A good security engineer possesses a professional suspicion of convenience. The login that feels effortless may be letting in the wrong person. The data lake that welcomes every analyst may be welcoming them to every record. The clever AI agent that finishes a task may have completed one it was never entitled to begin. Don Bosco Durai has spent much of his career standing at those doors, asking to see the credentials.
His résumé can be read as a brisk tour of enterprise computing's anxieties. First came online fraud, when banks and merchants were learning that a password was not quite the same thing as a person. Then came Hadoop, when companies gathered oceans of data and discovered that an ocean is difficult to lock. Then cloud platforms scattered those waters across services and providers. Now autonomous agents can reason, choose tools, call an API and alter a system. Each era arrived promising abundance. Durai arrived asking about authority.
This is not the usual founder mythology. There is no garage fable on offer, nor a childhood gadget pulled apart at the kitchen table. The public record begins more usefully, with a pattern: three security companies, two acquisitions, an open-source project that outlived the startup which created it, and a return to the same engineering question in progressively more complicated rooms.
The first suspicious transaction
At Bharosa, which Durai co-founded and served as chief architect and engineering leader, the problem was real-time fraud detection and stronger online authentication. Oracle announced its purchase of the company in July 2007. Bharosa's Tracker and Authenticator products already served more than 25 million users, according to the acquisition announcement. The essential idea was that identity could not rest on a password alone. Context and behavior mattered too.
Durai's patent record from this period and its aftermath reads like the contents of a careful bank vault: online data encryption and decryption, fraud monitoring, tiered user authentication, personalized security signatures. Six issued United States patents appear on his professional profile. The titles are dry, which is often a compliment in security. Drama is what happens when the system fails.
At Oracle, Durai led work on security and governance products for large enterprises. Scale changes a security argument. A rule that makes sense for one application becomes a negotiation among thousands of employees, old systems, auditors and regulatory obligations. Permission is no longer a switch. It is an institution with software attached.
“There's no silver bullet. The best way is to have multiple layers of solutions.”Don Bosco Durai, on agent security
The startup that became plumbing
By 2012, Durai and Balaji Ganesan were building XA Secure. Hadoop had made distributed data processing practical, but its growing menagerie of components created a familiar mess: different systems, different controls, different audit trails. XA Secure proposed a central place to administer policy and see who had touched what. It was the permissions desk for a town whose streets were still being paved.
Hortonworks acquired XA Secure in May 2014 and said it would move the technology into an Apache community project. The work became Apache Ranger. Its purpose is plain even if the machinery is not: administrators can define fine-grained authorization policies across data services and retain a central audit record. Durai remained involved as a project management committee member and committer.
There is a peculiar elegance in a startup disappearing into open-source infrastructure. Founders are trained to desire a durable name. Infrastructure achieves durability by becoming so ordinary that engineers invoke it without reciting its origin story. Ranger traveled well beyond the first Hadoop clusters. Cloud services integrated it. Thousands of organizations encountered the architecture, even when Durai's name was nowhere on the screen.
Durai and Ganesan founded Privacera in 2016. The partnership was familiar; the terrain was new. Enterprise data had moved into combinations of Amazon Web Services, Microsoft Azure, Google Cloud, Snowflake and Databricks. Policy had to follow it without turning every new platform into another handmade permissions project. Privacera took Ranger's centralizing instinct into cloud and hybrid environments, then added discovery, classification, masking and privacy controls. In 2021, the company announced a $50 million Series B led by Insight Partners.
A machine arrives with its own errands
Generative AI altered the shape of the problem. Traditional software follows paths its developers specify. An agent can interpret a goal, assemble a workflow, select tools and call services. The freedom is the attraction. It is also the part that makes the security department reach for coffee.
In a 2025 talk, Durai described an architecture in which agents, tasks and tools may share a single process. A database tool needs credentials. An API tool needs a token. If those credentials are broadly privileged and visible within the process, one component may reach things it should not. The agent can also choose a route its developer did not predict. Durai called these the “unknown unknowns,” a phrase that has aged rather well in computing.
He recounted a recent conversation with a major credit bureau. The company had built many agents, but production was another matter. It treated an agent rather like a human hire: before it touched regulated data, it needed onboarding, training and enforceable limits. A prototype's ability to retrieve an answer was irrelevant if the requester lacked consent or authority. The agent could be impressively right and institutionally wrong.
A successful answer is not sufficient evidence of correctness. The requester must have been entitled to the answer.
Durai's response is a three-part operating model. It is less theatrical than a robot uprising and considerably more useful.
Evaluate
Test leakage, permissions, unsafe actions and runaway behavior before release.
Enforce
Apply identity, policy and approval limits as every task and tool executes.
Observe
Watch live behavior for failures, exposure and anomalies that tests missed.
Evaluation asks whether the agent should enter production. Ordinary software checks still apply: scan dependencies, test vulnerabilities, establish expected behavior. Agents add stranger cases. Can a prompt injection reveal private data? Can the system distinguish an employee asking for their own salary from one asking for a colleague's? Can a bad prompt send it into a loop? The point of an evaluation is not to admire the model. It is to produce enough evidence to make a release decision.
Enforcement makes that decision real. Durai insists on preserving two sets of limits: the agent's and the human user's. A payroll agent may be allowed to read compensation records, but that does not mean every employee using it inherits the keys to payroll. The user's identity must travel from the first request through each task and tool to the final database query or API call. If the identity evaporates halfway and the backend sees only a powerful service account, authentication has become a decorative archway beside an open gate.
Observability accepts that testing is incomplete. Models change. Libraries change. People phrase ordinary requests in unanticipated ways. A system must notice when failure rates rise, sensitive information begins leaving unexpectedly, or an agent wanders beyond its usual operating boundaries. Durai talks about near-real-time evidence, thresholds and human intervention. Autonomy, in this view, is not the absence of supervision. It is supervision engineered at machine speed.
The open gate, carefully watched
Privacera open-sourced PAIG, a framework for security, safety and observability in generative-AI applications. The project has since been associated with the Trust3 AI name. The choice repeats the XA Secure pattern: an enterprise problem becomes a shared engineering problem, and shared problems benefit from inspectable machinery. Durai closed his conference talk by inviting contributors and design partners rather than announcing that the matter had been solved.
That modesty suits the subject. Security products are forever tempted to sell certainty. Durai's own language is layered, conditional and operational. Evaluate. Enforce. Observe. Put thresholds around automated approval. Bring a person in when the action crosses them. Carry identity to the point where something actually happens. These are not promises of perfect safety. They are instructions for remaining accountable while useful work proceeds.
His career has moved from recognizing a suspicious bank transaction to governing a machine capable of inventing its own sequence of transactions. The systems grew more distributed. The actors became less predictable. The vocabulary changed from authentication to Hadoop to cloud to agents. Yet the governing question stayed almost comically stable.
Who are you? What are you permitted to do? Can we prove what happened afterward?
Every technology boom prefers to discuss possibility. Durai's contribution is to discuss permission without making permission the enemy of possibility. A door is useful because it can open. It is trustworthy because it does not open for everyone.