No Trade Secrets

Why Your AI Tool Fails, The Future of On-Device Models, and a $20 Security Win w/ Kamil Mansuri (Part 2) - Ep. 33

Jarome McKenzie

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 27:14

Welcome back to the playbook! We're diving back in with Kamil Mansuri, a privacy-first founder and software engineer. In PART ONE, we laid the groundwork for building with AI agents. In PART TWO, we’re getting brutally honest about why most AI products fail to gain traction and how to build one that lasts. What if the biggest threat to your AI startup isn't the competition, but the third-party models you rely on? How can a simple $20/month tool drastically improve your security? And why is the future of truly useful AI running entirely on your local machine?

⏮️ Catch Up on Previous Parts

💡 Unlocking the Playbook

Your $20 Security Blanket: Don't wait for a data breach to think about security. The first step is a simple audit of the customer data you're collecting (PII, cookies, etc.). For an immediate, high-impact boost, Kamil recommends using Cloudflare ($20/month) to set up a Web Application Firewall (WAF). This protects your domain from common vulnerabilities and is a foundational, cost-effective layer of defense before you even think about expensive penetration testing.

The AI Privacy Paradox: Most AI wrapper tools fail to achieve daily use because they're built on the same handful of third-party models (OpenAI, Anthropic, etc.). This creates a massive privacy vulnerability: you're sending your customer data to the tool, which then sends it to the model provider. For B2B or any privacy-conscious product, this is a deal-breaker and why a privacy-first approach is the ultimate competitive advantage.

Bet on On-Device AI: The solution to the privacy paradox is to bring the models to the data, not the other way around. Kamil argues the future of dominant AI tools lies in on-device, local models that run entirely on the user's computer. This eliminates the need to send sensitive data to external servers, building a truly private and secure user experience that fosters deep trust and wins in the long run.

🤫 PART TWO's Playbook Secret (The official No Trade Secret drops in PART THREE, but here is the hidden secret of PART TWO!)

Use AI against itself to audit your system. "I would actually spin up a separate agent that has no knowledge of your code base, no knowledge of anything. And you want that agent to ask you questions. And you could feed in those questions into other AIs... you wanna start developing a context and an understanding of your own system."

🗣️ Words to Build On

"[The] best tools are the ones that can leverage local models, the ones that can actually run on your computer and keep data local. And I think that's kind of why... those companies don't fully succeed." – Kamil Mansuri

"If you're building functionality on top of AI, you're essentially feeding it a new system prompt... The truth is you are sending that data to Anthropic, you're sending that data to OpenAI... which, of course, then violates that constraint." – Kamil Mansuri

"Sign up for Cloudflare. So your primary domain, it's $20 a month... You could put a WAF, a web application firewall. It will handle all sorts of crazy, like zero-day vulnerability." – Kamil Mansuri

👤 About Kamil

Kamil Mansuri is the founder of Bad Command AI, a Princeton, New Jersey studio building native AI applications for Apple platforms. Bad Command AI builds practical AI products, including Telescopo (a Markdown workspace for macOS), Telepath (an on-device AI voice agent call center for Mac), and Telefoto (an AI headshot platform). Before founding Bad Command AI, Kamil was VP of Engineering at Vapor IO, leading engineering across edge computing, cloud infrastructure, private 5G, automation, observability, and AI infrastructure. He previously led mobile backend engineering at Take-Two Interactive, helping launch Garden Tails on Apple Arcade, and served as CTO at Momentum Technology, working on telecom infrastructure and automation for products including Robokiller, SpoofCard, and TapeACall. 

He also worked as Lead Automation Engineer at Comcast, building foundational software for enterprise change management and alerting systems supporting NBC Sports and Xfinity Business Internet. His background spans finance, software engineering, telecom, cloud infrastructure, gaming platforms, native Apple software, and AI products, including award-recognized products like Robokiller and Garden Tails, and today he focuses on building software that is practical, fast, private, reliable, and thoughtfully designed. 

🔗 Links & Resources

 🎧 Missed the beginning? Go back and listen to PART ONE!

🎧 Make sure to tune in to PART THREE to hear Kamil Mansuri’s ultimate "No Trade Secret" and keep this momentum going

SPEAKER_00

Yeah. So this is this is a great build versus buy example. And you're thinking like a software engineer. I mean, and and you even though you know there's AI assistance used here, the ideas and thoughts you're putting into this are exactly the thought process of any sort of engineering team I've been a part of. Um as we kind of contemplate and evaluate, hey, we're paying all these SaaS providers, why don't we just build the thing? Um we gotta think about a lot of concepts, right? You mentioned some of them, security and and and um data protections. Um this these are really, really important. And uh I would say it's also one of the most challenging aspects of working with as sort of an AI assistant developer that isn't familiar with um how to safeguard data. Uh I would actually say if you the second that you realize that you might be working with customer data of any sort is to understand the customer data itself and saying, okay, what data are we collecting? And then really kind of keep a strong accounting of it. And you see this for, you know, I'll talk a little bit about GDPR and the California privacy protection laws, but um, it's very, very important when you're doing things like anything sort of analytics or marketing, like if you use Google Analytics, right, like there are a lot of disclosures you need to put into place. And you have to be very, very cautious about the data that you're collecting, if you're collecting email addresses, if you're placing cookies, right? Um some of these web applications, they're they'll they'll place cookies or they'll use local, you know, local storage. Like these are things that you kind of have to be aware of because there are very real implications there for those particular laws. Um so using AI, I think, in the in in this manner, just to understand and do a quick audit. And it goes back to agent skills, right? There are plenty of agent skills where you can say, hey, like let's evaluate the inputs and outputs, what data are we actually collecting? And then use that as sort of a baseline, right? You don't need to necessarily go and do crazy pen tests yet. But you you could, if you're using a cloud provider, um, you could put in an additional security, you know, with AWS, and depending on how you've uh you're rolling out your services, uh it's AWS or GCP, or even if you're using Firebase or Superbase or I don't know, any of these other services. There are ways you can protect your endpoints. Oh, actually, I'll give a really easy, quick and easy one. Sign up for Cloudflare. So your primary domain is 20 bucks a month. Sign up for Cloudflare. You could put a WIF, a web application firewall. Um, it will handle all sorts of crazy like zero-day vulnerability. It'll handle a lot of stuff. And you have a good, you'll have good strong analytics or anonymized. Um, it is fully compliant with all sorts of GDPR and CCP, uh, the California privacy laws, um, and will actually help secure uh your data a bit. But in terms of internal processing of PII of customer information, you you really should do an audit. And um you could use AI for that. You could use AI skills for that. But that would be a separate thread than your core development. I would actually spin up a separate agent that has no knowledge of your code base, no knowledge of anything, and you want that agent to ask you questions. And you can feed in those questions into their other AIs. That's fine that you're using. But you want to start developing a context and an understanding of your own system. And pitch for telescope. Uh create create this as a markdown file. And you can actually create this as a series of markdown files. In fact, all your agents should be communicating uh and writing to markdown files so that you can have a complete understanding of every single version of the application that you've built, and also have a complete audit, that's sort of a living audit of any security issues that uh light security issues, hopefully. If it's high severity, you should fix those right away. But any ongoing lingering security concerns or issues, especially with data. Um so there's just kind of my my two cents is use Cloudflare. Um, just pay for it, it's worth it. Um and use um uh use other agents to do audits. Now, if if if you really have a big challenge here and you really want to make sure that uh you you you could hire a pen test company to kind of handle penetration testing, but it it's gonna cost you a lot of money. So um just be prepared for the sticker shock. Um but again, depending on the stage of your company, depends how much uh how much traffic and volume and and um I guess the nature of the customer information or the effect if if there is a compromised API. Um based on that, it might be worth paying one of those companies too.

SPEAKER_01

Yeah, no, and I think and I think that's where a lot of uh the maybe uh recklessness does come in, knowing and unknowing uh with people shipping products that are have you know security risks, is that uh like you're saying, to get it tested to that extent is extremely expensive. And so, you know, then with that being something that you know a lot of founders are kind of just taking the risk on or uh potentially unaware uh that they have risks. Um but you know, and I think obviously I like your to your point of kind of how you're explaining that there's I think there's different layers of security risks, right? Like it's the critical ones. Uh but then I think there's also kind of a category of like uh simple, stupid mistakes that uh a lot of people are making, like um that are very easy to eliminate a lot of risks, like like not pasting in API keys into uh into the chat uh thread with your Claude code, or and not having those API keys hard-coded into the markdown files or or into the code itself, and um and instead using a very you know cheap, often free if you're a tool like Railway or Versell to store some of those keys uh that it can access to, you know, and I think you know that could eliminate a lot of these security risks uh you know in itself. Um but then to get these tools to being actual like the longevity of some of these tools. You know, if you when you've got all of those like all these things uh lined up and you've you've min minimized the big at least security risks um I still like there's still a lot of these AI tools that are like impressive uh you know initially, um, but then uh very few seem to make it to the point of being part of a company's you know daily workflows.

SPEAKER_00

Why why do you think that happens You mean for for AI, like all these disparate AI tools that are out there?

SPEAKER_01

Yeah, yeah, because like I feel if those ones are making it uh to that point where they're mass produ you know available to people, uh you would assume that they've gone through some layer of going through those important things that like it's not a tool that's gonna leak your social security number or like be so vulnerable that to uh to come back and bite you and oh I see. But so then like if they're at that point where they're at least good enough from a security level and they're they function uh and they're a real product that someone can just go and sign up for and download or or start using, like why why why is it that very few of these really kind of become part of a company's actual systems that they use day in and day out?

SPEAKER_00

I can I think I can I can guess an answer, that's probably probably very close to right. Um, and that's because the they are all using the same thing under the hood. They're all using the same models. And really, they're all using either you know, anthropic models or open AI models or Gemini models, uh Google models. They're they're using a mixture of one of maybe six different models that are all either it's running it's running uh it's running basically gonna have like a AI camera. Pretty cool. Um follow me. Uh yeah, I need to get me one of those because mine doesn't follow me. Let's think's awesome, but like it hand gestures, right? So like it'll pan. Um sorry about that. So backing track, backtrack. They're all using the same models under the hood. And really, what where's the moat then, right? It's it's the layer you put on top. But the thing is, if you're talking about data and you're talking about data privacy, you're taking talking about any sort of functionality. So to me, if you're building functionality on top of AI, you're essentially feeding it a new system prompt, a new initializer. So something to say, hey, like and you can do this in ChatGPT, right? Like, hey, you are an expert at UX, you are uh a wizard at Java, I don't know, and you're basically good at something. And go and give me this, these are the inputs, these are constraints, these are the outputs. And so in the constraints, you could say, yeah, don't don't um you know safeguard user data, don't do this, don't do that. The truth is you are sending that data to anthropic, you're sending that data to open AI, you're sending that data to another service, another system, which of course then violates that constraint, right? You're essentially sending customer data technically there. And that is why, even though all these people were building tools and technologies, they're not always going to be adopted because they're not private. Um and you're seeing you're seeing a little bit of that backlash in different ways manifest. I mean, there's this whole anti-like data center thing, which uh and then there's uh this backlash of uh privacy, which is also another like just these areas. And so I'm for me, I'm I'm focused very largely on privacy and very largely on just making sure no data is really sent externally for most of the products I'm building. Um most of the products I'm building are actually using on-device data, on-device um uh foundational models so that are running entirely on your computer. To me, that is a future. Um, it's gonna be a little bit of time until we get to that future for everything. But I think the best tools are the ones that can leverage local models, the ones that can actually run on your computer and keep data local. And I think that's kind of why even though OpenClaw is kind of a mess because it ties to like, it ties to all sorts of APIs, your data is leaked everywhere. Um, it it also speaks MCP. You could also run things locally. You can run local models, and you can actually have um a chain to like OLAMA, which can run local models, and it can do certain operations for you locally. And I think that to me is more interesting than necessarily trusting a third party who's then sending your data to another third party and like and you have customers, right? So technically, four parties down, it's it's the your data is being shared with three at least three parties. It's it's just a lot. So to me, that that is kind of why I think that those companies don't fully succeed, is because people do read the privacy policy, especially for for business for B2B. Um if that that's kind of the approach that you're taking to sell. Um they they they need these ironclad policies. You can't leak business data, enterprise data.

SPEAKER_01

That's interesting, especially when you talk about the locally hosted uh end because I know that's like that's less built-out and uh less uh you know uh able to be mass uh integrated, I guess uh a way of saying it, uh, than just being able to you know go through a claude or a g uh uh chat GPT and uh have everything, you know, it's that's it's obviously a lot easier, but um I actually today just uh replace so um I'm sure you're familiar with uh the uh the dictation voice dictation app Whisper. Um today uh I saw something uh a few days ago and I just tried it out. Um uh it's called Fluid Voice and it's it's runs on locally hosted uh AI models and does the same thing, and it's actually so far, uh you know, three-quarters of the way through the day, has been a lot faster and a lot more accurate than Whisper. But then because when you you know, I feel like some sometimes you don't stop and think about what's actually happening to the data when you use some of these products. But then like a company like Whisper like it would be incredible, it'd be cr it's crazy to think about what data they have stored on all of their users, where it's literally a fly on the wall to whenever a user y pushes the button to use Whisper, their entire conversation of what they're saying, what they're talking about, um uh is and what you can do with that data. And we're like uh, you know, because you know data selling data is its own huge massive industry and because it tells a lot of these other companies what people are talking about, what what what are the data points that we can capitalize on to make a profit on, uh based on what what people's real data, you know, and real the things they talk about and care about are, and it's uh like that's kind of crazy because especially when it's you know could be you could be s having a private conversation using Whisper, and then that data now could be sold to anyone in the world if it's uh not stored and kept local. Um but where do you think uh where do you think those advancement advan advancements in the locally hosted local storage uh kind of way of going about things that you uh you know that you said you think is the way of the future, what needs to happen before we can get there?

SPEAKER_00

Yeah, I um so this particular thing I've been working on for about a year. This exact exact scenario. Um Whisper actually is a fantastic product, and I've actually based a lot of the technology that I'm building for upcoming product called Telepath, voice agents, uh, on the concepts and ideas that Whisper kind of brought to market, running these um text-of-speech models, like running running these models locally on Apple Silicon, but then also safeguarding the recordings and also making sure there's compliance to the recordings, right? Um there's a lot of different pieces to it. So to unpack it without getting too technical, the to unpack uh the first part of it is um the US, right? We have the Telecommunications Privacy Act, TCPA. The TCPA requires us to actually inform, especially with there are many states in the US that have um that require consent for a call recording. And so something that Telepath does is that um big on transcription, I can do automatic transcription on voicemail, live voicemail, it's all directly on your computer, by the way. You don't have to pay a penny to any sort of AI company for doing running an entire call center on your machine, which is nuts. Um you can do all of this on your computer. Uh transcription is free and it shows you live. Also, while calls are happening, you can see in real-time the transcription. But the way that all works is that the AI voice agent is going to hard code in the states that are required to um, hey, we're gonna, this call might be recorded for quality assurance. And because you say that disclosure, you're able to now record the conversation. Now, the recordings are all local and they're kept in a safeguarded vault that is hardware protected. Because the the product only runs on Apple computers, Apple silicon-based computers, Apple provides a way to actually have um hardware encoded uh system to actually store those files. And so we take advantage of that. Uh we're able to use hardware um hardware secure uh encryption to safeguard recordings. And those recordings are not stored or sent, or they're they're just really for transcription purposes and for the user to view. And you can also turn them off completely if you don't want to use that feature. But yeah, in terms of um in terms of selling recordings and all that, there's a lot of laws uh against it because it's highly privatized. Um I've actually I founded a company, uh Commomento Technology, that we actually dealt with. Um we helped build a few different products um in its predecessor company. One product was called RoboKiller, which actually is an anti-spam calling product. It's uh still very popular. I think it's owned by an Italian company now. I need that. But yeah, it's it's it's awesome. It's it's uh it's interesting how like you know, it's it's been like eight years or so since I've I've worked on it, but it's it's kind of grown and evolved, and it's really proud of that product. And um in that particular product, there are plenty of like voice recordings and and and uh you know just answering machines, but those aren't those aren't customer recordings, those are sample bits for the customer to assess, like, hey, like when they're getting a spam call, like how is the answer bot combating the spam call for them so they can kind of see it and they can share it because some of these are recordings are funny. Um the way RoboKiller worked, just to back up for a sec, we basically this is before AI, this is before all that. Uh we basically had a script that would essentially play back a recording to the person. It would make it seem like they're conversing with somebody, but really it was they were conversing with just a random chat bot or a random uh recorded uh line that made it sound like they were actually listening to them and engaging with them. And it would be on a loop. But this the loop was like maybe like 45 minutes long. And so you really had no sense or idea that you were speaking with a bot until maybe about I don't know, about 10 minutes in. It was really hilarious. And so you're basically trolling in a way uh these spam callers, these spoof callers, um, almost indefinitely and wasting their time. So that's that's and the technology is very cool behind it um where you're actually kind of leveraging different, like different different collective different pieces of technology to actually put this answer bot in the middle of this answering service call so that they never they're just sent to the void. They never hit your answering machine, they never hit like your missed calls, they're just they go into another bucket of spam callers. Um But anyway, uh with those call uh recordings, like you know, the whole thing is privacy focused and the whole thing is is supposed to help you, right? So from that perspective, you could never sell recordings, you can never do any of that. But what you could do is you could uh start understanding, hey, like you now have a list of like these these fraudulent numbers, these spam callers. Could you work with some um some companies on expanding that list? You know, um or what what are the rules around that? Um But so like in terms of monetization for data, I I'm not a big fan of it personally. I I think there are other ways to make a buck. Um I don't, you know, even for my products, I don't uh famously just don't track, I don't have any telemetry at all. The only telemetry I really have are very anonymous telemetry around analytics on crashes and diagnostics to make sure my users like experience isn't uh has zero crashes. Um that's very important to me. But that's uh aside from that, I don't I don't sell any data. I think um I think if you're in the business to sell data, uh there are ways to go around it, go about it. But again, you'd have to comply with GDPR, you have to comply with privacy laws and all sorts of other stuff. Um but yeah, that's a fascinating thing with Whisper. Like um, I think I don't know how Whisper stores its data ultimately, um, but I could tell you how telepath will. Um and Whisper should probably, if they're not already, use if they're running on Apple Silicon, um, they could just use the hardware capabilities of that.

SPEAKER_01

That's uh no, that's that's I mean it's something I also don't know how Whisper is uh what they're doing with the data, but um I f I just it's something I see more and more uh with how many data breaches are are are occurring right now. Um and and then you know it was when I stopped and paused and thought which of the applications that I use are uh uh doing things with my data that I probably don't w want to be happening? And the answer is I don't know for s for some of them. You know

SPEAKER_00

Does Whisper does Whisper do voice cloning? I I don't I haven't I haven't really used Whisper in a while. I I don't know if it does that. But if it does, that would be that would be something I'd be worried about.

SPEAKER_01

I don't I don't think it does. Uh but I mean that's a completely different topic where uh when it comes to voice cloning and like Hey Jen's ability to make pretty good uh AI replicas, clones of you that talk pr like you, sound like you make pr like pretty darn close, like where uh you could probably tell if you were close with the person, but if it was a complete stranger, like they do look like real people. Um and it's quite hard to tell the difference, and um you know, especially like when it comes to like uh you know the like I think a lot because in in my industry I see a lot of people uh you know not a lot, but you know, you see uh instances of people falling victim to phishing schemes and such like that. Uh but especially if you know when you have s people calling and it sounds like your boss and they were able to if they're able to purchase data where they know things that were whispered to you in a text between someone, uh so that like you know, that was only shared between, you know, say if I texted you and said something, uh and then that data was able to be purchased, and then they were able to take pictures of you, uh and then they would be able to take this recording to clone your voice, and then the data of a text thread between only you and I to call you, and like that's not really something that you'd think about like uh you know kind of decoding uh whether that's real or not. Um, but especially you know when it comes to like you know, people uh the elderly people who uh already were uh you know, pretty susceptible to those. My favorite is the the social the the people calling needing some someone's social security number. And it's um and I'm the guy who would pretend to be stupid and just waste their time uh and then at the point where they figure out that I'm messing with them uh how how angry they get when they hang out. Uh because that's just I so you know occasionally that's kind of funny. Um at least for me, not for them. And you know, then you're talking about your your company, I'm like, man, that's pretty cool. I kind of need that because it wastes their time and they're getting less calls then. Uh anyway, sidetrack for that. But um but no, uh to your question, I don't know if Whisper does I don't I don't think they clone clone voices.

SPEAKER_00

Yeah, yeah.

unknown

Yeah.

SPEAKER_00

Whisper Whisper has a transcription and um like it. I think it's it's voice to text, right? It's uh I mean it's it's huge. They just had a I think they just completed a fundraising round. Oh really?

SPEAKER_01

Yeah, I'm not surprised. I mean they're um because I mean it for me it's I can't imagine not using a voice-to-text dictation for 90% you know, I use it for 90% of anything that's typed um for me now. And so I can't even imagine typing these these long emails or Slack messages anymore without just pushing a button and speaking. Um so like but yeah, I you know I think there are some, you know, there are other things to consider and um uh when it comes to that stuff. For you, it how how how did you uh I want to know about your path from finance to software engineering to then now founding your company? Uh how how did you how did you go that route?