Startups

Traceable AI nabs $60M to secure app APIs using machine learning

Comment

Image Credits: NicoElNino / Getty Images

Traceable AI, a startup offering services designed to protect APIs from cyberattacks, today announced that it raised $60 million in a Series B round led by IVP with participation from BIG Labs, Unusual Ventures, Tiger Global Management and several undisclosed angel investors. The new capital values the company at more than $450 million post-money, and CEO Jyoti Bansal — who’s also the co-founder of BIG Labs and Unusual Ventures — says that it’ll be put toward product development, recruitment and customer acquisition.

APIs, the interfaces that serve as the connections between computer programs, are used by countless organizations to conduct business. But because they can provide access to sensitive functions and data, APIs are an increasingly common target for malicious hackers. According to Salt Labs, the research division of Salt Security (which sells API cybersecurity products, granted), API attacks from March 2021 to March 2022 increased nearly 681%. Gartner predicts that 90% of web-enabled apps will have more attack surfaces exposed in APIs than user interfaces and that API abuses will become the top attack vector for most companies in 2022.

Bansal saw the writing on the wall four years ago, he said, when he co-founded San Francisco-based Traceable with CTO Sanjay Nagaraj. Bansal is a serial entrepreneur, having co-founded app performance management company AppDynamics (which was acquired by Cisco for $3.7 billion) and Harness (which recently raised a $230 million Series D). Nagaraj, a Harness investor, has long been close within Bansal’s orbit, previously serving as the VP of software engineering at AppDynamics for seven years.

“APIs are the glue that keeps modern applications and cloud services together. As businesses large and small migrate en masse from monolithic to highly distributed cloud-native applications, APIs are now a critical service component for digital business processes, transactions, and data flows,” Bansal told TechCrunch in an email interview. “However, sophisticated API-directed cyberthreats and vulnerabilities to sensitive data have also rapidly increased. Businesses need machine learning here. To have zero trust you need API clarity. You can no longer easily buy or hire security people, so you need to solve these vulnerabilities via technology.”

Like several of its competitors, including Salt, Traceable uses AI to analyze data to learn normal app behavior and detect activity that deviates from the norm. Via a combination of “distributed tracing” and “context-based behavioral analytics,” the startup’s software — which works on-premises or in the cloud — can catalog APIs including “shadow” (e.g. undocumented) and “orphaned” (e.g. deprecated) APIs in real time, according to Bansal.

Traceable describes distributed tracing as a technique involving the use of “agent modules” that collect diagnostic data from within production apps as code executes. Context-based behavioral analytics, meanwhile, refers to understanding the behavior of APIs, users, data and code as it relates to an organization’s overall risk posture.

“APIs often expose business logic that threat actors use to infiltrate applications and private data. Every line of code needs to be observed in order to properly secure modern cloud-native applications from next-generation attacks,” Bansal said. “Automated and unsupervised machine learning allows Traceable to go deeper and complete the API security requirement better than anyone. As its name suggests, Traceable traces end-to-end application activity from the user and session all the way through the application code.”

Traceable AI
Traceable AI’s monitoring dashboard. Image Credits: Traceable AI

Traceable provides a risk score based on “a calculation of likelihood and the possible impact of an attack,” using 70 criteria (reportedly). The software also maps app topologies, data flows and unique security events, including runtime details on APIs and data stores.

The API security solutions market is quickly becoming crowded, with vendors including Cequence, 42Crunch and Noname Security vying for customers. The growth correlates with the general rise in API usage — particularly in the enterprise. In twin reports, API marketplace RapidAPI found that 90.5% of developers expect to use more or the same number of APIs in 2022 compared to 2021 and that 98% of enterprise leaders believe APIs are a critical part of their digital transformation efforts.

According to Crunchbase data, companies that describe themselves as securing APIs received $193.4 million in venture funding from late 2019 to June 2021, underlining the opportunity that investors see in the technology.

Traceable has done quite well for itself despite the competition. Bansal says that the company has a number of paying customers, and — to spur further adoption — Traceable recently released its tracing technology in open source. Dubbed Hypertrace, it enables enterprises to monitor apps with technologies similar to those powering the Traceable platform.

“The very nature of the pandemic fallout further helped accelerate digital transformation that was already under way. The creation and adoption of millions of microservices and APIs has been a core underlying enabler for the rapid growth of digital services,” Bansal said. “As different organizations have either created, adopted, or used millions of … APIs, it has greatly increased the attack surface vulnerable to API based attacks which cannot be detected or stopped by traditional security solutions. This problem requires a completely new approach to detect and stop these new attacks.”

While Bansal declined to reveal annual recurring revenue when asked, Traceable’s total capital stands at $80 million — the bulk of which is going toward supporting product development and research, he said.

“Businesses use Traceable’s rich forensic data and insights to easily analyze attack attempts and perform root cause analysis,” Bansal continued. “Traceable applies the power of machine learning and distributed tracing to understand the DNA of the application, how it is changing, and where there are anomalies in order to detect and block threats, making businesses more secure and resilient.”

More TechCrunch

Sarah Myers West, profiled as part of TechCrunch’s Women in AI series, is managing director at the AI Now institute.

Women in AI: Sarah Myers West says we should ask, ‘Why build AI at all?’

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI and publishers are partners of convenience

Evan, a high school sophomore from Houston, was stuck on a calculus problem. He pulled up Answer AI on his iPhone, snapped a photo of the problem from his Advanced…

AI tutors are quietly changing how kids in the US study, and the leading apps are from China

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Well,…

Startups Weekly: Drama at Techstars. Drama in AI. Drama everywhere.

Last year’s investor dreams of a strong 2024 IPO pipeline have faded, if not fully disappeared, as we approach the halfway point of the year. 2024 delivered four venture-backed tech…

From Plaid to Figma, here are the startups that are likely — or definitely — not having IPOs this year

Federal safety regulators have discovered nine more incidents that raise questions about the safety of Waymo’s self-driving vehicles operating in Phoenix and San Francisco.  The National Highway Traffic Safety Administration…

Feds add nine more incidents to Waymo robotaxi investigation

Terra One’s pitch deck has a few wins, but also a few misses. Here’s how to fix that.

Pitch Deck Teardown: Terra One’s $7.5M Seed deck

Chinasa T. Okolo researches AI policy and governance in the Global South.

Women in AI: Chinasa T. Okolo researches AI’s impact on the Global South

TechCrunch Disrupt takes place on October 28–30 in San Francisco. While the event is a few months away, the deadline to secure your early-bird tickets and save up to $800…

Disrupt 2024 early-bird tickets fly away next Friday

Another week, and another round of crazy cash injections and valuations emerged from the AI realm. DeepL, an AI language translation startup, raised $300 million on a $2 billion valuation;…

Big tech companies are plowing money into AI startups, which could help them dodge antitrust concerns

If raised, this new fund, the firm’s third, would be its largest to date.

Harlem Capital is raising a $150 million fund

About half a million patients have been notified so far, but the number of affected individuals is likely far higher.

US pharma giant Cencora says Americans’ health information stolen in data breach

Attention, tech enthusiasts and startup supporters! The final countdown is here: Today is the last day to cast your vote for the TechCrunch Disrupt 2024 Audience Choice program. Voting closes…

Last day to vote for TC Disrupt 2024 Audience Choice program

Featured Article

Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Among other things, Whittaker is concerned about the concentration of power in the five main social media platforms.

1 day ago
Signal’s Meredith Whittaker on the Telegram security clash and the ‘edge lords’ at OpenAI 

Lucid Motors is laying off about 400 employees, or roughly 6% of its workforce, as part of a restructuring ahead of the launch of its first electric SUV later this…

Lucid Motors slashes 400 jobs ahead of crucial SUV launch

Google is investing nearly $350 million in Flipkart, becoming the latest high-profile name to back the Walmart-owned Indian e-commerce startup. The Android-maker will also provide Flipkart with cloud offerings as…

Google invests $350 million in Indian e-commerce giant Flipkart

A Jio Financial unit plans to purchase customer premises equipment and telecom gear worth $4.32 billion from Reliance Retail.

Jio Financial unit to buy $4.32B of telecom gear from Reliance Retail

Foursquare, the location-focused outfit that in 2020 merged with Factual, another location-focused outfit, is joining the parade of companies to make cuts to one of its biggest cost centers –…

Foursquare just laid off 105 employees

“Running with scissors is a cardio exercise that can increase your heart rate and require concentration and focus,” says Google’s new AI search feature. “Some say it can also improve…

Using memes, social media users have become red teams for half-baked AI features

The European Space Agency selected two companies on Wednesday to advance designs of a cargo spacecraft that could establish the continent’s first sovereign access to space.  The two awardees, major…

ESA prepares for the post-ISS era, selects The Exploration Company, Thales Alenia to develop cargo spacecraft

Expressable is a platform that offers one-on-one virtual sessions with speech language pathologists.

Expressable brings speech therapy into the home

The French Secretary of State for the Digital Economy as of this year, Marina Ferrari, revealed this year’s laureates during VivaTech week in Paris. According to its promoters, this fifth…

The biggest French startups in 2024 according to the French government

Spotify is notifying customers who purchased its Car Thing product that the devices will stop working after December 9, 2024. The company discontinued the device back in July 2022, but…

Spotify to shut off Car Thing for good, leading users to demand refunds

Elon Musk’s X is preparing to make “likes” private on the social network, in a change that could potentially confuse users over the difference between something they’ve favorited and something…

X should bring back stars, not hide ‘likes’

The FCC has proposed a $6 million fine for the scammer who used voice-cloning tech to impersonate President Biden in a series of illegal robocalls during a New Hampshire primary…

$6M fine for robocaller who used AI to clone Biden’s voice

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Is it…

Tesla lobbies for Elon and Kia taps into the GenAI hype

Crowdaa is an app that allows non-developers to easily create and release apps on the mobile store. 

App developer Crowdaa raises €1.2M and plans a US expansion

Back in 2019, Canva, the wildly successful design tool, introduced what the company was calling an enterprise product, but in reality it was more geared toward teams than fulfilling true…

Canva launches a proper enterprise product — and they mean it this time

TechCrunch Disrupt 2024 isn’t just an event for innovation; it’s a platform where your voice matters. With the Disrupt 2024 Audience Choice Program, you have the power to shape the…

2 days left to vote for Disrupt Audience Choice

The United States Department of Justice and 30 state attorneys general filed a lawsuit against Live Nation Entertainment, the parent company of Ticketmaster, for alleged monopolistic practices. Live Nation and…

Ticketmaster antitrust lawsuit could give new hope to ticketing startups