Geng Sng is co-founder and CTO of Cogent, which builds autonomous agents that remediate vulnerabilities for enterprise security teams. Today, Cogent's agents process billions of security events per day, maintaining a live context graph of every asset and vulnerability across customer environments. In this conversation, Geng walks through Cogent's hot vs cold context split, the sub-agents that handle side quests, and the two graphs they run in parallel.
–
We also discuss:
- Why defensive security is harder for AI than offensive
- Under the hood of Cogent's three agents
- Inside Cogent's “read only” by-default sandboxes
- Why graph databases don't scale for security data
- Cogent Research and the move into formal verification
- Why interactive agents need a deeper planning phase to one-shot
–
Referenced:
–
Where to find Geng:
–
Where to find Harrison:
–
Where to find LangChain:
–
Send feedback or questions to maxagency@langchain.dev
–
Timestamps:
(00:00) Why mean time to exploit collapsed from years to minutes
(02:08) Inside Cogent's Agent Lake architecture
(05:11) Why Cogent rejected graph databases
(10:48) The trust ladder before agents touch production
(15:13) The three types of agents inside Cogent
(17:07) How Cogent sandboxes its agents
(19:16) Short-circuiting interactive agents with a deeper planning phase
(24:31) What to do when users believe agents too much
(31:21) Why sub-agents let agents go on side quests
(34:59) Two-tiered evals and the metric that catches bad prompts
(40:00) Cogent’s unique approach to context
(48:39) Cogent Research and the move into formal verification
(51:33) The single trait Cogent hires for
(54:00) Open-sourcing models within six months
(57:07) Why defensive security won’t be commoditized anytime soon
(1:00:51) The founding insight behind Cogent