All News
Portfolio1 October 2026

The Builder's Chair: Joseph Saunders on Protecting the Software You Can't Simply Reboot

By Critical Ventures

Share
The Builder's Chair: Joseph Saunders on Protecting the Software You Can't Simply Reboot

The Builder's Chair is Critical Ventures' founder interview series — conversations with the people building the companies in our portfolio. We go deep on the decisions that shaped the business, the hard years that didn't make the press release, and the bets they're making on the future of their industry.

RunSafe Security is a Virginia-based cybersecurity company founded by Joseph M. Saunders (CEO) and Doug Britton (EVP). It provides Embedded Runtime Security (ERS), Software Bill of Materials (SBOM) generation, and vulnerability management for embedded and firmware software, including C/C++ software running in vehicles, defense platforms, and critical infrastructure that can't simply be patched or rebooted on demand.

RunSafe's patented technology neutralises memory-based vulnerabilities and zero-day exploits at runtime, without changing source code or adding performance overhead, which means regulated or safety-certified software can be protected without triggering re-certification. The company holds 17 patents and counts the U.S. Air Force, Army, and Navy, Lockheed Martin, GE Aerospace, Schneider Electric, Bell Flight, and Critical Software among its customers and partners.

Critical Ventures backed RunSafe because it protects the software you can't simply reboot — embedded code running inside fielded vehicles, defence platforms, and critical infrastructure, where a compromise is a safety event, not an inconvenience. What sold the firm was that RunSafe's patented cyberhardening neutralizes memory-based vulnerabilities and zero-day exploits at runtime with no performance overhead and without changing a single line of code, meaning even regulated or safety-certified software can be protected without being re-certified — something almost nothing else on the market can claim.

Joe Saunders is founder and CEO and brings roughly 25 years of experience across national security and cybersecurity: he started his career as a consultant at PricewaterhouseCoopers building quantitative models for financial institutions, later led the digital technology division at AIMS Worldwide, was part of the management team at TARGUSinfo when it was acquired by Neustar for $750M in 2011, and served as director at Thomson Reuters Special Services, building analytical solutions for law enforcement and national security threat identification. He holds a BS in mathematics from the University of Michigan, an MS in predictive analytics from Northwestern University, and an MBA from George Mason University. Outside RunSafe, he founded Children's Voice International, a nonprofit supporting displaced, abandoned, and trafficked children.

Read our full investment thesis here.

You spent years building quantitative models at PwC and doing predictive analytics work before pivoting hard into national security and cybersecurity. What's the moment that actually pulled you toward protecting critical systems?

The through-line for me has always been using data to understand risk. At PricewaterhouseCoopers I built quantitative models for financial institutions, and later at Thomson Reuters Special Services, I built solutions to help law enforcement identify national security threats, including economic espionage and theft of intellectual property. That work put me close to how adversaries actually operate, how patient they are, and how much of what they go after lives inside software.

What pulled me in was realizing how badly the dominant approach was failing. Despite heavy spending on perimeter defenses and patching, the systems we depend on most — the embedded software inside vehicles, defense platforms, and infrastructure — were still being exploited regularly. My co-founder Doug and I connected over that frustration and made a bet on changing the economics of cybersecurity to favor defenders rather than attackers. That idea sparked the creation of RunSafe's Embedded Runtime Security (ERS) technology, and it has only become more important as AI-driven vulnerability discovery and exploit development have made getting those economics right even more urgent.

Outside RunSafe, you founded Children's Voice International, a nonprofit supporting displaced and trafficked children — about as far from embedded cybersecurity as a cause gets. What draws you to that work, and does it ever inform how you think about running RunSafe?

What draws me to it is the simple fact that these are children who have been displaced, abandoned, or trafficked, and they have almost no ability to protect themselves. Founding a non-profit does inform how I think about RunSafe, though maybe not in the obvious way.

One of the things we encourage at RunSafe is volunteering and giving our time back to causes that matter. Every employee gets a week each year to spend on volunteering. Stepping away from daily work and investing time in something outside the business provides a reset and a fresh perspective when returning to tackle the challenges of embedded cybersecurity.

Joseph Saunders at the Critical Ventures ecosystem summit

You were part of the management team at TARGUSinfo, which was acquired by Neustar for $750M in 2011. What's a lesson from being inside such a high-growth company that you've carried into building RunSafe from scratch?

I often say I grew up as an entrepreneur at TARGUSinfo. We had a lot of motivated people aligned around a common vision. We had clear, unique differentiation and were able to get customers to pay a premium for the value-add we brought. We tackled new solutions and new markets with the same spirit as the last one.

What tied it all together was the culture and the mindset the CEO established for how we operate as a company. He often said phrases like "Plow the dirt with your face" and "Have the courage of your convictions." They may sound like silly phrases on one level, but they were a unifying battle call for all of us. If you ask any employee of TARGUSinfo, they will all tell you that those phrases have an enduring imprint on how we all go about building business. So, I brought the same mindset to RunSafe Security, and sprinkled in some additional lessons learned from my own school of hard knocks. Today, the RunSafe team has a similar spirit to how TARGUSinfo operated.

RunSafe's core pitch is protecting embedded software with zero source code changes and no performance overhead, specifically so that regulated or safety-certified systems don't need to be re-certified. What was the hardest technical problem in making "no recertification needed" actually true, rather than just close to true?

The hard part is that safety-certified software is certified against specific behavior. In avionics, for example, you have DO-178C. Certification authorities care that the system does exactly what it was shown to do. Any security additions must be deterministic. Any protection that changes functional behavior, timing, or performance in a way that matters puts you back in the certification queue, which can cost months or years.

Our approach, Load-time Function Randomization (LFR), relocates functions in memory so that each running instance is logically unique. That denies attackers the predictable memory layout they need to build a reliable exploit. The engineering challenge was changing the memory layout without changing what the software actually does or how fast it does it. Functionally identical, logically unique. Getting overhead low enough to be negligible was part of it, but the key demonstration we achieved was proving that behavior is preserved, so a customer can make the case to a certification authority that nothing material changed. Close is not good enough there. It has to be genuinely behavior-preserving, and that is where most of the difficulty lies — but we succeeded in demonstrating it.

RunSafe holds 17 patents around memory protection and software hardening. Is there one patent or technical approach you're most protective of, and one you'd happily see the rest of the industry copy?

The one I am most protective of is our know-how to relocate and randomize software in memory while preserving exact functionality. That is the heart of RunSafe Protect, and it is what enables us to defeat memory-based exploits without touching source code or adding meaningful overhead. It took years to get right, and it is genuinely hard to replicate. But our customers and partners appreciate its elegance and simplicity at the same time. It is easy to deploy and easy to support, but it was hard to develop.

The one I would happily see the whole industry adopt is the principle underneath it — that protection should be built in at the binary and build level and should not depend on developers rewriting code they cannot always change. Memory safety vulnerabilities account for roughly 70 percent of the serious issues in critical infrastructure software. If more of the industry made memory-based exploitation economically unattractive by default, attackers would lose one of their most reliable techniques, and that helps everyone, including our customers. I do not think we win by being the only ones who take memory safety seriously. We win by being the best at it while the whole floor rises.

Regulations like ISO 21434, UN R155/R156, and the EU's Cyber Resilience Act are turning embedded security from a nice-to-have into a legal requirement for automotive and critical infrastructure. Is that regulatory wave actually driving urgency inside the companies you sell to, or is it still mostly a paperwork exercise for most of them?

It is driving real urgency, but not evenly, and not always for the right reasons yet. Regulations like ISO/SAE 21434 for automotive cybersecurity engineering, UN Regulations 155 and 156 on vehicle cyber and software updates, and the EU Cyber Resilience Act (CRA) are certainly moving security from optional to mandatory. That gets it onto the executive agenda. But I see a lot of organizations mistake having the ingredients of a program for actually being ready. They will tell you they have a Software Bill of Materials (SBOM), they have a vulnerability management process, and they patch critical issues. Then, a fielded product has an actively exploited vulnerability, the CRA reporting clock is running, and the real questions surface. Which versions are affected? Is the vulnerable function even reachable in your build? Where are those devices physically? What can you do today if a tested patch is weeks away? Companies that take this opportunity to align with regulations and strengthen their security programs will see the most benefit.

RunSafe works with both defense customers — the Air Force, Army, Navy, Lockheed Martin — and commercial ones across automotive, energy, and industrial. Does the sales motion and buying urgency actually differ much between defense and commercial critical infrastructure, or is it more similar than people assume?

The technical problem is nearly identical on both sides. It is embedded C and C++ code running in systems that are long-lived, hard to patch, and where a compromise can become a physical or safety event rather than just a data breach. A memory-based exploit does not care whether the device is in a fighter jet or on a factory floor. Where they differ is what creates urgency and how the buying decision gets made.

On the defense side, the driver is mission assurance and a clear-eyed view of the adversary. Those customers have long understood that a capable nation-state is trying to get in, so the conversation is about proof, program requirements, and long procurement cycles. On the commercial side, the urgency has historically been softer, and what is changing now is regulation, geopolitics, and AI. In the US, we've seen more nation-state attacks on critical infrastructure, including telecommunications and water systems. AI is increasing the capability for these attacks to expand further. They are more similar than people might assume in terms of actual risk, and they are now converging on urgency.