Back to Blog
AI People

AI People Interview: Lucas Guzmán on Why the Safest Data Is the Data That Never Leaves Your Device

Ravi Prajapati

Author

Ravi Prajapati

August 17, 2026
/api/uploads/1786992764090-lucas-guzman-neural-defense-privacy-first-ai-cybersecurity.webp

AI People Interview on ReadInBrief: Lucas Guzmán, founder of Neural Defense, on building privacy-first AI cybersecurity for SMEs with zero cloud data.

Lucas Guzmán, Founder of Neural Defense, explains why he built a cybersecurity platform for small and medium businesses that runs entirely on-device, with zero data ever sent to the cloud, and why he thinks privacy-first security is about to stop being optional.

Lucas Guzmán is the Founder of Neural Defense, a privacy-first cybersecurity platform built for small and medium-sized businesses (SMEs). Rather than sending emails, documents, or logs to a cloud server to be analyzed, Neural Defense runs AI-driven heuristic analysis directly on the user's own device, detecting threats like phishing and Business Email Compromise (BEC) without the data ever leaving the business's hands. The platform is currently in an active MVP testing phase, with the local detection engine being refined based on real-world user feedback.

In this AI People interview, Lucas talks about the gap he saw between enterprise-grade security and what SMEs can actually afford or trust, why he thinks "I'm too small to be a target" is the most dangerous belief a small business owner can hold, and where he sees AI-driven cybersecurity heading next.

Background & Personal Journey

Ravi Prajapati: What's your background, and what led you to focus specifically on cybersecurity for small and medium businesses?

Lucas Guzmán: My background is rooted in the intersection of AI development and practical security architecture. I noticed a massive gap in the market: enterprise-grade security tools are too complex and expensive for SMEs, while free tools often compromise user privacy by sending sensitive data to the cloud. I focused on SMEs because they are the backbone of the economy but are currently the most underserved and vulnerable demographic in the cyber landscape.

Ravi Prajapati: What was the moment or problem that made you decide to build Neural Defense?

Lucas Guzmán: The turning point was realizing that privacy and security were being treated as separate products. Most AI security tools require you to upload your emails, documents, or logs to their servers to be analyzed. For an SME handling client data, that's a compliance nightmare. I built Neural Defense to prove that you don't have to choose between advanced AI detection and absolute data privacy. The problem wasn't just attacks, it was the lack of trust in existing solutions.

Ravi Prajapati: Why did "privacy-first" become a non-negotiable principle for you, rather than just a feature?

Lucas Guzmán: Because in cybersecurity, trust is the product. If a security tool requires you to send your sensitive data to a third-party cloud to check if it's safe, it creates a new attack surface. Privacy-first isn't a feature for us, it's our architectural foundation. We believe that the safest data is the data that never leaves your device. Making it a "feature" would imply it's optional, but for us, it's the only way to build a truly secure system for SMEs.

Neural Defense & Its Mission

Ravi Prajapati: For readers who've never heard of it, how would you describe Neural Defense's mission in one sentence?

Lucas Guzmán: To democratize enterprise-grade cybersecurity for SMEs through a privacy-first AI platform. Currently in an active MVP testing phase, we're continuously refining our local heuristic engine based on real-world user feedback to ensure it perfectly balances detection accuracy with absolute data sovereignty.

Ravi Prajapati: You use AI-driven heuristic analysis running entirely client-side with zero data transmission. Can you explain what that actually means for a non-technical business owner?

Lucas Guzmán: Imagine having a top-tier security expert sitting right next to you at your desk, analyzing every email and document instantly, without ever needing to send them to an outside office. That's what client-side means. Traditional tools act like a mailroom: they take your letters, send them to a central lab for testing, and send them back. We do the testing right there in your hands. As we're currently in an MVP optimization phase, we're actively gathering feedback from early adopters to fine-tune how these local models interpret context, ensuring that the expert at your desk gets smarter with every iteration without ever needing cloud connectivity.

Ravi Prajapati: Why is "zero data transmission" important for the SMEs you serve, and what are they protecting against by not sending data externally?

Lucas Guzmán: SMEs often handle sensitive PII, financial data, and intellectual property. By not transmitting data, we eliminate the risk of interception during transit and the risk of data breaches at the vendor's end. Furthermore, many SMEs operate under strict regulations like GDPR or HIPAA. Sending data to a cloud AI processor can sometimes violate these compliance standards. Zero transmission ensures they remain compliant by design.

Ravi Prajapati: How does client-side AI detection compare to traditional cloud-based security tools in terms of speed, accuracy, and trust?

Lucas Guzmán: A few things stand out:

  • Speed: We're significantly faster because there's no network latency. Analysis happens in milliseconds on the device.

  • Accuracy: While cloud models have massive datasets, our local heuristic engines are optimized for specific SME threat patterns, like BEC and phishing, which reduces false positives.

  • Trust: This is our biggest advantage. Being in an MVP phase allows us to be radically transparent, users can see exactly how the system evolves based on their input, fostering a level of trust that static, black-box cloud tools simply cannot match. Users don't have to trust us blindly with their data, the processing is contained locally.

Threats Facing SMEs Today

Ravi Prajapati: What are the most common attacks SMEs face right now: phishing, BEC, ransomware, mobile payment fraud, or something else entirely?

Lucas Guzmán: While ransomware makes headlines, Business Email Compromise and sophisticated phishing are the silent killers for SMEs. These attacks don't always need malware, they exploit human psychology. Attackers know SMEs often lack rigorous verification protocols, making them prime targets for invoice fraud and credential theft.

Ravi Prajapati: Why are SMEs often more vulnerable to these attacks than large enterprises, despite having less to lose on paper?

Lucas Guzmán: It's not about having less to lose, for an SME, one successful attack can be existential. They're more vulnerable because they lack the layered defense infrastructure of large corporations, like dedicated SOC teams. They rely heavily on individual employee vigilance, which is inconsistent. Attackers also view SMEs as low-hanging fruit, easier to breach and often used as stepping stones to attack larger partners in their supply chain.

Ravi Prajapati: What's a real-world example, anonymized if needed, of an attack Neural Defense caught that a traditional tool likely would have missed?

Lucas Guzmán: We recently detected a highly targeted BEC attempt where the attacker used a domain that was visually identical to a legitimate vendor, a typosquat, but hosted on a newly registered server. Traditional spam filters missed it because the email content was polite and grammatically perfect. Our local heuristic engine flagged it based on the subtle mismatch between the sender's historical behavior and the new domain reputation metadata, preventing a potential wire transfer fraud.

Ravi Prajapati: What's the most dangerous misconception SME owners have about their own cybersecurity risk?

Lucas Guzmán: The belief that "I'm too small to be a target." In reality, automation has made attacking SMEs cheap and scalable. Hackers don't care about your size, they care about your vulnerabilities. Thinking you're invisible is the most dangerous vulnerability of all.

AI in Cybersecurity: The Current Moment

Ravi Prajapati: How has AI changed the sophistication of phishing and BEC attacks in the last couple of years?

Lucas Guzmán: AI has removed the language barrier and the grammar tell. Previously, you could spot a scam by poor spelling or awkward phrasing. Now, LLMs generate perfect, context-aware emails in any language. Attacks are also more personalized, AI scrapes LinkedIn to craft messages that reference real projects or colleagues, making the social engineering aspect terrifyingly convincing.

Ravi Prajapati: Attackers are also using AI now. How does that change the arms race between attackers and defenders?

Lucas Guzmán: It shifts the battle from volume to precision. Attackers can now launch thousands of unique, high-quality campaigns instantly. For defenders, this means signature-based detection is dead. We must move to behavioral analysis and intent detection. It's no longer about matching a known bad link, it's about understanding the intent of the communication, which is where local AI heuristics shine.

Ravi Prajapati: What's your take on AI-generated deepfake voice or video scams targeting businesses? Is this already a real threat for SMEs, or still mostly enterprise-level?

Lucas Guzmán: It is absolutely a real threat for SMEs right now. While deepfake video gets the press, voice cloning is the immediate danger for smaller businesses. An attacker cloning a CEO's voice to call an accountant and demand an urgent transfer is low-cost and high-impact. SMEs often have less formal verification processes for verbal requests, making them highly susceptible.

Ravi Prajapati: What's one AI security capability that's currently overhyped, and one that's underhyped?

Lucas Guzmán: Overhyped is "autonomous self-healing networks." The idea that AI will automatically fix breaches without human intervention is still science fiction for most SMEs, and it creates a false sense of security. Underhyped is local and edge AI processing. The ability to run powerful models on-device without cloud dependency is the future of privacy-compliant security, yet it gets far less attention than massive cloud LLMs.

Privacy, Trust & Business Model

Ravi Prajapati: How do you convince security-conscious customers to trust an AI system, especially one running heuristics locally, without needing to see "the cloud" processing their data?

Lucas Guzmán: We flip the script: we ask them not to trust us, but to trust mathematics and architecture. With cloud AI, you have to trust the vendor's integrity. With local AI, the cloud is your own hardware. We provide transparency into our heuristic logic. When the processing happens on your laptop, you are the cloud. That's the ultimate form of trust.

Ravi Prajapati: Is there a tradeoff between privacy-first design and detection accuracy, or has AI closed that gap?

Lucas Guzmán: Historically, yes. Cloud models had the advantage of massive global data. However, modern optimization techniques, like quantization and distillation, allow us to run highly accurate models locally. We've found that for specific SME threats, a specialized local model often outperforms a generic cloud model because it's tuned for relevance, not just scale. The gap hasn't just closed, in some niches, local is now superior.

Ravi Prajapati: How do you see regulation, like GDPR-style privacy laws, shaping the future of cybersecurity products?

Lucas Guzmán: Regulation will force a migration away from black-box cloud analytics. As data sovereignty laws tighten globally, companies will be legally pressured to keep data within their borders, or better yet, on their own devices. Privacy-first won't just be a selling point, it will be a compliance requirement. Tools that can't guarantee data residency will become liabilities.

Advice & Forward-Looking

Ravi Prajapati: What's one practical step you'd tell every small business owner to take this month to reduce their risk?

Lucas Guzmán: Implement an out-of-band verification policy for all financial requests. If you get an email or message asking for money or data changes, verify it through a different channel, for example by calling the person on a known number. Technology helps, but this simple human protocol stops 90% of BEC attacks.

Ravi Prajapati: Where do you see AI-driven cybersecurity heading in the next few years, and what should SMEs prepare for?

Lucas Guzmán: We're heading toward hyper-personalized defense. Generic security suites will fail against AI-tailored attacks. SMEs should prepare for tools that understand their specific business context, not just general threats. Also expect a rise in sovereign security, tools that guarantee data never leaves local infrastructure. Prepare by auditing your current tools: if they require uploading your data to work, start looking for alternatives.

About Lucas Guzmán

Lucas Guzmán is the Founder of Neural Defense, a privacy-first cybersecurity platform designed for SMEs. With a background in AI architecture and security engineering, he specializes in developing client-side heuristic systems that protect businesses without compromising data sovereignty. Neural Defense is currently in an active MVP testing phase, continuously refining its local detection engine based on real-world user feedback.

Live MVP Platform: neuralfocus-ia-khaki.vercel.app

Neural Defense Academy: defensefocus.vercel.app

LinkedIn: linkedin.com/in/lucas-guzmán-a694a418

This interview is part of ReadInBrief's AI People series, where we talk to AI founders and experts building at the edge of the industry. Have someone you'd like us to feature? hello@readinbrief.com or drop a message to Ravi Prajapati.

Comments (0)

No comments yet. Be the first to share your thoughts!

Leave a Reply