Automatically transcribed, so names and technical terms may be misspelled. The audio is the record.
The Colorado Equals Security podcast is your local source for regional security news, local events, and interviews with key individuals in the region. Now here are your hosts, Robb Reck and Alex Wood. Welcome to Colorado Equals Security. This is your newscast for episode 214 for the week of June 14th, 2021. Alex, we just said we're almost halfway through this year.
It is hard to believe we were already halfway through the year, Robb. I feel like the year— I think I feel like 2020 just started. Yeah, it has been. It's been— I mean, relative to the year, the bar that was set last year, it's been a pretty good year. Yeah.
At least we're able to go do some things. The world is a little bit more normal. As you know, I just got back from my, my 2-week road trip out going east. We, we saw all of the parts of America that I had never wanted to go to before. It was fun.
That is pretty fun. How many states have you been to, Robb? Are there still states that you haven't— do you need to check off your list? You know, I don't know off the top of my head. I have a few states left.
I didn't make it to Vermont when I was over there. I haven't been to Montana yet. There's just a couple left that I need to— I can't remember if there's another one or two, but I'm just about done now. I don't remember the number either, but I'm in, I'm in the 40s. I think Vermont is still one for me and Maine.
Well, so you think to yourself, oh, I'll just go to Maine and Vermont. Vermont's kind of a pain in the butt to get to. We, we did a drive from Boston up in New Hampshire and, you know, up to, up to Maine, enjoyed the whole coast. But yeah, if you're going to go to Vermont, you're going to Vermont like for the sake of checking Vermont off your list. It's like 3 hours west.
So you're, you know, if you're just doing a like we did like a 5, 6 day trip, Like you're really kind of killing a day to just to check off a state. And I wasn't up for that. Vermont's not important enough to you to kill a whole day? The Ben and Jerry's factory may very well be important enough for me. But, you know, we didn't do it this time.
Oh, well, next time. All right. Hey, let's jump into some housekeeping. As a reminder, we have a Slack channel. We'd love to have you guys join us over there.
We have over 1,900 folks. Go out to the website, colorado-security.com, and click the link to request an invite to Slack. We also have a mailing list while you're on the website. Uh, go to the mailing list form, put your email in, sign up. You'll get one email every week from us letting you know what the show notes are.
And, uh, that's it. And if you like the show, we would love it if you would rate us on your favorite podcatcher. Let people know, um, that Colorado Equal Security is the best place to stay connected with the Colorado security community. Um, and of course, we'd love it if you would subscribe. So each week the show comes into your inbox with no extra effort.
Yeah. And you can also tell a friend, let them know all the great things happening with Colorado Equal Security. And if you want to really go over the top and you want to support us financially, we do have a Patreon campaign that, that campaign helps us cover the costs that we have for the podcast and all the other stuff. And big thank you to the current patrons. We really do appreciate you guys kind of give us the inspiration to move on.
You are the wind beneath our wings, as, as the famous song goes. Are we going to splice that in after the fact? Put a little music behind the scenes. Pause for the splicing. Hope you guys enjoyed that.
All right, Alex, not only was I on the road last week, but you were doing something big last week. What was going on? Yeah, last week was the annual Rocky Mountain Information Security Conference. A little bit different this year as that it was a virtual conference. You know, it was in the sweet spot of when people could come back and see each other again, but that we didn't know that, you know, 8 months ago when we started planning.
So we figured it was safest just to plan for a virtual conference. Nonetheless, it was a great show, some great keynotes, a lot of great, great talks. Of course, even if you didn't attend, then you could actually register after the fact and see all of the recorded sessions. I think we're still working out the details on how to do that. But, you know, even if you want— didn't— weren't able to attend but wanted to come see some of the great sessions, they're all recorded, all available for several months.
That's awesome. And I have heard some really good things about a few of the sessions. So I think it's worth signing up and poking through to find what content you enjoy. Now, wasn't there like an in-person element to one single happy hour? We did have a closing happy hour on Thursday so that we got some people together for that.
That turned out nice as well. But we had several in the hundreds of people that attended, and obviously we couldn't have that many people attend the happy hour. So much smaller. All right. Well, hey, let's jump over to some news.
We have a story this week about a Stealth Denver popcorn startup. This is not words I ever thought I would string together. Yeah, those things don't seem to go together in my mind, but it is pretty cool. This popcorn startup. Okay, what do you think?
How do you pronounce it, Robb? Do you think it's a pop pop? Oh, pop pop.
Oh, pop pop. You think it's oh pop pop? Yeah, that's what I was gonna guess too, but it's also pop. Op op op. Op op op.
It's O P O P O P. Correct. And you wouldn't think popcorn and startup and stealthy for that matter would go together, but these guys have been working on this startup for a little while now, and their first product is actually better flavored popcorn. So it's it's interesting because they first called themselves a popcorn technology startup. Right? When you read the article, and I was like, well, does that mean that they're like creating technology for other companies that make popcorn?
To do better making their popcorn, better poppers, or that kind of thing. That's what I was wondering. And the people who created this, um, at least one of the two was really involved with the, uh, Apple Music product back when it was Beats Music. Um, and so really kind of an entertainment technology background. Um, but the very first line that the thing I pulled out of this was, um, maybe we can make popcorn cool, wondered one of the founders.
And, and I wondered to myself, Is it possible to make popcorn cool? Well, they're gonna try and find out. Yeah, it seems like they were going down the road of, of technology and maybe making physical devices to make popcorn better or something like that. But it seems like they have stalled on that, still working on it. But their first product to get something to market was actually kernels that are covered in flavor as opposed to adding flavor after the fact.
Yeah. So you basically cover each of the individual kernels in some flavoring. And then you pop it and it, it's supposed to work really well that way in terms of flavoring. Now, and what, what it suggested to me in the article was that maybe they were trying to sell a technology that does this, covering the kernels, right, to different popcorn companies. And all those companies were like, well, let me try your popcorn.
And they're like, well, if everyone wants to try our popcorn, why don't we just start selling this popcorn? Right. Uh, right now they have 6 flavors which you can buy through their website, uh, including fancy butter, you know, not regular butter, fancy butter. Yeah. Salted umami and vanilla cake pop.
Yeah, and there was another— I looked at the website and there was something that looked pretty good to me, some kind of spicy— now I can't remember what it was, but something spicy. I'm like, ooh, I'd like to try this out. So anyway, Fancy Popcorns. These folks have raised over $11 million as a part of this company, so they are— they've at least convinced some investors that they have a real business. Yeah, and one quote in here says, over the next 36 months, we're gonna be really busy We have 2 or 3 more launches of major products this year.
And then it all ladders up to the bigger stuff next year. So, you know, we're still in the beginning of this, there's going to be much more to come apparently from Oh Pop Pop. I can't wait to see it. And of course, I can't wait to hear how they really pronounce their name. Well, you know, hopefully, Robb, their popcorn machines that come out don't burn the popcorn.
But there's a lot of Denver workers out there that have been burned because Denver worker burnout is at an all-time high. Well, your smooth, smooth segue is well appreciated, Alex. And I would say also that this popcorn could be a nice employee perk that you could give your employees to stop them from getting so burned out. That's true. This is an article here from— oh, I started that sentence without knowing the answer— from the KDVR.
Yeah, from Fox News. Fox News 31. But it's really just referencing a study that was done nationally by someone. Man, I'm doing really well right now. You can tell you've been on vacation, Robb.
The bottom line here is that 44% of Denver workers say that they are more burned out now than in June of 2020. Robert Half made this survey. Oh, okay. So, so a lot of folks are burned out in Denver. We're not at the top of the list.
Fortunately for us, that's Charlotte, North Carolina. Yeah, but we are pretty high on the list for burnout. And I think there's no surprise, right? It's awfully hard to to go through what we've done over the last year and work from home as earnestly as we have. There's a couple tips in the article about how to alleviate it.
It's really to be disciplined and committed to taking care of yourself and create that boundary between work life and personal life. And the better you are able to create maybe the kind of like ceremonies, like beginning of the day, okay, I'm doing these things that tell me it's work time, and then a ceremony at the end of the day, Those make a big difference in terms of keeping those separate and avoiding burnout. I'm also pretty sure it said in there that you should take the summer off and go on road trips. But I think that that will only help your burnout. Yes.
Hey, speaking of things, there's a Denver startup that's a Postmates for staging. This is for staging homes, and they just raised a $3 million seed round. Yeah. As I was going into this, I thought, really? So someone's trying to say that they're a whatever for staging.
I mean, staging a house in my mind doesn't seem like it is really that difficult and that you really need to disrupt that industry. But according to these guys, it was something that there was room to do. They started out doing something else. And now that I'm going to have vacation brain too, even though selling bags, he was selling bags, but from his house. And as people would come and they would admire his furniture and they would ask, oh, you know, where's that from?
Can you know, where can we buy that? Right. Can I, can I have your couch too? Are you selling your couch? And so it all led to the fact that they thought, oh, well, maybe there's a market here for us to do this as part of staging houses.
We could get these, these great products that people like, put them in houses, and then, you know, either sell it to the people that are are looking to potentially buy that house, or if someone is going to be moving in and, you know, buy the house, they could say, well, why don't we just keep that couch and we'll, you know, pay for that and just leave it here? So, so they've created this business where basically in these few different markets they're in— Denver is one of them— they will put a well-vetted stager out to your place to stage, to put furniture in there. And they say they have stats that houses that use their staging sell 40% faster and average 5% more on the sale price. That's pretty cool. Yeah, they did mention that many of the current staging companies have old, not necessarily fashionable kind of furniture that they're using as part of the staging.
So, you know, when these guys bring in sort of name brand stuff from Crate and Barrel and West Elm and wherever else, they said it makes your house look better. So the— they do say they're going to use the money from this raise to scale up their platform, grow their platform, scale the team. It's currently 12 employees. They're going to grow from that 12. So it's a real business.
Did we even say the name? It's called Guest House. I don't think we did. I don't think we did. Guest House.
Yeah. Yeah. Take a look at them. Yeah. Pretty cool.
Next, 2 Colorado companies have made a big jump in the Fortune 500 rankings that just came out. And these 2 companies are Dish Network Newmont Mining. So pretty cool. Dish Network, definitely not a surprise to me as they are expanding their business and moving into wireless, you know, rolling out their 5G network. So that seems to me like a good reason for them to move up on those Fortune 500 list.
So basically it's what rank did they move from and to on the list. That's what this is about. And, and Dish had moved from number 251 last year to their 197 now. So they moved up quite a bit. Newmont, they moved up 55 spaces as well, or 55 spaces, and now they're at 273.
So they— big growth there. They actually have the whole list of Colorado companies in the Fortune 500 and how they moved. You know, number 1 for us in town is Arrow. Arrow is actually number 8 in the Fortune 500. That's a lot of revenue, right?
Yeah, a lot of revenue as a distributor. They have an awful lot of money that goes through them. Some other interesting ones on here. I'll tell you, as I was reading it, I did not remember who Eventive is, but that's the new name for Encana, the natural gas company. So Encana is now Eventive and they are here in Colorado.
I didn't— I actually thought they were a Canadian company, but they're numbered 458. Yeah. Also DCP Midstream, another oil and gas company at 442. Uh, some other big names. Um, uh, Corte Real, uh, excuse me, Retail, which is, uh, that's the QVC parent company.
Yeah. Um, Ball, VF Corp. Um, you know, that pretty cool VF Corp is on, on that list since they just moved here a couple years ago. Uh, DaVita and, uh, Liberty Media. So good stuff. Good stuff.
Can you go next? I just lost my Trello. Uh-oh. Next we have— oh, this is actually really big news. The Colorado legislature has passed the Colorado Privacy Act.
So we've talked about the Colorado Privacy Act several times in how it was introduced and then watered down and then maybe unwatered down and then finally got passed. So we are just waiting for the governor to sign the Colorado Privacy Act and then it will become law. Yeah, it went pretty fast. The House passed the final version on the 7th and the Senate passed it on the 8th. So we're really just waiting on— maybe by now it's been signed.
I don't know. I haven't heard. If so, I think when I looked, I saw an article from Friday that said it had not been signed yet. So I'm guessing probably this week. Awesome.
Well, that's going to put us on that very elite list of states that have their own privacy regulation. Uh, what is it? California? Is it Massachusetts? Virginia?
Virginia. Virginia. And then now Colorado will be one of 3 and, you know, give it 18 months and we'll be one of 30. Uh, yeah, that, that's potentially true. So, hey Alex, have you thought to yourself, you know what, I need a really expensive keyboard?
Because if so, I've got good news for you. You can buy a Colorado-made keyboard. Uh, not only that, it's a Colorado-made keyboard, um, with real clicky-clack switches. So if you want to have that tactile feel of real switches, not the these cheap keyboards that they make these days, then this is for you. Yeah, I actually would really like to have this keyboard.
I'm throwing rocks because I'm jealous. So this is made by System76, which we've talked about on the show a number of times. Yeah, they've created the— I think it was like the only US-manufactured laptop, right? Something like that. That they are maybe like the only US-manufactured Linux laptop, something like that.
Yeah. Hard to remember. Yeah. Anyway, they are creating and manufacturing this this new keyboard here in Colorado. It's, uh, it works with Linux, Windows, and Mac.
It's 100% open source. And, uh, and I'm, and it's beautiful. Or it, it looks old is what it looks like. Yeah, it does look old. It's got big keys.
Uh, you can actually, uh, get different types of switches, one that is really loud and one that is less loud. Um, you, you can, uh, it's easy to move the keys around if you wanna change, uh, configurations or they have some extra key colors if you need to, you know, have your S be blue instead of white or whatever. I think it looks great. I think the only thing I'm disappointed about is they do not have a tenkey option, understanding that, right, they're selling it as a benefit that your mouse is now closer to your keyboard. But I would like the tenkey option.
And that would, that would probably put me over the top on this one. You know, honestly, I use the tenkey so little that I probably wouldn't miss it there. I mean, I do use it occasionally. Um, when I want it, I really want it though. I'm gonna do a lot of numbers.
Yeah, I suppose I did. I, I did, uh, like accounting in school and, and I got really used to 10-key. Go fast. I can go much faster that way. Yeah.
I mean, you can always get one of those, you know, the extra 10-key keypads for the couple times you need 10-key. I could do that anyway. Uh, also, uh, you know, you mentioned how this is a very expensive keyboard. I don't think we said it starts at $285. So it, It's not cheap.
It only goes up from there. It only goes up from there. That's where it starts. That's like when you buy your Tesla, right? It, right.
The, the, the option price starts at, starts at $38,000, but we'll see you at $150,000. I did not pay $38,000 for my Tesla. Uh, all right. Uh, moving on. Uh, next we had an article from Coalfire talking about, uh, transitioning to the new version of, uh, Star because of the cloud control matrix version 4.0.
So 4.0 is the newest and greatest. This is the, uh, the Cloud Security Alliance's standard that basically different vendors can be judged against or use themselves to talk about their security practices. You know, coming from a SaaS vendor, we've used STAR in the past. Alex, what's in this new version? You know, I've, I've been told that version 4.0 is, uh, 33% better than 3.0.
Um, uh, anyway, uh, so the— for those of you that don't know, the Cloud Controls Matrix is, uh, from CSA. This is their, uh, their version of a control framework for cloud security. Uh, the STAR is the registry that you can be part of if you are certified on the Cloud Controls Matrix. And, uh, with this new version, they have added some additional controls more in the privacy area, more in encryption. They've changed some wording.
I think that the— they said the last version 3, I think, came out— or no, sorry, the last version of version 3, which was, I think, 3.1.1, came out in, I believe, 2019. So it's been a while since they've updated this. And obviously the— obviously the cloud has changed a bit since 2019. So it makes sense that they are— they're adding new stuff to this. If you are someone that is on the STAR registry or being audited against the Cloud Controls Matrix, you'll be required to use the new version 4 sometime by the middle of 2022.
All right, good stuff. Moving along, we have a blog this week from Red Canary, and this is about how you're going to basically test your Linux runtime threat detection tools. When you think of, call it like what, like host intrusion detection systems, EPP, EDR, whatever you want to call it, on a Linux box. It really is different. Um, on, on Windows or Mac, you have relatively closed environments where, you know, if you say I'm on Windows, well, I say, okay, well, what version of Windows?
And then you know. But with Linux, there's so many different flavors and different versions, it's much more difficult to, to test. So this article from Red Canary is getting into if you're going to put some kind of threat detection on your Linux boxes, here's how you know if it's going to work in your environments. And, and just because they say they have Linux support doesn't mean that that support's going to work for what you're actually running, right? Yeah, it's a, it's a pretty interesting article talking about doing those— that testing.
And, um, after reading it, it's, it's something to me that seems pretty obvious, right? That there is enough difference that you're going to want to test this. But, you know, probably something that I hadn't really thought about enough in the past that is probably something you really need to do. Yeah, I think of this as something that it's perfect for, for search engine optimization. If, if you need to test EDR on Linux, that's a good search and this is going to show up.
Hopefully it shows up and then you'll have your answer because they, they give you specifically like what the test should look like and walk you through how to, how to do it in more detail than just like you and I could brainstorm right now, right? Yeah, while this wasn't a, uh, you know, a detection engineer blog It is another one of the very detailed blogs from Red Canary. So good stuff. All right. Final article of this week is from LogRhythm talking about the top 8 benefits of a remote internship at LogRhythm.
Pretty cool stuff. LogRhythm, you know, local security company. They are, they are, they have an internship program and this was actually written by one of their interns. I couldn't tell if it's a current or past intern, but someone who talks about what their experience looks like. And why it was such a good experience for them.
Yeah. First on that list is doing impactful work. They say from the start you're going to be actually doing work with them, not just, you know, sort of getting coffee and donuts and that sort of thing. Yeah, they're— they have a networking program for the interns. They also provide additional learning modules and mentorship.
They're going to be doing a presentation. The interns will do a presentation Um, I think it includes members of the executive team that are part of receiving that presentation. So you have a project you're going to present, and then of course you have an individual project that interests you, and that's the kind of work you're going to be doing there as some part of your work. Yeah, they also encourage self-guided learning for their interns by providing a Udemy subscription to all the interns, as well as getting used to actually working at a real company. So they talk about business workflows, you know, Agile ceremonies and other things like that that you might experience as part of working in IT.
That's it. Well, good stuff. Good on LogRhythm for having that program. Let's jump over to our Slack message of the week. Big thanks to Andre Gade.
It's actually not Slack message of the week, is it, this year— this week? No, we are— we're doing a little different. We're switching it up. We talked about it a few weeks ago that we wanted to recognize a member of the community who, who really just makes the community better for other folks, and that's what we're gonna do this week. But I do need to once again thank Andre.
Andre, who allows us to recognize folks and gives a prize for this. So the person who we recognize here is going to get to pick an item from the Colorado Equal Security store. Yeah. And in case everyone forgot, we, we took some nominations from people in the community about who they thought deserved an award like this. And this week's winner is Greg Sternberg.
Greg Sternberg. Greg, I mean, you and I have known Greg for a long time. Yeah. How long did you work on it? When did you guys work together on ISS?
Yeah, I mean, we worked together at ISSA for, you know, many years ago. I don't even remember when it— when he first started volunteering with us, like a decade plus ago. And, and when I was president after you, he was an active member of the board. And he's been not only involved with ISSA for a long time, and he— we were talking about he's generally the one who would go to the— go to the meetings that I'd be there, right? Like, right, we just need people to be at the meetings to, to get things set up and, and do registration and all that.
And he was always willing to be that guy to show up. We appreciate that. He's also a regular speaker at security events around town. He's an expert in architecture and AppSec, and, uh, he, he shares that in a number of different speaking opportunities. Uh, and many of you may not know Greg because he does tend to keep a low profile, and he does this because he loves to do it, not because he wants recognition.
Yeah. And I will just throw out one other thing. At the beginning of COVID uh, Greg volunteered to run a a Colorado Equal Security Dungeons and Dragons campaign. So he's been doing that for the last year. Greg, thank you for all you do to support the community.
Well, that you, you'll get one item from the store email coming soon. All right, uh, let's jump over to the events. As a reminder, we do have a calendar of events on our website. You can see all the good stuff coming in the area over the next few months. Uh, so first, on Tuesday the 15th, uh, the Colorado Equal Security Poker Night.
I think that there are still a few spots available. Uh, come onto the Slack channel and join the, the poker channel there and, uh, or talk to Jason Jaques for more details. Yeah, I, I am supposed to be defending my title at this tournament. We'll see. We'll see.
Number one, if my personal life allows me to show up, and number two, if I can once again take home all of the money. Uh, also on the 15th, the Cloud Security Alliance has their June meeting. On the 17th, ACES is doing a, an event called Propaganda and Extremism Today, which sounds really interesting. It's probably not for helping increase propaganda. I hope, I hope this is about combating it.
On the 17th as well, Denver IA— the Denver IAM User Group has a meeting that's embracing disruption and identity proofing. On the 23rd, ISC² Pikes Peak is doing their June hybrid meeting. Also on the 23rd, our last event here, the Denver Splunk Meetup is doing an in-person event at the Wynkoop. What? They're going to be increasing value and managing costs with Splunk DSP and workload pricing.
I don't know what that means, but it's in person. You'll get to find out in person. There's probably beers. I would hope so if you're at WinCoop. All right, so go ahead and jump over to jobs.
Starting at the top here, we have a job at Vail Resorts working with our friend Ian Buxton. This is for a director of IT security. CoBank is looking for a security manager for threat management. Uh, Charles Schwab is hiring a senior manager of security. Premier Members Credit Union is looking for an information security manager.
Oracle is hiring a development security manager. Netscope is looking for a senior product security engineer. SCL Health with our friend Howard Hale is hiring an IT risk analyst. Coinbase is looking for a product manager for security engineering. That sounds cool.
Guild Education, which is like the hottest unicorn here in Colorado, they're hiring a senior information security analyst with Julie Ciccolo. And the Boulder Valley School District is looking for an information technology security specialist. Good stuff. Well, that is it for the newscast. We once again, we have a nice long run of having interviews.
We do have an interview this week as well. This week I sat down with the co-founder and CEO for HACA, which is a local security company, Travis Goode. Travis, super interesting guy. Repeat entrepreneur, um, really helping tackle the problem of security awareness training and security. And I'm excited to share what he's doing with you guys.
Sounds awesome. I look forward to it. All right, well, that is it. We will talk to you guys again next week. Thanks, Robb.
This is Cole Metzner, IT Security and Compliance Officer for Unifocus. Welcome to Colorado Equals Security, the podcast for Colorado security professionals by Colorado security professionals. All right, welcome to the interview portion of Colorado Equals Security. This is Robb, and today I am sitting with Travis Goode. Travis, you are the co-founder and CEO of a local company, Haika, and we've talked about Haika here on the show, I think maybe once or twice over the years.
I think you guys were a part of Techstars and some interesting stuff we'll get into there. But first, I'm super interested to hear about your family and what you guys are doing that's maybe a little bit Um, more, uh, well, animal-focused than some of us. So tell me what you guys are doing. Yeah, so, um, I guess we, we have a— I have a big family, and that includes 4 kids. But then also, uh, sort of beyond that, we have a lot of, uh, lives that we've, uh, sort of integrated into our, into our lives and into our, into our property here outside of, uh, Steamboat Springs.
So we have what we describe as a hobby farm to differentiate from the fact that, you know, we're not really dependent on it for a living, but we got into raising animals probably 6 or 7 years ago now. We started just, you know, with chickens and over the years we've had, you know, milking goats and meat goats and llamas and my wife's really into like mini animals. So for some reason, like mini horse and mini donkey, which is kind of odd, but you know— So you gotta tell me about a mini horse and a mini donkey. Is this like a horse the size of a German Shepherd? What are we talking about here?
Yeah. So the one we have is actually, we had the mother and father, it was actually born on our property. And so when it was born, it was like teensy. I mean, you could carry it around, it could go like in our house and stuff. He's more like 200, 220 pounds now.
So I guess maybe like a really big St. Bernard maybe. How tall? Ooh, that's a hard one. I would guess, He's probably 3 feet-ish. I mean, that's a pretty small little— he's got some decent girth.
Um, I mean, the entertaining thing about him is he thinks he's a— he thinks he's a full-size horse, so like he'll try to like act like he's a full-size horse at times. But like, you know, his— when he like rears up, the, the highest he can get is maybe like shin or knee level. Um, he's just not very agile, uh, based on that shape. Uh, but yeah, he's, he's He's relatively entertaining when he's not, you know, getting into things he shouldn't get into. So, so how many— do you just have the one miniature horse now?
You said the mom— yeah, we had 3. We have one. When we moved, we moved to Colorado about 3 years ago from— we lived in Taos, New Mexico. And we— anyway, we pared down the horses at that point. So we just have one horse.
We have one mini horse and one mini donkey to keep it company. And then they live with 3 llamas. Uh, that we have as well. So does the— is a mini donkey roughly the same size? Is that bigger or smaller?
Yeah, he's, he's like totally misshapen. Um, like he's a little bit bigger in terms of body size, but his head is like almost the size of a full donkey, which makes him like kind of entertaining, um, to look at. Uh, and he, and he's, he's loud as a, as a regular donkey. So you can definitely hear him. Um, and somehow he can hear like every stirring, um, you know, at the house in the morning.
So you, you hear him braying, um, as soon as, as soon as anybody's out. In the house. So you've got chickens, you get eggs, and you get milk from goats, and sounds like meat from goats. Any other parts of your diet coming from animals? Yeah.
So we have— yeah, we do. We don't have goats anymore. We've done those in the past. We have turkeys that we raise for eggs and for meat as well. And then for part of the year, our kids raise pigs.
Um, and they do that as a part of like 4-H projects. And so pigs are, you know, you have them for, I don't know, 4 months, maybe, maybe 5 months depending on when you get them. Uh, so it's a pretty short stint. And, and here where we live outside of Steamboat, I mean, you know, it's— we have friends who have, have property and animals where it's a little bit warmer year-round. Here it's, uh, the winter is, is, is like super challenging, uh, with animals.
And so it's kind of nice with pigs at least to only have them Um, when the, when the ground is mostly thawed, it makes it a lot easier. Yeah. Well, that's awesome. I am, I'm so excited to hear these stories. Thank you for sharing.
Um, that sounds like a lot of fun. Well, let's, let's go back, uh, and start off at the beginning. Where, where are you from? Uh, so I'm from, um, a place that is nothing like where I live now. And, you know, I didn't grow up raising animals, so I'm actually from South Florida.
Really just kind of the epitome of like suburbia in a sense. And so that's where I actually, my wife and I, we met in high school. So we both are from South Florida and still, I still have some family there and go back from time to time. My sister's getting married this summer in Florida. So I'll be back there this summer.
It was a fun place to grow up, very different from where I live now. Yeah, both in terms of, in terms of like every single aspect— climate, culture, uh, you know, pretty much everything is different. Uh, but it's a— we, we like the— we, we really love the seasons. Uh, and so that's why we, we really kind of have fallen in love with this, this part of Colorado. Um, so your wife and you met in high school, and, and my wife and I also met when I was in high school.
Um, did, did you guys date in high school and then, you know, go all the way through? Did you, did you break up? Like, did you— didn't Were you friends for years? Like, how'd that work? Yeah, so we dated in high school, and then we went through a period— we went to actually different colleges.
I went to University of Florida and she went to Brown in Rhode Island. And so we kind of went through a period like where we broke up in college, and then we got back together in college, and then at the end of college moved in together and moved in and got married, depending on the order for grandparents there. And yeah, and that was still on the East Coast. So we were in DC at the time and eventually made our way out here. But yeah, we've known each other since, you know, or we met each other like when I was 15, she was 14, and then dated and then, you know, kind of a small break and then got back together and have been together all the way through.
It's kind of fun. Like there's not a lot of surprises, right? Like all of your histories are all pretty well out in front of each other. Yeah, yeah, I think that's true. And your families tend to know each other, you know, like your families have that history and background as well, which is— I don't know, I guess I don't know anything else, uh, but it works well for us.
That's awesome. All right, well, let's, uh, let's, let's dive into your, your kind of education. You said you went to University of Florida. It looks like you got your, um, your bachelor's in information systems. Yeah, I got my, uh, yes, uh, master's, bachelor's and master's.
Excuse me, in information systems. And then I was recruited out of college by a partner at PwC who went to the University of Florida, a guy named Paul Connolly. Super, super cool guy. He's actually, I think he still is maybe the CISO at, oh man, why am I blanking on the largest like healthcare, HCA, sorry, in Tennessee. He's there now, but he recruited me.
He was like, really cool history. He was communications officer for the Reagan White House, and so has all these really interesting stories about secure communication links on horseback with Gorbachev and Reagan. Anyway, so he hired me and I worked at PwC and Booz Allen Hamilton out of college doing cybersecurity assessments, like white hat hacking, pen testing, things like that. Yeah, it's pretty Wild West. It looks like 2002 to 2006 timeframe, Yeah, you guys are probably, you know, kind of creating a lot of that on your own.
Uh, yeah, I think the tools are a lot better now that you can, you can download and, and, and automate. Um, so yeah, we, we, we did end up doing, uh, actually a lot of, um, programming and tool creation. It was a lot of fun. I mean, I really enjoyed it, uh, you know, learned a ton. Um, like the group I was working with, and, you know, right out of, right out of college to be able to do that and and travel and have those experiences.
I really enjoyed it. Yeah. Well, if your LinkedIn profile is any indication, it looks like after Booz Allen, you made a pretty significant veer in your career. Yeah. Yeah.
Yeah. I did. So I ended up going back to school, going back to graduate school, to medical school. I had spent some time working, shadowing with a couple different physicians. I was living in— when I was working for PwC in Booz Allen, I was working in the DC metro area, and I started actually just sort of shadowing to explore, you know, different career paths.
And I don't come from like a family of doctors, and so, you know, if you don't, you tend not to get much exposure to that world. And so that exposed me to that world, and I felt like it was what I wanted to do. And so was fortunate. I actually had to take some additional prereqs, um, while I was still in DC, um, to, you know, sort of finish out my application, but applied to med school and, um, was fortunate to, to have some options, and, and one of them was the University of Colorado. And so, uh, that brought me, uh, off the East Coast and got me to Colorado and to Denver.
So a guy who had a bachelor and master's in information systems with 4 or 5 years of analyst kind of doing security assessments is able to get into medical school. That's a path that exists, or you created that path, I guess? Yeah, so medical— yeah, yeah. I mean, it's not a path, I guess, but, you know, medical school, I can't remember, you know, there's lots of stats about like what the average age is now coming into medical school. So you have a, like, an interesting mix at some schools, medical schools more than other schools, where you get an interesting mix of people that are, you know, 3, 5, 8, 10 years into some career and they're shifting to something else.
So I was definitely not the only— I mean, I think I was the only one probably that was doing like the type of cybersecurity work I was doing, but, you know, I met a lot of people that were, you know, computer programmers or, yeah, I mean, farmers, you kind of name it. There's kind of a broad range these days in medical school, but yeah, yeah, so it was definitely a different path and it getting back in, you know, to the— and med school's kind of, you know, it's— you start strong in terms of the requirements and the academics. And so like getting back into it after being kind of out of it for 4 or 5 years was definitely a, you know, an awakening. But, um, but yeah, I mean, I, I actually really loved, uh, medical school. It was a, you know, it was a great— I ended up doing 5 years because I did, uh, I added an MBA year onto my MD.
So you can do that at Colorado as a 5-year program. You take a break for a year from medical school and do a year of business school to do your MBA. And so, yeah, but I love those 5 years. I really enjoyed it and exposed me to the healthcare system in a way that I think is hard to get exposed to it in other ways. And so, yeah, it was a great 5 years and it was great to get out to Colorado.
And so, I'm certainly not a doctor, but I think basically you do the in-class learning and then you're going to do residency and internships. Is that true? Yeah, so, so yeah, so medical school, I mean, there's some variations on this now in the US, but you know, yeah, by and large it's, you know, 4 years. And traditionally it's 2 years of like classroom work and 2 years of clinical work. Yeah, that, you know, that's kind of skewed a little bit these days, or people are changing that.
But yeah, and then you end up doing anywhere from, you could do a 1-year like internship you know, through, you know, residencies plus fellowships. And, you know, you can kind of keep going with training forever if you want to. But yeah, medical school, you, after medical school, after you graduate and get your MD, you apply to the residency match and that kind of determines the direction you go in terms of clinical specialty. So you finished your education and then next would have been residency. Did you do a residency somewhere?
No, I didn't. So next would have been residency. You know, interesting one on that. So I, I wasn't sure what clinical specialty I was interested in when I was in medical school. I went back and forth between emergency medicine and ophthalmology.
And the interesting thing about that was I had done some research in my first 2 years with, with, with an ophthalmologist at CU, and then I went away for a year to do my MBA, went away, you know, just to the other side of town to do my MBA. And I started working for, like, interning essentially for a couple healthcare organizations in Denver, you know, started working with Denver Health, started working with Catholic Health Initiatives, it's based in South Denver, the office of CIO there. And then I came back and your 4th year you spent applying and interviewing and all that for residency. And I talked to those mentors in ophthalmology that I'd done research with, And not just them, other clinical mentors that I had met during my clinical rotation, surgeons and some other primary care doctors as well. And without fail, like literally 100% said, if you're considering not doing, you know, at that point I was interested in technology and I wasn't sure what I wanted to do clinically.
Without fail, 100% of them were like, you shouldn't do a residency. They were like, you should go down the non-clinical path if you think that's what you want. I mean, I think for, for a lot of those, um, providers, the reason, you know, it's kind of a grass is greener thing. You know, a lot, a lot of providers, uh, clinicians, MDs, at some point in their career they do something non-clinical, whether that's business-related, technology-related, research-related, um, you know, whatever it might be. And so, you know, there's all of them, um, sort of steered me towards that path.
And I think that, I mean, I, I'm 100% not regretful. I'm glad I didn't, um, match into the residency. My wife is a practicing physician And, you know, having watching sort of, you know, firsthand her and a lot of close friends from medical school go through it, I mean, I don't, I, yeah, I don't, I don't think I would've ended up practicing at the end of it. So I don't, I don't think it would've been a good, a good way to spend, you know, 80 hours a week for, for 3 to 5 years of my life. So what did you do?
So at the end of medical school, I founded my last company. So During my 4th year of medical school, I, I, when I knew I wasn't going to go into the match, I actually started writing for a health IT blog publication. This must have been like 2009-ish, I guess. And I was writing about a lot of sort of new technologies that were coming into healthcare. So there are companies like now, the ones that have succeeded that, you know, that you hear of, there are companies that are just getting started like Teladoc and American Well, and, you know, these telemedicine companies that are, you know, big public companies now.
It's OckDoc, which is a huge schedule, you know, sort of all of these new types of technology-enabled healthcare services, and I started to sort of COVID that for this publication called HIS Talk. And through that process, you know, ended up engaging with a lot of people that were building these tools or people that were at innovation groups, you know, at insurance companies or pharmaceutical companies or healthcare organizations, healthcare delivery organizations, and everybody was looking to build modern technology. And at the time, you know, this is like 2010-ish, like I said, 2010 to 2012, there were a lot of different developer tools being developed. So Heroku had grown and been sold as a platform as a service. There were other types of, you know, sort of backend services that made it easier to onboard or sort of, you know, build and deploy applications.
But if you want to do it and your application contained PHI, protected health information, you couldn't use a lot of those tools. So you were kind of working from scratch. And so the hypothesis behind my last company that I founded at the end of medical school, a company that company called Datica, was to build a HIPAA-compliant— and eventually we went through HITRUST— but really is a way to remove some of those roadblocks to enable people who were building applications for healthcare that were going to contain PHI to do it in a way where they could take advantage of cloud services, so take advantage of AWS, but also pass their audits and pass their security reviews with their customers so they could, you know, more quickly focus on— more quickly build applications. And focus on, you know, the value of what they were building and not on becoming experts in how to configure, you know, cloud services to pass HIPAA assessments or HITRUST certifications. So that was an accelerator for adopting cloud services and building your own cloud applications.
Is that what I'm hearing? Yeah, exactly, exactly. As a tool really built for developers that wanted to come into healthcare and build new tools, but do it in a way where they could, you know, actually sell into healthcare organizations. Yeah, so talk about the kind of the road there, you know, as you looked to build that company up and through, obviously you're not doing that anymore, so just tell me about the life of that company. Yeah, so I mean, that was, I look back, it was interesting, like I really had no idea what I was doing in terms of like starting a company.
I mean, you know, you tend to get a lot of like an MD, for better or for worse, gives you like credibility when you walk into a room or into meetings, but like it obviously doesn't prove prepare you for a lot of things. And one of those things is like starting a technology startup. So, you know, I look back and really didn't have any idea like what I was doing in terms of company building, but was fortunate to connect with, connect with, you know, a good group of people and got introduced to, you know, a couple of good groups of investors who were really intrigued by the idea. And, you know, was able to, you know, raise some initial funding and hire on some developers and build an initial product and then, you know, kind of snowball from there. And so yeah, we raised money through, I guess, 3 rounds of funding and grew that business to about 130 or so customers.
Those were— that was a mix of like our largest customer was Johnson Johnson, so pharmaceutical company. We had some insurance companies. The bulk of our customers were like healthcare startups. And so we grew that business and then eventually sold that business almost 3 years ago now to a company out of Minneapolis called Sensorial Health. And so, yeah, that was an interesting journey.
And, you know, like I said, I really learned a ton, made tons of mistakes, you know, but we were super fortunate in terms of timing and perseverance to succeed in building a real business there. And so yeah, it was a great experience and taught me a ton, not just about company building, but a lot of other things, which I'm hoping— I tell people that I'm hoping I don't make the same 1,000 mistakes with this new company. I'll probably make other mistakes, but maybe not all the same ones over again. That's my goal. So one more question about Datica.
It looks like it was called Catalyze. At the beginning. What, what was the name change about? Yeah, so we founded the company as Catalyze, um, and, uh, the name change was about, you know, a couple years in realizing that Catalyze was— I mean, you could have realized this, I guess, but you'd known or thought about it from the beginning. But, you know, catalyze was a dictionary term, an English word, and so in trying to, to, to defend that name, um, with trademarks and in search and things like that, we just, we just found we couldn't do it.
So that's a whole nother— you could do an entire podcast on like Renaming a business after a couple of years, even a business that's not that big. That was like a very big process. But yeah, anyways, we rebranded the company a couple of years in from Catalyze to Datica. Well, all you have to do is look at our telcos who change their name every 5 years or so after everyone hates the original name. So they come up with a new one to try and rebrand.
Yeah. It's kind of a different angle on that. That problem. Yeah, you're right, you're right. There's probably something to be learned there.
Uh, so there probably is something to be learned. Hey, so it looks like you, you, uh, kind of moved on, uh, in November of 2019. At least that's what LinkedIn tells me. And then very shortly thereafter, March of 2020, you started a new company with Heika. Number one, that's not a very long break to take after, after what I would imagine was like, you know, uh, a marathon that you ran at the speed of a sprint.
What was your thought process that you're like, hey, I need to get back into starting a new company so quickly? Yeah, so I think part of what I came to realize in building Catalyze, Nodatica, and then going through multiple rounds of funding and ultimately selling was that I realized where I was, where my interests were, where my strengths were, you know, kind of what, you know, helped get me up in the morning. And that was really around sort of starting and building things. And so, you know, I really, one, wanted to get back to that. And, you know, I don't know, I can't remember how my wife phrased it, but she phrased it where like, you know, like I need something like that.
That's just kind of what makes me tick. And so, yeah, so I really wanted to get back into starting something, and there were a few things that my co-founder and I batted around, my co-founder now at Hika and I batted around, but I really ultimately wanted to jump back into something. I felt like my experience being at, like, 2013 was when people in, in healthcare or who aren't in healthcare, 2013 is when the HIPAA Omnibus Rule went into effect. And so that's when cloud providers started to have, you know, have to sign business associate agreements. So it's when, like, you know, healthcare in the cloud sort of became relevant.
And so, um, you know, being, being there as a part of that, that, uh, that trend and as a part of sort of healthcare's onboarding to modern technology, I felt like, you know, it exposed me to just generally, um, the, I guess, the market or intersection of of regulation and technology. And so I felt like I had a lot of potentially relevant ideas that I wanted to explore based on that experience at Datika and things that I had seen and experienced myself. So yeah, I just kind of felt like I wanted to jump back into it. It's funny, I just had somebody send me a note who they sold their company a few months ago and they were like, man, I'm, you know, they're still working there, but they were like, man, I'm just kind of enjoying you know, my— I'm enjoying kind of cruising at this point. And so I was just chatting with them just a few days ago in a very similar conversation where I told them the same thing and just, you know, felt like there was stuff I really wanted to get back into and do again.
So what was the problem you and your co-founder decided you guys can help solve? So what we experienced at Datica as we were growing that business, and we were you know, we were focused. We weren't just a, like a, you know, a technology company or healthcare technology company. I mean, we were focused on compliance. We were focused on security.
Like we were a key part, you know, a key component of how our customers pass their audits and their security reviews, and they were inheriting things from us. And so, you know, despite that focus and, you know, really like value proposition in the market, we continually would get asked by our employees You know, and we were using, you know, like SaaS applications, we're using Slack, Zendesk, HubSpot, you kind of name it. And we would always get asked like, what data can I share? If I'm going to dump this lead list, where can I put it? Like, how do I set these permissions for these Google Docs?
How do I share this with customers? Right. And we, at the time, you know, this at the time, this is, I guess, probably 2015 when we first wrote our training, but we ended up writing and open sourcing our own training material. Were at Datica, and we used it. A lot of our customers use it.
It's open source, you know, other people use it as well. We also open source our, like, you know, privacy policies and procedures, all those things, which, you know, a lot of people still use. But in terms of the training, yeah, we— and then after leaving, you know, Datica, we really felt like, you know, cybersecurity has obviously exploded in terms of the types of tech, you know, the types of products out there and the types of automations and all these other pieces around technology, but there's still a lot of risk associated. People talk about this a lot, but there's still a lot of risk associated with employee actions and really human risk, human decisions, security hygiene of your employees. And we felt like there was nobody who was really effectively serving the market.
And a lot of the tools that existed were largely bolted on and geared more towards passing audits as opposed to like really helping employees make better decisions and reducing risk. And we felt like there was a way to leverage those— the tools I was just mentioning, those workflow tools like Slack and like Zendesk and others to actually, you know, deliver, you know, the right content. We can talk about it as the right content to the right people at the right time, where, you know, what we think of traditionally is like security awareness training or HIPAA privacy training, or now, you know, GDPR training, CCPA training, you kind of make that disappear and then you embed that content and you embed the delivery of it into the tools that people are using every day. So you can do it in an intelligent way, you can do it in a relevant way, and ideally in a way that isn't like a big burden for your employees. And I'd say that one thing you've got out of there, which I can imagine a lot of our compliance folks listening, is you're still able to report on it.
We're still able to see metrics. And I can speak to this because you did show it to me, and I'm— so I did I got to see how it works. So yeah, you're putting it in the tools people use, you're making it a part of day-to-day activities. What's the— where are you so far in this kind of, hey, we had this idea, we're starting to develop this thing out. Where are you in terms of having a product ready to go?
Yeah, so we released— we were a new company. We're actually about a year old this month. And we, you know, went to market last fall with a private version or private beta version of a Slack application that made it, you know, really want to leverage Slack and channels and all those things for user management and other things. But, you know, where people could essentially create and assign trainings and people could take training. So it made it super simple to create and administer trainings, download evidence, but then also for learners to actually engage with training.
And so we launched that in the fall. We went to a public beta this, you know, in February, went to Techstars. We went to public beta coinciding with starting Techstars, went through Techstars. We've onboarded almost 100 companies to the application, or 100 companies have installed the application. We have about almost 1,500 active users that are training on it, and, you know, we've just gotten really like phenomenal feedback and iterated pretty quickly.
And then really, you know, what we've discovered is people want to be able, they really love our delivery mechanism. And I think what differentiates us is the delivery. And so now what we are doing, and we're gonna have some announcements in the next, you know, 1 to 2 months around integrating other types of content and other forms of content. So we're going to be the delivery mechanism and the assignment mechanism and, you know, the evidence mechanism, but we're going to enable people to bring content that they're already using, you know, via, you know, other security awareness vendors, or to very easily, you know, create their own content. And then, you know, really quick plug for anybody out there that's developed training or feels like they have, you know, something to contribute, we actually are starting like a a contributor program where we're actually working with people to develop specific types of training around security awareness and privacy.
So they— but within that, you know, they don't have to be just sort of your general security awareness training curriculum. They can be super specific for like, you know, compliance for marketing and sales or, you know, GDPR for frontline support workers, whatever it might be. And so we're really excited about that. As well. So as of today, if I'm a beta customer, I'm getting the training that you— your company created, is that right?
You're getting it coming. Yes, right now that's true. Uh, in the next, uh, 2 to 4 weeks, that will be— there'll be a more extensive content catalog. Yeah, but yes, right now it's, um, content that we've created in-house. And we're talking in mid-May, and this will run end of May, so maybe by the time this runs, people are— it's already changed.
We'll see. Yes. So yeah, podcast timing and product timing are something you gotta work out.
And, you know, I'm just thinking, you know, I know you're focused on security and compliance training and maybe privacy training as well, but like, why wouldn't this work just fine for any training? Right. For my, you know, foreign corruption, foreign corrupt private, I can't remember how to say it. FCPA, whatever that is. Anyway, that training or my diversity training or, you know, any training, is there a reason that you guys are focused in one area?
Area? Just you can't do everything at once, or what? Yeah, I mean, it's primarily, it's, it's primarily the last. I mean, we're letting the kind of market drive us, and we're definitely focused on building the company like in stages, you know. And so, so, and working closely with the companies that we have as customers during those stages.
Um, there's not any— yeah, we've had all of— we've had conversations with companies about all of those things you just mentioned, those types of trainings you just mentioned. We just don't want to, you know, sort of veer too far, you know, and chase too many things. Speaking of like, you know, not making the same mistakes again, you know, I think one of the things I did at my last company was you can kind of very quickly, you know, chase, as some people call it, like shiny things. And so, but yeah, the ability to, you know, import content, to deliver, to develop custom content, all those things definitely open up you know, the ability to do different kinds of training. So yeah, and so I know you're as of today, um, serving a Slack application for, for doing this, and I think there's a roadmap to move beyond just Slack, right?
Uh, yeah, so we're starting with Slack, and Teams is kind of a natural extension from Slack because, you know, there's similar sort of, uh, like functionality within the app. Um, and but yeah, the goal beyond those 2 is to integrate with you know, the other types of apps, uh, and we call like workflow tools and support, you know, things like Zendesk on the marketing and sales side, Salesforce, HubSpot, Marketo, um, and then, um, you know, Stripe and some others who have APIs we can use. And then, um, we're even, uh, actually going to be testing this summer with a couple of customers, a Chrome extension, and it'll, you know, kind of work like, um, like, like Honey, the coupon extension, where you can kind of inspect the URL and then provide training based on what somebody is specifically doing, if it's configuring accounts in their banking application or configuring something within the AWS console, like an S3 bucket or a VPC for networking or whatever it might be. But the idea being to get our— to be as close to the actual actions that people are taking, because the decisions associated with those actions are where the rubber meets the road in terms of security procedures and policies and procedures. Um, that's the goal.
Yeah. I mean, you're speaking exactly my language where like the worst kind of training is a big bulk training where I'm going to try and teach you 75 things all at once and hope that you remember them for the next year until I give it to you again. Like the best training is when I teach you one very small discrete thing exactly when you need it. Right. Yeah.
And, and, and I'm not, not to suggest that I can, we're going to be able to do all 75 or Honestly, there's probably 750, right? 'Cause once you get out of the paradigm that I'm gonna have to deliver them all at once and to everyone, you just train someone on the thing they need when they need it, and that's the only time you get it, right? The closer you can get to that, the less we have employees who are our customers internally, you know, dreading the security training, and really they're actually starting to get value out of it because like, how do I share this S3 bucket in a secure way? Oh, look at this, let me watch this training because it's my first time doing it. Like, the closer we can get to that reality, the better.
And that's why I was trying to lead you to that Chromancer, because I feel like the Chromancer— Chrome is, you know, as you're able to finally really, you know, get it nuanced enough within that user experience in those, um, in those applications and those URLs, you're going to really be able to get that as close as possible to the, the place where it matters. Yeah, yeah, definitely. So I mean, we philosophically have the same approach. So we, you know, we, we talk about it a lot, like human risk, employee risk, and it's almost like we're dinging them, like employees as bad guys, you know. And, and the, the challenge is like they're constantly under attack from social engineering, you know, attacks and, you know, phishing attacks, or they're constantly, you know, being put into a position to have configurations, options for SaaS applications or whatever it might be.
And so like it is a, it is a matter of trying to level the playing field, because they really do want to make— they do want to be able to make those right decisions. They do want to configure the S3 bucket the right way. They do want to be able to share that log data in a Zendesk ticket, but in a way that doesn't share either secrets or PII or something that they shouldn't expose. But they really need help in figuring that out, because it's gotten really, really broad, and it's changing really, really fast. Yeah.
So, I mean, that's obviously super exciting. If there are people listening who, number one, they would like to be a part of your beta program or just want to know more, what's the right way? Number one, is your beta program still open if there's new companies who want to get involved? Yeah. So we're open.
We'll be coming out of it soon. We're in what we're calling the public beta, and that's only because there are a few additional features and things that we want to layer in before we go into just public launch. But yeah, I mean, you can sign up on our website, which is just haekka.com, hard to spell, but H-A-E-K-K-E, uh, sorry, H-A-E-K-K-A, uh, .com. And, or, uh, you know, if we provide in the notes, you know, contact information, I'm happy to talk to people about what we're doing as well. Um, but yeah, we're definitely looking to onboard new people, get feedback.
Um, we're looking for people that potentially, you know, feel like they can contribute content or develop internally they have internal content that, you know, they'd be interested in porting. Um, so yeah, we're definitely open to that. Um, and, you know, as of today, Slack is the one app, you know, so obviously that's an ideal candidate pool of people who might be interested. You know, if people are, are using Teams exclusively, is this a good time for them to talk to you, or should they hold off? Yeah, no, we're, we're definitely actively talking to, you know, Teams is, is in development.
We're definitely actively talking to people and trying to understand you know, we, what we discovered is, is Teams and Slack are kind of talked about in the same way, and there's lots of similar, you know, I mentioned it, like functionality, but there are some differences in how people view, like, you know, Teams and Slack, like, as a part of their company. So we're definitely open to talking to folks that are on Teams to understand if there are certain, if there are certain types of functionality that they want that Slack customers might not want. And so, yeah, we're definitely, you know, having those conversations. Awesome. Let me think.
You guys, did you kind of fund yourself? Did you go to VC at the beginning of this? How did this thing get kicked off from a financial perspective and where are you in that process? Yeah. So we raised, yeah, we have raised venture.
So we raised what we call the pre-seed round of funding. So we raised an initial round last summer, pre-product. We have now gone through or are going through the process of raising a seed round of funding. And so, and that's, you know, we're, I guess, very fortunate to, we still have the bulk of our pre-seed money in the bank. We're raising a seed because we do feel like there's a much more, a much larger and more immediate opportunity for companies to to leverage us as a delivery mechanism for their existing content.
And so that's where there's some additional stuff that we're building, but yeah, we raised a pre-seed and now in the process of raising a seed round. That's pretty exciting stuff. And what are you hoping to use that seed round to go fund? So there's a few things we wanna fund. Some of that is tooling to make it easier to, one, integrate existing content that you have Whether that be internally created or from, you know, potentially other vendors, which is— there's some unique challenges in doing that in a Slack format or in a Chrome extension, right?
The other is make it much easier for people to create content on Haiku, and that's people that are creating it for their companies or people that want to be a part of our content creation program. Uh, which we're launching here in the next few weeks. Um, so those are 2, uh, like major features that we're gonna bring to the market and then looking to go beyond and accelerate going beyond Slack to Teams and then to that Chrome extension that I mentioned and some additional integrations, uh, later this year and then into next year with like, um, you know, Zendesk and Salesforce and some of the other ones I mentioned. Well, I feel like the natural progression here then is, uh, uh, what kind of people are you gonna be looking to hire? If people out listening right now are looking for their next gig, what are you guys looking to hire?
So we have a lot of openings for— or a lot of openings— we have several openings for software developers, both frontend developers, frontend like web, React specifically developers, and then backend, primarily Python developers. So those are the the 2, I guess, primary things on the engineering side. So, you know, a lot of development work. If you do, you know, front-end, back-end, full-stack, like, we're interested in talking to you, definitely. We operate— we're based in Colorado and we're trying to hire the majority of people sort of in this region, but we're operating the company as a remote, you know, company.
So we do have some flexibility there. And then We talked about this just before the podcast. We're looking for folks that we're actually hiring for a director or head of growth role. And so that includes product marketing, which we talked about before this, but that's really somebody who feels like they can wear multiple hats, has worked in a, you know, probably a startup environment. And we, you know, are really looking for somebody that is, you know, focused every day on how do I find people to talk to?
And then, you know, when I'm talking to those people, what, you know, how do I help figure out what the message is and what the right things are to say to, you know, you know, get those people to want to try Hika? Awesome. Well, I have one more question for you and then I'll let you tell me anything you want to tell me. Okay. What does Hika mean?
And I'm cheating because your website has it on here, but I'll let you tell if you remember. Yeah, yeah, I do. I get asked that a lot. So it It's Icelandic. It means to elevate.
And so we talk about it as elevating security engagement, elevating security awareness.
And, you know, we also— my co-founder, as we went through the process, not surprisingly, a lot of companies that are being founded now, we have the .com. And so that's kind of how we went about the naming. But the elevate language helps a lot. Yeah, that's awesome. And we're going to be using it actually more and more.
I actually really love that name. The fact that not only is it a good name, but the URL was available, that's pretty impressive. I sat down with one of the co-founders from AccuVant, if you know AccuVant, and his answer about the name was, yeah, it means this domain name was available. That's the definition of AccuVant. I found that very funny.
Yeah, that's a good one. Yeah, I was gonna say, last company, part of that rebranding story to Datica was like we had to— we found a guy who had owned this domain. He was in Canada. We had to go through a whole process of like masking who was buying it so he didn't ask for too much money. It was a whole thing, but domain names are hard.
Yeah. Like really hard. But you definitely want the .com because if you don't have it, somebody else is gonna have Exactly, exactly. Yeah, cool. Well, that was all my questions for you.
Is there anything else that I should have asked you about there that you wanted to make sure to share?
You know, I don't think so. This is like impressively thorough. And so, no, I mean, I mean, the only thing I'll add, or the only thing I'll like reiterate, is yeah, I mean, if there are folks, you know, if there are folks, any folks, but, you know, particular folks here in Colorado that want to learn more and not just learn more to become a customer. We're really actively soliciting and trying to talk to people about how they're doing these things today. And if there are things we can do to improve that experience, improve the product experience to meet some of those needs, we're really actively looking to talk to those people.
Awesome. Well, Travis, it's been a real pleasure getting to know you personally. Such an interesting background. The tech to consultant to medical school to starting a medical technology company. To security, that's, that's a pretty fantastic path.
And I'm definitely looking forward to seeing how this goes. And, you know, maybe we can check back in 12 to 18 months and, and you can tell us about the awesome steps you guys have made in the meantime. Yeah, definitely. Maybe if you do these in person, maybe that's the point. Yeah, we're awfully close to in person.
I mean, I— this was— this is borderline right now. We probably could have done it, but, uh, uh, well, Awesome. All right, thanks a lot. And that's it for this week's Colorado Equals Security. We'll talk to you guys again next week.
Learn more about the Colorado security scene at colorado-security.com, where you can see information about local security groups, a calendar of upcoming security events, and learn more about Colorado Equals Security. Reach out to Alex and Robb by emailing info@colorado-security.com.
Until next time, remember, Colorado equals security.