing down Meta's launches so much that Meta said, We have to veto your ability to delay launches. We have to, you no longer can delay launches because you're slowing us down a lot. Our solution to businesses is

Move at full speed, but also do things right by privacy and security. And that's really how how we think of the pitch, the approach. And then we work with the customers on how do we build this step by step and how we support their needs as they evolve over time. Because that's the other thing. Nothing stays constant. So we're constantly working with our customers to meet their new goals. And that's what the pitch is, a trust relationship, really.

Hm.

Mm-hmm. Yeah, that's great. I mean being able to cut what four weeks? Like that's that's g that's great. And who do you think benefits the most from TerraTrue services? Like is it more on the enterprise side or do you serve also mid market?

The we s we absolutely serve mid-market and the enterprise. We have customers from a few hundred employees all the way to over a hundred thousand. And what we see typically is that if you're still, you know, pre-market, if you're still working on the initial versions of your product, maybe you don't need that security and privacy guidance because it's only slowing you down and you're still prototyping and evolving. But the minute you hit the market, the minute you have

Paying customers who are using and paying maybe for your service. That's when you have to start to think about these considerations. so we can get in very, very early. and then as the organization grows, there is that realization that you can't make up, you can't grow with just adding more and more subject matter experts. They're very, very expensive in privacy and security and AI.

They're very hard to find. And then the more you have, sometimes the less consistent the output is. So we help organizations say, use your resources better, scale them better, get them to work in more intelligent and automated ways, thanks to AI efficiencies and intelligence and data intelligence we built into the platform, and then be able to respond better to the business. So everybody's happy.

Mm-hmm. I have a tricky question for you, Jad. Like you've you've been building for quite some time now and you've probably seen a lot of things. So is there anything that you would do differently from day one?

Yeah, sure.

Yes.

Yes, absolutely. the certainly, you know, w were part of these startups that grew and received funding initially when the environment was more supportive of that. And then, you know, COVID hit, w global wars hit, inflation hit, AI disrupted things, in good ways for us, but ultimately it took a while to figure these things out.

If I could sort of go back in time, I would a little bit moderate my approach and plan sort of and sort of understand the power of lean teams. If you grow too fast, sometimes you have inefficiencies within the organization that ultimately slows you down. And you don't need that big a team to have a very profound impact. So now what we're learning, we're a leaner organization.

And we're able to support all of our customers better than we ever could before, and grow the product more intelligently than we ever could before. And we're more ruthlessly prioritizing and thinking through things and just enabling and leveraging AI technologies wherever possible to do more with fewer resources. And it's it's a it's a great feeling.

How much people are on the board?

So we are under 20. We are somewhere between 10 and 20 people at TerraTrue. And and we support really, really complex and interesting and amazing customers who are constantly innovating, pushing boundaries, feeling pride as they are able to better catch risk early on.

better work with the business, which is something that is so, so hard to do. And and the journey is incredibly exciting.

Okay, well Jad it's great to have you here on the show. my last question is if people want to check TerraTrue out or or or you or connect with you, where should they go?

Yeah, I mean I I'd love that folks find me on LinkedIn. Maybe we can share a link there and connect with me. We post quite a bit of interesting market information and TerraTrue information. And then TerraTrue's website is teratruehq.com. We have a newsletter where every week we share information about how security and privacy is changing, interesting tidbits, and also more information about us. and so I welc I you know encourage your

audience to subscribe and read it's just one email a week, but it's it's informative. we've done a good good job on that.

Okay, well thank you, Jad.

Was great to was great to be on your podcast, Mikulas, and thank you for the great questions.