Antimatter — RSA Conference 2024 Innovation Sandbox

RSA Conference 2024 · Innovation Sandbox

Overview

In an era where Generative AI (Gen AI) is rapidly reshaping enterprise IT landscapes, traditional data security paradigms are proving insufficient, leading to significant data breach risks. This talk, delivered by Andrew Krukoff, co-founder and CEO of Antimatter Security, during the RSA Conference 2024 Innovation Sandbox, introduces Antimatter as a foundational solution to this burgeoning problem. The presentation highlights how Gen AI's inherent generality and expansive data requirements fundamentally challenge existing security frameworks, which were designed for siloed applications and tightly controlled data access.

Watch on YouTube

Visual summary for Antimatter — RSA Conference 2024 Innovation Sandbox
Visual summary for Antimatter — RSA Conference 2024 Innovation Sandbox

Key moments

  1. 0:00 Introduction and Gen AI's data security challenge
  2. 0:40 Why existing security approaches and prompt filters fail
  3. 1:02 Antimatter's solution: a data control plane
  4. 1:20 How Antimatter works: connect, scan, observe
  5. 2:00 Demo: Chatbot respecting user data permissions
  6. 2:30 Team, investors, and customer traction

Antimatter

Speakers: Andrew Krukoff, Co-founder and CEO, Antimatter Security

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=YPKdIQq4wHM

Overview

In an era where Generative AI (Gen AI) is rapidly reshaping enterprise IT landscapes, traditional data security paradigms are proving insufficient, leading to significant data breach risks. This talk, delivered by Andrew Krukoff, co-founder and CEO of Antimatter Security, during the RSA Conference 2024 Innovation Sandbox, introduces Antimatter as a foundational solution to this burgeoning problem. The presentation highlights how Gen AI's inherent generality and expansive data requirements fundamentally challenge existing security frameworks, which were designed for siloed applications and tightly controlled data access.

The core issue, as articulated by Krukoff, is that Gen AI thrives on vast datasets and is accessed by a wide array of users across different departments, making application-specific permissions and reactive prompt filters ineffective. Gartner's alarming statistic—30% of enterprises adopting Gen AI have already experienced data breaches—underscores the urgency of this challenge. Antimatter proposes a radical shift: a data control plane that sits directly between data sources and Gen AI applications, ensuring that granular permissions are enforced at the root, regardless of how data is accessed or processed. This approach aims to secure sensitive information proactively, preventing leaks and maintaining compliance in the face of evolving AI capabilities.

Background

▶ Watch: Introduction and Gen AI's data security challenge (0:00)

The advent of Generative AI has introduced a paradigm shift in how enterprises interact with and leverage their data, simultaneously exposing critical vulnerabilities in conventional security architectures. Historically, enterprise IT security has revolved around a model where multiple applications each serve specific user groups, with data permissions managed intrinsically within those applications. Access control typically involved restricting user logins to particular applications and then configuring granular permissions for data objects within that application's confines. This "application-centric" security model worked well for decades, creating isolated security domains for different business functions.

However, Gen AI fundamentally disrupts this model. Its power derives from its "generality" – its ability to process, analyze, and synthesize information from vast, diverse datasets across an entire organization. Furthermore, Gen AI tools are designed for broad utility, often accessed by a wide spectrum of employees from various departments, transcending the traditional boundaries of application-specific user groups. This combination of expansive data consumption and widespread accessibility renders legacy security approaches obsolete. Attempting to secure Gen AI through prompt filters, which aim to restrict the types of questions users can ask or the outputs AI can produce, has proven to be an endless "cat and mouse game." Researchers have already demonstrated bypass techniques, such as asking questions in ASCII art to circumvent OpenAI's filters, highlighting the futility of reactive, surface-level controls. This fundamental disconnect between Gen AI's operational requirements and existing security capabilities is directly contributing to a concerning statistic: Gartner reports that 30% of enterprises that have adopted Gen AI have already suffered data breaches, underscoring a critical need for a new, root-level security paradigm.

Key Findings

▶ Watch: Antimatter's solution: a data control plane (1:02)

Antimatter Security's key contribution is the introduction of a data control plane designed to address the fundamental security challenges posed by Generative AI. This innovative approach moves beyond application-specific permissions and reactive prompt filtering, establishing a robust, centralized mechanism for data governance. The core findings and capabilities presented by Antimatter include:

  1. Root-Level Permission Enforcement: Antimatter positions itself as an intermediary layer, a "data control plane," that sits directly between an organization's raw data sources and its Gen AI applications. This strategic placement ensures that existing data permissions are respected and enforced at the most fundamental level, rather than relying on application-level configurations or post-processing filters.
  2. Universal Data Access Control: The system guarantees that users, regardless of whether they interact with data through chatbots, data science tools, or any other Gen AI application, will only ever access the specific data appropriate for their roles and permissions. This universal enforcement prevents unauthorized data exposure across diverse AI-driven workflows.
  3. Comprehensive Data Source Integration: Antimatter is engineered to connect with and protect a wide array of structured and unstructured data stores. This broad compatibility ensures that an organization's entire data estate, irrespective of its storage location or format, can be brought under the purview of the data control plane.
  4. Integrated Data and Permission Ingestion: A critical aspect of Antimatter's functionality is its ability to not only pull in the raw data but also the associated permissions from the connected data sources. This dual ingestion allows the system to accurately map existing access policies to new Gen AI use cases, ensuring continuity and consistency in data governance.
  5. Sensitive Data Discovery and Protection: The platform incorporates advanced scanning capabilities to identify Personally Identifiable Information (PII), Protected Health Information (PHI), and other sensitive data fields. Upon detection, Antimatter provides mechanisms to redact or mask this sensitive data, adding an extra layer of protection before it is exposed to Gen AI models or end-users.
  6. Complete Observability and Audit Trails: Antimatter offers comprehensive logging and observability features. Security teams and CISOs gain a detailed audit trail of "who's accessing what data through what app, where and when." This provides crucial insights for compliance, incident response, and understanding data flow in the Gen AI ecosystem.

These findings collectively propose a proactive, data-centric security model that enables enterprises to harness the power of Gen AI without compromising their data's integrity or privacy.

Technical Deep Dive

▶ Watch: How Antimatter works: connect, scan, observe (1:20)

Antimatter's core innovation lies in its architecture as a data control plane, a conceptual shift from application-centric security to data-centric security, specifically tailored for the unique demands of Generative AI. Unlike traditional security models that manage permissions within individual applications, Antimatter operates as an intelligent intermediary layer, enforcing policies at the point of data access, regardless of the consuming application.

At a high level, the architecture can be understood as a centralized gateway that intercepts data requests from Gen AI applications and orchestrates data delivery from various enterprise data sources. The process begins with Data Source Connectors. These connectors are designed to integrate with a "wide range of structured and unstructured data stores," implying support for databases (e.g., SQL, NoSQL), data lakes (e.g., S3, Azure Blob Storage), document management systems, and potentially other proprietary data repositories. The ability to abstract data access across such diverse sources is fundamental to Gen AI's "general" nature, as it often requires synthesizing information from disparate locations.

Crucially, Antimatter doesn't just pull in raw data; it performs Permission Ingestion. This means it extracts and understands the existing access control lists (ACLs), roles, and policies already defined within the enterprise's data sources. This is a significant distinction, as it allows Antimatter to leverage an organization's established security posture rather than requiring a complete redefinition of permissions for Gen AI contexts. By integrating these native permissions, Antimatter can ensure that a user who traditionally lacked access to specific data in a database will similarly be denied access to that data when queried via a Gen AI chatbot.

Following data and permission ingestion, Antimatter employs Sensitive Data Discovery mechanisms. This involves scanning the data for known patterns or classifications of sensitive information, such as Personally Identifiable Information (PII) like names, addresses, social security numbers, and Protected Health Information (PHI) as defined by regulations like HIPAA. The talk also mentions "other sensitive fields," indicating configurable or custom data classifications relevant to specific organizational needs. This discovery process is likely powered by a combination of regular expressions, machine learning models, and potentially integration with existing data loss prevention (DLP) solutions.

Once sensitive data is identified, Antimatter provides Data Transformation and Protection capabilities, specifically redaction or masking. Redaction involves completely removing sensitive data segments, replacing them with placeholders (e.g., [REDACTED]). Masking, on the other hand, replaces sensitive data with structurally similar but non-identifiable values (e.g., replacing a credit card number with XXXX-XXXX-XXXX-1234). These transformations are applied dynamically, ensuring that the Gen AI application or the end-user only receives a sanitized version of the data, while the original sensitive information remains protected at its source. This dynamic filtering prevents sensitive data from being inadvertently ingested by AI models or exposed in AI-generated responses.

The core of the data control plane is its Policy Enforcement Engine. This engine continuously evaluates incoming data requests from Gen AI applications against the ingested user permissions and the identified sensitive data policies. For instance, if an engineering team member requests information about development servers, the engine checks their permissions against the underlying data source permissions. If authorized, the data is retrieved. If the data contains sensitive fields not relevant to the user's role, the engine applies redaction or masking before presenting the information. Conversely, if a sales team member makes the same request, the engine identifies their lack of permission for that specific data, resulting in a denial of access.

Finally, Antimatter provides Auditing and Logging capabilities, ensuring "complete observability." Every data access request, permission check, redaction, and masking event is logged. This creates a detailed audit trail specifying "who's accessing what data through what app, where and when." This level of granular logging is indispensable for compliance (e.g., GDPR, CCPA, HIPAA), forensic investigations, and demonstrating adherence to internal security policies, offering CISOs unprecedented visibility into data flows within the Gen AI ecosystem.

While the Innovation Sandbox pitch naturally provided a high-level overview, the described technical components outline a robust, layered security approach that fundamentally shifts the burden of security from the application layer to a dedicated data control plane, enabling secure and compliant Gen AI adoption.

Demo / Proof of Concept

▶ Watch: Demo: Chatbot respecting user data permissions (2:00)

The talk effectively demonstrated Antimatter's core functionality through a clear and relatable use case involving a knowledge-based chatbot. The scenario presented two different employees attempting to access sensitive operational information through the same Gen AI interface, illustrating how Antimatter dynamically enforces access controls based on user identity and permissions.

The demonstration centered around the query: "How do I log into our development servers?" This is a common question that might be posed to an internal knowledge base powered by Gen AI, but one that carries significant security implications if answered indiscriminately.

  1. Sales Team Member's Experience: When a sales team member, who typically would not have access to sensitive IT infrastructure details, posed this question to the chatbot, Antimatter's data control plane intercepted the request. Based on the sales team member's pre-defined permissions, which likely excluded access to development server login details, Antimatter filtered the response. The chatbot, under Antimatter's control, returned a polite denial: "I'm sorry, I can't provide an answer to that question." This outcome clearly showed that the system successfully prevented unauthorized disclosure of sensitive information to an unprivileged user.
  2. Engineering Team Member's Experience: In contrast, when an engineering team member, who would legitimately require access to such information, asked the identical question, Antimatter's engine recognized their authorized status. Consequently, the engineering team member received "a complete response," implying full access to the detailed login instructions or relevant documentation. This illustrated that Antimatter does not simply block all sensitive data but intelligently grants access based on established roles and permissions.

Beyond the end-user experience, the demonstration also highlighted the crucial perspective of the CISO. For the security leader, Antimatter provides "a log of who saw what data where and when." This comprehensive audit trail is vital for compliance, incident response, and understanding data flow within the Gen AI environment. It provides irrefutable evidence of access control enforcement and data governance, reinforcing trust in the Gen AI deployment.

This proof of concept effectively showcased Antimatter's ability to provide granular, context-aware access control for Gen AI applications, ensuring that sensitive data remains protected while legitimate users retain necessary access.

Defensive Implications

▶ Watch: Team, investors, and customer traction (2:30)

Antimatter's data control plane offers profound defensive implications for organizations grappling with the security challenges of Gen AI. By shifting the security perimeter from individual applications to a centralized data control plane, it provides CISOs and security teams with a powerful arsenal to mitigate risks and ensure compliance in the AI era.

  1. Centralized Data Governance for Gen AI: Antimatter enables a single point of control for all data accessed by Gen AI applications. This eliminates the complexity of managing permissions across disparate AI tools and models, ensuring consistent policy enforcement regardless of the AI interface (chatbots, data science tools, etc.). This centralized approach significantly reduces the attack surface associated with distributed data access.
  2. Mitigation of Data Leakage and Prompt Injection Risks: The primary defensive benefit is preventing unauthorized data exposure. By enforcing permissions at the root and dynamically redacting/masking sensitive information, Antimatter directly counters the risk of data leakage through Gen AI outputs. Furthermore, by controlling the data fed to the AI, it indirectly helps mitigate certain forms of prompt injection attacks that aim to trick the AI into revealing sensitive information it shouldn't access. The AI simply won't "see" or be able to generate responses containing data it's not authorized for.
  3. Preservation of Existing Enterprise Permissions: A key advantage is Antimatter's ability to ingest and respect an organization's existing data permissions. This means security teams don't have to re-architect their entire access control strategy for Gen AI; instead, Antimatter extends and enforces those established policies into the new AI context, preserving investment in existing security infrastructure.
  4. Automated Sensitive Data Protection: The platform's capability to automatically scan for and protect PII, PHI, and other sensitive fields through redaction or masking is a critical defensive measure. This proactive sanitization reduces the manual effort and potential for human error in identifying and securing sensitive data before it reaches Gen AI models, significantly lowering the risk of compliance violations and data breaches.
  5. Enhanced Observability and Auditability: The provision of "complete observability" with detailed logs of "who's accessing what data through what app, where and when" is invaluable for defensive operations. This audit trail is crucial for forensic investigations, demonstrating regulatory compliance (e.g., GDPR, CCPA, HIPAA), and proactively identifying suspicious access patterns or potential insider threats. It transforms abstract data flows into concrete, auditable events.
  6. Empowering Secure Gen AI Adoption: Ultimately, Antimatter's solution empowers organizations to adopt Gen AI broadly and confidently. By providing a fundamental security layer, it allows businesses to leverage the transformative power of AI across all departments and data sources without the constant fear of data breaches or regulatory non-compliance. It shifts the focus from restricting AI use to enabling secure AI use.

In essence, Antimatter provides a robust, data-centric security framework that allows enterprises to manage the complexities of Gen AI data access proactively, moving beyond reactive measures and enabling a more secure and compliant AI-driven future.

Key Takeaways

  • Gen AI's unique architecture fundamentally breaks traditional enterprise data security models, leading to a high incidence of data breaches (30% of adopters according to Gartner).
  • Antimatter introduces a novel "data control plane" that sits between data sources and Gen AI applications, enforcing permissions at the root level.
  • The solution integrates with diverse structured and unstructured data sources, ingesting both data and existing access permissions.
  • It offers critical capabilities for scanning, redacting, or masking sensitive information like PII and PHI before it reaches Gen AI models or users.
  • Antimatter provides complete observability, logging all data access events (who, what data, through what app, when) for robust auditing and compliance.
  • By enforcing granular, context-aware access, Antimatter enables organizations to securely leverage Gen AI across the enterprise while mitigating data leakage and compliance risks.

About the Speaker(s)

Andrew Krukoff is the co-founder and CEO of Antimatter Security. He is part of a founding team described as three experienced entrepreneurs with a prior successful exit. The team's background includes six years of research conducted at UC Berkeley, with published papers at prestigious venues such as USENIX Security. Antimatter Security boasts an "all-star group" of investors, advisors, and customers, including John, the CISO of Ironclad, who is noted as using their product in production to secure sensitive data.

All talks from RSA Conference 2024