A paper napkin is a peculiar place to put a data protection company. It is absorbent, easily lost, and rarely backed up. In 2014, Tarun Thakur used several of them to sketch an idea for Puneet Agarwal of True Ventures over coffee. Avinash Lakshman, the founder of Hedvig, had made the introduction. Thakur was thinking about the new kinds of databases entering companies and the awkward business of recovering their data when something went wrong.
At that point, the technology did not exist. There was a drawing and a conversation. After roughly ninety minutes, Agarwal was convinced enough by Thakur’s thinking to see a company in it. Datos IO, which Thakur co-founded with Prasenjit Sarkar, would spend almost two years building and launching RecoverX. A napkin could suggest the architecture. Making the thing work took rather longer.
The engineer before the napkins
Thakur had already spent years around the machinery that makes enterprise computing dependable. His career included IBM Research, Symantec, and EMC Data Domain. His education combined engineering with an MBA in strategy and marketing at Duke University. That combination makes sense for someone whose working life has involved translating technical problems into products that businesses will pay for.
Storage, distributed systems, and security are recurring subjects in his work; his published biography credits him with more than twenty patents. These are fields where a clever demonstration is only the beginning. A customer needs the product to keep behaving sensibly when the databases multiply, the environment changes, and the original designer has gone home. Thakur’s later companies would occupy that same awkward territory between a good technical idea and the everyday obligations of keeping a business running.

Selling the company, surrendering the name
Rubrik acquired Datos IO in February 2018. A year later, Thakur was writing about the experience with a frankness that acquisition celebrations often lack. The expanded sales operation and worldwide reach brought opportunity. They also brought the work of explaining the product to a much larger organization, keeping the engineering team together, and balancing technical integration with the business itself.
His advice to other founders was practical: communicate more, listen carefully, build relationships, and put the parent organization’s success ahead of the old job title. He acknowledged that feedback could be difficult to absorb. Even the name had to go. Datos IO’s platform became Rubrik Mosaic. For a founder, that is a small linguistic change carrying a sizable emotional bill. The business could reach more customers precisely because it no longer had to carry his original company’s name.
“As founders, we need to leave our ego at the door.”
Tarun Thakur, reflecting on the Rubrik acquisition, 2019
In another account from that period, Thakur described conversations with more than fifty customers. He was visiting CIOs, enterprise architects, and database engineering leaders, trying to understand how their systems were changing. NoSQL databases were becoming part of ordinary enterprise architecture. Developers could download software and begin building; the resulting applications still needed dependable operational tools.
His observations were concrete. Different databases served different jobs. Traditional systems remained in place while newer ones arrived. Companies wanted applications in the cloud and still had substantial investments in their own data centers. The neat diagram in a presentation could become a rather crowded house in practice. Thakur kept returning to the question of how to make that mixed environment manageable. Customer conversations supplied the friction that a tidy product plan might miss.
The question the backup could not answer
In early 2020, Thakur, Maohua Lu, and Rob Whitcher began asking senior technology leaders about data moving into the cloud. They spoke with dozens of executives. The worry that kept surfacing was basic: the organization could not confidently explain who had access to its most sensitive information. A business could move its data, run its applications, and still lack a useful picture of the permissions surrounding them.
The three founded Veza around that problem. Authorization became their organizing idea: map the relationships between identities and data so a security team can understand the access that actually exists. It was a natural continuation of Thakur’s career in infrastructure, with a different point of attention. Recovery asks how to get information back. Access asks what somebody can do with it while everything appears to be running normally.

When Accel invested in 2022, Eric Wolford described an authorization problem complicated by incompatible languages. Identity systems, cloud platforms, applications, and databases each expressed permissions in their own way. Veza’s work was to pull those differences into a view people could use. Its platform already connected with more than forty systems, including SharePoint, GitHub, Snowflake, and AWS Redshift.
For Thakur, that puts a particular demand on product leadership. The complexity has to be understood by the builders before it can be made legible to the buyer. A customer should not need to become an expert in every platform’s vocabulary simply to find out whether an employee can reach a file. The interface is where years of infrastructure experience either become useful or remain an impressive collection of details.
Service account
AI agent
Write
Delete
Database
Cloud resource
A customer gets a vote
Thakur’s account of building Veza includes a two-page document from an early prospect that changed the team’s understanding of both the problem and the solution. The first hire was a sales development representative. Both details suggest a founder willing to bring buyers into the process early, when their objections could still be useful.
He also describes company building as a sequence of refoundings. A team of three and a team of two hundred require different habits. He has worked with a leadership coach, and he places trust at the center of co-founder relationships. In his telling, a good executive hire needs to fit the company’s stage as well as possess ability. It is a less glamorous hiring philosophy than collecting famous names, but rather easier to put to work on Monday morning.
That willingness to revisit decisions helps explain the continuity between the founder drawing on napkins and the executive discussing coaching. In both situations, the idea has to survive contact with somebody else. Conviction gets a company started. Listening gives it somewhere to go.
The permission problem acquires a budget
In April 2025, Veza announced a $108 million Series D led by New Enterprise Associates, at an $808 million valuation. The round brought total equity financing to $235 million. Atlassian Ventures, Workday Ventures, and Snowflake Ventures joined the financing alongside existing investors. Veza said it would use the money to expand product development and its sales operations worldwide.
The customer list included Blackstone, Workday, Sallie Mae, and Snowflake. For Thakur, selling into such organizations meant the original access question had become a recurring enterprise purchase. There is a large distance between recognizing a problem and getting an institution to allocate a budget to it. Funding marks one stage of that journey; adoption inside customers supplies the more demanding test. His responsibilities now included making the company’s commercial organization keep pace with the product he and his co-founders had conceived.
April 2025 figures. Company financing and valuation are separate measures.
AI agents gave the access question another dimension. Thakur argues that organizations need to understand what an automated identity can actually do across systems. A bot, a service account, or an agent can act on data without resembling an employee in a directory. His ambition includes access environments that can detect inappropriate permissions and help correct them automatically.
This is where his product instincts remain visible. He starts with actions: reading a storage bucket, changing a record, deleting a database row. The language is concrete because the consequences are concrete. An enterprise can admire what an agent produces and still need to constrain what it can reach. Thakur’s proposed answer is to make the permissions understandable enough that a business can govern them continuously, rather than rediscovering them when a review comes due.
Another acquisition. Another first day.
ServiceNow announced its intention to acquire Veza in December 2025 and completed the transaction on March 2, 2026. At the announcement, Veza had 230 employees worldwide and nearly 150 global enterprise customers. ServiceNow planned to bring its identity visibility and governance capabilities into a broader security portfolio, linking access intelligence with workflows.
For Thakur, the move returned him to a familiar leadership problem at a different scale. The product has to fit into another company’s operations while continuing to serve the people who bought it. The stated aim was control over access belonging to people, machines, and AI agents. That creates work beyond a dashboard: decisions must connect to the processes that request, approve, update, and remove permissions. A mapped relationship is useful only if an organization can act on what it reveals.
Thakur greeted the closing with the words, “Today is Day 1.” He thanked Lu and Whitcher and credited customers with shaping the company’s thinking. He also spoke of working with ServiceNow chief executive Bill McDermott and president Amit Zavery. His ambition was to integrate Veza’s identity controls into the wider platform and build for enterprises adopting agents.
There is a pleasing consistency here. The founder who once advised people to leave their ego at the door was again describing an acquisition as a beginning. The original sketch had concerned recovering data. The next company concerned its permissions. Now those permissions have to travel through a larger system of work. Thakur keeps following the data into a new setting, asking the question again. Who can do what? It remains short enough to fit on a napkin.