Leader Spotlight: Designing products around data control, with JP Ayyappan
JP Ayyappan is Director of Product Management at Virtru,a data-centric security company focused on keeping sensitive information both protected and productive as it travels outside of the perimeter. He began his career as a web developer before moving into solutions architecture and IT leadership roles at companies including Convergys and NorthgateArinso. JP later transitioned into product management, spending eight years at GlobalEnglish leading integrations, assessment, and B2C ecommerce products before joining Learnship. Today, at Virtru, JP focuses on building products that help organizations keep sensitive data secure while maintaining user control.
In our conversation, JP discusses why encryption should be viewed as a product experience rather than just a security feature. He explains how AI is reshaping data governance and how, with AI technology, product teams need to think differently about access and permissions. JP also talks about the role of transparency and user control as it relates to customer trust.
When encryption works best for users
Traditionally, encryption has been treated like an IT or security concern rather than a product experience. Why should product leaders outside of security care about encryption right now?
The ideal outcome is that encryption never becomes a product concern. The best encryption is completely invisible, so you can do the things you’re supposed to do while your information remains protected behind the scenes.
The real question product leaders should be asking is what happens to the information people share with us. There are a lot of free services where you’re not paying with money — you pay with your information. That’s a perfectly reasonable trade if users understand it. The question becomes, “Can I still control my information after I’ve shared it?”
Right now, by default, once data is shared, it’s gone. The problem we’re trying to solve is how to give people continued control over their information, even after they’ve shared it.
If the best encryption is invisible, where does it actually show up in the user journey?
A lot of encryption already exists — you just don’t notice it. For example, when you’re on a banking website, your connection is encrypted. Nobody asks whether you’d like the encrypted version of your online banking experience; it’s simply there as the default. When you’re on a video call, you’ll often see an icon showing the session is encrypted. Many laptops encrypt everything stored on the drive, so if someone removes the hard drive, they still can’t read the contents.
The bigger question is who holds the keys. In most enterprise software, the vendor controls the encryption keys, but in many consumer products, the platform does. That’s why end-to-end encryption has become such an important conversation. Ideally, the people communicating — not the platform — control access to the information.
There’s also a usability problem. Say I go to a doctor’s office, and they want to send me medical records. Instead of emailing them securely, they’ll likely ask me to create an account, since that’s how they’ve chosen to manage encrypted information. I already have thousands of accounts, and I don’t want another one. However, the purpose of creating another account is simply to verify that I am who I say I am.
We should be able to accomplish that identity verification without adding friction for users. That’s what Virtru is working to solve — our products ensure users can send encrypted emails in Gmail or Outlook without creating a new account. We have many other products coming soon, but that’s the core of what we do.
How does encryption come into play with chatbots and AI assistants?
Encryption itself is just a tool, but the true end-goal is protecting information. Information is only valuable if it’s shared. Say I write my autobiography and want an AI assistant to help summarize it. The AI needs access to that information, but if I give it unrestricted access, it will also process information I might not want included.
AI has dramatically increased our ability to process information. It can analyze enormous amounts of data in minutes, which means organizations need much better control over what those systems can actually see. Today, the only practical way to do that is to separate the information manually. We’re working toward allowing people to label or tag portions of information so only the appropriate content is accessible to AI, while protected information remains encrypted and invisible. Ultimately, it’s about giving people control over what AI is allowed to access.
How product teams are thinking about data
What mistakes do you see product teams make when incorporating encryption into their products?
In my view, the ideal scenario for encryption and decryption is that it’s completely invisible. The biggest mistake is making security so restrictive that information can’t be shared, because Information that’s never shared isn’t useful. I’ve heard this repeatedly from customers in the intelligence and defense communities.
One example people often reference is that multiple organizations each had pieces of intelligence before the September 11 attacks. Because the information wasn’t shared effectively, no one assembled the complete picture.
Organizations already classify information as public, internal, or confidential. The next step is enforcing those classifications. Today, someone can accidentally send a highly confidential document outside the company. Product experiences should help prevent those mistakes by enforcing the policies that organizations already have.
AI systems are fundamentally data-hungry, but organizations are becoming more cautious about where sensitive data flows. How does that change product design?
AI changes one of security’s long-standing assumptions. Historically, teams could grant broad access and revoke it later if something went wrong. That approach doesn’t work with AI. Once an AI system has processed information, you can’t undo that. There’s no way to put the toothpaste back into the tube. Instead, product teams need to start with the minimum access possible and expand permissions only when necessary. That requires much more deliberate security thinking early in the design process.
Building customer trust through transparency
Are there certain industries where this becomes even more important, such as healthcare or finance?
Yes — there’s a push-and-pull model. Imagine a large pool of information that I’m dumping all my data into. It’s still my pool, but I’m letting an AI model that’s been trained by someone else, such as Anthropic, OpenAI, Google, or another company, come along, swim in it, and walk away with all the information inside it.
More and more, the approach is shifting away from giving AI all of your information. Instead, it’s, “Come and swim in my pool, but here’s the lane you can swim in. Everything else is off limits.” That’s where I believe things are headed. Rather than simply giving AI models access to our data, we’re inviting them in, creating structures, and setting boundaries that define what they can and can’t access. There are already companies specializing in creating those boundaries. From our perspective, if you’ve already segmented your information, you can build on that and use those segments to define exactly what the AI model is allowed to use.
Are there specific product decisions that can either erode or strengthen customer trust regarding data security and privacy?
One of the biggest trust-builders is transparency. Show people exactly what information is being collected, why you need it, and how it’s being used. Regulations like GDPR and state privacy laws increasingly require companies to disclose those practices, but organizations that go beyond compliance and are upfront about data use build much stronger customer trust.
Another important factor is relying on open standards and open source software. With closed-source systems, you’re effectively asking customers to trust that you’ve implemented security correctly. For example, Anthem was hacked in 2015, although it was only disclosed a few years ago. It was one of the largest data breaches ever seen, with nearly 80 million people’s health records exposed. When incidents like this happen, the question becomes, “Well, did you not know that there was someone in your system snooping around? Is your software safe enough?”
When you use open source software, you’re basically saying, “Here is the source code that we’re running, check it out.” You can actually go in and look at it. When software is open, people can inspect it, identify issues, and improve it.
Our own software is based on open standards, and we run bounty programs that reward people for finding security issues. That openness creates confidence because security isn’t based on “trust me” — it’s validated by the community.
I also think AI is changing how companies think about competitive advantage. Writing code is no longer the differentiator it once was. AI can generate code extremely well, so I foresee a shift where the real value comes from designing great user experiences, providing excellent support, solving meaningful customer problems, and building products people trust.
For organizations evaluating an encryption platform, what questions should they ask?
One thing people forget is that companies don’t last forever. When you’re choosing an encryption or data security partner, you should ask what happens if that company disappears, gets acquired, or you simply decide to stop using the product. Can you still access your data?
There are the three questions I recommend organizations or individuals always ask:
Who controls the keys?
Is the encryption format open and documented?
What happens to my data if I stop using your product?
The first question about who controls the encryption keys is related to access. If the vendor controls the keys, they ultimately control access. In our case, we have solutions that encrypt information, but we can’t decrypt it ourselves. Customers retain that control.
The second question is whether the encryption format is documented and based on open standards. If it’s proprietary, you’re dependent on that company forever. If it’s open, you have options even if you eventually move away from the platform.
The third question is about offboarding. If you leave the product, what’s the process for getting your data back? Can you still decrypt it? Can you still use it?
Ultimately, our mission isn’t solely about encryption. It’s about helping create a world where data remains under your control wherever it goes. Encryption is simply the tool we’ve chosen to achieve that goal. The objective isn’t to make security something users constantly think about. It should work in the background, protecting information without getting in the way of people doing their jobs.
What does LogRocket do?
LogRocket’s Galileo AI watches user sessions for you and surfaces the technical and usability issues holding back your web and mobile apps. Understand where your users are struggling by trying it for free at LogRocket.com.


