This week on Dark Rhiino Security’s Security Confidential podcast, Host Manoj Tandon welcomes Yagub Rahimov. Yagub is the CEO and co‑founder of Polygraf, an AI security company that builds “AI application firewalls” and small language model guardrails for enterprises and governments. He helps organizations control what data goes into and comes out of AI systems so they can safely deploy tools like ChatGPT‑style assistants, internal chatbots and meeting note‑takers without leaking sensitive information.
Chapter Titles:
00:00 Intro
02:03 Our Guest
10:39 Does the license agreement on AI platforms protect company data?
21:00 Companies should control their own data
27:01 Where are security trends going?
30:55 LLMs Cannot be re-ruled
36:45 False Positives
39:28 You can get hacked with nothing but Emojis
44:15 Connecting with Yagub.
Audio:
Important Links
Transcript
Manoj Tandon: Hello everyone. This is your host, Manoj Tandon. Welcome to another episode of Dark Rhino Security Confidential. Please hit the like and subscribe button. It helps us out quite a bit with the algorithms, and it allows us to keep bringing you great guests. We appreciate a little bit of love. We have a fantastic guest for you today. He is Mr. Yagub Rahimov. He is the CEO and Founder of Polygraf AI, an AI security company that builds AI application firewalls and small language models, contrary to LLMs. These small language models are guardrails for enterprises and government, helping organizations control what data can go into LLMs like ChatGPT, Claude, or whatever internal chatbot they may be using. This is going to be a very interesting conversation. Welcome to the show, Yagub. I really appreciate you being here.
Yagub Rahimov: I appreciate you. I really love your energy. I think we’re going to have lots of fun today.
Manoj Tandon: Yeah, we are. Give us a little bit about your background. We were talking a little bit off-camera, but tell us about your history. How did you get into this business?
Yagub Rahimov: The cat is kind of out of the bag. Once, on one of the podcasts, I mentioned that my close friends call me “Mr. Paranoid.” At first, I thought maybe it was an insult, but the more I think about it, it’s actually a good thing because I can be paranoid for my network so other people don’t have to be. That’s kind of been my guiding principle. I was born on a reservation, and in the early 2000s I was sponsored by the U.S. State Department as an exchange student in California. That was the first time I was introduced to technology. I fell in love with both technology and finance, went back home, started trading, and made very good money doing it. In fact, I earned the “Best Trader of the Year” award a couple of times.
Manoj Tandon: Wow.
Yagub Rahimov: I also dropped out of college because that’s what you do when you’re a young, successful kid. You think you know everything.
Manoj Tandon: I mean, you’re in pretty good company—Mark Zuckerberg, Bill Gates…
Yagub Rahimov: I still have a lot to accomplish before I get there. Eventually I was pushed to go back to college. I received a scholarship from the Presidential Administration of Azerbaijan, and the choice was simple: either go to the army or go to college. I said, “I’ll go to college.” I went to the Netherlands, dropped out again, and started my first official company focused on fighting trading-related scams. We built one of the first social trading platforms. We sold it the same year, and after that I joined a brokerage where I helped grow the company into what was then the world’s second-largest brokerage, processing over a trillion dollars in monthly turnover.
Manoj Tandon: Wow.
Yagub Rahimov: About eighteen months later, I left to build my second company, Seven Markets, which eventually became the Seven Markets Group of Companies. That’s where we started doing a lot more work with machine learning. We built one of the first algorithms to detect fake news back in 2017. We developed algorithms that identified sentiment in cryptocurrency and commodities markets. We became an OpenAI partner and also worked with Google DeepMind. Then, in 2020, I came to the United States to speak at South by Southwest in Austin. As everyone remembers, the event was canceled just a few days after I arrived because the world shut down during COVID. I initially got stranded here, and while I was here my company was acquired. That’s how I ended up staying in the United States.
Manoj Tandon: Sounds like a tough life. I’ve got to ask—with your knowledge and your success in finance—you could easily be running a hedge fund and making billions, especially given today’s market volatility. Why make the move into technology?
Yagub Rahimov: Let me get a little closer. You see all of this behind me? I’m not forty years old yet. The real answer is that I enjoy making money, but I enjoy making money by creating value. I don’t want to make money simply for the sake of making money.
Manoj Tandon: That’s a very noble answer, and unfortunately not enough people think that way. I hope our audience takes inspiration from someone as successful as you. In business, money is often just a byproduct of creating value. If you focus on delivering value in your profession, financial success usually follows in one form or another.
Yagub Rahimov: Absolutely.
Manoj Tandon: Let’s switch gears and talk about SLMs and AI application firewalls. First, for our audience, what exactly is an application firewall, and more specifically, what is an AI application firewall?
Yagub Rahimov: Internally, we actually don’t call it an AI application firewall. We call it AIBC, which stands for AI Behavioral Control Plane.
Manoj Tandon: That almost sounds like an oxymoron—AI behavioral control—because AI is probabilistic, not deterministic.
Yagub Rahimov: It’s both yes and no. Notice we don’t say “behavior”; we say “behavioral.” When it comes to security, I think you’ll agree with me—and if you don’t, we have a serious problem—that around 96% of cybersecurity failures aren’t caused by technology itself.
Manoj Tandon: Please continue. You’re preaching to the choir.
Yagub Rahimov: They’re caused by user mistakes. Let’s eliminate the word “human” and just call them “user” mistakes.
Manoj Tandon: And you’re sure it’s only 96%? Not 98 or 99?
Yagub Rahimov: I’m quoting IBM’s numbers from last year.
Manoj Tandon: Fair enough.
Yagub Rahimov: I’ll add another statistic. Around 24% of failures happen because of user negligence or lack of awareness. That’s why companies spend millions training employees. That’s where our focus begins. We don’t just provide security controls that prevent privileged information from being sent into ChatGPT, Claude, meeting note-takers, or other AI tools. We also educate the user in real time. Take Google Translate as an example. Imagine you’re communicating with a Japanese client and you paste confidential client information into Google Translate. Many people don’t realize Google Translate is itself an AI service. That means your data is leaving your environment. The question becomes: how do you teach your employees not to do that? Have you ever used Grammarly?
Manoj Tandon: Sure.
Yagub Rahimov: Grammarly underlines mistakes and provides suggestions as you type.
Manoj Tandon: Right. It gives you options and recommendations.
Yagub Rahimov: Exactly. Our approach is similar, but with one important difference. Grammarly processes your data somewhere else, on someone else’s infrastructure. We deploy our operational tools directly into your environment. If that’s your laptop, then it’s your laptop. As you’re typing into Google Translate, ChatGPT, Claude, or any other application, our system analyzes what you’re entering in real time. Before you even press Enter, it highlights where you’re violating compliance policies or exposing sensitive information.
Manoj Tandon: But aren’t most companies using enterprise accounts with ChatGPT, Claude, or OpenAI? Don’t those license agreements specifically prevent providers from training on company data or sharing it?
Yagub Rahimov: Let me take that one step further. What if you’re using a local, open-source LLM that’s completely deployed inside your own infrastructure?
Manoj Tandon: That’s certainly possible.
Yagub Rahimov: Does that mean you no longer need AI security?
Manoj Tandon: No. In fact, I’d argue you need it even more. AI is like an incredibly intelligent person with very little real-world experience. It can still be manipulated or tricked.
Yagub Rahimov: Exactly. Through prompt injection, jailbreaks, and other techniques. Security isn’t only about deciding what data leaves your organization. That’s only one piece of the puzzle. We take a holistic approach. For example, if your organization operates only in English, why should another language be allowed to become a prompt injection vector? I actually demonstrated this once against a multimillion-dollar AI platform. I speak several languages—English, Spanish, Turkish, among others. During a live demonstration, I entered the beginning of a restricted prompt in English, continued it in Spanish, and finished it in Turkish. The system returned information it claimed was impossible to retrieve. That showed us the importance of language-based controls.
Yagub Rahimov: We look at language controls, prompt injection, toxicity, topic controls, and user permissions. Think about it this way: your legal department has access to certain documents, HR has access to others, marketing has its own information, and sales has its own resources. You wouldn’t give unrestricted access to HR documents to your sales team. Access controls still matter in an AI environment. Let’s say Manoj is the HR manager and I’m an employee. Manoj should be able to view everyone’s Social Security numbers and personnel records because that’s part of his role. I shouldn’t be able to see those records, but I should be able to access information that’s relevant to me. Our behavioral control engine applies those access controls based on the individual user, company policies, and permissions, then presents that information directly to the user.
Why is that important? Because showing people these controls actually teaches them over time. It’s similar to Grammarly. Someone who isn’t a native English speaker may start using Grammarly because they need help, but after six or eight months, their grammar naturally improves because they’re constantly being educated. We apply that same concept to compliance. When organizations deploy the Polygraf AIBC desktop overlay, we don’t just improve AI security. We also improve their traditional DLP, or Data Loss Prevention, performance.
Manoj Tandon: Data Loss Prevention. There are a lot of DLP solutions that specialize in that area.
Yagub Rahimov: Exactly. One of our most recent deployments was with a public transportation organization. Within three or four months, their DLP violations dropped by 72%. Think about that—72% fewer violations. The interesting part is that we didn’t even have to integrate with their DLP solution. Based solely on company policies, users received real-time guidance while typing in any application—AI or otherwise. The system might tell someone, “Don’t put your employee ID number into that Google Drive file,” or “Don’t share this particular information.”
Manoj Tandon: So does the software simply suggest those changes, or does it actually block users from performing those actions?
Yagub Rahimov: It can do both. When organizations first deploy it, we generally don’t block anything. We simply provide visual guidance. Red means “absolutely don’t do this.” Yellow means “this is confidential, proceed carefully.” No highlight means everything is acceptable. That visual guidance alone significantly reduces DLP violations.
Manoj Tandon: Let’s use a practical example. Imagine I’m a surgeon writing a post-operative report. Many doctors are beginning to use ChatGPT to help draft documentation more quickly. Inevitably, they’re going to need to include patient information that would normally violate compliance policies. Or take an attorney dealing with confidential legal documents. Let’s stay with healthcare because HIPAA carries significant financial penalties.
Yagub Rahimov: That’s actually a great example. Every prompt, document, and piece of information is tokenized and anonymized according to HIPAA requirements before it ever reaches the LLM. The anonymized version is what gets sent to ChatGPT or whichever model the organization is using. When the response comes back, our small language models reconstruct the original information locally and present it to the user as though nothing ever changed. All of that anonymization and reconstruction happens entirely within your own infrastructure and on your own device. From the surgeon’s perspective, everything works normally. That’s really our philosophy. Most security products either prevent the surgeon from entering the patient’s information altogether—which dramatically limits the usefulness of AI—or they simply allow everything through and leave compliance entirely up to the user. We believe both approaches are wrong. A surgeon should focus on treating patients, not memorizing every HIPAA regulation.
For example, if the surgeon enters a patient’s full date of birth, perhaps only the birth year is sent to the AI because that’s sufficient for clinical context. If they include an address, perhaps only the state is transmitted. If they enter a Social Security number, maybe only the last four digits remain while the rest is tokenized. The AI receives enough information to perform its task effectively without ever receiving the protected data itself. When the results come back, the surgeon still sees the complete date of birth, full address, Social Security number, and everything else because the reconstruction happens locally. If they hover over the information, they can even see exactly which pieces were anonymized before being transmitted. That means the AI’s usefulness isn’t degraded. I don’t want this to sound like a sales pitch because that’s honestly not my intention. Our belief is simply that AI exists to improve productivity. If security solutions constantly interrupt productivity, then we’ve defeated the entire purpose of using AI in the first place. Instead of restricting people, let’s empower them to use AI safely while maintaining compliance.
Manoj Tandon: A CISO might respond by saying, “That’s great, Polygraf, but who’s watching you? How do I know your company isn’t seeing all of this patient data? You know the patient’s birthday, address, and all of this sensitive information.”
Yagub Rahimov: We don’t. We don’t have access to your infrastructure. Everything is deployed inside your own environment. We have zero access to customer data. Period.
Manoj Tandon: So you’re not operating as a cloud service?
Yagub Rahimov: No. Everything runs entirely inside the client’s infrastructure.
Manoj Tandon: I’m curious about the training process for these SLMs. Is training one of these models similar to training a large language model with enormous computing requirements, massive power consumption, and long training cycles? Help educate us because this is still a relatively unfamiliar space for many people.
Yagub Rahimov: I won’t reveal everything about our methodology, but I’ll give you an example. Recently, we introduced Polygraf for the Japanese language. I traveled to Japan just before Christmas and met with eight different companies. Several of them told us that if we supported Japanese, they would purchase our solution. I told them to give us two months. Because of the holidays, two months turned out to be a little optimistic, but by March we had released our Japanese language model. Even though it was still considered experimental, our privileged data discovery engine outperformed the second-best solution on the market by 46%. In other words, we were 46% more accurate at identifying sensitive information.
Why does that matter? Because training that model only required two NVIDIA H100 GPUs and approximately three weeks of training. For us, retraining a model generally takes three to five weeks, depending on the requirements. In government and defense environments, that’s considered incredibly fast. We’ve recently been involved in projects where the planning phase alone lasts twelve months, so delivering a retrained model in just a few weeks is a significant advantage. Another major difference is that our small language models don’t require GPUs during deployment. They run entirely on CPUs and RAM. That’s important because the average hospital, bank, or government agency doesn’t have racks full of H100s or A100 GPUs. Many organizations are still running surprisingly old hardware. Our models were intentionally designed for resource-constrained environments with very low computational requirements. Today, our privacy engine typically consumes only about 40 to 80 megabytes of RAM per device. To put that into perspective, simply unlocking your iPhone uses over 250 megabytes of RAM. They’re extremely lightweight, extremely fast, and consume very little power. I believe that’s ultimately the direction the industry is heading. Our long-term vision is to bring AI security to every handheld device and every IoT device. One thing I strongly disagree with is when people say, “That’s just the enterprise policy.” I don’t care about the enterprise policy if another company can still access my data. If that company gets breached, then everyone who trusted them is affected. Why should I leave those decisions in someone else’s hands? We believe enterprises, government agencies, and businesses should decide exactly what information they’re willing to share, who they’re willing to share it with, and how it’s controlled. By using SLMs, we put those decisions back into the organization’s hands. You can decide that Chrome-based applications can’t access certain identifiers, or that no internet-connected application is allowed to receive uploaded documents. Those are your policies—not ours. You can assign different permission levels for executives, managers, employees, and interns. That’s where my conviction lies. Organizations should control their own data, not the applications they’re using.
Manoj Tandon: That’s a great concept from a privacy standpoint, but when you look at where AI is heading, especially with the rise of Agentic AI, how does what you’re building fit into that future? Where do you see AI security trends going?
Yagub Rahimov: Let’s step back to that statistic I mentioned earlier—that roughly 96% of security failures are caused by users rather than technology. No matter how cybersecurity evolves, the structure remains the same. At the foundation is your data. On top of that sits the technology. Above the technology are the processes and workflows, and finally, at the top, are the users. Today those users aren’t just people anymore. Some are humans, while others are AI agents. We don’t believe they should be treated differently. In fact, treating them differently creates unnecessary risk because we’re already seeing human and machine operations blending together. We provide a gateway environment for both types of users and apply policies to each of them. We literally treat AI agents as another user identity. Just as I have different identities depending on whether I’m acting as a contractor, the CEO of Polygraf, or serving on an advisory board, each identity has different permissions and policies associated with it. We apply that exact same principle to AI agents. They receive permissions based on the role they’re performing. In many ways, defining policies for AI agents is actually easier than defining policies for people because agents operate within predefined workflows and processes.
Manoj Tandon: At least today they do. As Agentic AI evolves, it may eventually decide, “I can’t complete this task within my assigned boundaries, so I’ll step outside those boundaries.”
Yagub Rahimov: But if it doesn’t have access, it can’t step outside those boundaries. That’s why there’s still a security layer separating the AI from the protected data.
Manoj Tandon: Being in cybersecurity, I don’t really believe in perfect data isolation. If someone truly wants access to something, they’ll eventually find a way. The real question is whether it’s worth the time and effort. Human beings build these systems, and because we’re imperfect, every system we build is also imperfect.
Yagub Rahimov: I agree that no human-built system is perfect, but there’s an important distinction here. Everything the AI sees has already been tokenized and anonymized. Even if an LLM were somehow compromised or behaved unexpectedly, it still couldn’t access the original information because the SLM operates independently. The LLM can’t instruct the SLM to reveal sensitive information because they’re completely separate systems. We’ve never seen an attack successfully bypass that architecture. We had one customer whose internal employees had previously tried accessing HR information such as bonus data and layoff information. After deploying our solution, those attempts stopped being successful. We also had another interesting situation where a customer complained that our software wasn’t working because it kept blocking HR from sending a document. We joined a support call where they shared their screen—because we never directly access customer environments—and discovered that hidden behind the company logo inside the PDF was the organization’s financial API key. The HR employee had no idea it was embedded there. To them, the document looked completely normal. Our system detected something they couldn’t even see. That’s one of the reasons we believe traditional regular-expression approaches have become outdated. We had to rethink named entity recognition by introducing contextual understanding. Instead of simply matching patterns, our system analyzes the context and reconstructs what’s actually happening. I don’t want this to sound like a product pitch because that’s honestly not my intention. We genuinely believe the industry needs to redefine what AI security means. Too many organizations think it’s simply another cybersecurity checkbox or believe bigger models automatically mean better security. We don’t think that’s true. AI security has to be approached holistically.
Manoj Tandon: What’s your biggest AI nightmare?
Yagub Rahimov: Fortunately, our own platform doesn’t have access to customer data, so that eliminates many concerns. But one area we watch very closely is the rapid adoption of AI-powered Security Operations Centers. More and more organizations are replacing Level 1 analysts with AI.
Manoj Tandon: We’re definitely seeing that trend throughout the managed security services industry. Companies advertise AI-powered SOC services at extremely low monthly prices, but if you read the fine print, you’re getting AI analysts instead of human analysts. One concern I have is that SOC operations already generate enormous numbers of false positives. That’s simply the nature of cybersecurity. Security professionals are naturally cautious because they’d rather investigate something harmless than overlook a genuine threat. The problem comes when an AI system incorrectly determines that a customer has suffered a breach and that information somehow leaks publicly. Even if a breach really occurred, you don’t necessarily want an autonomous system making those decisions or communicating that information without human oversight.
Yagub Rahimov: Let me ask you something. Do you know the average accuracy of today’s named entity recognition systems when they’re identifying email addresses?
Manoj Tandon: No, I don’t.
Yagub Rahimov: It’s less than 65 percent. Most people assume identifying an email address is easy because there’s a username, an “@” symbol, and a domain name. But today there are social media handles, mentions, usernames, and many other patterns that look almost identical. False positives and false negatives become incredibly important. Earlier I mentioned our reduction in DLP violations. We never intended to become a DLP product—that improvement is simply a byproduct of what we do. When you examine DLP alerts, many of them turn out to be false positives. The challenge is separating meaningful signals from background noise. That’s exactly the same challenge SOC teams face every day.
Manoj Tandon: Absolutely.
Yagub Rahimov: In fact, if you send me your address, I’ll send you one of our Polygraf AI SOCs.
Manoj Tandon: A SOC?
Yagub Rahimov: A real SOC. We created it because everyone kept talking about SOCs, and I realized very few people think about how they constantly evolve. We printed our branding on an actual sock because you don’t wear the same socks forever. Eventually they wear out, develop holes, and need to be replaced. Security Operations Centers are exactly the same. If your SOC stays the same while attackers change every single day, you’re doing something wrong. The threat landscape evolves daily, so your defenses have to evolve daily as well. That’s the message we’re trying to reinforce.
Manoj Tandon: Amen to that. There’s simply no such thing as a static SOC anymore. That’s impossible.
Yagub Rahimov: Do you know that you can get hacked on your AI operation with nothing but emojis?
Manoj Tandon: Tell us a little bit about that.
Yagub Rahimov: If you search my name along with “emoji hack attack,” you’ll find a write-up I recently published about it. Pakistani hackers discovered a methodology where they could send nothing but emojis to certain chatbots and trigger prompt-based actions. One example involved sending two key emojis followed by a skull and a grave emoji. To a person, those emojis don’t necessarily mean much, but to the AI they effectively translated to “kill the key,” and the agent actually executed the instruction. That’s one of the things we still don’t fully comprehend about generative AI. I’m trying to choose my words carefully, but I don’t think we truly understand what these systems are capable of. You can communicate with Morse code made up of dots, and the model understands it because it has been trained on it. You can communicate with emojis, and it will infer meaning from them. You have to rethink what data actually is in an AI environment. Data isn’t limited to words anymore. Think about seeing a pair of sneakers hanging from power lines. Most people simply see shoes, but in certain places they communicate something entirely different. AI is similar. These systems can recognize hidden meaning inside symbols, images, and patterns. That’s why our security approaches and SOC operations have to evolve just as quickly. Every day we discover a new attack technique. Every day another vulnerability or breach is announced. If organizations simply wait six months for the next software patch, they’re already behind. I honestly don’t think we’ve even begun to understand how large language models can be used for malicious purposes. There are countless ways to jailbreak them, manipulate them into performing actions, or convince them to reveal information they weren’t supposed to reveal.
Manoj Tandon: And if you’re good at it, you can engineer a very sophisticated cyberattack. Think about everything these models can already do. You could have an AI scan every employee on LinkedIn, analyze public Facebook profiles, determine what people like and dislike, craft highly personalized phishing emails, embed psychological triggers into those messages, and dramatically increase the chances that someone clicks on something they shouldn’t.
Yagub Rahimov: We’ve actually done something similar as a case study. We looked at nothing more than a person’s public Amazon reviews. From those reviews alone, we were able to build a surprisingly accurate profile of their family, estimate their income, identify where they likely lived, determine many of their interests, and infer numerous personal characteristics. Imagine what someone with malicious intent could do using that kind of information. We did that exercise with only one person on our team, simply as an experiment.
Manoj Tandon: There are some things I’d love to tell you off the air that are incredibly interesting. But you’re absolutely right—we’re leaking data everywhere. Most people are sharing far more information about themselves than they realize. I’m sure I’m guilty of it too. That’s the tradeoff we’ve always faced. Whenever convenience and security collide, convenience usually wins because that’s simply human nature.
Manoj Tandon: We’re coming up on the end of our time together, so I want to give you an opportunity to tell our audience about anything you’d like to share and let everyone know how they can connect with you.
Yagub Rahimov: I think we’ve already shared a tremendous amount of information today. More than anything else, I’d love the opportunity to work with organizations that found today’s conversation relevant. My team, our researchers, and our PhDs are all focused on helping companies improve AI security. You can connect with me on LinkedIn by searching for Yagub Rahimov, or you can visit our website and schedule time with me directly through the Contact Us page. I’d love the opportunity to help bring stronger AI security to more enterprises and government organizations across the country.
Manoj Tandon: One final question before we wrap up. Is Polygraf focused exclusively on large enterprise organizations, or do small and medium-sized businesses also have opportunities to work with you?
Yagub Rahimov: That’s a great question. Right now we’re actively piloting with several small and medium-sized businesses while continuing to simplify our pricing model. A year ago my answer probably would have been no, but as we’ve grown we’ve been able to open more opportunities for SMBs as well. We also work with researchers. If you’re a student studying AI security, data security, or related fields, we have programs available for you. If you’re a startup building an AI solution for industries like insurance, banking, healthcare, or anything else that requires data protection, we’d love to hear from you. We have dedicated startup programs, and in some cases we even invest in organizations ourselves. There are a lot of initiatives happening behind the scenes. Polygraf is growing very quickly, and we’re incredibly grateful that our growth has been driven by successful customers and strong partnerships. We’d love the opportunity to build even more partnerships going forward.
Manoj Tandon: Sounds fantastic, Yagub. I’m really glad you joined us today. It’s been a pleasure having you on the show, and you’re welcome back anytime.
Yagub Rahimov: Thank you so much. I really appreciate it.
Manoj Tandon: Take care. This was a great conversation.
Read more about Yagub on his LinkedIn.
Learn more about Polygraf AI on their website
Check out the vCISO bot we created
Check out the other episodes in Season 19:
Ep. 0 Diyar Saadi – How Hackers Exploit Hidden Vulnerabilities
Ep. 1 Krisztian Kiraly – Who Really Controls Your Algorithm Data?
Ep. 2 Jason Roos – What the U.S.–Saudi Relationship Means for Cybersecurity
Ep. 3 Jasson Casey – Identity Attacks Are the #1 Threat
Ep. 4 Andy Smith – What Good Is Cybersecurity Tech… If It Still Fails?
Ep. 5 Murphy John – The Future of Decentralized Data
Ep. 6 David Linthicum – Artificial Intelligence Mistakes Every Company is Making Right Now
Ep. 7 Bronwen Aker – Treat Artificial Intelligence like a Drunk Intern
Ep. 8 Yagub Rahimov – You Can Get Hacked With Emojis
Ep. 9 David B. Cross – The Future of Cyber Threats
Ep. 10 Mark Kreitzman – The Hidden Cost of Mobile Identity Theft
About Yagub Rahimov

Yagub Rahimov is a technology entrepreneur and the CEO & Co-Founder of Polygraf, an AI security company focused on helping organizations safely adopt AI without compromising data privacy or integrity.
Through Polygraf’s AI application firewall, governance tools, and AI content detection technology, Yagub helps enterprises and government agencies control what data enters and leaves AI systems.
Before founding Polygraf, he successfully built and exited multiple companies, including 7MARKETZ Group, which became one of the leading media groups in the blockchain and financial technology space.
With a background spanning AI, cybersecurity, business development, and emerging technologies, Yagub is passionate about making AI secure, trustworthy, and enterprise-ready.
About Us:
Dark Rhiino Security’s Security Confidential is a weekly Cybersecurity podcast where Host Manoj Tandon talks to Infosec and Cybersecurity professionals about the current issues going on in our industry. Guests are able to share their stories about how they began their journey into cybersecurity and connect with our audience. Listeners are able to tune in through Spotify, Apple Podcasts, Google Podcasts, Amazon Music, iHeartRadio, YouTube, LinkedIn, and more.
For inquiries, please email media@darkrhiinosecurity.com
