Bedrock Security — RSA Conference 2024 Innovation Sandbox
RSA Conference 2024 · Innovation Sandbox
Overview
In a rapidly evolving digital landscape where data oceans proliferate and regulatory icebergs loom, traditional data security mechanisms often prove inadequate. Pravna Aduri, co-founder and CEO of Bedrock Security, delivered a compelling presentation at the RSA Conference 2024 Innovation Sandbox, introducing Bedrock Security as "the frictionless data security company." Aduri leveraged the evocative analogy of the Titanic, highlighting how modern enterprises, much like the ill-fated ship, often navigate vast and perilous data environments with insufficient visibility and outdated tools, leading to potential catastrophic data breaches, regulatory non-compliance, and the ever-present threat of ransomware.

Key moments
- 0:00 Introduction and the three fatal flaws of security
- 0:28 Commoditizing data discovery for continuous, efficient scanning
- 0:59 AI reasoning (Air) for business context, reducing false positives
- 1:33 Proactive solutions: trust boundaries and auto-containment
- 1:53 Bedrock's impact: protecting petabytes and saving operator time
Bedrock Security — RSA Conference 2024 Innovation Sandbox
Speakers: Pravna Aduri, Co-founder and CEO, Bedrock Security
Conference: RSAC 2024
YouTube: https://www.youtube.com/watch?v=_s-9Sc2a294
Overview
In a rapidly evolving digital landscape where data oceans proliferate and regulatory icebergs loom, traditional data security mechanisms often prove inadequate. Pravna Aduri, co-founder and CEO of Bedrock Security, delivered a compelling presentation at the RSA Conference 2024 Innovation Sandbox, introducing Bedrock Security as "the frictionless data security company." Aduri leveraged the evocative analogy of the Titanic, highlighting how modern enterprises, much like the ill-fated ship, often navigate vast and perilous data environments with insufficient visibility and outdated tools, leading to potential catastrophic data breaches, regulatory non-compliance, and the ever-present threat of ransomware.
The core of Bedrock Security's mission, as articulated by Aduri, is to fundamentally re-engineer how organizations protect their most critical asset: data. The talk critically evaluated the shortcomings of legacy Data Loss Prevention (DLP) and first-generation Data Security Posture Management (DSPM) solutions, which are often plagued by false positives, alert fatigue, and an inability to scale with the exponential growth of enterprise data. Bedrock Security proposes a paradigm shift, moving beyond mere alerts to deliver actionable solutions, driven by advanced artificial intelligence (AI) reasoning.
This presentation is particularly significant for security leaders, data privacy officers, and IT professionals struggling with the complexities of securing vast, distributed data estates in the cloud and on-premises. Aduri’s insights into AI-driven contextual classification and automated data containment offer a fresh perspective on achieving continuous data visibility and protection. By addressing the critical challenges of scale, accuracy, and operational efficiency, Bedrock Security aims to empower organizations to sail their data oceans safely, transforming a reactive, burdensome task into a proactive, intelligent, and integrated security function.
Background
▶ Watch: Introduction and the three fatal flaws of security (0:00)
The journey of data security has been marked by a constant race against an expanding threat landscape and the inherent challenges of data sprawl. Early solutions, primarily Data Loss Prevention (DLP) systems, emerged to monitor and control data movement, typically focusing on network egress points, endpoints, and sometimes storage. These systems relied heavily on predefined rules, regular expressions, and keyword matching to identify sensitive information. While foundational, legacy DLP systems quickly encountered limitations. They were often resource-intensive, difficult to configure and maintain, and notorious for generating high volumes of false positives, leading to significant alert fatigue for security teams. Their static rule sets struggled to keep pace with dynamic data types and evolving business contexts, rendering them less effective in modern, agile environments.
With the advent of cloud computing and the proliferation of Software-as-a-Service (SaaS) applications, data began to scatter across diverse environments, making traditional perimeter-based DLP increasingly inadequate. This led to the rise of Data Security Posture Management (DSPM). First-generation DSPM solutions aimed to provide visibility into data assets across cloud environments, identifying where sensitive data resided, who had access to it, and its security configuration. They offered a step forward by extending discovery and classification capabilities to cloud data stores. However, as Pravna Aduri highlighted, even these solutions harbored "three fatal flaws."
Firstly, Aduri noted that these systems "fatigue us with false positives." This issue stems from their reliance on static classification rules, which struggle to understand the nuanced context of data. For instance, a simple string like "salary" might be sensitive in one context but innocuous in another. Without contextual understanding, such systems often misclassify data, leading to a deluge of irrelevant alerts that distract security analysts from genuine threats.
Secondly, Aduri pointed out that legacy solutions "give us alerts instead of solutions." This highlights a fundamental gap: knowing that a problem exists (an alert) is different from knowing how to fix it or having the system automatically initiate remediation. Security teams are often left to manually investigate each alert, determine its criticality, and then devise and implement a resolution, a process that is time-consuming and prone to human error, especially in complex environments.
Lastly, and perhaps most critically in the era of hyperscale cloud and big data, Aduri stated that these solutions "were built for data puddles, not scale out data oceans." Traditional architectures, whether agent-based or appliance-based, struggle immensely with the sheer volume, velocity, and variety of data found in modern enterprises. As data scales into petabytes and beyond, the cost and performance overhead of scanning and classifying data with legacy tools become prohibitive. Aduri cited an example where a customer could only afford to scan once a month due to the expense of their DLP, leaving critical data exposures unnoticed for extended periods. This fundamental inability to provide continuous, cost-effective, and comprehensive coverage across vast, distributed data estates creates significant blind spots and leaves organizations vulnerable to regulatory non-compliance, data exfiltration, and ransomware attacks. Bedrock Security was founded to directly address these systemic shortcomings, leveraging modern AI and distributed architectures to build a more intelligent, scalable, and actionable data security platform.
Key Findings
▶ Watch: Commoditizing data discovery for continuous, efficient scanning (0:28)
Bedrock Security’s approach, driven by its AI Reasoning (Air) engine, directly confronts the "three fatal flaws" identified in legacy data security solutions, presenting three core findings or contributions that redefine data protection:
- Commoditized, Continuous, and Scalable Data Discovery: Bedrock Security has re-engineered data discovery to be highly efficient and cost-effective, making continuous scanning a reality even for "scale out data oceans." Aduri highlighted that their "serverless, distributed discovery mechanism" adapts to an organization's data landscape, effectively "commoditizing" a process that was previously expensive and intermittent. This allows customers to move from monthly, limited scans with expensive legacy DLP to continuous, comprehensive scanning, dramatically enhancing visibility and reducing the time sensitive data remains exposed. This addresses the challenge of scale by providing an always-on, adaptable view of the data ocean, rather than just periodic glimpses.
- Contextual Data Classification through AI Reasoning: Recognizing that "data classification is actually a business context problem," Bedrock Security has ditched static, rule-based classification in favor of its Air engine. Air leverages AI embeddings to learn an organization's unique business context, moving beyond superficial keyword matching to understand the semantic meaning and sensitivity of data. This innovation directly tackles the problem of false positives and negatives. By reasoning based on similarity to known sensitive data types (like a W2 or W4), Air can accurately classify previously unseen data (such as a 1099) as restricted, even without explicit rules. This ensures more accurate and adaptive data identification, reducing noise and improving the signal for security teams.
- Actionable Solutions, Not Just Alerts, with Automated Containment: Bedrock Security shifts the paradigm from merely alerting security teams to empowering them with actionable solutions and even auto-containment capabilities. By enabling organizations to "deputize your business to protect their own data," Bedrock allows for the establishment of trust boundaries. These boundaries "ring fence" data that Air deems important. If this data is detected to be in trouble—for instance, moving to an unauthorized location or being accessed inappropriately—Bedrock works with the customer to "auto contain the problem." This proactive and automated response mechanism significantly reduces the manual burden on security teams, minimizes the window of exposure, and transforms data security from a reactive alert-driven process into a proactive, policy-enforced system.
These three findings collectively represent Bedrock Security’s vision for a frictionless data security posture, where enterprises gain continuous visibility, intelligent classification, and automated protection across their entire data estate.
Technical Deep Dive
▶ Watch: AI reasoning (Air) for business context, reducing false positives (0:59)
Bedrock Security's innovative approach hinges on its AI Reasoning (Air) engine and a serverless, distributed discovery mechanism designed for the modern "data ocean." The technical architecture moves away from the rigid, resource-intensive models of legacy DLP and first-generation DSPM to provide scalable, intelligent, and actionable data security.
At the core of Bedrock's data discovery is its serverless, distributed architecture. Unlike traditional solutions that might deploy agents on endpoints or utilize centralized scanning appliances, Bedrock operates within the customer's cloud environment. The "15 minutes, no agents, no proxies" deployment claim suggests a cloud-native integration, likely leveraging cloud provider APIs and serverless functions (e.g., AWS Lambda, Azure Functions, Google Cloud Functions). This model offers several critical advantages:
- Scalability: Serverless functions automatically scale up and down based on demand, allowing Bedrock to efficiently scan petabytes of data without requiring customers to provision or manage dedicated infrastructure. This directly addresses the "data oceans" problem.
- Cost-Efficiency: Customers pay only for the compute resources consumed during data scanning, making continuous discovery economically viable compared to always-on, fixed-cost solutions.
- Adaptability: The distributed nature allows Bedrock to "adapt to your data," meaning it can connect to various data sources (object storage like S3, databases, file shares, SaaS applications) and process different data types and formats in parallel, optimizing for each specific context. Data is likely scanned in situ, minimizing data movement and associated security risks.
The true intelligence lies in the AI Reasoning (Air) engine, which is responsible for contextual data classification. Aduri explicitly stated, "we ditched the rules and instead built Air to learn your business context." This represents a significant departure from static rule-based systems. Air leverages AI embeddings, which are dense vector representations of data. Instead of matching keywords or regular expressions, AI embeddings capture the semantic meaning and relationships within data. For example, documents, text snippets, or even structured data entries can be transformed into numerical vectors in a high-dimensional space. Data points that are semantically similar will be closer to each other in this embedding space.
The process likely involves:
- Ingestion of Representative Data: Air is initially trained or fine-tuned using examples of an organization's sensitive and non-sensitive data, or it could leverage a pre-trained general knowledge model that is then adapted. The example provided, "If you have a W2 and a W4 and both are restricted," illustrates this. These documents serve as anchors in the embedding space for "restricted employee tax information."
- Embedding Generation: When new, unseen data is discovered (e.g., a 1099 form), Air generates its embedding.
- Similarity-Based Classification: Air then compares the embedding of the new data (1099) to the embeddings of known sensitive data types (W2, W4). If the new data's embedding is sufficiently close to the "restricted employee tax information" cluster, Air "reasons it was restricted based on its similarity," even if no explicit rule for "1099" exists. This dynamic, learning-based approach allows Air to handle the constantly evolving nature of data and business terminology, significantly reducing false positives and improving classification accuracy. The "24/7" operation implies continuous learning and adaptation as new data and contexts emerge.
Beyond classification, Bedrock introduces trust boundaries and auto-containment. Trust boundaries are logical policy constructs that define where sensitive data is permitted to reside, who can access it, and under what conditions. These are likely defined based on the output of Air's classification and integrated with an organization's existing identity and access management (IAM) systems and cloud security policies. When Air identifies important data, Bedrock helps "ring fence" it, meaning it applies these predefined policies to enforce isolation and access controls.
If data "gets into trouble"—e.g., it is detected outside its trust boundary, accessed by an unauthorized entity, or shows signs of exfiltration—Bedrock can "auto contain the problem." This automated response could involve:
- Revoking Access: Automatically modifying IAM policies to restrict access to the compromised data.
- Quarantining Data: Moving the data to a secure, isolated storage location or marking it for immediate deletion.
- Network Isolation: Modifying network security groups or firewall rules to prevent unauthorized communication with the data store.
- Alerting and Orchestration: Triggering specific alerts to relevant security teams, initiating incident response workflows, or integrating with Security Orchestration, Automation, and Response (SOAR) platforms.
By integrating AI-driven discovery, contextual classification, and automated response capabilities, Bedrock Security aims to provide a comprehensive, intelligent, and highly scalable data security platform that transcends the limitations of its predecessors.
Demo / Proof of Concept
▶ Watch: Proactive solutions: trust boundaries and auto-containment (1:33)
As an Innovation Sandbox pitch, Pravna Aduri's presentation was a concise overview of Bedrock Security's vision and capabilities, rather than a live technical demonstration. The transcript does not describe a specific demo or proof of concept being presented during the talk.
However, based on the claims made in the presentation, a typical demonstration of Bedrock Security's platform would likely showcase several key functionalities:
- Rapid Deployment and Initial Scan: A demo would begin by illustrating the "deploy in your cloud environment in 15 minutes" claim, showing the quick setup process without agents or proxies. Following this, it would showcase the initial, rapid discovery scan of a customer's cloud data estate, quickly identifying various data stores and their contents.
- AI Reasoning (Air) in Action: A crucial part of the demo would focus on Air's contextual classification. This might involve:
- Presenting a dataset containing known sensitive information (e.g., W2 forms) and then introducing new, related, but previously unseen sensitive data (e.g., 1099 forms).
- Demonstrating how Air, using AI embeddings, correctly identifies the 1099 forms as restricted, even without explicit rules, based on its learned business context from the W2/W4 examples.
- Highlighting the reduction in false positives compared to a simulated rule-based system.
- Showing the "ocean is now visible" by displaying a comprehensive, continuously updated inventory of sensitive data across various cloud services.
- Trust Boundaries and Auto-Containment: The demo would then illustrate the policy enforcement and response capabilities:
- Setting up a trust boundary for a specific type of sensitive data (e.g., financial records).
- Simulating a policy violation, such as an unauthorized user attempting to access the data or the data being moved to an unapproved location (e.g., a public S3 bucket or a Gen AI environment without proper controls).
- Demonstrating Bedrock's auto-containment in action, showing how it automatically revokes access, quarantines the data, or triggers an incident response workflow, preventing data exfiltration or misuse in real-time.
- Presenting the audit trail and reporting capabilities that provide visibility into these events and the actions taken.
While not explicitly shown in the provided transcript, such a demonstration would effectively validate Bedrock Security's claims regarding continuous discovery, intelligent classification, and automated remediation, offering a tangible vision of how enterprises can "sail the oceans safely."
Defensive Implications
▶ Watch: Bedrock's impact: protecting petabytes and saving operator time (1:53)
Bedrock Security's approach offers several profound defensive implications for organizations grappling with modern data security challenges. By addressing the fundamental shortcomings of legacy systems, Bedrock empowers defenders to adopt a more proactive, intelligent, and scalable security posture.
- Continuous Visibility and Reduced Blind Spots: The "serverless, distributed discovery mechanism" that "commoditizes data discovery" enables continuous scanning of "scale out data oceans." This means defenders gain an always-on, real-time understanding of where their sensitive data resides across all cloud environments. This eliminates the dangerous blind spots created by infrequent, expensive scans, allowing security teams to detect newly created or moved sensitive data almost instantly, drastically reducing the window of exposure to threats like insider risks or misconfigurations.
- Enhanced Accuracy and Reduced Alert Fatigue: By leveraging AI Reasoning (Air) and AI embeddings to learn business context, Bedrock significantly improves the accuracy of data classification. This directly tackles the problem of false positives that plague traditional DLP and DSPM solutions. Defenders can trust the alerts generated by Bedrock, allowing them to focus their limited resources on genuine threats rather than sifting through noise. This reduction in alert fatigue leads to more efficient security operations and a higher likelihood of promptly addressing critical incidents.
- Proactive Risk Mitigation through Contextual Understanding: The ability of Air to understand the semantic meaning of data, rather than relying on static rules, allows defenders to identify and protect sensitive information more intelligently. For instance, detecting salary data leaking into a Gen AI environment, as mentioned by Aduri, becomes possible even if specific rules for that scenario haven't been manually configured. This proactive identification of contextually sensitive data enables defenders to implement appropriate controls before a breach occurs, mitigating risks associated with shadow IT, misconfigured cloud services, or accidental data exposure.
- Automated Response and Faster Remediation: Bedrock's focus on "solutions, not alerts" and its auto-containment capabilities are transformative. Instead of merely notifying defenders of a problem, Bedrock can automatically initiate actions to "ring fence" data and "contain the problem." This capability significantly reduces the mean time to remediate (MTTR) data-related incidents. Automated responses, such as revoking access or quarantining data, can prevent minor incidents from escalating into major breaches, especially critical in scenarios like ransomware attacks or data exfiltration attempts.
- Empowering Business Owners for Data Governance: The concept of "deputizing your business to protect their own data" is a powerful defensive strategy. By providing business units with insights into their data's sensitivity and enabling them to define trust boundaries within Bedrock, organizations can foster a shared responsibility model for data security. This decentralizes some aspects of data governance, making it more agile and aligned with business operations, while still maintaining centralized oversight and enforcement through Bedrock's platform.
- Strengthened Compliance Posture: With continuous visibility, accurate classification, and automated policy enforcement, organizations can more easily demonstrate compliance with various regulatory frameworks (e.g., GDPR, CCPA, HIPAA). Bedrock's capabilities provide the necessary audit trails and evidence of controls, streamlining compliance efforts and reducing the risk of costly fines and reputational damage from data breaches.
In essence, Bedrock Security enables defenders to move beyond a reactive, manual, and often overwhelmed state to a proactive, intelligent, and automated data security posture, making it possible to "sail the oceans safely" even amidst complex and dynamic data environments.
Key Takeaways
- Legacy Data Security is Failing: Traditional DLP and first-gen DSPM solutions are inadequate for modern enterprises due to false positives, alert fatigue, lack of actionable solutions, and inability to scale for "data oceans."
- Continuous, Scalable Data Discovery is Essential: Bedrock Security offers a serverless, distributed mechanism that commoditizes data discovery, enabling continuous, cost-effective scanning of petabytes of data across cloud environments, eliminating critical blind spots.
- AI Reasoning (Air) Provides Contextual Classification: Bedrock's Air engine leverages AI embeddings to learn an organization's business context, accurately classifying data (e.g., 1099s based on W2/W4 similarity) without relying on static rules, significantly reducing false positives.
- Solutions, Not Just Alerts, with Automated Containment: The platform moves beyond mere alerts by enabling trust boundaries to "ring fence" important data and offering auto-containment capabilities to proactively address problems, reducing manual burden and minimizing exposure time.
- Frictionless Deployment and Operations: Bedrock deploys in the cloud in 15 minutes with "no agents, no proxies," signifying ease of integration and lower operational overhead compared to traditional solutions.
- Empowering Business for Data Governance: By enabling business units to define and manage trust boundaries, Bedrock fosters a shared responsibility model for data protection, aligning security with business context.
About the Speaker(s)
The speaker for this presentation was Pravna Aduri, who is the co-founder and CEO of Bedrock Security. While the talk was brief, Aduri's background was highlighted by his statement: "My co-founder and I built the scale out file systems that power the Fortune 500s today." This indicates a deep technical expertise and extensive experience in developing high-performance, scalable data infrastructure solutions for large enterprises. This prior experience is directly relevant to Bedrock Security's mission, as it underpins their ability to re-engineer data discovery for "scale out data oceans" and overcome the limitations of older systems. His leadership at Bedrock Security focuses on leveraging AI and security best practices to create a "frictionless data security company" that addresses critical challenges in modern data protection.