I'm happy to announce that AuthZed recently renewed our SOC2 compliance and our SOC2 Type 2 and SOC3 reports are now available on security.authzed.com.
Having just endured the audit process again, I figured it would be a good time to reflect on my personal feelings toward compliance and how my opinion has evolved.
Want to build enterprise-ready AI that respects data access permissions? Learn how Relationship-based Access Control (ReBAC) provides superior security for Retrieval-Augmented Generation (RAG) systems by enabling pre-filtered queries and granular access control through relationship-based access controls. Read on to discover why ReBAC outperforms traditional authorization models for AI applications.
AuthZed's CEO and co-founder joins the Cube at the NYSE for a deep dive into the critical role of access control in the age of AI. Discover how AuthZed is building "guard rails for AI" to ensure secure and reliable access to sensitive data, prevent unauthorized access, and enable granular permissions. He explores real-world applications in healthcare, finance, and the sharing economy, and shares insights on the company's origins and their unique approach to solving authorization challenges. Watch the full interview to learn more.
What do Benjamin Franklin's satirical letter about waking up early and a failing CI test have in common? When our automated tests mysteriously started breaking after the end of Daylight Saving Time, we uncovered unexpected timestamp behavior and embarked on a systematic debugging journey to find a fix.
The release of SpiceDB v1.38 debuts new foundational API functionality for SpiceDB: Transaction Metadata. When writing relationships, you can now include arbitrary metadata that will be stored alongside the transaction and published to consumers of the Watch API.
SpiceDB v1.36.0 introduces a new feature: relationship integrity. It ensures that all relationships written to the backing datastore are signed by a key only known to SpiceDB, protecting your SpiceDB permissions system from modifications to their relationship data.
The article discusses two approaches to authorization: embedding it directly into your application using a library like Casbin, or centralizing it with an external service like SpiceDB.
Casbin gives you fine-grained control and flexibility, ideal for smaller projects or custom needs.
SpiceDB simplifies management for large-scale systems, offering scalability and auditability.
The choice depends on your project's specific needs and priorities.
Both SpiceDB and Zanzibar combine performance, scalability, and correctness into one manageable, global authorization solution. Strong consistency is key to ensuring correctness, but caching is necessary for performance. Consistency and caching are often diametrically opposed so how do SpiceDB and Zanzibar solve this problem? With a few key realizations around staleness, when consistency is necessary and how the two interact.
In this episode of That Tech Pod, Jake Moshenko, co-founder and CEO of AuthZed, discusses his journey from Amazon and Google to building a leading permissions system.
AuthZed's CEO and co-founder Jake Moshenko is interviewed at The Open Source Startup Podcast. Learn about the Google Zanzibar approach, AuthZed's focus on large-scale applications, and how a Hacker News launch propelled SpiceDB growth.
Jake Moshenko, co-founder and CEO of AuthZed, discusses his entrepreneurial journey and the challenges of building a distributed authorization platform. He emphasizes the need for fast, consistent authorization in modern applications. The conversation also touches on the technical complexities of distributed systems and AuthZed's approach to addressing them.
While the practice of building authorization in applications is not new, modern approaches are evolving rapidly and our language for defining it remains unsettled.