SPEAKER_00: Coming up on Twist today, we're talking to some of the best founders out there in the world, AI, solar, robotic factories, and also what happens if you take agentic AI and bring it to the world of cybersecurity. We got a lot to talk about, friends. Let's go. SPEAKER_01: This Week in Startups is brought to you by Pilot. Focus on your product. Let Pilot handle your SPEAKER_04: bookkeeping. Pilot provides the most reliable accounting, CFO, and tax services for startups and small businesses. Head to pilot.com slash twist and get $1,200 off your first year. Superpower. The best founders know better health equals better business. Visit superpower.com slash twist to join and skip the waitlist. And HubSpot for Startups. Smart founders aren't piecing together random tools. HubSpot is the customer platform that thousands of startups use to scale efficiently. Get up to 75% off plus three months of perplexity AI for free. SPEAKER_00: Go to hubspot.com slash startups. Hey, everybody. Welcome back to Twist. This is Alex. I have two amazing interviews for you today. The first one is with a company called Zeosec, and it touches on two things that I care a lot about. One, cybersecurity, and two, agentic AI, a term that I'm sure you've heard by now. Zeosec wants to apply the latter to help with the former. Yes, agent-driven cybersecurity. I love the idea. I love talking to them. You're going to love it too. Then after that, Terabase, a company from the Twist 500 that wants to use robots on site to build simply enormous solar panel fields. If you've heard us talk about AI and the enormous power demands that come with it, well, this interview touches on a lot of those themes and it's good fun. Let's get started. I'll see you on the SPEAKER_09: flip. On the show, you have heard us bang on about AI week in, week out, day in, day out. I'm sure you're very sick of it. But one thing that I'm also very excited about is AI in a cybersecurity context, or perhaps I should say cybersecurity in an AI context. The world now has digested AI models and is getting used to AI agents, deploying them across the enterprise and the consumer landscape. But what that does is open up new security issues. And there's one startup, Zeosec, that is working on agentic AI security. So I wanted to bring them on, talk to them and learn more. So please join me in welcoming Aaron Walls and Andreas Ushetkas. Hi guys, how's it going? Hey, thanks for having us. All right. So let's start absolutely up at the top guys. We're talking about agentic AI security. Everyone's heard the phrase AI agents or agentic AI. Perhaps we should just start with some ground SPEAKER_14: level here. How does your company define that concept? AI agents are effectively an LLM that sits within a framework, right? You have a web application that connects off to different tools and they do different things. It can be as simple as going to open up an email program and sending an email on your behalf, all the way down to operating something more local and physical within an environment, security systems, locking doors, unlocking doors based on inputs. They have far, SPEAKER_16: far reaching applications. So LLMs are powerful, but LLM agents are game changing. SPEAKER_09: Okay. And the reason why I think cybersecurity or security in general in an agentic AI context matters SPEAKER_18: is because the thing is doing its own activities. It's executing on its own frameworks per se, SPEAKER_09: but like it's still out there on its own. And that to me, from the lay person's perspective, Aaron really opens up a lot of, uh, worrying security issues. Am I, am I driving down the right SPEAKER_20: road here? You're exactly right. And really what's happening is we have guardrails that are being SPEAKER_16: developed by the model producers, by the hyperscalers. But really the challenge when it comes to adopting these from an enterprise standpoint, from a corporate governance standpoint, is we currently don't have very many good ways of confirming that those guardrails are working SPEAKER_18: properly. I'm going to try some big words here. Is that because AI models are inherently probabilistic instead of deterministic and therefore old tests, the old methods of testing to see if something is operating as it should don't exactly apply? Effectively. Yeah. And I think Audris can actually go SPEAKER_25: into a little bit more detail on that. Yeah, absolutely. So, uh, if you look at the models these days, they're not just models. They're not just answering your questions anymore. They're integrating with all these tools. So they have all of these, uh, new protocols coming up like model context protocol, like MCP, that allows you basically to call all of these tools in a standard way. Now that gives the model a lot of power, and there is not much validation and security for the, for that power. So basically, you know, they can interact with the databases, they can interact with APIs, and that opens not just new ways of, uh, hacking into the systems. It also opens new ways in to hacking into the systems using all the vulnerabilities. So you can still, if, if you have a model, for example, that interacts with the database, you can still use like old school vulnerabilities, SPEAKER_28: like SQL injection, and basically tell the model to execute the SQL injection against the actual database SPEAKER_09: and get the data that way out of it. Now, when would that come up? Because when I think about uh, AI agents, I think about someone sort of a corporation setting something up, setting some rules for it and putting it to work. It's not something that I thought you could do from the outside. So when I think about someone who might want to do SQL injection, I'm thinking about an external person who wants to get in there and cause mayhem. But my view of AI agents was always that they're SPEAKER_11: internally sourced. So Andrews, what am I missing in this picture to make this make sense? SPEAKER_25: So not all agents are internally sourced. I mean, there are a lot of offerings out there, obviously that can, you know, call APIs to send an email, for example, like an assistant agent or SPEAKER_32: something like that. So that's an interaction that happens from the public perspective. SPEAKER_18: Ah, so model context protocol allows for interaction with other data and other sources of information saying so from them, you could have, ah, okay, I understand. SPEAKER_25: Absolutely. So just MCP is basically what the model calls in order to get the data out of the actual tool. So it's just a way to talk to the actual tool, but, but you mentioned the private models as well. I mean, obviously they're not exposed, but there's still an issue there, but it's, you know, local user exploit availability. So basically somebody could still do like horizontal privilege SPEAKER_39: escalations, vertical privilege escalations, and get data that they're not allowed to access to, SPEAKER_11: even if they're internal employee. Okay. Aaron, if I understand this correctly, if I'm using an AI agent and I'm using MCP, which is the Anthropics new framework that everyone seems to really like, and people are adopting to bring in information into my AI context, is there no built-in security there whatsoever? It just brings stuff in and then huzzah, you can, the agent can use it. Cause that seems, uh, even from my perspective, relatively insecure. It's less that there's no built-in SPEAKER_14: security and more that the fact that when you are bringing this information in, your attack surface is now expanded. And there are more things, there are more links in the chain that could have a vulnerability exploited in it. So really it's just a matter of, well, we used to have something, you know, a gen AI that was all contained. And all we really had to worry about was, can we make it give us, you know, an answer that is clean or prevent it from telling us how to make a bomb? Whereas now we're really expanding out the different areas of infiltration that can happen with the, the advent of NCP and A2A frameworks. SPEAKER_18: A2A is agent to agent. It's the recent Google standard that allows agents to talk to one another. So NCP connects to applications externally. A2A is essentially an agent to handshake as far as I can tell. Okay. So this actually now makes perfect sense to me. I was a little confused while you SPEAKER_09: guys were choosing agentic AI as your focus area, but based on the last two minutes of conversation, I now really get it. I guess my silly question, Aaron, is given how much the attack surface is being broadened here, why aren't we hearing more people talk about the cybersecurity risks of using AI agents? Because based on what you guys just told me, it seems like a pretty glaring issue for a product that seems to be gaining real enterprise market share and dollar share. SPEAKER_14: Right. And, and I think you hit something that's endemic to the cybersecurity market in general is that the, a lot of the cyber defenses tend to be chasing the problem and the development of these secure services first has not really been a thing we've done as an industry. A lot of what's going on now is we have these enterprises, the development teams who are building brilliant AI solutions and transforming the way these companies are operating. And then you have governance committees within the organization. And then the security team saying like, whoa, let's pump the brakes here and talk about like, how do you know what you have built is, is secure? And a lot of what the development team will say is like, well, we are utilizing AWS bedrock. You know, we have the right guardrails in place, or we've trained the model, or it has the correct permission sets. It's like, great. That's a great step one. But what about the 67 other potential issues that are very well documented by the company, the likes of OWASP, as well as MITRE? You know, they have gone forward and published an incredible amount of information on where all of these holes could be. So we have this- SPEAKER_11: Aaron, I'm going to just pause and do some acronyms here. OWASP is the Open Worldwide Application Security Project. OWASP is the acronym. I missed the second one. I'm not familiar with it. Can you SPEAKER_52: just explain that to the folks? If you're a startup founder, you've got a million things that you're worrying about at this moment. You know what you shouldn't worry about? Your bookkeeping. Your bookkeeping should be perfect. And you should have a partner who makes sure it is so. At that partner is Pilot. It's the industry standard. Pilot is the largest accounting firm out there built for startups. They know how high the stakes are. And that's why companies like OpenAI, ScaleAI, and Airtable trust them with their books and have done so since day one. When you use Pilot, you're going to get a dedicated team for everything you're doing from booking to taxes. And now, you know, listen, if you need that CFO level guidance, they're going to give you that. So you can stay focused on what matters, building your team, building your product, and delighting your customers. You should not be stressing over spreadsheets with your TNL and all this nonsense. You want accurate financials delivered on time every time. And you want to be compliant with your taxes. You don't want any last minute surprises. And when it's time to raise your next round and you're scaling up, Pilot CFO services team is going to help you plan and grow with confidence. Startups that use Pilot tend to raise a bigger Series B and a bigger Series C round than the average startup. Why? Because when you're buttoned up from the start, everything gets easy. Focus on your product, let Pilot handle your bookkeeping. This week in startups, listeners get $1,200 off their first year. Chamath Palihapitiya: Just go to pilot.com slash twist. That's P-I-L-O-T dot com slash T-W-I-S-T. SPEAKER_14: Yeah. So MITRE and MITRE Atlas in particular is this new framework for establishing where the specific holes are when it comes to these agent frameworks. So MITRE has a long history of providing intelligence and attack service management to the industry. And they have this great MITRE attack framework that has been used for a good part of the past decade. They've updated with the MITRE Atlas framework, which is now focused on AI deployments. SPEAKER_11: Okay. Now, Andrews, I think I now understand why we need to secure AI agents more so than we are today. Tell me why you guys have picked pen testing, offensive security, continuous testing. Why is that the right approach to this issue as opposed to a different angle to start? SPEAKER_32: Well, first of all, pen test is my background. I've been doing pen testing now for 25 years. SPEAKER_18: Is that why you're on Linux today and you couldn't use QuickTime like everyone else who comes on the show? SPEAKER_32: That is why I'm on Linux. Yes. It's much easier to do testing from Linux environment than it is, SPEAKER_25: you know, from a lot of other environments. Why, why offensive? Because again, validation is needed. And the best validation is basically acting as an adversary. So basically you're, you're the hacker in that case, you get into that persona and you try to break into these systems. LLM is advancing so much that you cannot just hire a pen tester once a year. That's usually, SPEAKER_32: you know, industry standards. So if you're running like e-commerce environment or something like that, you will hire and do a manual pen test once a year. But these environments advancing so fast, SPEAKER_25: you need something that can do it on weekly basis or sometimes even daily basis. That's why continuous pen testing. And again, you know, coming from this background, we're not just aware of this new, new attack vectors, like, you know, prompt injection and things like that. We're also looking at all the old school stuff that we can do just through the LLM. So we're using LLM not as, SPEAKER_32: you know, all in one, so to say, we're using it as a way to get into the system and see just exactly SPEAKER_63: how far we can go, just like an actual attacker would do. SPEAKER_69: Okay. And in most cases, when you run a pen test on a company that hasn't really worked on its SPEAKER_09: agentic AI security, what do you find? Are they wide open like a barn door to exploitation? Or is there security okay, but just needs a little extra help? SPEAKER_25: It depends on the environment. But these days, we're early in this game. So we see a lot of issues SPEAKER_32: like, you know, getting access to things like financial reports and financial information and getting access to the user information that you're not supposed to have and things like that. SPEAKER_73: Which could be a HIPAA violation, a GDPR violation, a breach violation and so on and so forth. Yes. SPEAKER_18: And all the bad acronyms essentially will come and bite you. Okay. So Aaron, I now understand the SPEAKER_11: problem. Why are you worried about it this way? I'm curious about the market itself, because to me, SPEAKER_18: we've been talking about AI agents industry wide for like 18 months or so, I presume that that's a little bit late. But what I'm not clear on yet is just how far they've been rolled out inside of SPEAKER_09: actual enterprise scale customers. Basically how much out there today is hype and how much out there is real use driving real need for what Zeosec is working on? Well, so I think that is such an SPEAKER_14: incredible question because we are at this point where the interest and the, from the executive team is there. They're pushing the organizations to deploy. Their investors are asking, how are we adding AI to our workflows? How are we adding AI to our products? So the momentum is going, but the challenge is the security teams don't have the tools to fully evaluate and fully mitigate that risk. So they're pumping the brakes. So you see a lot of talk about this, but if you talk to the organizations and you see how many agents have you onboarded, we're talking two or three, maybe, right? We're not talking a lot. SPEAKER_11: But so just to put that number into context, how many agents do you think the average, I don't know, Fortune 50 company will have in say five years? SPEAKER_15: Uh, thousands. They're going to have- SPEAKER_20: So essentially they have basically zero compared to what they're going to have down the road. You got it. And it's because of these systemic issues that we're facing. The technology is new, SPEAKER_14: kind of like you're saying, probabilistic models, they can get things right most of the time. Right. But it's not perfect. So a lot of what we're trying to do with our testing, or offensively testing, but we can also do things like make sure that the model is giving the same answer, or at least within the same context of an answer. And being able to report out that degree of granularity to the security team, the compliance team, and the governance teams will then empower deployment of AI throughout the enterprise. Because right now that's the major hold back is they don't know what they don't know. And they're pulling back because the risks are huge to having an agent, you don't know how it works completely have access to all of your critical SPEAKER_09: internal company data. Yeah. That's what interns are for, not agents. I mean, I joke, but it sounds, it sounds like a real problem, but to me, it feels like everyone who's currently trying to sell SPEAKER_18: AI agents, be it Microsoft or Sierra or whomever should be piling capital into Zeosec because if you guys can solve this issue, it could unlock an enormous explosion of adoption of agents that right now are sitting somewhere between the C-suite and actual implementation. Is that fair? SPEAKER_15: That is exactly how we feel. Yes. All right. Microsoft, come on. You have a VC firm, cut the SPEAKER_09: check. My next question is, what's the curve going to look like here? Clearly, there are still some issues that you guys are helping to sort out, but when do we reach the actual agentic era, if you SPEAKER_11: will? Because I feel like we're not quite there yet, but we've been on the cusp of it for some time, SPEAKER_14: Eric. Yeah. And I think talking to a lot of the leaders in the industry, Eric. You know, the leader of Anthropic, I mean, we've got, you know, Mark Betty off at Salesforce, I mean, it's saying there's going to be over a billion agents, you know, deployed within the next, what is it? Six months, 12 months. You know, I think there's a lot of expectation about this, but until we truly have those business cases that work within the enterprise and ones that are safe to deploy, then it's going to be a matter of like solving these problems in order to get to that point. I'm guessing six months is when we're really going to start seeing the floodgates open. SPEAKER_09: Andrews, do you agree with that timeline? Six months until the floodgates open and the agents come and take over our lives and ruin our ability to have jobs? I think it's optimistic, but again, SPEAKER_94: this industry is moving so fast that I can't really predict at this point. I'm not even going to venture, I guess, but yeah. Six months to two years. Six months. Well, that's also fusion and a SPEAKER_09: whole bunch of other things. Okay. So we mentioned MCP from Anthropic. We've talked about A2A from SPEAKER_18: Google. You guys wrote a post, uh, digging into kind of multi-agent systems. And to me, like, there's going to come a time in which the idea of an agent that does multiple things plug, SPEAKER_09: it's collapsed into chains of agents. Does that make the security issue simpler or more complicated? SPEAKER_32: Way more complicated. Because now these agents basically interact with each other and, you know, they can talk to each other and extract information from each other. So it's not just testing one agent at that point. You're basically testing an entire environment, so to say, entire infrastructure. SPEAKER_69: Right. And so that's where the idea of pen testing in an agentic context to me, Andrews, SPEAKER_18: doesn't seem to be as effective because if you have so many agents constantly talking, is penetration testing the right way to go about it? Or maybe I'm asking what's the next step in securing agentic AI past pen testing? Because it doesn't seem to cover every single problem that I could invent in my head that you might want to solve. Yeah, but usually pen testing is not limited SPEAKER_25: to single application. Usually when you hire a pen tester, they will test an entire environment. They will even go to like LinkedIn and get the profiles and see, you know, what they can hack into, where they can send spam emails to a phishing emails and get, you know, information that way. It's the entire like holistic testing. And that's how the agent testing is going to become as well. So eventually, the pen testing is not going to be this simple single agentic AI. It's going to be SPEAKER_106: an entire environment that you're going to be testing at the same time. SPEAKER_108: Okay, founders, it's all about efficiency and performance in your startup. But what about you? What about optimizing yourself? When's the last time you got in there and said, how could I be better, stronger, faster, sleep better, diet, exercise, mentally, all of that stuff gets skipped until now, because there is a new product that I'm using called super power. It's the ultimate health membership specifically designed for founders, but anybody can use it. It's built to keep high performers at peak performance. You get full body testing across 100 plus biomarkers. This is your organ health, your hormones, inflammation, and it gives you actionable data and clear insights. You track all of your KPIs in your startup. Why not track these for yourself with super power? Visit superpower.com slash twist to claim your spot and unlock peak health today. I can't say enough about self-directed healthcare, which I believe this is the foundation of. I've used a bunch of other services, and this is the best one I've ever used. Better health equals better founder. It's that simple, which equals better business. Again, SPEAKER_11: superpower.com slash twist. How long until we have AI agents doing pen testing for other AI agents? SPEAKER_25: And I'm not being facetious. I'm actually curious. Right now. So our solution is based on AI testing AI. It's not just one-off prompts, basically. It can interrogate the other AI. So we can basically tell our system, you have 10 turns and you have to extract this information from the other AI. And it's our model doing that extraction. So you guys are literally like the AI police. SPEAKER_20: Yeah, I guess. It's a really interesting paradigm that we're moving into because, SPEAKER_14: you know, police are for bad actors and AI itself can be trained to be bad actor or just the negligence of an AI can have bad actor tendencies. So we need to do the discovery of these tendencies and provide visibility into the org where it's needed the most and give them the ability to say like, this, you know, exposure here, like, yeah, maybe they didn't get the answer right all the time or whatnot. But that's okay, because it's customer service. And we're only going to be getting 70% of those right anyways, even with humans. So, right. So it totally depended on the application. Whereas let's say you're now dealing with loan processing and applications, totally different set of requirements. So I think, you know, saying like, we're policing, this is a really interesting way, but these agents are the, I think the right way to think about agents is they should be treated much like humans in the organization. They are unpredictable, much the same way humans can be unpredictable, but they are given jobs and they need to be evaluated on the work that they're doing. And I think that's where we can play a critical role. Talk to me about the future though. I think SPEAKER_09: I have a reasonable grip on pen testing in this context, but what's next for the company? SPEAKER_14: Well, I think the most interesting piece of this is the company where we're going now, the people who understand this problem are on the security side of the equation. That's their job. That's what they've always been there for. That's their function in the company is to secure the assets of the organization. Where I view us going is if we can expand that purview into, um, you know, the engineering side of the world too, and allow the engineers to understand that code is not innately secure. It's your job to secure this code and being able to lever a lot of these vibe coding assistance, um, you know, which are phenomenally powerful tools, um, the code that they're producing, not necessarily the most secure code. And that's not any fault of the vibe coder or of the engineer. It's just, you're taking again, probabilistic. You took the average of 10 years of stack overflow and that's what we're getting. So now where we have this code that's being generated and we're not able to confirm out of the gate is this stuff secure. So I, I really see us moving in the direction of fitting within that model of code being produced by AI and then checked by AI as SPEAKER_88: well, but from an offensive perspective. Okay. Um, well, that sounds very exciting. So it sounds SPEAKER_09: like a feature that's both very fast, very flexible and also secure. And that would be lovely because currently I feel like development isn't any of those things. So that sounds like a much better feature. All right. Uh, last question before we go is just, how are you guys doing on landing first customers going out to the market? How are those conversations going when the rubber meets the SPEAKER_14: actual enterprise road? It's going great. Right. So we have, um, we've had a lot of really great, you know, conversations with design partners, as well as companies that are really just starting to get a sense of the, uh, of the new landscape. And we've been able to identify certain companies that style, right? Who is our ICP? And they tend to skew larger. They tend to skew towards finance. They tend to skew towards those critical regulatory environments, because that's the kind of company that truly understands SPEAKER_126: that the problem is there and they have to deal with it because they've been, SPEAKER_14: they've been working in these frameworks forever. And we're also partnering with a couple of hyperscalers, which is incredibly exciting. Um, and being able to offer innately, um, our services, if you are, you know, signed up with this particular hyperscaler. Well, there's only so many, SPEAKER_15: there are only so many, but. Blink twice if it's Azure. Blink three times if it's Google or four SPEAKER_09: times if it's AWS. No, no links at all. All right, fine. Well, actually I was just thinking that it'd be a really smooth way to sell this. If you had a partner like Sierra, which builds AI agents and SPEAKER_11: just kind of work with them as like a preferred, essentially software vendor. And then you could probably just grow alongside some of these other companies that are doing well, but I think going SPEAKER_09: the hyperscaler routes even better than that. All right. The website is ziosec.com. Just before we go, what is a role you guys are hiring for where you desperately want that excellent candidate? SPEAKER_136: Andres, you want to take it? SPEAKER_32: Yeah. So at this point we're looking for security analysts, especially, you know, ones that have been doing band testing in this space. There are not many of them. So those kinds of people that we need. We're also looking for a couple of, uh, full stack engineers, um, particularly with the expertise in rust and typescript on the front end. All right. Well, guys, thank you very much. When SPEAKER_09: you have those first couple of enterprise customers, please come back and tell me all about them and we can wrap on about business models, but in the meantime, good luck. And here's SPEAKER_00: to our agentic future. Thank you. Thank you. I hope you're ready for us to stop saying AI every third word for the back half of this show. But if you're curious about where all those GPUs are going to get their juice. Well, look up to the sky and then say the word Haribase out loud. Let's go. If you are a long time listener of the show, you have heard Jason and I bang on ad nauseum about AI and the enormous, enormous energy inputs that doing all that number crunching is going to take. Now, some people think we need to bring back nuclear. Cool by me. Some people think that fusion is closer to a commercial viability than other people do. Cool. But one thing we do have today is a whole lot of sunlight and we have amazing technology, we as humans to capture that energy and turn it into juice, juice that can power data centers, homes, whatever you want to call it. Now we all know this exists. Why isn't it everywhere? Well, there are some labor issues, some supply issues, but there's one company called Terabase that is doing excellent work to try to bring mass scale solar to the world using automation out there in the field. I wanted to learn more. I added them to the Twist 500. So please join me in welcoming Matt Campbell from Terabase. Matt. Hey, how are you doing? Great. How are you doing? I'm doing pretty good because when I was prepping for our chat today, I was surprised at just the scale of progress in installing solar power in the United States. The narrative out there is that it's all happening in China and that we are infinitely far behind. But according to the Solar Energy Industry Association 2024 report, we installed 50 gigawatts here in the United States of solar power last year, which is more than I expected and I thought rather encouraging. So from a high level perspective, are we doing okay at overall solar install here in the States? SPEAKER_146: Uh, fantastic. Yeah. I mean, I think like you said, 2024 was a banner year. SPEAKER_147: Uh, I forget the exact stat, but it's like more than 80% of the new generation in the US was solar. SPEAKER_151: 66%. Oh, 66. Okay. David Friedberg: Um, but still, I mean, it's a, it's a huge percentage of the new energy coming online and I think it bodes well SPEAKER_00: for what's ahead. So Terabase is a company that melds, uh, software, both for planning and operations. And then in the middle, there is an element called TerraFab that helps you guys, as far as I can tell, construct solar panels out in the field for folks who are not familiar with Terabase. Can you just walk me through the product mix really quick? SPEAKER_156: Sure. Yeah. So Terabase is focused on, and let me just start explaining the utility scale solar market. So these are a good point. Yes. SPEAKER_160: Giant solar power plants out in remote areas that span SPEAKER_147: thousands or tens of thousands of acres. Um, and so a hundred megawatt to multi-gigawatt type sites. And so what we do at Terabase is we build, um, digital and automation tools to design, build and operate these giant projects more efficiently. So there's three parts to this. SPEAKER_00: There's the engineering work that goes in before boots are on the ground. Then there's the construction element of this, which is TerraFab, which I want to start with. And then at the end, there's stuff to help run the solar farms. So it does seem kind of like a vertically integrated company. Is that a SPEAKER_165: fair estimation? SPEAKER_108: All right. Everyone knows that CRM isn't just software. It's basically the heartbeat of your business, but it can get ugly quick. If your data isn't organized and you're dealing with a messy tech stack. That's why I love HubSpot for startups. It's the all-in-one customer platform. So you don't need a Frank inside of pools. No, right now, early stage companies are going to get 75% off. And with this one system, you're going to automate marketing and actually converts track your sales pipeline without spreadsheet chaos. And you're going to manage your customers like the Amon hotel, six stars all the way. You're going to get investor ready analytics that tell your story perfectly. And man, when you pull up HubSpot and you got those metrics, you got those analytics, things are going to go really faster for you as a startup with potential investors. Plus you're plugged into an amazing community of founders who've already tackled what's ahead. They've been around those sharp turns and they can tell you how to navigate them. HubSpot was built by scrappy founders. I know them and they understand every dollar counts. That's why hundreds, thousands of startups trust HubSpot to scale their businesses. Here's an amazing call to action. So generous from my friends at HubSpot, 75% off. That's right. Seven, five, not 7% off, not 5% off, 75% off HubSpot for startups. You're going to get three months of perplexity AI for free. That's a great pot sweetener. Head to hubspot.com startup. SPEAKER_147: Yeah. It's sort of like a synthetic vertical integration through a software platform. David Friedberg: Yeah. Synthetic. Why synthetic? Just because it's digital? SPEAKER_147: Well, because a true vertical integration, you would actually be the developer and the contractor and SPEAKER_162: and it's just the software is doing those functions, but we ourselves aren't playing those SPEAKER_00: roles in the, in the value chain. Okay. So back in, uh, late 2023, you guys were talking about the successful completion of your first commercial Terra fab project. That was, I believe 17 megawatts. So a portion of a larger project. And then, uh, in late 2024, you wrote on LinkedIn that you were wrapping up your latest Terra fab project. So I'm really curious how many projects has terabase been involved with that have used kind of its soup to nuts software planning through construction, through, SPEAKER_147: uh, operation software size project. Yeah. Yeah. So we, so we've been involved in, uh, dozens of projects around the world. And then as you mentioned, like the big thing called Terra fab, which is the system, which robotically automates the construction. So we've completed three of those projects. Uh, today actually we started our fourth. Uh, so, um, good, good coincidence with this chat. Uh, and then, uh, in two weeks we'll start a fifth project. So, um, and we're kind of at this point of graduating from sort of mid, mid scale commercial pilots to be like sort of large scale, um, deployments, SPEAKER_00: you know, and sort of the hundreds of megawatts. Is that why you guys raised the very large 130 million dollar round from vision fund two in March, because you're moving from the pilotish stage to the kind of SPEAKER_180: enormous project stage. And so more capital, more capacity is just useful for this stage of the SPEAKER_160: business. Exactly. Yeah. No, the capital is really to, you know, help, uh, fund the, the growth inflection SPEAKER_147: for the company, um, but also to accelerate our investments in, uh, robotics software, AI. Um, and really, you know, how can we, cause the, the market is there, the, the need is there, David Friedberg: the value is there, but we want to go faster. And so with more capital, we're able to do that. SPEAKER_182: All right. Let's talk about Terra fab because I've seen, uh, drone clips of this and we're going to play one in just a minute, but I think it might help people. If you just explain what kind SPEAKER_00: of in situ or on site manufacturing you're doing with this process and, and kind of, uh, what you bring on to site and then what you put together for actual installation. Basically the, the, SPEAKER_147: the problem statement is we want to find a way to automate construction of solar plants. Now, um, no, no construction industry has really been automated yet, right? Like this is Greenfield. And, um, the nice thing about solar is it tends to be a very repetitive type of install, you know, row after row, after row, after row. And so it kind of lends itself to more of an industrial automation approach to, to construction. Um, now there's a lot of ways you could imagine to do the automation with, you know, humanoid robots or other types of robotics. Um, but the approach that we've chosen is, uh, an onsite prefab facility. So if you're familiar with prefab as a concept, it's like pre-assembling things or to enable rapid deployment. And, um, in, in our analysis, we concluded that doing an onsite prefab facility called Terra fab was the way to affect automation as opposed to offsite. Cause these projects are super remote. So if you prefab offsite, SPEAKER_146: you'll have too many trucks going out to the site. Okay. Tell me about remoteness here. Cause like, SPEAKER_182: I, I, I've, I was in Boy Scouts. I've been out in the sticks. Uh, but I'm curious, like how far off the beaten path are we talking about when you say remote? Cause that could be two miles out of town or SPEAKER_188: that could be 500 miles out of town. I'm not sure the scale here. Well, well, first you head out to the SPEAKER_147: sticks and then you keep going for another six hours. Got it. Okay. So pretty remote generally, you know, cause that's where you find the big pieces of land and the sun. And, um, so, so generally, you know, at least a couple hours from a major city. Um, but sometimes it could be even days from a major SPEAKER_00: city. Before we get back to the prefab point, I have a question about a transference of electricity because I read back in the day that taking a lot of juice and throwing it through copper cables over a long distance is a lossy that you lose some of the, some of the power generation. I've also read that that's gotten better. So I'm kind of curious if you are five, six, 10, 12 hours out of a city by car and the power needs to get to a, let's just say major urban center. How much do you lose in SPEAKER_193: transference? Yeah, it depends, but, uh, it's not as much as you might think. I mean, it could be SPEAKER_147: 6%, 8%, 9%, you know, again, it's a function of distance and voltage, but, um, and, and, you know, there's already now transmission in general is a constraint on the industry, but there's, you know, a lot of examples, like there's a high voltage line that goes from Arizona to California and it passes through a lot of desert where you can do solar. So those pathways exist. And of course we need more SPEAKER_00: of that capacity, the more solar we want to do. Got it. Okay. Back to prefab, uh, your point is that if you do the prefab on site, you limit the total number of trucks that are coming in. I presume because that's the parts you're going to assemble on site are much more compact, uh, before they're SPEAKER_147: put together. Exactly. Exactly. So, so what we do is we come to the site, we have a pop-up factory. So, you know, think of it as a 200 foot long assembly line. You can set it up in four hours. Um, it's, um, it, it could produce a megawatt in eight hours. So of course in the solar business, we, uh, everything's a megawatt or a kilowatt or a gigawatt or a terawatt. Um, and so, um, so that's our unit of production and, and then you build a section of the plant and then you pick it up and you move it and you build the next section and, and, um, and you sort of go around SPEAKER_00: until the farm is completed. Oh, so you actually move the terrafab facility itself. You don't just plop it in one place and then export. Oh, okay. I guess if you're doing, as you said earlier, acres of coverage, you want to reduce the amount of travel time after prefab. Okay. Now, once terabase has taken in, uh, materials and components and done the prefab, you're still using humans to take those solar panel arrays and installing them because after your first, um, terrified project, you said that you guys quote demonstrated labor productivity improvements of 25%. And so I read that as humans still in the loop, but just more efficient. Is that correct? SPEAKER_202: That's right. Yeah. Yeah. And I think in, in, in the field of automating construction, humans are SPEAKER_147: going to be in the loop for a very long time. Um, and so humans and robots and machines have to work together. And, um, but yeah, definitely there's a lot of tasks that humans are best suited for, especially fine motor activities and other things. So it's a combination of our robotics along with, with workers. SPEAKER_00: So my question about your overall goal is, is, is the goal of terabase to speed up the pace at which we can build out domestic solar capacity, or is it to, to lower the costs thereof? Because I feel like you could make the argument either way for what kind of the, the North star is for the business, SPEAKER_180: but I'm curious from your end, what gets you out of bed in the morning when it comes to improving SPEAKER_147: our kind of grid health via more solar? Yeah. I mean, I think it's, um, speed is certainly SPEAKER_160: critical. Like the world needs to build more solar faster and labor is a constraint everywhere. It doesn't matter if you're in, even in India, where you think there'd be no labor constraint, there are labor constraints, especially at the scale, you know, the name of the company's Terra, like terawatt at the terawatt scale. And you really think about these scaling limits that you run SPEAKER_147: into and people is a big part of it. So, so faster is certainly one thing. Cost is always center. Um, quality is a big thing. Um, you know, hot, you know, we're building assets that need to operate with little maintenance for 40 or 50 years. So you want to build them with the highest possible SPEAKER_00: quality so that they'd last 40 or 50 years is a much longer timeframe than I would think we would have for in the field solar installs. And this may just be my sectoral ignorance speaking out, but when I, when I think about things left outside after five years, they tend to look a little worn. And after 15, I mean, my Lord, 50, w what about hail? What about dust? I mean, it seems like solar would struggle to last for that many decades. So what am I missing here, Matt? David Friedberg: Well, I mean, most, um, power plants, whether it's a hydro, like Hoover dam or coal plant, most of them SPEAKER_212: are operated for decades, three decades for, even the nuclear power plants. I mean, SPEAKER_160: so there's no like intrinsic reason it can't last long. I mean, you have to think about things like UV degradation, but like steel and concrete and cables, they last a long time. And then the panel, um, has to just be engineered for that duration. And, um, so I think, you know, a 30 year life for SPEAKER_147: the panel or 34 years, totally realistic. Uh, probably what's going to happen in practice is the panels that will be replaced because in 20 years, there'll be a panel that's twice as good and half the cost. And you, you just go in and you swap out the panels. Yeah. SPEAKER_180: But once you've done all the work to set up the actual, uh, I, I call them solar farms. I think you're calling them solar power plants. Yeah. SPEAKER_00: Yeah. Potato potato. Yeah. Uh, you can take off the cells and replace them and you can leave the underlying foundations in place. Okay. Yeah. And lower the cost. Like Hoover dam, the, the turbines SPEAKER_160: generating electricity, you know, have been replaced multiple times with more modern, more efficient, SPEAKER_182: but the, the concrete dam is the same. I mean, I, I hope so. No one told me they replaced it. SPEAKER_00: Uh, on the point you just made about solar getting, you know, better, uh, and, and the pace at which we've seen improvements in efficiency in terms of capturing, you know, what share of the solar rays that are coming down and converted them into power. It's been insane to watch the cost curve of, of the solar industry. I, I guess maybe the question is how much more efficiency is there to be squeezed out of actual solar cells in the next five or 10 years? Is it going to continue to be impressive or have we reached a point in which, uh, improvements are going to be a little bit SPEAKER_160: more incremental? You know, for the current generation of technology, we're definitely at the point of SPEAKER_147: incrementalism. You know, the cost is extremely low, um, in most countries. Um, and, uh, and the performance for silicon, which is the predominant type of solar cell, uh, is, uh, is at the limit of kind of what you can achieve. Um, there are some next gen semiconductor compounds. Uh, there's a whole family called perovskites, um, that would, you know, today we're at like 22% efficiency. So you, you convert 22% of the sun's energy into electricity. Clearly we, you know, we can get to 35, 40%. That takes a step change. Now, how long that will take is, is a question. I would guess it's going to be about 10 SPEAKER_06: years to get there. Um, that's not bad. Yeah, no, from 22 to 40% in 10 years. My Lord, that's, SPEAKER_00: that's crazy good actually. Now that I think about it, that, that would make solar even, SPEAKER_180: I mean, everyone I think believes that thermal power production via burning coal is going to eventually fade away. And I think a great way to do that would be doubling the efficiency of solar SPEAKER_00: panels. I mean, that would be, that'd be crazy. Okay. Well, that all feels, that all feels pretty good. I, I presume that for your future terawatt installs of solar, there's going to be a storage component to it. Um, but when I was just going through kind of all the terabase products and history, I didn't really see a lot about storage. And so I'm kind of curious, do you guys team up SPEAKER_165: with other companies to handle the storage site? Is that always done by the customer themselves? And so not your business, how does that play into your planning and processing? SPEAKER_160: Yeah. I mean, we definitely work closely with the storage companies and we're building some SPEAKER_147: software that, that manages the interaction between the solar farm and the grid and charging the batteries. So sort of the, sort of the control level system. I mean, storage at this point is, I mean, in, in a way it's a prefab system. So these, they, they show up in these containers David Friedberg: and it's sort of plug and play. Um, so it's like minimal work that's required on site. SPEAKER_00: The stack here is gonna be exciting because you guys have software to help design solar power plants. You have software terrain pro to help people sort out how to actually set them up on hills and so SPEAKER_180: forth. Actually, if you have a second, you're watching this, you're listening to it, look up terabase and look up their software for terrain. It's it's the graphics are pretty cool. Uh, SPEAKER_00: then you have construction and then you also have stuff to help run it. If other people have plug and play storage, it really does feel like the, the barrier to building out a solar power plant is just capital and time now, but there's no like tech risk or vendor risk. It feels solved in a really SPEAKER_147: positive way. Is that, is that fair, Matt? Yeah, no, I mean, solar is super well established. I mean, um, you know, globally, the market last year was, I mean, we don't have a precise number yet, but it's probably about five, 600 gigawatt. Um, I mean, that's it, which is unbelievable. I mean, when I started in the industry, it was a gigawatt a year. Oh, okay. That helps a lot of me explain the SPEAKER_00: differential. I was just my face and disappointment there was realizing that our all time record SPEAKER_180: breaking year brought us up to less than 10% of the, the global total last year. This is an unfair SPEAKER_00: question, but I have you here. So why not? What percentage of that should we be targeting? Like 25%? I mean, clearly we're a big nation. We have a lot of places that have a lot of sun. So to me, I feel like there's no reason why we shouldn't be, uh, at the absolute tip of the spear when it comes SPEAKER_147: to solar installation at the national level. Yeah. I mean, I think that the U S should get to the point of doing a couple hundred gigs a year now, now a couple of things have to happen because I think within the existing sort of framework, 50, 60 gigs is probably about the right number. And when I say existing framework, I mean, the existing transmission system building solar projects, most of which now include batteries and connected to the grid in Texas or California, Arizona or wherever. Um, but the future, and this is sort of where there's an SPEAKER_160: interesting convergence with data centers, which is in the future, we can get off the grid. Um, SPEAKER_147: it's, it's actually, it's an interesting cause solar started as an off the grid thing. Like, uh, like, uh, people would use it in remote areas to get power. Um, and, and we see it going for full circle because at the point that you've got other forms of backup in the form of batteries, or maybe some gas backup or something, you can pull the plug and you could, all you need into the data center is a fiber optic cable and you don't need to connect SPEAKER_160: yourself to the electrical system. And at that point, there's no constraint. I could build five gigs. I could build 10 gigs. Um, so there's an interesting, and we see this all over the world SPEAKER_147: where people are looking at, you know, getting to the point of cutting the cord and doing multi gigawatt systems on a standalone basis. We call it an island basis. That's awesome. SPEAKER_244: But just because I have no idea the answer to this, what would that cost? Let's say that I wanted SPEAKER_182: to do, I don't know, a one gigawatt install as an island to use your parlance. Um, how much capital? SPEAKER_147: So in the United States, if it was just solar, it's about a dollar a watt. So a gigawatts about a SPEAKER_160: billion bucks. Now, if you go to other parts of the world, it's a lot cheaper. So there was a project announced in January this year in the UAE. This is a really important one SPEAKER_147: to track. So this one has got, um, 5.2 gigawatts of solar. It has a 19 gigawatt hour battery, which is gigantic. Um, and then it has one gigawatt of 24 seven solar as the output. So, so basically the math is you've, you've built five times as much solar as you need, and you put a big battery so that you can charge the battery and then at night, and then you get 24 seven power. And the total cost of that project is about six, I think it's about 6 billion. Okay. Um, but if you compare that, if I built a one gigawatt 24 seven nuclear power plant, you know, best case would probably be 15 or 20 billion. So, and 15 or 20 years, if we're lucky or 20 years, I mean, you could build this in a year. I mean, it's, you know, the economics are there. And then part of the gap that we see is the, the construction part of the deployment is stubbornly expensive, which is why we want to apply digital and automation because you say, well, to really unleash the potential, I want to cut the cost in half again. SPEAKER_182: Yeah. Is that what TeraFab V2 is going to be? Does it increase throughput, make these more SPEAKER_147: efficient and introduce cost savings? Yeah. Yeah. So our next gen TeraFab that's coming out this summer, uh, you know, it's going to be, you know, fully automated system. It's, uh, going to be twice the speed as the current generation. Okay. I have a lot of other unique capabilities and it's really kind of setting the foundation to get to this lower cost, faster deployment world. I kind of think of SpaceX as sort of a inspiration for me where, you know, they had to start by building a rocket to get to orbit and then they got to a reusable rocket and then they could launch Starlink and then they could, eventually they'll get to Mars, right? So, so, you know, we, we know where Mars is for the solar industry, but to get to Mars, we've got to do like a hundred things. And so part of that is getting the automation with the TeraFab V2 and then, and then building in more automation and more software and more AI, um, to get to this SPEAKER_00: sort of entitled future state. We've talked a lot about growth, bigger projects, more TeraFab, TeraFab V2, that huge $130 million round. How much is the company going to grow this year? Do you hope? SPEAKER_203: And then also, uh, can I put you on the 2026 IPO calendar? Well, uh, 2026 might be a little soon, SPEAKER_147: but, uh, 2027, I'll write you down. Don't worry. Yeah. You know, I, I was fortunate to ring the bell on NASDAQ when SunPower went public, you know, a long time ago and, you know, we hope to get there someday. So, uh, you know, right now we're just focused on building, uh, uh, an awesome tech platform and a great business, you know, and, and we're also, I should say active globally. So U S is an important market, but Australia, Europe, other, you know, middle East, those are markets. We're kind of at that classical inflection point, um, as, as most tech companies go through. It's like a hundred SPEAKER_261: percent growth this year. What's the target? Oh, oh, I'm sorry. Uh, yeah. Yeah. We'll double year over SPEAKER_00: year. Yeah. Okay. And if folks want to learn more terabase dot energy, and we ask every founder the following question, what's a role you're having a hard time hiring for it. Just so we can shout SPEAKER_147: that out into the ether and maybe it'll bounce back. We're always looking for awesome, uh, programmers SPEAKER_00: and roboticists. So we've got lots of openings and if you want to help secure essentially a less carbon full future, go check out terabase dot energy. I think this company rocks. Let's light up the planet. Thanks, Matt. Thanks. I've been doing this job for roughly 10,000 years and it never, ever, ever, ever gets boring talking defenders. Every single time I do it, I leave with more energy than I came in. It's just an absolute treat, especially when I get to talk to people building such cool stuff. So shout out to both the companies today. And if you are excited about more interviews like this, well, just go to twist 500.com where you'll find a list of more than 300 of what we think are the best companies in the world. More interviews coming. We're taping all the time. So expect more goodies in your feed soon. This is Alex. This is twist. I think you're the best and we'll talk to you soon. Bye.