Before Daniele Perito knew how to secure a payment network, build a marketplace or start an AI company, he knew one sentence in English. It was the sentence a young man needs when he wants a summer job in Cambridge: “I am looking for a job. Do you have any vacancy?” He had memorized the words without quite mastering their meaning. Restaurant managers replied. Perito could not reply to them.
This might have sent a less stubborn applicant home. Perito found two Sicilian roommates instead, followed a tip to Gonville and Caius College and told an Italian catering manager that, yes, naturally, he had waited tables before. He had not. Within two weeks, he was serving at an event attended by the Duke of Edinburgh. The leap came first; the competence had to catch up.
That bargain became one of the durable patterns of his career. Raise your hand. Enter the unfamiliar room. Then work hard enough to justify the confidence that got you through the door. It carried him from Cassino, a city between Rome and Naples, into computer-security labs, through the early team at Cash App, across the improbable terrain of wholesale retail and, finally, back to security. His route is not a straight ascent. It is a loop, and the loop is the point.
The first computer arrived by way of family
Perito grew up in a working family. His father worked in a factory; his mother ran the home. His two sisters, ten and eleven years older, were the family's first university students. One helped with mathematics. The other went to France for doctoral work. An uncle had worked in London and later opened a small hotel in Geneva. His parents had spent time in Paris, London and Geneva too. Cassino was close-knit, but the household's mental map extended well beyond it.
A future brother-in-law brought home a 286 PC, one of those beige machines that now looks less like a portal than an appliance. Perito immediately liked what it could do. At fourteen, he found a scientific high school with a computer-science track and joined a class of only thirteen students. Later he left for Sapienza University of Rome, an expense his family managed through sacrifice and scholarships. He earned both bachelor's and master's degrees with honors.
The academic journey widened: an exchange year at the University of Birmingham, a PhD at INRIA Rhône-Alpes and the University of Grenoble, research visits at UC Irvine and Stanford, then postdoctoral work at UC Berkeley. His papers examined the internet's revealing seams: how usernames can identify the same person across networks, how web-search histories can leak, how personal information can strengthen password guessing and how small embedded devices can establish trust. The topics differed. The question stayed neat and slightly mischievous: where does the system betray its own assumptions?
The long route back to security
At Square, instinct met an unfinished product
Perito once turned down a research role at Samsung because the office felt less energetic than the place he wanted to grow. Square produced the opposite sensation. The people he met were passionate and seemed to know things he barely knew. During a visit, a favorite electronic track played as engineers deployed new server software. It was a private coincidence in a public office, hardly the material of a spreadsheet. He took it as a signal.
He arrived in 2012, when Square was still small enough for a single engineer to imagine changing its trajectory. A new money-transfer product sent payments using email, which struck the security specialist as an invitation to trouble. He raised his hand. He did not yet understand every relevant email-security protocol, but soon he was sitting in a meeting with Square's chief technology officer and learning at speed. Cash App became his practical education in the odd intimacy between growth and abuse: an incentive that attracts an honest customer also attracts someone eager to manufacture ten customers and collect ten rewards.
“You can fake it until you make it, but then you are writing checks you cannot cash. You have to work twice as hard to learn.”Daniele Perito on volunteering before feeling ready
Square also gave him future co-founders. Perito, product leader Max Rhodes and engineer Marcelo Cortes began discussing startup ideas in 2015. They did not meet at a mixer, exchange grand declarations and incorporate by Monday. They had worked together. They knew one another's habits under pressure. For Perito, this mattered more than any isolated flash of inspiration. A young company, he argues, is rarely better than its founding team. Choosing co-founders resembles choosing a spouse, except the romance includes cap tables and customer support.
Faire was built from Lego pieces and awkward sentences
Wholesale retail did not look like the obvious next chapter for a security researcher. That was part of its charm. Independent shopkeepers carried discovery risk: order an unfamiliar brand, pay for the inventory and hope customers wanted it. Faire's proposition used software and financing to soften that risk with payment terms and free returns. The founders entered Y Combinator's Winter 2017 batch and began with a self-imposed pace of roughly one hundred work hours a week.
The product did not arrive whole. Perito describes the early features as Lego pieces assembled and reassembled: terms, returns, selection and the words used to explain them. For six to nine months, the team searched for the right combination. Then, around July 2017, it adjusted the way the offer was presented. The underlying machinery had not suddenly transformed. The customer could finally see it. New-customer acquisition moved from roughly one per day to roughly ten.
Cash App had taught Perito how referrals could compound a good product and how fraud could counterfeit success. Faire applied both lessons. Incentives had to be large enough to prompt a genuine introduction but not so generous that the bonus became the product. Retention separated the enthusiastic customer from the opportunist. Security thinking, smuggled into retail, became growth discipline.
Faire expanded internationally and, in 2021, reached a reported valuation of $12 billion. Perito served as co-founder and chief data officer, helping build the company's data, analytics and risk foundations. The accomplishment is easy to flatten into funding totals. More revealing is his explanation of the work before product-market fit: move quickly because time and money are finite; each experiment buys another chance to find the combination people want.
Several useful features, assembled correctly but explained in language customers did not immediately grasp.
A clearer proposition, followed by an immediate increase from about one new customer a day to about ten.
AI made the old problem urgent again
Perito stepped out of Faire's daily operating role in 2023 while remaining a co-founder and board member. He read, exercised, advised younger companies, especially Italian ones, and waited for the next adventure to feel both logical and alive. The inspiration arrived close to where his professional life had begun.
In 2024, he joined Qasim Mithani and Andrea Michi to form depthfirst. Their founding premise was that large language models would soon discover previously unknown vulnerabilities in complex code at a speed human teams had never faced. That prediction implied its own defense: AI systems able to reason through an application, distinguish a genuine route to exploitation from background noise, verify the weakness and suggest a fix inside a developer's workflow.
Perito explains the shift with a bear joke sharpened into strategy. The old advice says you do not need to outrun the bear; you need to outrun the person beside you. AI changes the quantity. There may be a thousand bears, tireless and inexpensive, each able to inspect another corner of the forest. Relative safety stops looking safe.
“We're really trying to secure the whole software world from AI bears.”Perito on the new economics of attack
depthfirst emerged publicly in January 2026 with a $40 million Series A. Less than ninety days later it announced an $80 million Series B led by Meritech Capital, bringing total funding to $120 million. Alongside the round came dfs-mini1, an in-house model initially focused on smart-contract vulnerabilities. Money supplies time and compute, but it does not settle the argument. The company's wager is that specialized intelligence, trained and tested on the work of security, can be cheaper and more useful than asking a general model to become an expert on command.
Watch / 45 minutesPerito discusses Cash App, Faire, “AI bears” and the reasoning behind depthfirst.
Play interview ↗A career held together by a way of seeing
Perito has a fond theory about the Italian contribution to security. Italian culture, he says with comic caution, teaches a certain skepticism toward rules and institutions. People learn to imagine how a system might be worked around. Direct that instinct toward protection rather than mischief and it becomes a professional advantage: anticipate the cheat, then close the gap.
His story complicates the tidier myth that expertise means remaining in one lane. He left research, but adversarial thinking followed him into payments. He left payments for retail, but incentives and fraud followed him into growth. He stepped away from a marketplace and found that the most consequential new technology had turned his oldest subject into a larger, faster contest.
The continuity is not an industry. It is an appetite for systems that almost work. The young waiter with one sentence, the engineer volunteering for a protocol he had not mastered, the founder rearranging product features until customers understood them: each accepts a gap between the current state and the possible one. Perito does not pretend the gap is already closed. He simply appears unusually willing to enter it.
His mother's prediction about Bill Gates was grander than the evidence available in Cassino. Perito laughs at the extravagance. Still, a useful idea hid inside it. The world beyond the town was reachable. First Rome, then Birmingham, Grenoble, Berkeley and San Francisco. Security, payments, wholesale and security once more. The places changed. The question at the center did not: if a rule, product or network can be broken, can careful people find the route first and build something better?