Hosted by Carlos Espinal
This Much I Know is the podcast from Seedcamp, Europe’s seed fund. Tune into hear the inside story from startup founders, investors and leading tech voices: the people who’ve built businesses, scaled globally, failed fantastically and learnt massively.
309 episodes · publishes monthly · latest 2026-07-01 · ~42 min/episode
Rank
#427
Substance
77.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#427 of 6183
Substance
Top 7%
outscores 93% of the index
This Much I Know ranks #427 on The B2B Podcast Index with a substance score of 77.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and insight density. Both guests are genuine hands-on practitioners building directly in the problem space - David with a prior security exit (Server Density/Cyberdentity sold 2018) and Johannes with direct enterprise sales discovery across hundreds of security and AI officers - making for credible firsthand testimony, though neither has operated a large-scale security organization and both are very early-stage on their current companies.
Averaged across 1 recently scored episode, with cited evidence.
The episode delivers a solid cluster of non-obvious technical insights - indirect prompt injection via hidden web page content, the MCP tool-blast-radius problem, the zombie identity issue, and the 5-10 action-point control gap in agentic flows - but is padded with repeated metaphors (the runaway train appears three times) and some generic developer-vs-security-mindset observations that dilute the density.
“I checked the other day. I think the GitHub MTP has over 100 tools. Bam. That's the exact opposite of least privilege.”
“when the agent decides to read a file, you need to sanitize the commands and then when it reads out the response you've got to look at the output. And you might have to do that five or 10 times in an agent flow. Whereas the firewall is looking at two the input and the output”
A few genuinely fresh angles emerge - that good developer experience accidentally produces agent-readable tooling, that the risk profile of agents has shifted from probabilistic to near-certain, and that pure policy-based control paradoxically destroys the autonomy value of agents - but much of the framing (OAuth wasn't designed for this, regulation lags innovation, security requires a disaster to change) is well-worn.
“an agent doesn't have to turn malicious in order to become a severe security risk...An agent might simply, quote, unquote, decide that it really needs to go to this instance now and delete that entire database in order to complete its job with very best intentions.”
“if you create a uh, product that works really well for developers, good docs like proper, uh, code comments, all those kind of things...you've also created something that an agent can read”
Both guests are genuine hands-on practitioners building directly in the problem space - David with a prior security exit (Server Density/Cyberdentity sold 2018) and Johannes with direct enterprise sales discovery across hundreds of security and AI officers - making for credible firsthand testimony, though neither has operated a large-scale security organization and both are very early-stage on their current companies.
“Started my first Company as you mentioned, Cyberdentity back in 2009 which is one of the original CCAMP companies...built that company and sold it in 2018 to an edge security platform.”
“I spoke in the last month to hundreds of security IT um AI adoption officers, um, in mid sized and enterprise companies”
The episode includes several concrete data points - GitHub's 100+ MCP tools, 50M tokens consumed in 30 minutes at ~$50, GitHub taking nearly two decades to ship fine-grained tokens, the 5,000-employee company anecdote - but relies heavily on illustrative hypotheticals ('Julia from marketing connecting Claude to the CRM') and unnamed companies, and produces no benchmark data, market sizing, or independently verifiable metrics.
“I used like 50 million tokens within half an hour. And so I was like, well, this is fun, but it's costing me $50 to play around with this”
“how many years are we like it was almost two decades now of GitHub and they've only just added that”
The host shows genuine structural creativity - flipping questions across domains and asking each guest to critique the other's space - and the accountability and 'unit of control' questions are sharp, but he regularly embeds the answer in the question, delivers multi-part compound questions that let guests pick the easiest thread, and visibly lets Johannes refuse to answer an entire question without any pushback.
“how do you stop a sequence that looks safe step by step, but becomes dangerous in aggregate? And what is the right unit of control for that? Is it at the login? Is it the API? Is it that the session? Is it the API request? Is it the business action, the outcome, the intent?”
“I have a strict no bullshit policy applied um, to myself. I launched a new product last week. I have too little context about David's company to uh, to give that one a go next time.”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/this-much-i-know-the-seedcamp-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/this-much-i-know-the-seedcamp-podcast/badge.svg" alt="Ranked #63 on The B2B Podcast Index" width="360" height="136" />
</a>Track This Much I Know's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.
The AI Native Dev
Tessl
Humans of Martech
Phil Gamache
The Azure Security Podcast
Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
AI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop
ClearTech Research / Jo Peterson
AI First with Adam and Andy
Forum3
The Scale Up Show
Ryan Staley