For most of its history, cybersecurity has been an outside-in business. Firewalls, endpoint protection, cloud security — all built around keeping intruders from getting in. Nishant Doshi, CEO of Cyberhaven, spent years on that side of the industry at Palo Alto Networks and Symantec. His argument now is that AI has quietly inverted the whole equation, and the vendors built for the old direction are going to struggle to turn around.
“Cloud democratized resources and compute. AI democratized knowledge and data,” Doshi said. “The risk has inverted, and now it’s an inside-out perspective that we really need to be focused on.”
Cyberhaven is launching Flow, an AI-native data security platform, at Black Hat USA 2026 as its answer to that shift. The pitch is unusual for the moment: that Cyberhaven’s pre-LLM roots — the company traces back to DARPA-funded research and the 2016 Cyber Grand Challenge finals, born out of an academic setting at EPFL — are an advantage in the agentic era, not dead weight waiting to be replaced.
The problem was never really about AI
Doshi’s case rests on a simple claim: the foundational problem Cyberhaven set out to solve hasn’t changed, only the cast of characters involved in it. “The way we used to work was more human workflows,” he said. “Human to human was really the context.” Cyberhaven’s original innovation was data lineage — tracing how data moves across an organization, who’s accessing it, where it came from, and where it’s going, stitched together into a full business-context story rather than a series of disconnected alerts.
“Now we interact with humans and AI, so you have humans and AI working side by side,” Doshi said. “It’s quickly progressing to AI-to-AI workflows.” Flow extends the same lineage-tracing foundation to cover human-to-human, human-to-AI, and AI-to-AI data flows in a single platform, built by a dedicated Cyberhaven Labs team of seven PhDs that’s been working the problem for three years.
What existing tools actually can’t see
Asked for a concrete example of what slips past traditional DLP and DSPM tools today, Doshi didn’t hesitate: an agent instructed to pull data from Salesforce and autonomously forward it to a personal email address. “If I was a malicious insider, I would call up an agent,” he said. “The agent would go and do something on a schedule, and then go send the data outside.”
A traditional DLP tool can’t catch that because it only sees a fragment of the picture — a prompt, a reply, maybe a data-access log. Catching it requires combining three things at once: what data is involved, what the agent’s identity and behavior look like layered on top of the human identity behind it, and where the data is ultimately headed. “It may be okay to send an email,” Doshi said. “But it may not be. You need all three to come together.”
How Flow actually works
Mechanically, Flow combines Cyberhaven’s existing DSPM capability — understanding what sensitive data exists and where — with agentic and human data lineage, identity, and behavior signals, wrapped in an AI-native interface that customers can also run headless or through published skills. Determining whether a given action is legitimate comes down to combining two signals: the full lineage of where a piece of data has been, and the identity and past behavior of whoever — human or agent — is moving it. Layer policy on top, and Cyberhaven can block an action outright or flag it for review.
Doshi described the difference this makes with a medical analogy: “the difference is you know, 4K X-ray MRI scan versus looking at a static image of an X-ray when you’re doing brain surgery.” Without full lineage, Doshi said, security teams are left guessing — and a wrong guess with a traditional tool means either missing a real exfiltration or blocking something legitimate and killing productivity. “We’re not just protecting data,” he said. “We’re protecting workflows.”
That distinction matters even for IP an agent legitimately accesses. If an employee asks an AI assistant for a company’s most sensitive customer data as part of their actual job, that’s not the problem — that’s the productivity gain the company is paying for. The problem is what happens next. “The challenge is when I take this data and exfiltrate that data to my personal email,” Doshi said. Stitching together the prompt, the response, and everything that happens to that data afterward — across tools, across hops, across whether a human or an agent is driving — is what he called “the holy grail” of the platform.
Why the same four customers, one problem
Cyberhaven counts SpaceX, Anthropic, OpenAI, and Palantir among its customers, and Doshi said it’s the same underlying problem across all four: organizations adopting AI aggressively while trying to protect sensitive IP. “They really need to stitch the journey of the data,” he said, “and be able to take action where it matters” — whether that action is blocking a transfer or simply educating a user in the moment.
What Doshi would tell a CISO to ask
With no shortage of vendors claiming an agentic security story at Black Hat this year, Doshi offered three questions worth pressing every vendor on: Do they have holistic visibility across the entire environment, or just siloed pockets of it? Do they actually understand the organization’s AI and agentic footprint — across employees, cloud, endpoints, and network? And is the solution mature and validated enough to operate at the scale AI introduces, given that agentic workflows can run at “10,000x” the volume of human ones. “I have 10,000 invisible hands typing away at the keyboard,” Doshi said, pointing to what’s already happening with AI-generated code and pull requests.
The tool sprawl problem is about to get worse
The inside-out reframing lands on an industry that already has a sprawl problem — the average Fortune 500 company runs more than 70 security tools, most of them built for the outside-in world Doshi described. Asked directly about it, he agreed the shift compounds rather than solves that problem: legacy vendors built around perimeter and endpoint defense now face the innovator’s dilemma of retrofitting an inside-out capability onto an outside-out architecture. “It’s not easy for these companies to just switch gears,” Doshi said. Companies that started from an inside-out orientation, in his view, hold a structural advantage heading into that shakeout — not because they’re newer, but because the underlying architecture doesn’t need to be rebuilt from scratch.
Flow protects data across both endpoint and cloud, according to Doshi, wherever it lives and however it’s being consumed — a deliberate answer to the fragmented, tool-by-tool visibility that’s defined the category until now.
##
ABOUT THE AUTHOR

Tom Smith is a technology writer and content strategist with more than 10 years of experience covering enterprise technology, agentic AI, cybersecurity, DevOps, and cloud infrastructure. He has published more than 2,500 articles and conducted more than 4,000 executive interviews across outlets including Coder Legion, Techstrong/DevOps.com, and Insights From Analytics. By day, Tom serves as a content strategist at Cognizant. He can be found on LinkedIn, X, and Bluesky at @ctsmithiii.






