Anjuna Security, a startup that develops hardware- and cloud-agnostic software that allows enterprises to deploy secure enclaves and automatically encrypt memory, launched today with partners spanning storage vendors, chip makers including Intel and AMD, and public cloud providers Amazon Web Services (AWS) and Microsoft Azure.

The Palo Alto, California-based company is also a new member of the Confidential Computing Consortium, a Linux Foundation group that’s working to make it easier for developers and companies to process encrypted data in memory. Anjuna says its technology enables this hardware-grade protection through software.

“The problem we’re solving is that any enterprise today has a data security problem that they can’t solve,” said Anjuna Security CEO Ayal Yogev. “And it all boils down to the fact that you can’t secure data and use it at the same time.”

Encrypting Data in Use

Data is typically encrypted at rest (in storage) and in transit (as it moves across the network and clouds). But encrypting data in use, thus allowing it to be processed in memory without exposing it to the rest of the system, is more difficult. Chip makers developed secure enclave technology to address this challenge at the silicon level, and now IT vendors and cloud providers build secure enclaves into their servers, virtual machines (VMs), containers, and public clouds. These secure enclaves provide CPU-level encryption and isolate application code and data from privileged users by automatically encrypting memory.

However, this technology remains proprietary and hardware specific. So if enterprises want to use these highly protected, isolated environments — to process highly sensitive data such as personally identifiable information (PII), health care, financial, and intellectual property data, for example — then they have to rewrite applications depending on the hardware and cloud environments.

“Like any other hardware technology, they need a software stack on top of it to actually make it usable at the enterprise level, which is what we do it at Anjuna,” Yogev said. “We’ve created something called Anjuna Enterprise Enclaves to take the secure enclave technology and actually make it ready for the enterprise.”

Anjuna Enterprise Enclaves

Anjuna’s software automatically establishes a secure enclave that isolates and encrypts all applications and data in runtime, at rest, and on the network with no changes to the application code, recompilation, or software development kit required — essentially a “lift-and-shift” approach, Yogev said.

The software runs on Intel, AMD, and Arm processors, as well as on all clouds, VMs, containers, and bare metal. In addition to supporting Azure Confidential Computing now, Anjuna will support Amazon Nitro Enclaves when that launches.

“The implications of this are phenomenal, and I think they go well beyond what Intel and AMD even imagined when they created this,” Yogev said, comparing it to the creation of public cloud infrastructure. “And secure enclaves are going to have the same level of impact in the market where new things are going to be born and because of what it enables.”

In fact, Anjuna is working with Microsoft to help its cloud customers take advantage of some of these new use cases. For example, financial services companies are using Microsoft Azure confidential computing to analyze data without exposing the underlying data to another party. By analyzing these transactions, banks can also better detect money laundering or fraud.

Anjuna’s Founders

The company’s co-founders, Yogev and CTO Yan Michalevsky, met 20 years ago when they both served in the Israeli Defense Forces. Michalevsky later graduated with a Ph.D. from Stanford University where his research focused on applied security and privacy. Meanwhile Yogev led several security product management teams including the Umbrella product management team at OpenDNS, which Cisco acquired for $635 million in 2015, and used as the foundation for its cloud security platform.

“And the problem was that we had to manage private keys for our customers,” Yogev said. “Part of the problem was we knew that if one of those private keys was compromised, that would have been the end of the company — we would never have recovered from breach like that. There was never really a 100% solution, and we end up building these processes and data software to try to protect it. But we could never really sleep easy at night knowing it was completely protected. And that’s when Yan and I got together again to start this company to finally be able to solve this problem.”

They founded Anjuna in early 2018, and raised $12 million in funding to date. Anjuna is already shipping its software, and Yogev said it’s in proof of concepts (POCs) with financial services, technology, and hospitality companies.

High-Profile Partners

In addition to its partnerships with AWS and Microsoft Azure, Anjuna also partnered with HashiCorp. Anjuna Enterprise Enclaves software protects HashiCopr Vault, which manages API keys, passwords, and certificates in one central location. Vault, however, uses a master key that is exposed in plaintext in memory, which makes it accessible to insiders who can use it to decrypt Vault secrets and gain access to protected data. Anjuna’s technology makes Vault access only when it's running in a secure enclave.

In another partnership with in-memory database Redis, Anjuna automatically creates secure envlaces that isolate and encrypt all Redis resources, even during runtime.

Both of these products, Anjuna Enterprise Enclave for Redis and Anjuna Enterprise Enclave for HashiCorp, are sold on the Microsoft Azure confidential computing marketplace or directly from Anjuna.

Proof Is in the POCs

While maybe a handful of other startups are also working on encrypting data in memory, they aren’t hardware agnostic. Fortanix, for example, which has probably the most developed technology in addition to partnerships with IBM Cloud, Microsoft, Alibaba Cloud, and Equinix, among others, only supports Intel SGX.

“What they [Anjuna] are doing is pretty unique in the market — and there’s not much of the market right now because secure enclaves are proprietary,” said Paula Musich, research director at Enterprise Management Associates (EMA) who covers security. To experience the security and data privacy benefits of encrypted in memory data, enterprises have to rewrite each application to work with Intel, AMD, and Arm secure enclave technology, she added. “These interoperability issues have prevented secure enclaves from taking off in a significant way, and this is the problem Anjuna appears to be solving.”

While the technology looks “promising,” Anjuna is a small startup and the proof will be in the POCs, she added. “They are just coming out of stealth mode, so educating the market about problems that they’re solving is probably their biggest challenge right now.”

By creating this abstraction layer for the different secure enclave technology implementations, and eliminating the need for organizations’ to rewrite their applications, Anjuna can help companies address fears about insider threats and bad actors stealing credentials and using those to steal corporate and customer data, Musich said.

“That double whammy of threats keeps a lot of CISOs awake at night,” she said. “And it looks like [Anjuna] potentially has a solution to that problem of when you have to do operations on the data, you have to expose it. This secure enclave eliminates that problem so that you can keep the data secure, even when you’re doing operations on it.”