Skip to content
YC Root AccessYC Root Access

Infisical: The Open Source Security Stack

Vlad Matsiiako, Tony Dang, and Maidul Islam started Infisical with a belief that secrets—like API keys and credentials—are the glue that holds modern software together. But managing them was still a mess: clunky tools, brittle workflows, and security that broke under pressure. So they built something better. What started as a small open source project at Cornell became a go-to secrets management platform for developers and large enterprises alike. After open-sourcing the product during YC’s Winter 2023 batch, traction took off. Now Infisical is trusted by companies like Hugging Face, LG, and Lucid, and has been downloaded more than 40 million times. Today, they announced a $16 million Series A led by Elad Gil, with participation from Y Combinator, Gradient, Dynamic Fund, and the CEOs of Datadog, Samsara, and Valor. Infisical is cash-flow positive, growing fast, and expanding beyond secrets into a full open-source security stack for the AI era. YC Partner Diana Hu recently sat down with Infisical's founders to talk about how they got here, their founding story, and the kind of company they are building. Learn more about Infisical at https://infisical.com. Apply to Y Combinator: https://ycombinator.com/apply Chapters 00:00 - Introduction 00:10 - What is Infisical? 00:33 - Managing Secrets at Scale 00:58 - Origin Story 02:43 - From Closed Source to Open Source 03:51 - Landing Big Contracts 05:17 - Competing in a Crowded Market 06:39 - Technical Challenges and Innovations 08:15 - Future Vision and AI Integration 09:48 - Hiring and Opportunities

Diana HuhostTony DangguestVlad MatsiiakoguestMaidul Islamguest
Jun 6, 202510mWatch on YouTube ↗

CHAPTERS

  1. 0:00 – 0:33

    Infisical overview: open-source secrets management for modern infra

    The team introduces Infisical as an open-source platform that helps developers and enterprises manage sensitive credentials across infrastructure. They position it as both a security and infrastructure product serving a wide range of company sizes.

    • Infisical is an open-source secrets management platform
    • Used by both fast-growing startups and Fortune 100 enterprises
    • Focuses on securing sensitive credentials across infrastructure
    • Operates at the intersection of security and developer infrastructure
  2. 0:33 – 0:58

    What counts as a “secret” and the scale Infisical handles

    The discussion clarifies the types of secrets Infisical manages and the operational scale of the system. They highlight that secrets span many credential types and that Infisical processes massive monthly volumes.

    • Secrets include database tokens, certificates, API keys, and other credentials
    • Secrets are anything sensitive in developer infrastructure
    • Processing volume is north of 10 billion secrets per month
    • Emphasis on large-scale reliability and throughput
  3. 0:58 – 1:31

    Founders’ origin: Cornell side projects and repeated collaboration

    The founders explain how they met at Cornell and built multiple side projects together before Infisical. Their prior teamwork and iteration set the foundation for identifying the right problem to tackle next.

    • Founders met at Cornell and collaborated throughout college
    • They built multiple side projects before Infisical
    • Infisical emerged as the next step after earlier attempts
    • Prior experience helped them iterate quickly on ideas
  4. 1:31 – 2:43

    Finding the wedge: the .env file pain and syncing secrets across teams

    They describe the concrete developer pain that inspired the initial product: handling secrets via .env files. The early mission was to make sharing and syncing sensitive configuration safer and easier, even for small teams.

    • Recurring issue across projects: managing .env files safely
    • Small teams struggle to share sensitive values securely
    • Initial focus: syncing secrets across teammates reliably
    • This early wedge later expanded into broader security needs
  5. 2:43 – 3:51

    Closed-source to open-source: the growth unlock and trust/compliance driver

    Infisical’s shift to open source is framed as a pivotal decision prompted by stalled growth and customer feedback. Open sourcing increased trust, enabled self-hosting, and accelerated adoption and community traction.

    • Originally shipped as a closed-source SaaS
    • Growth flattened, prompting a strategic rethink
    • Users wanted trust and to run it on their own infrastructure
    • Open source enabled compliance/security requirements and drove GitHub adoption
  6. 3:51 – 5:13

    From community users to enterprise revenue: how big customers adopt

    They explain how Infisical often starts with individual developers self-hosting, then expands inside organizations. In one case, a user carried Infisical from a prior company into a new Fortune 50 enterprise, turning grassroots adoption into a major contract.

    • Developer mindshare and community are a key distribution channel
    • Many users start with self-hosting in labs or small projects
    • Bottom-up adoption expands into company-wide usage
    • User job changes can trigger adoption in large enterprises
  7. 5:13 – 6:39

    Operating in a crowded market: why customers pick Infisical over incumbents

    Diana frames the competitive landscape (Vault, AWS Secrets Manager), and the team details a major defense customer choosing Infisical. The differentiator is a product philosophy centered on accessibility and dramatically faster deployment than legacy tooling.

    • Competes with established solutions like HashiCorp Vault and AWS
    • Example win: large federal defense contractor (20k+ employees)
    • Core philosophy: make security accessible to all engineers
    • Deployment time advantage vs. legacy tools (months/weeks vs. ~21 months)
  8. 6:39 – 7:11

    Engineering for on-prem and self-hosting: building for many environments

    Maidul discusses the engineering mindset required to support diverse enterprise environments, especially on-prem deployments. Every feature is evaluated not just for functionality but for how smoothly customers can self-host it.

    • Infisical must accommodate many customer environments
    • On-prem deployment simplicity is critical for largest customers
    • Feature development includes self-hosting experience as a first-class constraint
    • Self-host focus introduces unique engineering and operational challenges
  9. 7:11 – 8:18

    Key architectural choice: stateless design for scalability and high availability

    They contrast Infisical’s stateless architecture with other tools that behave more like databases, complicating scale-out. Stateless containers enable easier replication, scaling, and high availability with less operational overhead.

    • Some secrets tools treat the app like a database, hindering scaling
    • Infisical is stateless, simplifying replication across containers
    • Scale-out becomes easier for fleets and HA setups
    • Avoids overhead of ensuring persistence on each replica before scaling
  10. 8:18 – 8:49

    Vision: expanding from secrets into a full open-source security stack

    Vlad outlines the roadmap beyond secrets management into adjacent security infrastructure offerings. Infisical aims to become a broader platform including PKI, SSH access, and encryption/KMS capabilities.

    • Mission remains: make security more accessible to developers
    • Expansion beyond secrets into certificate management (Infisical PKI)
    • New product line: SSH access (Infisical SSH)
    • Encryption as a service / key management direction (Infisical KMS)
  11. 8:49 – 9:43

    AI agents as a new security actor: securing agent access and trust

    They describe how AI changes the security model by introducing AI agents that need controlled access to resources and to each other. Infisical positions itself to manage and secure agent-to-infrastructure access in this emerging paradigm.

    • AI introduces new “actors” beyond users and machines
    • AI agents need secure access to infrastructure resources
    • Future need: enabling agents to trust and communicate safely
    • Infisical could become a control plane for agent access security
  12. 9:43 – 10:32

    Team growth: roles and hiring priorities across engineering and go-to-market

    The conversation closes with an overview of hiring needs as the company scales. They’re recruiting across many functions, from technical roles to sales and operations, including developer relations.

    • Hiring for 15+ positions
    • Engineering roles: frontend and full stack
    • Go-to-market roles: account executives
    • Operations and recruiting, plus developer relations roles

Get more out of YouTube videos.

High quality summaries for YouTube videos. Accurate transcripts to search & find moments. Powered by ChatGPT & Claude AI.