Services

Open source

EN

KUBICAST #184 - Brazilian AI at the Service of Security

Clavis and Otto will help you a lot in your day-to-day life

mansplainer

João Brito

Brazilian AI at the service of security: Otto in the field

Episode 184 of Kubicast with Leonardo Pinheiro, CRO of Clavis

When it comes to cybersecurity in Brazil, context changes everything. Our traffic carries Pix, boleto, WhatsApp Business, local marketplaces, and a myriad of integrations from banks, acquirers, and public services. It was in this terrain that Otto, Clavis's AI, was born, which is the theme of Kubicast 184. In this post, we unpack the lessons from the chat and show — without magic — how an AI trained on Brazilian reality accelerates risk prioritization, connects data that already exists in your stack, and helps the team move from alert to action with governance.


Why does a “Brazilian” AI matter?

Generic models understand broad patterns; Otto was designed to operate within our ecosystem: national bank terminology, invoice formats, authentication variations, legacy integration quirks, and local fraud nuances. In practice, this means:

  • Fewer false positives in detections common over here (phishing mimicking DARF, CNAB, Pix/QR, etc.).

  • Smarter correlation between EDR, WAF, CloudTrail, API logs, and vulnerability scanners.

  • Situational responses: recommendations that respect Brazilian compliance, team maturity, and operational limits.

The result? Time returned to the team, more objective communication with the business, and materially lower risks.


What Otto is (and what it isn't)

Otto is not a magical antivirus nor a Swiss Army knife that replaces professionals. It acts as an intelligence layer over the sources you already have: asset inventory, scanners, EDR/XDR, cloud, and change pipelines. The proposal is to:

  1. Unify evidence (multi-source telemetry) into a single view.

  2. Score risk by context (exposure, asset criticality, exploit probability, business impact).

  3. Suggest the next action: mitigate, accept, transfer, or investigate — with clear playbooks.

Think of Otto as the tireless senior analyst who forgets nothing, never gets tired, and explains decisions.

It is not a substitute for pentesting, reliability engineering, nor human incident response. It is a multiplier.


From alert to outcome: how prioritization changes the game

Without prioritization, security becomes an endless treadmill. With Otto:

  • CVEs stop being “all urgent”: the score adjusts urgency based on exposure (is it internet-facing?), the presence of an active exploit, and how much that system supports critical processes (e.g., billing, checkout, onboarding).

  • Executable runbooks: for every relevant finding, Otto generates step-by-step instructions — from the patch to temporary compensation — and records accountability.

  • Metrics that the C-level understands: estimated financial risk, reduction trends, and legacy backlog cleared per quarter — without jargon.


Supply chain security: outsourcing without outsourcing the risk

Suppliers and partners have become part of your perimeter. Otto helps evaluate and monitor third parties with objective checklists (minimum controls, cloud posture, evidence of data protection) and alerts you to breaches of commitment (remediation SLAs, log coverage, changes in scope). This avoids the classic “leaked via a partner” scenario and provides contractual ammunition to tighten things up without damaging the relationship.


Cloud, Kubernetes, and doing the basics right

The conversation also covered cloud security and orchestration. Guardrails like CIS Benchmarks, least-privilege IAM, managed secrets, network policies, and observability remain the foundation. Otto helps make the invisible visible (broad permissions, public buckets, vulnerable images, configuration drift) and turns this into a prioritized queue that connects directly with the DevOps pipeline.


Automation + service: where flesh-and-blood people come in

Automation shines in volume and consistency. However:

  • Pentesting still requires human creativity and hypotheses.

  • Threat modeling and architectural analysis benefit from organizational context.

  • Crisis management requires experience and leadership.

Clavis's proposal is product + service: Otto accelerates and organizes, while the specialist team acts where the machine cannot see.


Talking with the business: simultaneous risk translation

A huge part of the pain is in communication. The CRO lives at the intersection of revenue, trust, and compliance. Otto helps answer questions that the board actually asks:

  • What is our risk score today and what is the projection in 90 days?

  • What do we need to mitigate first to reduce exposure by X%?

  • Which suppliers are driving our risk up and why?

  • What is the opportunity cost of accepting this risk for a quarter?

With comparable month-over-month answers, security joins the executive decision-making cycle without drama.


Who should read/listen to this content

  • Security/Infra/Platform leaders who need to show results.

  • DevOps/DevSecOps teams wanting to reduce configuration debt.

  • Procurement/Legal involved in third-party assessments.

  • Executives who need to translate risk into business decisions.


Questions that Otto helps answer

  • Which vulnerabilities really matter this week?

  • Where are we exposed to the internet unnecessarily?

  • What is the aggregate risk per business unit?

  • Which supplier is not meeting remediation SLAs?

  • What can we accept/transfer/mitigate today?


Practical checklist to apply tomorrow

  1. Map sources of truth: inventory, scanners, EDR, cloud, CI/CD.

  2. Connect these sources to an intelligence layer (like Otto).

  3. Define score criteria with the business (impact, probability, exposure).

  4. Prioritize the top 10 risks per quarter with owners and deadlines.

  5. Integrate the security queue into the DevOps workflow (pull requests, pipelines).

  6. Monitor suppliers with objective evidence and reassessment triggers.

  7. Report in executive language: financial risk avoided, trends, snapshot vs. timeline.



If you enjoyed the topic, share it with your team and tell us how a Brazilian AI can accelerate your operations. Your next security sprint might be the most effective one of the year.

Join our early access program and secure your environment in moments! https://getup.io/zerocve

🎧 Also listen to Kubicast on Spotify, and share it with everyone who thinks Otto is that Brazilian singer :D

Newsletter Getup.

Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.

Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.