Startups

To cope with stricter data regulation, enterprises should look to fully open APIs

Comment

High angle view of many yellow padlocks on yellow background. One of them is open.
Image Credits: Javier Zayas Photography (opens in a new window) / Getty Images

Jean-Paul Smets

Contributor

Jean-Paul Smets is the CEO of Rapid.Space, a hyper open cloud provider offering virtual private servers (VPS), content delivery networks (CDN) and global IPv6 (SDN).

Picture this scenario as a young enterprise: You are a customer of Azure, AWS, or the Google Cloud Platform, assuming they are the frontrunners. While traveling in Russia or a European Union country on a mission to expand your business, you discover that you’re required to have data locally stored. Even worse, in the EU, you face the GDPR and have national regulatory authorities warning you how using U.S.-based clouds in the EU violates the GDPR.

This is a huge problem. No matter where you go outside the U.S., you’ll have to comply with different regulations that could ultimately prevent you from deploying your applications successfully. By using the APIs of the big players, there’s either the possibility of no connectivity or even legal risk.

How can enterprises get around this issue? This is where fully open APIs based on open source software are a great help and the technology of the future.

“Fully open” APIs contain open source software with open source operation procedures so that the technology can be reproduced and audited in any region, which resolves the geopolitical conflict mentioned above.

Fully open APIs give the end-user control on how to debug the software (which powers the API) while also potentially keeping costs down due to their scalability and a complete lack of maintenance costs compared to a closed-loop system. These closed systems are limited by their dependency on a particular platform, driving costs and other limitations on developers. Fully open APIs don’t just harness open-source software, but rather are combined with a complete description of how the infrastructure is made and how it operated – it’s an entirely open process.

In Europe, security is becoming increasingly critical. New security qualifications, such as the French-German ESCloud Label for secure cloud computing, are examples of cooperation aimed at raising the level of cybersecurity in Europe. Any technology that extends the extraterritorial application of U.S. law could soon be banned from both government markets and processing personal data.

In many international markets, local laws regarding personal data require that the services or technologies used are free of technical components that could lead to foreign surveillance by the U.S. This creates an apparent conflict that is deeply connected to legislation, and U.S.-based companies that provide APIs are in the middle of it.

Adopting fully open APIs

To implement a fully open API, you essentially require an open process that lets third parties implement APIs independently of their original creator. For the process to be open, all the steps need to be described in such a way that a third party can reproduce them and verify that the outcome satisfies customer expectations.

Ideally, the software and hardware that implement the API should also be open source. Use of software without being able to audit its source code poses a risk of backdoor presence, which is incompatible with certain legislations for data protection. Use of hardware without being able to audit its design poses a risk of logistics attacks. Both risks are well understood by hyperscalers for their own infrastructures, which are now mainly based on open source hardware and software.

Enterprises should adopt the same attitude as hyperscalers when selecting an API. They should ask their API vendor: “Can you provide us with the detailed process, software, and hardware to implement this API by ourselves on a network without Internet access?”

If the vendor says “Yes,” it’s safe to assume this is a “fully open” API and you can use it without risk. Just make sure the API subscription agreement includes reversibility provisions with prices so that you can later access the process, software, and hardware to implement the API yourself.

If the vendor refuses, though, it will mostly be illegal to use the API in many regions globally, unless they already have independent, local partners to implement it in every region.

In Europe, ten cloud providers are offering governments to license their APIs – software, hardware, and processes. OVHCloud, which previously acquired VMWare vCloud, announced that it would make its cloud platform and APIs open source.

Rapid.Space has produced a step-by-step tutorial on installing open source networking APIs for the Accton Operating System on the Edgecore AS5812 switch. Many companies related to the open source community are ready to provide or develop fully open APIs at a very reasonable cost.

If your API vendor is adamant on refusing to let you maintain the API yourself, try explaining that you are not requesting to make its technology open source but only to license it. If they still refuse, then do as hyperscalers do – develop or sponsor the development of an open source software for a fully open API. This could even get you a tax break.

Why fully open APIs are the answer

We have already seen the implementation of document storage APIs used by the /e/ Foundation as an alternative to Google Drive. They provide the service, the source code, and the corresponding steps for installation so that anybody can reinstall it anywhere in the world despite any geo-restrictions in place.

Taking it a step further, enterprises that want to create a content delivery network (CDN) or implement their own instant messaging can look beyond Cloudflare or Whatsapp, which are restricted in various countries. Delta.Chat enables end-to-end encrypted instant messaging everywhere, even in North Korea, based on the standard Incoming Mail (IMAP) and Outgoing Mail (SMTP) server APIs.

Both APIs, widely available and already used by Gmail, can be replicated with open source software called Dovecot and Postfix. Nexedi’s SlapOS operation management software includes a cloud-native, open-source CDN that can be self-deployed everywhere, including in China. Again, these two solutions quell the problems created by data access being blocked in a particular country.

How secure is open source software?

Those considering switching cloud providers know that security is a priority concern – customers will make buying choices based on the reputation for confidentiality, integrity, and resilience, and the security services offered by a provider, more so than in traditional environments.

The development of fully open APIs marks a clear point of transformation regarding business behavior with data. The common wisdom used to be that organizations need to do everything in their power to hold data on their premises. This has evolved into enforcing trust through contracts and policy compliance with facility management and cloud. However, to take advantage of the sharing of tools and data through a “plug-and-play” model, it’s crucial to use fully open APIs.

In the case of clouds powered by proprietary software, the customer has no hope of discovering backdoors, because they have no access to the source code. They just have to trust the supplier without any way to verify what they are doing.

Open source projects at the core of fully open APIs are less likely to include bugs and security vulnerabilities than closed source clouds, because closed source clouds tend to have much longer release cycles for some of their software, so vulnerabilities will take longer to resolve. Many open source projects have hundreds or thousands of contributors who can review any problems almost immediately.

Beyond fully open APIs, open processes

Fully open APIs give any developer the same level of control and freedom in the cloud as open source brought to the software industry, with no adverse effects. They present an opportunity for greater innovation to customers, partners, and vendors in ways that we may not have already considered for APIs.

Creating a fully open API that the external end-user can integrate into their application and customize removes any barriers. With data regulations imposed by governments worldwide continuing to tighten, cloud computing isn’t far from hitting a wall, and embracing a completely open process for cloud-based on open source software could well prove to be the answer.

More TechCrunch

The startup has been pursuing a ground-up redesign of a well-understood technology.

‘Star Wars’ lasers and waterfalls of molten salt: How Xcimer plans to make fusion power happen

Sékr, a startup that offers a mobile app for outdoor enthusiasts and campers, is launching a new AI tool for planning road trips. The new tool, called Copilot, is available…

Travel app Sékr wants to help you plan your next road trip with its new AI tool

OpenAI’s chatbot ChatGPT has been down for several users across the globe for the last few hours.

ChatGPT is down for some, OpenAI is working on a fix

Microsoft’s education-focused flavor of its cloud productivity suite, Microsoft 365 Education, is facing investigation in the European Union. Privacy rights non-profit noyb has just lodged two complaints with Austria’s data…

Microsoft hit with EU privacy complaints over schools’ use of 365 Education suite

Since the shock of Russia’s 2022 invasion of Ukraine, solar energy has been having a moment in Europe. Electricity prices have been going up while the investment required to get…

Samara is accelerating the energy transition in Spain one solar panel at a time

Featured Article

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

It’s clear that this year will be a turning point for DEI.

11 hours ago
DEI backlash: Stay up-to-date on the latest legal and corporate challenges

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

Hello and welcome back to TechCrunch Space. Unfortunately, Boeing’s Starliner launch was delayed yet again, this time due to issues with one of the three redundant computers used by United…

TechCrunch Space: China’s victory

The court ruling said that Fearless Fund’s Strivers Grant likely violates the Civil Rights Act of 1866, which bans the use of race in contracts.

An appeals court rules that VC Fearless Fund cannot issue grants to Black women, but the fight continues

Instagram Threads is rolling out the ability for users to signal which sort of posts they wanted to see more or less of by swiping.

You can now customize your For You feed on Threads using swipes

The Japanese billionaire who commissioned SpaceX for a private mission around the moon on a Starship rocket has abruptly canceled the project, citing ongoing uncertainties around when the launch vehicle…

Japanese billionaire pulls plug on private ‘dearMoon’ lunar Starship mission

Malicious actors are abusing generative AI music tools to create homophobic, racist, and propagandic songs — and publishing guides instructing others how to do so. According to ActiveFence, a service…

People are using AI music generators to create hateful songs

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC

Dallas is the second city that Cruise is easing its way back into after pulling its entire U.S. fleet late last year.

GM’s Cruise is testing robotaxis in Dallas again

Featured Article

After raising $100M, AI fintech LoanSnap is being sued, fined, evicted

The company has been sued by at least seven creditors, including Wells Fargo.

16 hours ago
After raising $100M, AI fintech LoanSnap is being sued, fined, evicted

Featured Article

Sonos Ace review: A high-priced contender

The Ace are a contender in a crowded market, but they’re still in search of that magic bullet to truly let them stand out from the pack.

16 hours ago
Sonos Ace review: A high-priced contender

The change would see Instagram becoming more like the free version of YouTube, which requires users to view ads before and in the middle of watching videos.

Instagram confirms test of ‘unskippable’ ads

Commerce platform Shopify has acquired Checkout Blocks, allowing Shopify Plus merchants to make no-code customizations in their checkout to enhance customer experience and potentially boost sales.  Checkout Blocks, which debuted…

Shopify acquires Checkout Blocks, a checkout customization app

After the Digital Markets Act (DMA) forced Apple to allow third-party app stores for iOS in Europe, several developers have launched alternative stores, like the AltStore and MacPaw’s Setapp (currently…

Aptoide launches its alternative iOS game store in the EU

Time is relentless and, right now, it’s no friend to procrastination-prone early-stage startup founders. The application window for Startup Battlefield 200 (SB 200) at TechCrunch Disrupt 2024 slams shut in…

One week left: Apply to TC Disrupt Startup Battlefield 200

Cloudera, the once high-flying Hadoop startup, raised $1 billion and went public in 2018 before being acquired by private equity for $5.3 billion in 2021. Today, the company announced that…

Cloudera acquires Verta to bring some AI chops to its data platform

The global spend management sector is experiencing a tailwind of sorts. North America is arguably the biggest market in this space, but spend management companies have seen demand rise across…

Spend management startup SiFi raises $10M to grow further in Saudi Arabia

Neural Concept lets designers model how components will perform before they can be manufactured.

Swiss startup Neural Concept raises $27M to cut EV design time to 18 months

The StrictlyVC roadtrip continues! Coming off of sold-out events in London, Los Angeles, and San Francisco, we’re heading to Washington, D.C. for a cozy-vc-packed, evening at the Woolly Mammoth Theatre…

Don’t miss StrictlyVC in DC next week

X will now allow users to post consensually produced NSFW content as long as it is prominently labeled as such.

X tweaks rules to formally allow adult content

Ashby consolidates existing talent acquisition tools and leans heavily on AI to automate the more repetitive steps in the recruitment pipeline.

Ashby injects recruiting with a dose of AI

Spotify has announced it’s hiking subscriptions for customers in the U.S., the second such price increase in the space of a year. The music-streaming giant reports that premium pricing will…

Spotify to increase premium pricing in the US to $11.99 per month

Monzo has announced its 2024 financial results, revealing its first full-year pre-tax profit. The company also confirmed that it’s in the early stages of expanding into the broader European market…

UK neobank Monzo reports first full (pre-tax) profit, prepares for EU expansion with Dublin hub

Featured Article

Inside Apple’s efforts to build a better recycling robot

Last week, TechCrunch paid a visit to Apple’s Austin, Texas, manufacturing facilities. Since 2013, the company has built its Mac Pro desktop about 20 minutes north of downtown. The 400,000-square-foot facility sits in a maze of industry parks, a quick trip south from the company’s in-progress corporate campus. In recent years, the capital city has…

1 day ago
Inside Apple’s efforts to build a better recycling robot

Early attempts at making dedicated hardware to house artificial intelligence smarts have been criticized as, well, a bit rubbish. But here’s an AI gadget-in-the-making that’s all about rubbish, literally: Finnish…

Binit is bringing AI to trash