Listen Here

| |

Conversation
Highlights

 

When Security Meets Modern Software Development: Smallstep’s Journey to Democratizing Complex Technology

Security infrastructure has always been complex, but what happens when you try to modernize it without breaking everything else? This question lies at the heart of Smallstep‘s journey, as revealed in a recent episode of Category Visionaries, where founder Mike Malone shared insights about building a security company that bridges traditional certificate management with modern software development practices.

The origin story of Smallstep stems from a fundamental tension in today’s software landscape. As Mike explains, the challenge emerged from his firsthand experience: “securing distributed systems in the context of modern software development… with Kanban and sort of that pace and scale of development, microservices like layering on security and having real strong security guarantees and compliance guarantees without breaking all of that sort of modern technology.”

Rather than just building another security tool, Smallstep took aim at a more nuanced problem: how to maintain robust security in an environment where development moves at breakneck speed. The traditional certificate management landscape wasn’t built for a world where, as Mike describes, “people don’t have just like a dozen internal certificates anymore. They have their kubernetes and their service meshes and their databases and all their VMs and microservices and Kafka and Elkstack and all of this distributed redis and kubernetes at multiple tiers.”

The company’s go-to-market strategy revolves around an open core model, but with a thoughtful twist. Mike’s candid assessment reveals both the opportunities and challenges: “it’s a marketing asset and it’s a feature for some enterprise customers to have an open source, an open core.” However, he notes that “maintaining open source is sort of thankless work” and describes it as “crappy product led because it sort of has some of the same characteristics as SaaS, like freemium, but with none of the bi-directional relationship and data that lets you actually optimize and pull people into a commercialization funnel.”

Their content marketing approach demonstrates an interesting departure from conventional playbooks. Instead of tightly controlled messaging, they’ve given their team “really broad mandate to just write about what they’re passionate about that’s in this space.” The results speak for themselves: “it turns out when you give people that sort of purview, you get really high quality content that’s really interesting and informative and it gets shared and it gets searched and people find us that way.”

What’s particularly notable about Smallstep’s approach is their focus on democratizing complex technology. As Mike puts it, “this certificate asymmetric cryptography, all this security stuff seems like it’s an area that a lot of smart software engineers shy away from and maybe don’t specialize in. It feels very baroque and obscure, and a lot of the tooling hasn’t helped with that.” By making this technology more accessible, they’re “actually making a contribution to the security of the Internet.”

The company has built a sophisticated commercial model that spans from “a free tier all the way up to a million dollars a year” with “over 100 customers taking advantage of various scale offerings on that platform.” This range allows them to serve different market segments while maintaining the integrity of their open source commitment.

Looking ahead, Smallstep is positioning itself for a larger transformation in enterprise security. Their focus extends beyond just managing certificates to “pursuing product vision in that direction” of making “enterprises and large software systems and the Internet as a whole is more secure and safer for everybody.”

The journey of Smallstep illustrates a crucial lesson for modern enterprise software companies: sometimes the most valuable innovation isn’t creating new technology, but rather making existing complex technology more accessible and aligned with modern development practices. As development cycles continue to accelerate and systems become more distributed, this approach to democratizing security infrastructure while maintaining its robustness could prove to be a winning formula.

 

Recommended Founder
Interviews

Evan Kaplan

CEO of InfluxData

Evan Kaplan, CEO of InfluxData: Over $170 Million Raised to Build the Leading Time Series Provider

Kevin McNamara

CEO & Founder of Parallel Domain

Kevin McNamara, CEO & Founder of Parallel Domain: $44 Million Raised to Power the Future of Autonomy

Robert Whiteley

CEO of Coder

Robert Whiteley, CEO of Coder: $85 Million Raised to Power the Future of Developer Productivity

Andrew Wolfe

Co-Founder and Co-CEO of Bloomfilter

Andrew Wolfe, Co-Founder and Co-CEO of Bloomfilter: $7 Million Raised to Power the Future of Process Mining

Lasse Andresen

CEO and Founder of IndyKite

Lasse Andresen, CEO and Founder of IndyKite: $10 Million Raised to Empower Teams to Move Beyond Legacy Identity and Access Management

Tomas Reimers

Co-Founder of Graphite

Tomas Reimers, Co-Founder of Graphite: $22.5 Million Raised to Build the Future of Code Reviews

Egil Østhus

CEO and Co-founder of Unleash

Egil Østhus, CEO of Unleash: $16.5 Million Raised to Build the Future of Feature Management

Pascal Weinberger

CEO of Bardeen

Pascal Weinberger, CEO of Bardeen: $18 Million Raised to Build the Future of No-Code Automation

Martin Mao

CEO of Chronosphere

Martin Mao, CEO of Chronosphere: $250 Million Raised to Build the Future of Observability

Marcin Wyszynski

Co-Founder of Spacelift

Marcin Wyszynski, Co-Founder of Spacelift: Over $22 Million Raised to Build the Future of IaC Management

Suresh Mathew

Founder and CEO of Sedai

Suresh Mathew, Founder and CEO of Sedai: $18 Million Raised to Automate Cloud Management for Critical Decisions

Romaric Philogene

CEO of Qovery

Romaric Philogene, CEO of Qovery: $4 Million Raised to Help You Deploy Your Apps on AWS in Seconds

Jacob Moshenko

CEO & Co-Founder of Authzed

Jacob Moshenko, CEO & Co-Founder of Authzed: $15.9 Million Raised to Build the Future of Authorization Infrastructure

Tommy Dang

Co-Founder & CEO of Mage

Tommy Dang, CEO of Mage: $6.3 Million Raised to Build a Modern Replacement For Airflow

Anish Dhar

Co-Founders of Cortex

Anish Dhar and Ganesh Datta, Co-Founders of Cortex: Over $52 Million Raised to Improve Developer Productivity

David Siegel

David Siegel of Glide

David Siegel, CEO of Glide: Over $20 Million Raised to Power the Future of No-Code Application Development

Mike Long

CEO and Founder of Kosli

Mike Long, CEO and Founder of Kosli: $3.5 Million Raised to Deliver Secure Software Changes at Scale and Deploy to Production with Speed

Costa Tsaousis

CEO and Founder of Netdata

Costa Tsaousis, CEO and Founder of Netdata: Over $30 Million Raised to Power the Future of Infrastructure Monitoring

Tom Tovar

CEO and Co-Founder of AppDome

Tom Tovar, CEO of AppDome: Over $26 Million Raised to Build the Future of Mobile App Security

Hersh Tapadia

Co-Founder & CEO of Allstacks

Hersh Tapadia, CEO of Allstacks: $16 Million Raised to Build the Value Stream Intelligence Category

Dylan Etkin

CEO and Co-Founder of Sleuth

Dylan Etkin, CEO and Co-Founder of Sleuth: $25 Million Raised to Make Engineering Teams More Efficient

Derric Gilling

Co-founder & CEO of Moesif

Derric Gilling, CEO of Moesif: $15 Million Raised to Build the Future of API Analytics

Paul Stovell

CEO and Founder of Octopus Deploy

Paul Stovell, CEO and Founder of Octopus Deploy: Over $170 Million Raised to Build the Future of Deployment Automation

Casey Rosenthal

CEO of Verica

Casey Rosenthal, CEO of Verica: $17 Million Raised to Build the Future of Chaos Engineering

Tom Hacohen

CEO and Founder of Svix

Tom Hacohen, CEO and Founder of Svix: $10.5 Million Raised to Power the Future of Webhooks

James Hawkins

CEO of PostHog

James Hawkins, CEO of PostHog: $21 Million Raised to Build the Future of Product Analytics

Benjamin Wilms

CEO and Co-Founder of Steadybit

Benjamin Wilms, CEO and Co-Founder of Steadybit: $7.8 Million Raised to Build the Future of Chaos Engineering

Yingjun Wu

CEO and Co-Founder of RisingWave

Yingjun Wu, CEO and Co-Founder of RisingWave Labs: $40 Million Raised to Make Stream Processing Simple, Affordable, and Accessible

Lukas Gentele

Co-Founder & CEO of Loft Labs

Lukas Gentele, CEO of LoftLabs: $5 Million Raised to Build the Virtual Kubernetes Category

Sophie Novati

CEO and Founder of Formation

Sophie Novati, CEO and Founder of Formation: $9 Million Raised to Build a Virtual Fellowship Program for Software Engineers

Gary Hoberman

CEO & Founder of Unqork

Gary Hoberman, CEO & Founder of Unqork: Over $400 Million Raised to Pioneer the Codeless as a Service (CaaS) Category

Stoyan Zulyamsky

Co-Founder of Costimize

Stoyan Zulyamsky, Co-Founder of Costimize: $5 Million Raised to Revolutionize Cloud Finance Management

Matthew O’Riordan

CEO of Ably Realtime

Matthew O’Riordan, CEO of Ably Realtime: Over $82 Million Raised to Build the Future of Realtime Experience Infrastructure

Ron Efroni

CEO and Co-Founder of Flox

Ron Efroni, CEO & Co-Founder of Flox: $28 Million Raised to Empower Developers with Reproducible Environments That Span the Enterprise SDLC

Ramiro Berrelleza

Founder and CEO of Okteto

Ramiro Berrelleza, CEO of Okteto: $18 Million Raised to Build the Future of Cloud Development

Liam Randall

CEO and Founder of Cosmonic

Liam Randall, CEO and Founder of Cosmonic: $8.5 Million Raised to Power the Future of WebAssembly

DeVaris Brown

CEO and Co-Founder of Meroxa

DeVaris Brown, CEO and Co-Founder of Meroxa: Over $19 Million Raised to Empower Engineering Teams with Better Stream Processing

Honey Mittal

Co-Founder, CPO & CEO of Locofy.ai

Honey Mittal, CEO of Locofy.ai: $3 Million Raised to Build the Future of Frontend Development

Yadhu Gopalan

CEO and Founder of Esper

Yadhu Gopalan, CEO and Founder of Esper: $100 Million Raised to Build the Future of Android Device Management

Johnny Dallas

CEO and Co-Founder of Zeet.co

Johnny Dallas, CEO & Co-Founder of Zeet.co: $6M Raised to Power the Future of CI/CD & Deployment

Prakash Chandran

Co-Founder and CEO of Xano

Prakash Chandran, Co-Founder and CEO of Xano: $5.4 Million Raised to Build the Next Generation of No-Code Backend Development

Tim Kraska

Co-Founder of Einblick

Tim Kraska, Co-Founder of Einblick: $6M Raised to Build the Visual Data Computing Category

Eden Full Goh

Founder & CEO of Mobot

Eden Full Goh, Founder & CEO of Mobot: Over $17 Million Raised to Power the Future of Mobile App Testing

Gil Feig

CTO of Merge

Gil Feig, CTO of Merge: $75 Million Raised to Help B2B Companies Build Customer-Facing Integrations via It’s Unified API Platform

Ori Keren

CEO and Co-Founder of LinearB

Ori Keren, CEO and Co-Founder of LinearB: Over $70 Million Raised to Build the Future of Software Delivery Management

Yana Welinder

CEO and Founder of Kraftful

Yana Welinder, CEO and Founder of Kraftful: Over $3 Million Raised to Help Product Builders Create Better Products and Communities

Ben Kliger

CEO and Co-Founder of Zenity

Ben Kliger, CEO and Co-Founder of Zenity: $21.5 Million Raised to Build the Future of Security and Governance for AI, Low-Code, and No-Code Development

Harpreet Singh

Co-Founder and CEO of Launchable

Harpreet Singh, Co-Founder and CEO of Launchable: Over $12 Million Raised to Build the Future of Software Testing

Michael Corr

Founder and CEO of Duro Labs

Michael Corr, CEO of Duro Labs: $4 Million Raised to Power the Future of Hardware Engineering

Will Wilson

Co-Founder of Antithesis

Will Wilson, Co-Founder of Antithesis: $47 Million Raised to Build the Future of Autonomous Testing

Joshua Aaron

CEO of Aiden

Joshua Aaron, CEO Aiden, $3 Million Raised to Build the Future of Software Packaging and Deployment

John Li

CEO and Co-Founder of Vimcal

John Li, CEO & Co-Founder of Vimcal: $7 Million Raised to Build the Future of Calendar Productivity

Ravi Parikh

CEO and Co-Founder of Airplane

Ravi Parikh, CEO and Co-Founder of Airplane: Over $40 Million Raised to Build Better Developer Infrastructure For Internal Tooling

Omri Gazitt

CEO & Co-Founder of Aserto

Omri Gazitt, CEO & Co-Founder at Aserto: $5 Million Raised to Build the Future of Authorization

Paolo Fragomeni

CEO of Socket Supply

Paolo Fragomeni, CEO of Socket Supply: $3.5 Million Raised to Build the Future of P2P Computing

Matt Butcher

CEO of Fermyon

Matt Butcher, CEO of Fermyon: $26 Million Raised to Power the Future of WebAssembly

Alan Shreve

CEO and Founder of Ngrok

Alan Shreve, CEO and Founder of Ngrok: $50 Million Raised to Help Devs Deploy SItes, Services, and Apps

Chetan Venkatesh

CEO of Macrometa

Chetan Venkatesh, CEO of Macrometa: $38 Million raised to Build the Hyper Distributed Cloud for the Next Generation of Applications

Zach Lloyd

CEO and Founder of Warp

Zach Lloyd, CEO and Founder of Warp: $70 Million Raised to Build a Better Terminal

James Evans

Co-Founder and CEO of CommandBar

James Evans, Co-Founder and CEO of CommandBar: $24 Million Raised to Build the Leading AI-Powered User Assistance Platform

Paul Kim

CEO of Notifi

Paul Kim, CEO of Notifi: $12 Million raised to Build the Future of Web3 Communication Infrastructure