Try Salt Code. Get your free token

Industry

Ten Years, Two Photos, and One Bet That Got Much Bigger

September 3, 2026

Roey Eliyahu
CEO & Co-founder

These two photos were taken almost ten years apart. The first is from 2016, with Sam Altman at Y Combinator. The second came from an unexpected encounter in Silicon Valley almost a decade later. I’ll come back to it at the end.

With Sam Altman at Y Combinator in 2016.

With Sam Altman at Y Combinator in 2016.

I was 22 when I arrived in Silicon Valley on a one-way ticket, with a little bit of cash that was barely enough for one month of living there, and a thesis I wanted to prove.

I found an Airbnb host who let me sleep on an air mattress in their living room. During the day, I met anyone willing to challenge the idea: customers, investors, and other founders.

Software architecture was changing quickly. SaaS was growing, Kubernetes and microservices were emerging, and applications were becoming increasingly distributed. APIs were becoming the connective layer between all of those systems.

My thesis was simple: APIs would become foundational to the future of digital business, and security would need a fundamentally different way to discover, understand, and protect them.

At a startup event, I met a Y Combinator partner who encouraged me to apply. A few days later, I found myself interviewing with Sam. That evening, he called to tell me YC wanted to invest. More importantly, he believed in the thesis itself: APIs were becoming foundational to digital systems, and securing that layer had enormous potential.

Salt as people know it today did not exist yet. After proving the core technology in a POC, one of our first steps was filing a patent in 2016 around using AI to discover and protect APIs. For the next two years, a small group built the underlying IP. In 2018, Michael Nicosia and I formally joined forces, named the company Salt Security, and later that year raised our seed round.

We got the direction right, but underestimated the magnitude

Over the following years, APIs spread across clouds, gateways, edge platforms, Kubernetes, internal services, legacy systems and third parties.

The hard problem was never just detecting an API. It was understanding what it was doing, who was calling it, what data it touched, how it behaved, and how it connected to everything around it. And equally important, making it easy for the practitioner to use and understand.

That required years of engineering: more than 100 runtime and infrastructure integrations, deep parsing and normalization, discovery, behavioral baselining, business logic understanding, and runtime attack detection. Over time, the real asset became context.

Then AI started moving from answering questions to taking actions.

AI agents are new. The APIs underneath them aren’t.

Take a simple example. A customer asks an AI agent to cancel an order and issue a refund. The model can reason about the request and tools can expose the capabilities available to it, but eventually the agent has to retrieve the order, move money and update business systems.

Those actions happen through APIs.

AI agents act like digital employees: models reason, MCPs and tools expose capabilities, and APIs execute actions.

Models provide reasoning, MCPs and tools expose capabilities, but APIs connect those decisions to real business systems. Every meaningful AI action ultimately becomes an API call.

AI does not replace APIs. It dramatically increases their importance and the number of interactions flowing through them.

That changes the security problem. Risk can move from a prompt, through a model and MCP server, into APIs, sensitive data and a real business action. Understanding it requires breadth across the entire path: agents, models, MCPs, tools, APIs, applications, data, and actions, plus depth into each component: exposure, code, configuration, permissions and runtime behavior.

That is how the Agentic Security Graph evolved. Agentic systems run on APIs end to end: users reach agents through APIs, agents connect to models and MCPs through APIs, and tools reach business systems through APIs.

The graph did not change direction. It expanded.

The Agentic Security Graph connects the entire agentic path and adds context across posture, sensitive data, and runtime behavior.

Agentic Security was a direct evolution of our original thesis: the API layer we spent nearly a decade securing became the foundation agentic systems now run on.

Which brings me to the second photo

With Jensen Huang in Silicon Valley, almost ten years after the journey began.

Recently, while having brunch in Silicon Valley, I saw Jensen Huang and went over to introduce myself. I told him a little about Salt and how much I admired what he had built as a founder still leading NVIDIA decades later.

He became curious about Salt, asked about the business and where we were heading, and eventually said, “Let’s do a founder photo together.”

We were only several minutes’ drive from the Airbnb where I had slept on that air mattress at 22. Back then, getting time with a senior person at a potential customer was difficult. Almost ten years later, I was discussing Salt with Jensen.

The more important connection between the photos is technological.

In 2016, I could not have predicted how quickly AI would advance or how rapidly agents would be adopted. What we did believe was more fundamental: APIs would become the foundational layer connecting the future of every company.

Back then, that meant applications, clouds, and microservices. Today, APIs are becoming the nervous system connecting AI to the applications, data, and systems that run the enterprise.

We didn’t predict the agentic era. We built for the foundation it would eventually run on.

And that original bet has only gotten bigger.

Our latest posts