The founding myth of DataLocker contains no garage, dorm room, or napkin. It begins in a hotel elevator in Korea. Jay Kim was there on business connected to his family’s steel-fabrication work when a friend introduced him to another man who had encryption technology and needed a partner. The three went upstairs. They talked. Kim, whose own résumé ran through pharmacy, manufacturing, e-commerce, and international trade, listened long enough for an unfamiliar industry to become a plausible next act.
This was 2007, just as a financial crisis was beginning to rearrange business plans everywhere. Kim, David Kim, and Hangsook Cho started with what Jay later called a simple idea and a shoestring budget. The idea was tactile: protect a storage device with encryption, but let the owner authenticate directly on the device. A password entered on a built-in keypad would not have to pass through a potentially compromised computer. No driver would be required. The security could travel with the drive.
It was an elegant proposition with an unglamorous consequence. The team spent roughly two years taking intellectual property from paper to a commercial product and through federal validation. Simplicity, as usual, had sent the difficult work backstage.
A founder from the adjacent possible
Kim did not arrive in cybersecurity by climbing a tidy ladder of engineering jobs. At the University of Kansas, he studied biology and pharmacy. At George Washington University, he earned an MBA in international business. He worked in pharmacy and later in a family manufacturing business. He had also joined the dot-com rush in 1998, building e-commerce sites and working across trading ventures.
The path looks eccentric only if a company must resemble its founder’s degree. Look instead at the operating muscles. Pharmacy teaches that procedures matter. Manufacturing teaches that a product must survive contact with a supply chain. International trade teaches that a good object still needs distribution, credit, and trust. Data security asks for all three.
By the 2013 RSA Conference, Kim could hold up the DL3 portable drive and explain the design in plain speech. Authentication happened on its touchscreen. Encryption happened in specialized hardware. The same drive could work across Mac, Windows, or Linux because it did not depend on a software driver. When an interviewer asked about building technology in Overland Park rather than a coastal hub, Kim praised the local workforce and costs, then supplied a local joke: a ten-minute commute was considered long.
Kansas was not a consolation prize in his telling. It was an operating advantage. The region offered talent from telecom and defense businesses, reasonable wages, and a life that did not require founders to perform a borrowed version of Silicon Valley. A cybersecurity company could be global from a suburb of Kansas City, provided it built something useful and learned how to sell beyond its zip code.
The product is also the behavior
Kim’s most persistent product argument is that formidable security cannot demand heroic behavior from ordinary users. He has described DataLocker’s job as delivering what security leaders need while preserving what users can handle. In late 2025, announcing new FIPS 140-3 Level 3 validations, he sharpened the point: “We believe complexity is the enemy of security.” A blinking light that nobody understands is not a minor interface flaw. It invites a mistake.
That philosophy moved DataLocker beyond individual drives. The company acquired Swedish developer BlockMaster AB in 2015, bringing its SafeConsole central-management technology into the portfolio. In 2016, a transaction with Kingston Technology gave DataLocker IronKey enterprise-management services and encrypted hard-drive assets. The object on the desk now belonged to a larger system: administrators could set policies, see audit records, recover passwords, and remotely disable devices.
This is the quiet arc of the company. The early breakthrough put controls onto a portable device. The later work connected thousands of devices to organizational policy. Physical storage did not disappear when cloud software arrived. Laboratories, government offices, factories, and disconnected systems still move information through hardware. The USB drive, routinely dismissed as office clutter, remains a small door into a very large building.
Kim is named on patents covering encrypted flash-drive designs and systems for secure data management. Yet his public language rarely lingers on technical ornament. He talks about use cases, users, and trust. A patent gives a company defensible property. A product that people can operate gives it a reason to exist.
The network needs maintenance
The elevator story could tempt a lazy lesson: be lucky near the right floor. Kim’s own lesson is stricter. A mutual friend provided what he called a kind of prequalification. Friend-of-a-friend trust made the first conversation easier. But he is candid that a network does not maintain itself. He participates in domestic and international organizations and makes a point of attending their events, in person or online.
“It’s not easy maintaining relationships and what we call ‘networks’ without putting a lot of work into it,” he said in a podcast conversation. The line strips networking of its cocktail-hour sheen. Relationships are an operating system. They require updates.
Borrowed trust opens the room
A credible mutual connection can make two strangers legible to each other.
Stay for the second conversation
The useful move in Kim’s elevator story happened upstairs, after the chance encounter.
Show up before the ask
Organizations and events matter because repeated participation turns contact into context.
Make the network useful
Kim’s board and trustee roles extend the pattern from company-building into community work.
His calendar reflects the point. Kim belongs to the Council of Korean Americans. He has served the Asian American Chamber of Commerce of Kansas City and sits among the University of Missouri-Kansas City’s community trustees. He has also held board roles with Axiom Strategies and the Kansas City chapter of AFCEA, a group connecting government, industry, and academia around defense and technology.
These are connections across categories, not one polished founder bubble. Education, regional business, Korean American leadership, public-sector technology, and international markets overlap around his work. DataLocker itself was born in that overlap: a Kansas operator, a Korean hotel, a manufacturing trip, a mutual acquaintance, and intellectual property waiting for a commercial home.
Gratitude as an operating record
When DataLocker reached its tenth anniversary, Kim wrote a retrospective that could have centered on the impressive nouns: patents, offices, acquisitions, certifications, growth. They are all there. The emotional emphasis lands elsewhere. He thanked current and former team members for investing part of their lives. He thanked partners for going the extra mile. He thanked customers for placing trust in the products.
The note also admitted how unlikely the outcome had once seemed. Had anyone told the early team in 2007 that they would end up at a Kansas-based data-security company a decade later, Kim wrote, every one of them would have laughed. It is a charming confession from an industry that prefers inevitability after success. Careers are usually clearer in reverse.
Recognition followed. The Asian American Chamber of Commerce of Kansas City named Kim an Entrepreneur of the Year in 2013. EY selected him as a Central Midwest Entrepreneur Of The Year finalist in 2017. In 2020, the Export-Import Bank of the United States named DataLocker an Exporter of the Year. EXIM said its credit insurance helped the company offer overseas customers more favorable terms while protecting against nonpayment. Useful security still needed useful finance.
In December 2025, DataLocker announced that its DL4 portable hard drive and Sentry K350 flash drive had both received FIPS 140-3 Level 3 validation while remaining compliant with federal trade requirements. The language was dense because the market is dense. Kim’s explanation returned to the user: clear screens and sensible controls reduce uncertainty. Nearly eighteen years after that elevator ride, the original premise remained visible.
There is a compact founder playbook here. Begin with a problem whose consequences are real. Borrow trust carefully. Learn the parts of the industry your résumé did not give you. Hide complexity through patient engineering, not slogans. Use geography as an advantage if it behaves like one. Maintain relationships when no transaction is pending. Thank the people who carried the work.
Kim’s story also offers a useful correction to the cult of the perfectly prepared founder. He was not waiting in 2007 with a cybersecurity career already assembled. He had enough experience to recognize a commercial opening, enough humility to work with people who held the technical knowledge, and enough patience to let validation take the time it required. Opportunity arrived by accident. Readiness looked like staying curious after the introduction.
The elevator makes the story memorable. Everything after the doors opened made it a company.