Episode Summary
Executive Summary: Santiago Castinera, co-founder and CTO of Maze, explains how repeated exposure to security teams drowning in vulnerability data led him to build an AI-driven platform that triages and remediates cloud, code, and SaaS issues. The episode covers Maze’s origin, MVP, architecture choices, scaling strategy, hiring philosophy, lessons from early mistakes, and his view that LLMs will transform cybersecurity toward autonomous defense and auto-remediation.
Main Topics: Origin of Maze from real security-team pain (Priority: 5/5): Santiago describes discovering that large enterprises had abundant vulnerability data but lacked context to decide what mattered, exposing a data-engineering and prioritization problem inside security operations. Building the first MVP with LLMs and agentic reasoning (Priority: 5/5): The team tested emerging LLM tooling to see whether models could interpret cloud metadata and configuration and use that context to judge vulnerability relevance. Product scope and roadmap driven by design partners (Priority: 4/5): Maze’s roadmap evolved through close feedback from design partners about how they would use outputs and fit them into existing security workflows. Hiring philosophy and team autonomy (Priority: 4/5): Santiago emphasizes hiring for high energy, high intelligence, and high integrity, and says strong teams should operate autonomously and propose their own improvements. Scaling architecture for enterprise volume (Priority: 5/5): Maze was designed from the start for very large environments, requiring scalable ingestion pipelines and thousands of concurrent agents per customer. Lessons from early architectural mistakes (Priority: 4/5): An early multi-agent design proved too expensive, leading the team to simplify toward a more efficient single-agent model and migrate frameworks. Future of cybersecurity and Maze’s role (Priority: 5/5): Santiago sees LLMs pushing cybersecurity toward autonomous monitoring, self-healing systems, and auto-remediation across more use cases and technology stacks.
Key Arguments: Security teams often have a data problem, not just a staffing problem: they need context to know which vulnerabilities matter most. LLMs can meaningfully interpret cloud metadata and configuration to assess vulnerability relevance, making agentic security automation viable. Starting with cloud context alone simplified the initial problem enough to build a usable MVP. Close collaboration with design partners is essential for shaping a roadmap that fits real security workflows. High-performing teams are built by hiring for energy, intelligence, integrity, and autonomy rather than rigid role conformity. Enterprise-scale security products must be designed for massive ingestion and heavy concurrent agent workloads from day one. Overly complex multi-agent systems can add cost without enough benefit; simplification can improve performance and economics. Cybersecurity is undergoing a major shift due to LLM capabilities, opening the door to autonomous defense and remediation. Founders should ignore generic startup lore and build businesses around well-reasoned choices that fit their actual constraints and goals.
Data Points: Founding team size: 5 people - Santiago describes the early founding team that validated the problem and launched Maze. Initial funding runway: About 2 months of salary funding - He says the team had only enough funding to try the idea briefly at the start. MVP build time: Mid-June/early July to November 2024 - Timeline for building the first version of the engine/MVP. Additional time to customer-ready MVP: Another 6-8 months - Time after the first engine MVP to reach a version usable by customers. Vulnerabilities published annually: Tens of thousands - Used to explain the scale of the security-management challenge. Agent workload target: Thousands and thousands of concurrent agents per customer - Describes the scale requirements Maze designed for. Products launched: 3 products - Cloud vulnerabilities, SCA, and SaaS vulnerabilities. Cloudflare-related platform claim: Unforked Postgres / same ORMs and drivers - Sponsor copy for TigerData, not Maze, but explicitly mentioned in the transcript.
Pivotal Quotes: "what are the vulnerabilities that we should be fixing today, and which are the ones that can't wait, or which are the ones that don't apply to us?" — Santiago Castinera: He defines the core enterprise security prioritization problem that inspired Maze. "we were going to go purely with the cloud context" — Santiago Castinera: A key early product decision that narrowed the initial scope and simplified the MVP. "high energy, high intelligence, and high integrity" — Santiago Castinera: His hiring framework for identifying strong candidates and building a reliable team.
Implications: Maze reflects a broader shift toward AI-native security operations: better prioritization, automation, and eventual self-remediation. For builders, the lesson is to start narrow, design for scale early, and use first-principles thinking over startup clichés.
About Code Story
Code Story is a podcast featuring startup founders, tech leaders, CTO's, CEO's, and software architects, reflecting on their human story in creating world changing innovation, disruptive digital products. Their tech. Their products. Their stories.