S13 Bonus: Scaling Real-Time Search Data: Secure APIs for AI Infrastructure with Alaa Abdulridha, Engineering Director at SerpApi
Alaa Abdulridha is from souther Iraq, but now lives in Austin, TX. Post wars in Iraq, the country had poor infrastructure, which got him interested in building and creating things to better and secure his life. He left the country to study, and ended up in Germany as a security engineer. Outside of tech, he enjoys playing RPG video games. In particular, he likes to play World of Warcraft, and enjoys the open world, and character development from scratch.
Alaa's current company was built to scrape google search engines, in order to get around a blocker for a prior project. In the past, he used to participate in bug bounty hunting during University, and wrote about his exploits. His now founder's came across his articles, and invited him to joint the company.
This is Alaa's creation story at SerpApi.
Links
https://www.linkedin.com/in/alaa0x2/
Current Sponsors:
Checkout our Stacklist! https://stacks.codestory.co/
Hosted by Noah Labhart | Technical Founder & Startup Mentor.
Our Sponsors:
* Check out Granola and use my code granola.ai/CODESTORY for a great deal: https://granola.ai
* Check out Perplexity and use my code pplx.ai/codestory for a great deal: https://www.perplexity.ai
Advertising Inquiries: https://redcircle.com/brands
Privacy & Opt-Out: https://redcircle.com/privacy
Transcribed automatically
In today's digital world, your data is more exposed than ever, scattered across various platforms and constantly under threat. Traditional, fragmented security tools just don't cut it anymore. They make processes cumbersome, slow, and complicated to manage when things go awry. That's why I'm excited to talk about Cohesity Data Cloud. It's a game-changer. Cohesity offers a single AI-powered platform that not only protects and secures your data, but also unlocks valuable insights. It uses AI and automation to detect threats early and enables you to recover your data in hours, not days.
With Cohesity, you're not just reacting. You're proactively building resilience across AI, cloud, and identity systems. Want to enhance your data security and management? Visit Cohesity.com slash data cloud. Cohesity. Resilience everywhere. That is our main goal at Cepart AI, that everyone should know everything. We try to share knowledge. The main challenges that we faced as SERP API at the beginning is how do we scrape search engines and provide the data through an API as organic results at the same time to keep these APIs safe?
Because at that time, there was no such services as SERP API. It was kind of a new technology. Even it was a mystery how to secure these type of APIs and what type of vulnerabilities that could introduce. My name is Allah Abdelreda. I'm Engineering Director and Cybersecurity Researcher at CERP API.
I don't exactly know what to do next. She took many goes to get right. Who built the teams that have their back. A company is its people. The teams help each other achieve more. Most proud of our team. Keeping scalability top of mind. All that infrastructure was a pain. Yes, we've been fighting it as we grow. Total waste of time. The stories you don't read in the headlines. It's not an easy thing to achieve, Mike. Took off the shelf and dusted it off and tried it again. Drive the ups and downs of the startup life.
need to really want it. It's not just about technology. All this and more on CodeStory. I'm your host, Noah Lappart. And today, how Allah Abdurrila is fueling your ability to scrape search engines through one fast, easy, and complete API.
This episode is brought to you by Tiger Data. Stop bolting separate databases onto your stack. Tiger Data is 100% unforked Postgres. Same ORMs, same drivers, no pipeline maintenance. As Cloudflare's team put it, you keep analytical and config data under one roof with specialized OLAP performance. Try it today at TigerData.com. This episode is brought to you by Protected Harbor. Your infrastructure scales, but does it actually understand your apps? With Protected Harbor's Application Aware Infrastructure, or AAI, your tech automatically aligns with app performance while built-in zero-trust security verifies every user and workload.
Give your team total control without the complexity. Go to ProtectedHarbor.com slash Codestory to learn how. This episode is brought to you by Render. Stop jumping between four vendor consoles just to host your stack. Render runs your web services, databases, background workers, and AI workflows all in one single cloud platform. Connect your repo, push your code, and you're live. No serverless timeouts or crazy setups. Ship faster today with Render.com.
Ala Abdurrida is from southern Iraq, but now lives in Austin, Texas. Post-wars in Iraq, the country had poor infrastructure, which got him interested in building and creating things to better and secure his life. He left the country to study and ended up in Germany as a security engineer. But outside of tech, he enjoys playing RPG video games. In particular, he likes to play World of Warcraft and enjoys the open world and character development from scratch.
Ala's current company was built to scrape Google search engines in order to get around a blocker for a prior project. In the past, he used to participate in bug bounty hunting during his time at university and wrote about his exploits. His now founders came across his articles and invited him to join the company.
This is Alaa's creation story at SERP API.
SERP API is a SaaS company. We provide an API. This API empowers developers and other companies to gain access to the search data, like search engine data. but in a consistent, structured and at scale. So they can use these data to train their AI models to, for example, news agencies. They use that for news monitoring. SEO, government use as for background check. If you have, let's say, an AI chatbot, you want to give your chatbot real-time access to the internet so it can do real-time searches for you, not limited to search engines.
for example, Amazon, eBay, Walmart, Home Depot, and so on. That's what we do at CERP API. We basically provide data for companies, for developers. It's a very interesting story how our founder started CERP API. He used to build other type of applications, an application that is used to take a picture of food and it can identify the type of food and such things. But our founder found an issue, faced an issue, a blocker. The blocker was how can he collect this information and images from Google without limitation.
As if you keep searching in Google, manually you will get capture, checking if you are a robot or not. So he decided to create an API. He scraped Google Images and he created an API for Google Images to connect it with his application so he can surpass that blocker. It's a very interesting story because at that time, no other companies or any other business out there provided the same service, which is Serp API. And by the way, Serp API is a shortcut for search engine results page. about how I joined CERPB.
I remember that I used to do bug bounty hunting. And bug bounty hunting, to explain it to the listeners, is basically, if you are a security researcher and you want to do a freelance work, you can find vulnerabilities on specific websites that are available on a platform called HackerOne, for example. You report these vulnerabilities to the companies or directly to their security team and they will reward you with the monetary rewards. And I used to write articles. I was just a second year university student, and I used to write articles and write-ups about my findings.
How do I find vulnerabilities? How much money do I get from these vulnerabilities? One of the targets that I worked on as a bug bounty hunter was Facebook. I managed to hack Facebook, and literally hack Facebook. I was able to gain access to their legal department admin panel multiple times, and I was able to gain access to their internal network. I wrote an article about that of two parts, how I hacked Facebook part one, how I hacked Facebook part two. The founder of CERB API was one of the readers for that articles, and he reached out to me and he mentioned that they have positions available at CERB API and there you're looking for talented people to work at Serp API.
And since then I gave it a try and I started working at Serp API back in 2021. I used to be a remote employee, used to work remotely from Ukraine. And now I am in office, on site working from the office from Austin, Texas. And I started as a junior engineer. Now I am engineering director and responsible for the cybersecurity certificates And just recently actually we got CERP API certified SOC 2 type 2 SOC 3 and ISO 27001 ISO 27701 And we are working on GDPR at the moment.
I'm curious about when you were invited to join the company, what was your quote unquote MVP, right? I ask a lot about MVPs on this show, but what was the first project you were pulled into that you had to jump in on, create something from nothing? Tell me about that process and how you went about it and what sort of tools you were using to bring it to life. So they wanted someone who can combine between software engineering and cybersecurity at CepAPI. That is our main goal at CepAPI, that everyone should know everything.
We try to share knowledge. The main challenges that we faced as Serp API at the beginning is how do we scrape search engines and provide the data through an API as organic results at the same time to keep these APIs safe? Because at that time, there was no such services as Serp API. It was kind of a new technology. Even it was a mystery how to secure these type of APIs and what type of vulnerabilities that could introduce by these APIs. And yeah, it was fun. It was challenging a bit because we managed to find a new vulnerability that can hit such type of APIs like SSRF, server-side request forgery.
And it's the same vulnerabilities that I used to hunt for before. It just comes in a different way, I could say. So in how you were approaching that, give me a decision or trade-off you had to make in how you approached it, how you went about solving that problem and being the quote-unquote guy to go take it on, and how you coped with those decisions. It wasn't easy at the beginning because I had to coordinate with multiple software engineers, multiple engineers at the team and not all security engineers and not all software engineers are familiar with security vulnerabilities especially when it comes to technical vulnerabilities like that and it was something rare and it was difficult to to explain the proof of concept that i came with for these vulnerabilities so we can address them properly because in the eyes of the As software engineers, these issues were not vulnerabilities, unless I managed to introduce a proof of concept that has a significant security impact there.
And I successfully managed to do that. I believe nowadays we have competitors. Most of these competitors, they follow the same security practices in their APIs to secure them. And it became like a standard. But after a while, these procedures that I used to take many years back, now they became standard when we develop or we introduce a new API. Just before that API goes into production, all these steps or methodologies have to be taken as measures before we release that API. This episode is brought to you by FitNexa.
All right, quick question. How many times have you tried to fall asleep only to be held hostage by a snoring partner, obnoxious traffic, or your upstairs neighbor practicing tap dance. Yep, in there. Listen up, because I just found your new secret weapon, Somnipods 3 by Fitnexa. These bad boys are ultra slim, coming in at under 10 millimeters thick and just 3.3 grams light. That means if you're a side sleeper, you won't even feel them in your ears. Plus, they pack powerful hybrid active noise canceling that shuts down up to 42 decibels of total noise.
Goodbye snoring. Hello, Sweet Dreamland. And it gets better. They feature built-in white noise, high-res audio for daytime tunes, and overnight AI sleep tracking so you can actually see how well you slept. You even get 10 custom tip sizes in the box to guarantee that perfect custom fit for your ears. Upgrade your sleep tonight. Head over to go.fitnexa.com slash Codestory or use the link in the show notes right now because Fitnexa is giving Codestory listeners $10 off of the Somnipods 3. Experience what uninterrupted rest actually feels like.
Trust me, your brain will thank you tomorrow. Let's talk about something crucial, your data. It's spread far and wide, and it's constantly under threat. And the truth, many organizations still rely on outdated, disjointed tools, making everything from daily operations to emergency responses slow and complex. Enter Cohesity Data Cloud. This isn't just another tool, it's a game changer. Imagine having one AI-powered platform that not only secures and protects your data, but also unlocks valuable insights.
With Cohesity, you can detect threats faster with AI and automation. And if things go south, you're not stuck waiting days for recovery. You're back up in hours. Ready to build resilience across AI, cloud, and identity? Visit Cohesity.com slash datacloud today. Cohesity. Resilience everywhere. This episode is brought to you by Tiger Data. If you're like me, your architecture diagram started simple until someone added a specialized time series DB, a couple of pipelines, and suddenly you're babysitting four databases at 2 a.m. Stop doing that to yourself.
Enter Tiger Data. It's 100% unforked, pure Postgres. Same drivers, same ORMs, same standard SQL. Zero new query languages to learn. And not just in theory. Plexigrid consolidated four databases down to just one instance and got 350 times faster queries. Glucco ingests 3 billion points a month, and Orca processes over $500 million in daily trading volume. Maybe you've heard of Cloudflare? Yeah, that Cloudflare. The way they put it, with TigerData, you get OLAP speed right alongside config data, all under one roof.
As you can see, Tiger Data handles serious scale. The storage compression is absurd, and your cloud bill will thank you. So streamline your stack today. Head over to TigerData.com and see why over 3 million Tiger Data databases are running right now. That's TigerData.com.
Okay, so as you've been at SERP API, I'm really curious about how you've progressed and matured at the company, maybe in that project, but also other projects, how you've gone from the engineer to the engineering director, all of the things that you've worked on. And I think to kind of wrap that in a little bit of a box, it's alongside what I'm asking is, how does SERP API build roadmaps? How do you guys decide that, okay, this is the next most important thing to build or to address? So when it comes to building things, it's different than when it comes to the career growth at CERP API.
As for career growth, we really support every opportunity and we provide many opportunities to career growth. So it was all about knowledge. This is a very important thing that everyone at CERP API share knowledge. We share everything with each other. We try to teach each other anything that we know and the other person might not be familiar with. For example, I tried to educate the team and share my knowledge and security with the rest of the team members. And when I joined as a junior engineer, it was the same thing for them.
They used to share their software engineering knowledge with me and I used to learn from the best at Serp API. As for the challenges that we face, we face huge amount of challenges, but most of the things that we want to support, let's say we have a new API we want to support, we just recommend that idea or we post it on our public roadmap. We have a public roadmap on GitHub. Anyone, all our clients, anyone interested can see that roadmap. We basically post the idea of introducing a new product on our public roadmap.
If we see that our clients that are interested about this product we going to go ahead and build it right away Sometimes some of the products are being requested by our clients directly They send us email, they contact us through our website chat, and they ask, can you please for this product or this feature, or introduce a new API? We do that. So that's how we take it from public roadmap into production. into production.
So I'm curious about how you build teams, right? What do you look for in those people to indicate they're the winning horses to join you at SERP API? We are very interested in hiring very talented people. We have many open positions. Either you are junior or senior, director, we are hiring all that. We even recently started hiring interns. We go to universities, we do events there, we help students, create hackathons to support them. We sponsor many events, different universities around Texas, California.
Anyone sees ability in themselves to work with CERP API as an engineer, and they are actually excited about doing what we do, they have it in them, then we will be very excited to welcome these people. We will share all our knowledge with them and we will have them either they're engineers or interns. And currently I manage a team of four, three engineers, juniors, seniors, and one intern. We recently hired one intern and she's part of my team. She's doing great. I'm sharing all my knowledge with her and with the rest of the team.
And we are looking forward to welcome more teams as we are growing very fast. Last year, we were around 30 engineers at Serp API. Today, we are around 68 or 65. And we were aiming to hit 100 engineers by the end of this year. This episode is brought to you by Render. If you're building modern full-stack apps or AI agents, you know the drill. Your front end is on one platform, your database is on another. Background jobs are on a third, and half your day is spent jumping between vendor consoles. It's exhausting.
That's why you need to check out Render. Render is the cloud for builders, a single platform for your web services, Postgres databases, background workers, and cron jobs. You connect your Git repo, push your code, and it's live in production with automatic TLS and zero downtime deploys. Connect your repo, push, and done. Plus, unlike serverless platforms that time out mid-execution, Render's compute is persistent with features like render workflows, long-running AI agent loops, and multi-step jobs run smoothly without you having to build complex queue or retry logic.
Over 6 million developers are shipping on Render, scaling from early builds to millions of users on the exact same platform. Head to Render.com and ship your next project today. That's Render.com. This episode is brought to you by Protected Harbor. Guys, I'm sure your IT infrastructure can scale, but does it actually know what your applications need? Or is it just throwing bandwidth at the problem and hoping nobody breaks in? That's where Protected Harbor and Application Aware Infrastructure, or AAI, comes in.
Instead of hoping for the best, Application Aware Infrastructure aligns your tech resources directly with what your apps actually need to perform safely. Plus, it's engineered with built-in zero-trust security. That means every user, device, and workload gets verified continuously. No automatic passes, no free rides. You get total visibility and ironclad control without making life a living nightmare for your dev teams. You get to build, deploy, and scale on infrastructure designed around security from day one.
So stop assuming your network is safe and start knowing it is. Go to protectedharbor.com slash codestory to learn how AAI can strengthen your stack today. That's protectedharbor.com slash codestory.
So I'm curious about scale for the product, but also scale for the projects that you've worked on and the things that you lead. I'm curious if there's been interesting areas where you've had to fight scale as you've grown. We started with very minimum amount of API engines, like 30 API engines or less. At the moment, we have more than 120 API engines. Each API engine is handling millions, hundreds of millions of requests per hour. So that's what I call it. I call at scale. If we combine all the search engines, we will have billions of queries per hour.
All that amount of data is being used. And we have more around 120 API engines. and we have different teams and we try to share knowledge about each API. An API might not be developed by me and I might never be, I never have been worked on the API before. But I try to get the knowledge of the API from the person who developed it. I personally developed multiple APIs at Serp API, like Amazon API, Home Depot, and I pass all that knowledge to my colleagues. So we always keep these APIs maintained. We keep our SLA very high and our latency as well.
We take the latency and the response times are very seriously. We try to keep the response times as minimum as possible. And at the moment, after all that, we are the lead in the search data and the world. As you step out on the balcony, you look across all that you've built thus far At SERP API, what are you most proud of? I'm proud of multiple things. Some of the API engines that I built, the compliance that I have been worked on, cybersecurity compliance. And I'm so proud that I have been maintaining a team of engineers and managing them.
They are very talented and they are the best. And mostly the biggest challenge that I faced was the compliance. I had to work on the cybersecurity compliance from scratch, going through audits. It wasn't easy.
So let's flip the script a little bit. Tell me about a mistake you made and how you and your team responded to it. We haven't made really huge mistakes, but we've been working on some APIs and some of the mistakes that happens at CERP API sometimes is updating the JSON keys where we are not supposed to update the JSON keys. we deal with that very seriously so we try to share knowledge about that the key to resolve these issues is to share knowledge so i wouldn't say it was really a huge incident or a challenge that i faced but it's something about it's very interesting to to see that once the customers start start using our service let's say never api they expect that the structure of our json always consistent, the same.
And we try to do that mostly. But sometimes the search engine itself gets updated in a way that forces us to update the JSON structure. And one day, one of the engines, which is NeverAPI, we had to update the JSON structure and we had to go and inform all the clients who are using NeverAPI. Before we pushed the update for production, We had to contact each client and explain to them that, hey, we're going to update our JSON structure. So please keep that in mind in case you hardcoded the structure in your code or in your application so we do not break it.
But it wasn't really a deal breaker for most of our customers because most of their applications were not hardcoded with that JSON structure. Okay So like AI adjacent infrastructure right Which is we talked about scale and now we talked about maybe mistakes but mistakes can often be lessons learned as well Tell me about some of the lessons you learned from operating this AI infrastructure at scale I believe that the most important thing when it comes to infrastructure is compliance This is the thing that I learned the most.
As we all know, that building a convenience AI demo is increasingly easy. But building an AI system that remains current, secure, reliable and trustworthy in production is an infrastructure problem. And let's focus on secure, reliable. I believe that the thing that every business owner should keep in mind is compliance. Because you will get to a level once you start your startup. You will get into a level where you will be required to work on compliance. and you do not want to deal with all that compliance at once and into a short amount of time.
You will get some clients who will be insisting on only contracting with a compliant company, security compliant company, ISO, security compliant, SOC 2, type 2, security compliant, SOC 3. And we really did not see that coming at the beginning, but later we had to work on it and we had to work on it in a very short period of time. I had to improvise to get that done. I had to go through every single documentation the company has, rewrite policies, then set everything up for audit and go for audit.
And it wasn't an easy process to go through all that because when you go through audit, every single control you have, every single security layer you have will be tested by an auditor, external auditor. Let's move forward then. This will be exciting. What does the future look like for Serp API 4? What you're building for the platform, for the product, where the industry is going, all the things there. AI systems will increasingly use tools and retrieval to interact with live information. and I would say here that data is the future and since we we know that most of the AI agents uses data and rely on data in training their models and empowering their models to have real time access to the search data the internet data that's why I believe the data is the most valuable asset in the future and let's focus here on not any type of data but the high quality data especially the search data the high quality search data because nowadays we see that many ai models have been trained on huge data sets but they suffer of hallucinating they are not reliable they are hallucinating and that makes them not trustworthy for the customers and for the others.
What we are focusing on as a BPI is to provide a very high quality amount of data for AI companies so they can train their AI models in the perfect way and reduce that hallucination to the minimum. The AI is just a movement without an intelligence. And when you add the data to it, then you are adding the intelligence to that model, to that movement. So I believe that we will be focusing, and we are focusing at the moment to provide the biggest amount of high-quality data to the customers so they can use it to train their AI models, to empower their AI models, to have access to their real-time internet data.
In the future of where we're going with AI-generated code, right, it introduces some failure modes that are something that we're not used to. It's a bit new, even for strong teams. What's the role in data there? And I think you've kind of touched on it a little bit here and there, but tell me about the role of data and search and AI systems and why moving faster generates this new failure modes. so as i mentioned before the most important thing when it comes to ai is the quality of the data if the data is low quality then the model will be hallucinating will produce a very bad quality code but if we provide and train the ai model on very high quality data the ai model will give a better quality code, better quality results, less hallucinating.
And then once you have that, then the AI system or AI model can be trusted. And it will not only lead to a better quality code, but it will even decrease the amount of time that is being taken to finish that task by the AI model. And I believe that AI coding compress build time and also can compress review time as well at the same time. Alal, let's switch to you. Who influences the way that you work? Name a person or many persons or something you look up to and why. The first one is our company founder, Julian Khaliki.
He's the one who inspired me to work in the field and he's the one who onboarded me at Serp API. and he shared all his knowledge with me at the beginning back in 2021. I learned most of my knowledge from him and other team members, so he was a huge inspiration for me. I always looked up to him, and I'm still looking up to him. He's a very smart, talented person, the best engineer I have seen in my life. The second person when it comes to cybersecurity, Dan Kaminsky. He is one of the people who used to inspire me in the cybersecurity world When I was a kid, when I started my journey, I was in high school, and I read about a vulnerability that he discovered in 2008.
And I read about that vulnerability just back in 2011 or 2012. I was still just a middle school student, and I was shocked about how did he find that vulnerability and the complication of that vulnerability. And the vulnerability is even difficult to understand. and he had a hard time to explain that vulnerability to other people in the world. And basically, that vulnerability changed the entire DNS, or how the world is dealing with DNS today. So I would say that he changed the entire internet. He changed the encryptions when it comes to DNS handling.
And yeah, he was a huge inspiration for me as well. Unfortunately, he passed away a few years ago, but he was one of my inspirational people.
Let's move into the last question. So you're getting on a plane and you're sitting next to a young entrepreneur who's built the next big thing. They're jazzed about it. They can't wait to show it off to the world. Can't wait to show it off to you right there on the plane. What advice do you give that person? Knowing where the industry is, knowing where it's going with all the things with AI and the advent of all the technology, what advice do you give that person? That's a really great question, actually.
And I would advise that if that person works in our field, then I would advise to solve a painful problem you have experienced. And I would say validate it early, instrument the system, speak to yours, and treat reliability and security as product features. That's a very important thing to note there. That's fantastic advice. Thank you for being on the show today. Thank you for telling your creation story at SERP API. Thank you. And this concludes another chapter of CodeStory. Code Story is hosted and produced by Noah Laphart.
Be sure to subscribe on Apple Podcasts, Spotify, or the podcasting app of your choice. And when you get a chance, leave us a review. Both things help us out tremendously.
And thanks again for listening.
Thank you.
Podbean