Skip to content
TrackPodcasts
businessOct 1, 202627:25

S13 Bonus: Scaling Real-Time Search Data: Secure APIs for AI Infrastructure with Alaa Abdulridha, Engineering Director at SerpApi

Get every episode summarized

Each time Code Story: Insights from Startup Tech Leaders publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

About this episode

“That is our main goal at SAP API, that everyone should know everything we try to share knowledge.”From the transcript

Alaa Abdulridha is from souther Iraq, but now lives in Austin, TX. Post wars in Iraq, the country had poor infrastructure, which got him interested in building and creating things to better and secure his life. He left the country to study, and ended up in Germany as a security engineer. Outside of tech, he enjoys playing RPG video games. In particular, he likes to play World of Warcraft, and enjoys the open world, and character development from scratch. 

Alaa's current company was built to scrape google search engines, in order to get around a blocker for a prior project. In the past, he used to participate in bug bounty hunting during University, and wrote about his exploits. His now founder's came across his articles, and invited him to joint the company. 

This is Alaa's creation story at SerpApi. 

Links

https://serpapi.com/

https://www.linkedin.com/in/alaa0x2/



Current Sponsors:

Checkout our Stacklist! https://stacks.codestory.co/

Hosted by Noah Labhart | Technical Founder & Startup Mentor.



Our Sponsors:
* Check out Granola and use my code granola.ai/CODESTORY for a great deal: https://granola.ai
* Check out Perplexity and use my code pplx.ai/codestory for a great deal: https://www.perplexity.ai


Advertising Inquiries: https://redcircle.com/brands

Privacy & Opt-Out: https://redcircle.com/privacy

Hosts & guests

Transcript ready

359 searchable segments. Every word is indexed and playable.

S13 Bonus: Scaling Real-Time Search Data: Secure APIs for AI Infrastructure with Alaa Abdulridha, Engineering Director at SerpApi

Code Story: Insights from Startup Tech Leaders

0:00
27:25

Full transcript

Code Story: Insights from Startup Tech Leaders — S13 Bonus: Scaling Real-Time Search Data: Secure APIs for AI Infrastructure with Alaa Abdulridha, Engineering Director at SerpApi. Machine-transcribed; use the interactive transcript above to jump the player to any line.

That is our main goal at SAP API, that everyone should know everything we try to share knowledge. The main challenge that we faced at SAP API at the beginning is how do we create search engines and provide the data through an API as organic results at the same time to keep these APIs safe because at that time there was no such services as SAP API. It was kind of a new technology even it was a mystery how to secure these type of APIs and what type of vulnerabilities that could introduce. My name is Alah Abdul-Rada, I'm engineer, director and cyber security researcher at SAP API. This is CodeStory, a podcast bringing you interviews with tech visionaries. I think six months moonlighting is nothing of the backhand. Who share what it takes to change an industry? I don't exactly know what to do next.

It took many goes to get right. Who built the teams that have their back? The company is its pitiful. The teams help each other achieve those proud of our team. Keeping scalability top of mind. All that infrastructure was at the end. Yes, we've been fighting it as we grow. Total waste of time. The stories you don't read in the headlines. It's not an easy thing to achieve, my friend. I'll figure out some shell if I can test it out. I'll try to begin. To ride the ups and downs of the startup line. I need to really want it. It's not just about technology. All this and more on CodeStory. I'm your host Noah Laphart. And today, how Alah Abdul-Rilla is fueling your ability to scrape search engines through one fast, easy and complete API. This episode is brought to you by TigerData. Stop bolting separate databases onto your stack. TigerData is 100% unforked Postgres. Same ORMs, same drivers, no pipeline maintenance. As CloudFlares team put it, you keep analytical and

config data under one roof with specialized O-Lat performance. Try it today at TigerData.com. This episode is brought to you by Protected Harbor. Your infrastructure scales, but does it actually understand your apps? With Protected Harbor's application-aware infrastructure or AAI, your tech automatically aligns with app performance while built-in zero-trust security verifies every user and workload. Give your team total control without the complexity. Go to ProtectedHarbor.com slash CodeStory to learn how. This episode is brought to you by Render. Stop jumping between four vendor consoles just to host your stack. Render runs your web services databases, background workers, and AI workflows all in one single cloud platform. Connect your repo, push your code, and your live. No serverless timeouts or crazy setups. Ship faster today with Render.com. ALA Abdu Rida is from Southern Iraq, but now lives in Austin, Texas.

Post Wars in Iraq, the country had poor infrastructure, which got him interested in building and creating things to better and secure his life. He left the country to study and ended up in Germany as a security engineer. But outside of tech he enjoys playing RPG video games. In particular, he likes to play World of Warcraft and enjoys the open world and character development from scratch. ALA's current company was built to scrape Google search engines in order to get around a blocker for a prior project. In the past, he used to participate in bug bounty hunting during his time at university, and wrote about his exploits. His now founders came across his articles and invited him to join the company. This is a LAAS creation story at SERP API. SERP API is a SAS company. We provide an API. This API empowers developers and other companies to gain access to the search data,

like search engines data, but in a consistent, structured, and at scale. So they can use these data to train their AI models to, for example, news agencies. They use us for news monitor. SEO, government use us for background check. If you have, let's say, an AI chatbot you want to give your chatbot real-time access to the internet so it can do real-time searches for you, not limited to search engines, but for example, Amazon, eBay, Walmart, Home Depot, and so on. That's what we do at SERP API. We basically provide data for companies, for developers. It's a very interesting story how our founders started SERP API. He used to build other type of applications, an application that is used to take a picture of food, and it can identify the type of food, and such things. But our founder found an issue, faced an issue at Blocker.

The blocker was, how can he collect this information and images from Google without limitation? As if you keep searching in Google, manually you will get capture that checking if you are a robot or not. So he decided to create an API, he's craved Google images, and he created an API. Google images to connect it with his application. So he can't surpass that blocker. It's a very interesting story because at that time, not other companies or any other business out there provided the same service, which is SERP API. And by the way, SERP API is a shortcut for search engine, results page, about how I join SERP API. I remember that I used to do a podbointy hunting. And podbointy hunting to explain it to the listeners is basically if you are a shorter SERP share and you want to do a freelance work, you can find vulnerabilities on specific websites

that are available on a platform called Akkarwan, for example. You report the vulnerabilities to the companies or directly to their security team and they will reward you with a monetary reward. And I used to write articles. I was just a second year university student and I used to write articles and write apps about my findings, how do I find vulnerabilities, how much money do I get from these vulnerabilities. One of the targets that I worked on as a podbointy hunter was Facebook. I managed to hack Facebook and literally hack Facebook. I was able to gain access to their legal department and moon panel multiple times and I was able to gain access to their internal network. I wrote an article about that of two parts how I hack Facebook part one, how I hack Facebook part two. The founder of SERP API was one of the readers for that articles and he reached out to me and he mentioned that they have positions available at SERP API and there you're

looking for talented people to work at SERP API. And since then I give it a try and I started working at SERP API back in 2021. I used to be a remote employee, used to work remotely from Ukraine. And now I am in office on site working from the office from Austin, Texas and I started as a junior engineer. Now I am engineering director and responsible for the cyber security certificate and just recently actually we got SERP API certified SOC 2, type 2 SOC 3 and ISO 27001, ISO 27701 and we are working on GDPR at the moment. I am curious about when you were invited to join the company, what was your quote unquote MVP, right? I asked a lot about MVPs on this show but what was the first project you were pulled into that you had to jump in on create something from nothing, tell me about

that process and how you went about it and what sort of tools you were using to bring it to life. So they wanted someone who can combine between software engineering and cyber security at SERP API. That is our main goal at SERP API, so everyone should know everything we try to share knowledge. The main challenges that we faced at SERP API at the beginning is how do we create SERG engines and provide the data through an API as organic results at the same time to keep these APIs safe because at that time there was no such services as as SERP API. It was kind of a new technology even it was a mystery how to secure these type of APIs and what type of vulnerabilities that could introduce by these APIs. And yeah, it was fun, it was challenging a bit because we managed to find a new vulnerabilities that can't hit such

type of APIs like SSR, SSR, server-centric, web-forgery and it's the same vulnerabilities that I used to hunt for before. It just comes in a different way I could say. So in how you were approaching that, give me a decision or tradeoff you had to make in how you approached it, how you went about solving that problem and being the quote unquote guide that go take it on and how you cope with those decisions. It wasn't easy at the beginning because I had to coordinate with multiple software engineers, multiple engineers at the team and not all security engineers, not all software engineers are familiar with security vulnerabilities, especially when it comes to technical vulnerabilities like that and it was something rare and it was difficult to explain the proof of concept that I came with for the vulnerability so we can

address them properly because in the eyes of the software engineers these issues were not vulnerabilities unless I managed to introduce and a proof of concept that has a significant security impact. There and I successfully managed to do that. I believe nowadays we have competitors, most of these competitors, they follow the same security practices in their APIs to secure them and it became like a standout after a while these procedures that I used to take many years back now they became standard when we developed or we introduced a new API just before the API goes into production. All these steps or methodologies have to be taken as measures before we release the API. This episode is brought to you by FitNexa. All right, quick question. How many times have you tried to fall asleep only to be held hostage by a snoring partner obnoxious traffic

or your upstairs neighbor practicing tap dance? Yep, in there. Listen up because I just found your new secret weapon, Somnipod's 3 by FitNexa. These bad boys are ultra slim coming in at under 10mm thick and just 3.3 grams light. That means if you're a side sleeper you won't even feel them in your ears. Plus they pack powerful hybrid active noise cancelling that shuts down up to 42 decibels of total noise. Goodbye snoring. Hello, sweet dreamland. And it gets better. They feature built-in white noise high-res audio for daytime tunes and overnight AI sleep tracking so you can actually see how well you slept. You even get 10 custom tip sizes in the box to guarantee that perfect custom fit for your ears. Upgrade your sleep tonight. Head over to go.fitnexa.com slash code story or use the link in the show notes right now because FitNexa is giving code story listeners $10 off of the Somnipod's 3. Experience what uninterrupted rest actually feels like.

Trust me, your brain will thank you tomorrow. This episode is brought to you by perplexity. If you run an e-commerce business I bet your morning starts with opening Shopify meta, Google ads, play the ode and a few half baked spreadsheets you promise yourself you'd fix. Before you've made a single decision half your day is gone just pull and day it together. That's why I'm stoked to tell you about perplexity computer. It connects all your tools into one single command center. Before you even wake up it pulls your revenue margins and inventory highlights what changed and sends a daily summary straight to your slack. It doesn't just tell you what's happening. It actually gets to work. Need to rewrite a clavio flow, launch a new ad campaign or draft creator outreach just ask and here's the genius part. It automatically orchestrates all the leading AI models behind the scenes picking the exact right model for every step. Stop drowning in dashboards just tell perplexity computer what you need done and get out of the way. Start your free trial of perplexity computer today. For a limited time only our listeners can

try perplexity computer for free head to pplx.ai slash code story. That's pplx.ai slash code story to try a computer today. Most AI tools are still answering questions while perplexity computer is completing full projects. This episode is brought to you by Tiger Data. If you're like me your architecture diagram started simple. Until someone added a specialized time series DB, a couple of pipelines, and suddenly you're babysitting four databases at 2am. Stop doing that to yourself. Inner Tiger Data. It's 100% unfort pure postgres, same drivers, same ORMs, same standard SQL, zero new query languages to learn. And not just in theory. Plexigrid consolidated four databases down to just one instance and got 350 times faster queries. Glucot in just three billion points a month and Orca processes over $500 million in daily trading volume. Maybe you've heard of Cloudflare? Yeah, that Cloudflare.

The way they put it with Tiger Data, you get OLAP speed right alongside config data, all under one roof. As you can see, Tiger Data handles series scale. Storage compression is absurd and your Cloud Bill will thank you. So streamline your stack today. Head over to TigerData.com and see why over three million Tiger Data databases are running right now. That's TigerData.com. Okay, so as you've been at SERP API, I'm really curious about how you've progressed and matured at the company, maybe in that project, but also other projects, how you've gone from the the engineer to the engineering director, all of the things that you've worked on. And I think to to kind of wrap that in a little bit of a box, it's alongside what I'm asking is how does SERP API build roadmaps? How do they, how do you guys decide that, okay, this is the next most important thing to build or to address? So when it comes to building things, it's different on when it comes

to the career growth as SERP API. As for career growth, we really support every opportunity and we provide many opportunities to career growth. So it was all about knowledge. This is a very important thing that everyone at SERP API share knowledge, we share everything with each other. We try to teach each other anything that we know and other person might not be familiar with. For example, I try to educate the team and share my knowledge and security with the rest of the team members. And when I joined as a junior engineer, it was the same thing for them, I they used to share their software engineering knowledge with me and I used to learn from the best at SERP API. As for the challenges that we face, we faced huge amount of challenges, but most of the things that we want to support, let's say we have a new API we want to support.

We just recommend that idea or we post it on our public roadmaps. We have a public roadmap on GitHub, anyone, all our clients, anyone interested can see that roadmap. We basically post the idea of introducing a new product on our public roadmap. If we see our clients that are interested about this product, we're going to go ahead and build it right away. Sometimes some of the products are being requested by our clients directly. They send us email, they contact us through our website chat and they ask can you please pour this product or this feature or introduce a new API. We do that, so that's how we take it from public roadmap into production. So, I'm curious about how you build teams, right? What do you look for and those people to indicate they're the winning horses to join you at SERP API? We are very interested in hiring very talented people. We have many open positions. Either you are Jr., or senior,

director, beautives, we are hiring all that. We even recently started hiring interns, we go to universities, we do events there, we help students, create hackathons to support them, we sponsor many events, different universities around Texas, California. Anyone sees their ability in themselves to work with SERP API as an engineer. They are actually excited about doing what we do. They have it in them. Then we will be very excited to welcome these people. We will share all our knowledge with them and we will have them either there, engineers or interns. Currently I manage a team of four, three engineers, three seniors, one interns. We are essentially hired one intern and she's part of my team since it's doing great. I'm sharing all my knowledge with her and with the rest of the team and we are looking forward to welcome more

teams as we are growing very fast. Last year we were around 13 engineers at SERP API. Today we are around 68 or 65 and we were aiming to hit 100 engineers by the end of this year. This episode is brought to you by Rinder. If you're building modern full stack apps or AI agents, you know the drill. Your front end is on one platform, your database is on another. Background jobs are on a third and half your day is spent jumping between vendor consoles. It's exhausting. That's why you need to check out Rinder. Rinder is the cloud for builders, a single platform for your web services, Postgres databases, background workers and cron jobs. You connect your Git repo, push your code and it's live in production with automatic TLS and zero downtime deploys. Connect your repo, push and done. Plus unlike serverless platforms that time out mid execution, Rinder's compute is persistent with features like Rinder workflows long running AI agent loops and multi-step jobs run smoothly without you having to build complex Q

or retry logic. Over six million developers are shipping on Rinder, scaling from early builds to millions of users on the exact same platform. Head to Rinder.com and ship your next project today. That's Rinder.com. This episode is brought to you by Protected Harbor. Guys, I'm sure your IT infrastructure can scale, but does it actually know your applications need or is it just throwing bandwidth at the problem and hoping nobody breaks in? That's where Protected Harbor, an application aware infrastructure or AAI comes in. Instead of hoping for the best application aware infrastructure, aligns your tech resources directly with what your apps actually need to perform safely. Plus it's engineered with built-in zero trust security. That means every user, device, and workload gets verified continuously. No automatic passes, no free rides. You get total visibility and ironclad control without making life a living nightmare for your dev

teams. You get to build, deploy, and scale on infrastructure designed around security from day one. So stop assuming your network is safe and start knowing it is. Go to ProtectedHarbour.com slash code story. To learn how AAI can strengthen your stack today, that's ProtectedHarbour.com slash code story. So I'm curious about scale for the product but also scale for the projects that you've worked on and the things that you lead. I'm curious if there's been interesting areas where you've had to fight scale as you've grown. We started with very minimum amount of API engines. Like, let's 30 API engines or less. At the moment we have more than 120 API engines. Each API engine is handling millions, hundreds of millions of requests per hour. So that's what I call it. I call at scale. If we combine all the search engines, we will have billions of varies per hour. All that

amount of data is being used. And we have more around 120 API engines. And we have different teams. And we try to share knowledge about each API. An API might not be developed by me and I might never have been worked on the API before. But I try to get the knowledge of the API from the person who developed it. I personally developed multiple APIs as a server. I like Amazon API, Home Depot, and I passed all that knowledge to my colleagues. So we always keep these APIs maintained. We keep our SLF very high in our latency as well. We take the latency and the response times are very seriously. We try to keep the response times as minimum as possible. And at the moment, after all that, we are the lead, it's a search data and the world. As you step out on the balcony and you look across all that you've built thus far,

at SERP API, what are you most proud of? I'm proud of multiple things. Some of the API engines that I built, the compliance that I have been worked on, cyber security compliance. And I'm so proud that I have been maintaining a team of engineers and managing them. They are very talented. They are the best. And mostly the biggest challenge that I faced was the compliance. I had to work on the cyber security compliance from scratch going through audits wasn't easy. So let's flip the script a little bit. Tell me about you, a mistake you made, and how you and your team responded to it. We haven't made really a huge mistake, but we've been working on some APIs and some of the mistakes that happens at SERP API. Sometimes it's updating the JSON

keys where we are not supposed to update the JSON keys. We deal with that very seriously. So we try to share knowledge about that. The key to resolve these issues is to share knowledge. So I wouldn't say it was really a huge incident or challenge that I faced. But it's something that is very interesting to see that once the customers start using our service, let's say, never API, they expect that the structure of our JSON always, always consistent, the same. And we try to do that mostly. But sometimes the search engine itself gets updates in a way that force us to update the JSON structure. And one day, one of the engines, which is never API, we had to update the JSON structure and we had to go and inform all the clients who are using never API. Before we pushed the update for production, we had to contact each client and explain to them, hey, we updated our, we can update

our JSON structure. So please keep that in mind in case you hard-coded the structure in your code or in your application. So we do not break it. But it wasn't really a deal breaker. Or most of our customers becomes most of the their applications were not hard-coded with the JSON structure. Okay, so like AI, adjacent infrastructure, right, which is we talked about scale. And now we talked about maybe mistakes, but mistakes in often be lessons learned as well. Tell me about some of the lessons you've learned from operating this AI adjacent infrastructure at scale. I believe that the most important thing when it comes to infrastructure is compliance. This is the thing that I learned the most. As we all know, that building a convenience AI demo is like increasingly easy. But building an AI system that remains current, secure, reliable, and trustworthy in production is an infrastructure problem. And let's focus on secure

reliable. I believe that the thing that every business owner should keep in mind is compliance because you will get to a level. Once you, once you start your startup, you will get into a level where you will be required to work on compliance. And if you do not want to deal with all that compliance at once and into a short amount of time, you will get some clients who will be insisting on only contracting with a compliant company to secure the compliant company. Iso, secure to comply. It's SOC 2, type 2, secure to comply, SOC 3. And we really did not see that coming at the beginning, but later we had to work on it. And we had to work on it in a very short period of time. I had to improvise to get that done. I had to go through every single documentation that company has and rewrite policies, then set everything up for audit and go for audit.

It wasn't an easy process to go through all that because when you go through audit, every single control you have, every single security liar you have will be tested by an auditor, external auditor. Let's move forward then. This will be exciting. A lot, what does the future look like for server API 4? What you're building for the platform for the product? Where the industry is going? All the things there. AI systems will increasingly use tools and to trival to interact with live information. And I would say here that data is the future. And since we know that most of the AI agents use data, rely on data, in training their models, and empowering their models to have real-time access to the search data, the internet data, that's why I believe the data is the most valuable asset in the future. And let's focus here on not any type of data, but the high-quality data,

especially the search data, the high-quality search data. Because nowadays we see that many AI models have been trained on huge datasets, but they suffer of hallucinating. They are not reliable, they are hallucinating, and that makes them not trustworthy for the customers and for the others. What we are focusing on as a PBI is to provide a very high-quality amount of data for AI companies, so they can train the AI models in the perfect way and reduce that hallucination to the minimum. I think the AI is just a movement without an intelligence, and when you add the data to it, then you are adding thousands to that model to that. So I believe that we will be focusing on, we are focusing at the moment to provide the biggest amount of high-quality data to the customers, so they can use it to train their AI models to empower their AI models to have

access to their real-time internet data. In the future of where we're going with AI-generated code, right? It introduces some failure modes that are something that we're not used to, it's bit new, even for strong teens. What's the role in data there? And I think you've kind of touched on it a little bit here and there, but telling about the role of data and search in AI systems and why, why moving faster generates this new failure mode. So as I mentioned before, the most important thing when it comes to AI is the quality of the data. If the data is low quality, then the model will be hallucinating. Will it produce a very bad quality code? But if we provide and train the AI model on very high-quality data, the AI model will give a better quality code, better quality results, less hallucinating, and then once you have that, then the AI system or AI model can't be trusted.

And it will not only lead to a better quality code, but it will even decrease the amount of time that is being taken to finish that task by the AI model. And I believe that AI coding is a very complex build time and can also compress review time as well at the same time. Well, let's switch to you. Who influences the way that you work? Name a person or many persons or something you look up to and why? The first one is our company, Faumandar, Julien Khaled, he's the one who inspired me to work in the field and he's the one who onboarded me at Serpepi and he shared all his knowledge with me at the beginning of the year 2021. I learned most of my knowledge from him onto other team members, so he was a huge inspiration for me, I always looked up to him and I still looking up to him. He's very smart, talented person, the best engineer I have seen in my life. The second person when it comes to

cybersecurity, Don Kaminsky, he is one of the people who used to inspire me at the cybersecurity world when I was a kid. When I started my journey, I was in high school and I heard about a vulnerability that he discovered in 2008 and I heard about the vulnerability just back in 2011 or 2012. I was still just a middle school student and I was shocked about how did he find the vulnerability and the complication of the vulnerability and it's the vulnerability is even difficult to understand and he had a hard time to explain that vulnerability to other people in the world. And basically the vulnerability changed the entire NS or how the world is dealing with DNS today. So I would say that he changed the entire internet, he changed the encryption when it comes to DNS handling and yeah he was a huge inspiration for me as well. Unfortunately he

passed away a few years ago but yeah he was one of my inspiration of people. Let's move into the last question. So you're getting on a plane, interesting next to a young entrepreneur who's built the next big thing. They're jazzed about it. They can't reach it off to the world, can't wait to show it off to you right there on the plane. What advice to give that person knowing where the industry is, knowing where it's going with all the things with AI and the advent of all the technology, what advice do you give that person? That's a really great question actually. And I would advise that if that person works in an hour field then I would advise to solve a painful problem you have experienced. And I would say validated early instruments, the system, speak to you and treat three other reliability and security as protect features. That's very important thing to know there.

Well it's fantastic advice. Thank you for being on the show today. Thank you for telling your creation story at Serb API. Thank you. And this concludes another chapter of Code Story. Code Story is hosted and produced by Noah Labhart. Be sure to subscribe on Apple podcasts, Spotify or the podcasting app of your choice. And when you get a chance, leave us a review. Both things help us out tremendously. And thanks again for listening. Listen just talking about multi-agentic AI. They already deployed one. It's called chat concierge and it's simplifying car shopping using self-reflection and layered reasoning with live API checks. It doesn't just help buyers find a car they love. It helps schedule a test drive,

get pre-approved for financing and estimate trading value, advanced, intuitive and deployed. That's how they stack. That's technology at Capital One. Rubric is the security and AI operations company. Build for what happens after an attack hits. Not just the moments before. AI has turned the threat landscape into quicksand, moving too fast for any human to fully predict. That's why an agentic cyber resilience platform matters. Automated recovery, clean data, a business that keeps moving, no matter what hits. One platform, not a patchwork of stitch together tools and gaps. Don't wait for the next attack. Secure and accelerate your business at rubric.com. Again, rubric.com.

More episodes

More from Code Story: Insights from Startup Tech Leaders

View all episodes →