1. The Landscape
~50 YC-funded security startups, from to . They cluster into 8 clear categories:
| Category | Count | Companies |
|---|---|---|
| AI Pentesting / Vuln Scanning | 8 | Hex, Veria, MindFort, Casco, Gecko, winfunc, ZeroPath, Corgea |
| Compliance Automation | 5 | Probo, Delve, Oneleet, Agency, Clearly AI |
| AI Agent Security | 5 | Multifactor, ContextFort, Alter, Golf, PromptArmor |
| Data Protection / DLP | 4 | Strac, CompliantLLM, Repacket, Adri AI |
| Monitoring / SIEM | 4 | Matano, Cotool, Haleum, SubImage |
| Auth / Identity | 3 | Better Auth, Firezone, Roundtable |
| Deepfake Detection | 2 | Reality Defender, Aedilic |
| Secrets Management | 1 | Infisical |
| AI-Native Code Security | 1 | Corridor |
Key observation: AI pentesting is absurdly crowded — 8 companies doing essentially the same thing with VC money. Meanwhile, proven boring categories like compliance and secrets management have fewer players.
2. Full Company List
W2026 Batch (4 companies)
- Crosslayer Labs
- Detects impersonation attacks on websites and APIs through "outside-in" DNS/BGP/TLS monitoring.
- BeeSafe AI
- Fraud prevention platform targeting trust-based attacks like pig butchering scams.
- Hex Security
- AI agents running continuous penetration tests 24/7 using reinforcement learning.
- Protent
- Real-time video intelligence identifying escalating incidents.
F2025 Batch (3 companies)
- Kestrel AI
- AI-native cloud incident response platform with self-healing capabilities for Kubernetes.
- Veria Labs
- AI agents discovering complex vulnerabilities in software and crypto systems.
- Multifactor
- Authentication and authorization for agentic systems with fine-grained controls.
S2025 Batch (3 companies)
- ContextFort
- Chrome extension providing visibility into AI browser agent activities and data leakage prevention.
- GhostEye
- Simulates personalized attacks across email, voice, SMS, and deepfakes for security awareness.
- Alter
- Zero-trust identity platform for AI agents with parameter-level verification.
X2025 Batch (8 companies)
- Probo
- Compliance automation handling documentation, controls, and audit evidence for SOC 2 / ISO 27001.
- Casco
- Autonomous security testing for web apps, APIs, and AI systems.
- Theorem
- Training models to accelerate program verification for secure code.
- MindFort
- Autonomous AI agents finding and exploiting web application vulnerabilities.
- Cotool
- Agentic platform automating alert triage and investigation for security teams.
- Golf
- Visibility and control platform for shadow AI and AI agent usage in organizations.
- Better Auth
- TypeScript authentication framework with bot and fraud detection. Open source.
- Tinfoil
- Privacy-preserving AI workload deployment using confidential computing hardware.
W2025 Batch (2 companies)
- Haleum
- AI monitoring communication channels for fraud and insider threat detection.
- SubImage
- Infrastructure mapping tool providing asset visibility and relationships.
F2024 – S2024 Batch (5 companies)
- Gecko Security (F2024)
- AI vulnerability finder simulating attacks and verifying exploitability.
- winfunc (S2024)
- AI hacker autonomously finding and patching code vulnerabilities.
- Clearly AI (S2024)
- Automates security and privacy reviews using AI in minutes.
- ZeroPath (S2024)
- Developer tool detecting and fixing vulnerabilities autonomously.
- Unbound (S2024)
- Security platform focusing on privacy and data protection.
W2024 Batch (4 companies)
- Aedilic
- Open-source software detecting AI-generated images and deepfakes.
- Delve
- AI compliance platform for SOC 2, HIPAA, ISO 27001, GDPR frameworks.
- PromptArmor
- Security for generative AI applications, preventing prompt injection.
- Superagent
- Red team testing and safety validation for AI applications.
W2023 – S2023 Batch (10 companies)
- CompliantLLM (W2023)
- Detects data leaks into third-party GenAI tools used by employees.
- Metalware (S2023)
- Firmware security solutions with automated binary fuzzing for critical infrastructure.
- Corgea (S2023)
- Autonomous application security finding and generating code fixes.
- Roundtable (S2023)
- API detecting bots and verifying human identity invisibly.
- Variance (W2023)
- Unified API for safety technologies combining fraud and security tools.
- Escape (W2023)
- AI-powered API security discovering vulnerabilities including business logic flaws.
- Adri AI (W2023)
- Monitors AI vendor infrastructure to prevent proprietary data misuse.
- Infisical (W2023)
- Open-source secrets management with versioning, rotation, and audit logging.
- Repacket (W2023)
- Employee endpoint protection blocking phishing and data leaks.
- Matano (W2023)
- Modern cloud-first SIEM built on a cost-effective Security Data Lake.
Non-YC — Notable Competitors
- Corridor (Seed, 2025 — backed by Conviction)
- AI-native code security. Instead of scanning code after it is written, Corridor embeds security at the code generation stage — securing AI-assisted development in real time. Founded by Jack Cable and Ashwin Ramaswami (both ex-CISA), with Alex Stamos (ex-Facebook CISO) as CSO. $5.4M seed round. Early customers include Cursor, Mercury, and GreyNoise.
W2022 – S2022 Batch (9 companies)
- Overwatch (S2022)
- Real-time intelligence for fraud, security, and risk decision-making.
- Oneleet (S2022)
- All-in-one compliance and security automation combining tools and expertise.
- Reality Defender (W2022)
- Deepfake detection platform flagging fraudulent content and users.
- Cinder (W2022)
- Digital safety orchestration and automation at scale.
- Bunkyr (W2022)
- Hardware-secured API enabling password recovery for encrypted data.
- Firezone (W2022)
- Zero Trust Access VPN using least-privileged access policies. Open source.
- Strac (W2022)
- Agentless data discovery, classification, and DLP across SaaS and cloud.
- Agency (W2022)
- Multi-party compliance platform for SOC 2, ISO 27001, CMMC standards.
- Munily (W2022)
- Community access control and visitor management via app and tablet.
3. Category Clusters
AI Pentesting / Vulnerability Scanning (8 companies — most crowded)
Hex, Veria Labs, MindFort, Casco, Gecko Security, winfunc, ZeroPath, Corgea
All doing variations of "AI finds and/or fixes vulnerabilities in your code." Reinforcement learning, autonomous agents, auto-patching — the buzzwords overlap almost entirely. This is an arms race funded by VC money. Not a bootstrapper's game.
Compliance Automation (5 companies — proven market)
Probo, Delve, Oneleet, Agency, Clearly AI
SOC 2, ISO 27001, HIPAA, GDPR. Companies are legally required to buy this. Incumbents like Vanta charge $10–25k/year. The demand is real, recurring, and non-optional.
AI Agent Security (5 companies — speculative)
Multifactor, ContextFort, Alter, Golf, PromptArmor
Securing AI agents, preventing prompt injection, monitoring shadow AI. The category might be huge. Or it might not exist in 2 years. Too early to bet on as a bootstrapper.
Data Protection / DLP (4 companies)
Strac, CompliantLLM, Repacket, Adri AI
Preventing data leaks — especially into GenAI tools. Real problem, enterprise buyers.
Monitoring / SIEM (4 companies)
Matano, Cotool, Haleum, SubImage
Security monitoring and incident response. Complex infrastructure, long enterprise sales cycles.
Auth / Identity (3 companies)
Better Auth, Firezone, Roundtable
Authentication, zero-trust access, bot detection. Better Auth is notable as an open-source TypeScript auth framework — developer tools with community adoption.
Deepfake Detection (2 companies)
Reality Defender, Aedilic
Requires massive ML investment. Not a small-team play.
Secrets Management (1 company)
Infisical
Open source, developer-friendly, proven model. Infisical has real traction with their open-source-first approach.
AI-Native Code Security (1 company — new category)
Corridor
A different angle from the 8 AI pentesting companies above. Instead of scanning code after it is written (reactive), Corridor embeds security at the code generation stage (proactive) — securing AI-assisted development as it happens inside tools like Cursor.
Founded by two ex-CISA employees (Jack Cable & Ashwin Ramaswami), with Alex Stamos (ex-Facebook CISO) as CSO. $5.4M seed from Conviction. Early customers: Cursor, Mercury, GreyNoise.
DHH filter verdict: Impressive team and positioning, but this is a VC play — big names, enterprise customers, $5.4M raised before revenue clarity. The "secure by design" approach is genuinely differentiated from the reactive scanners, but it requires deep integration with AI coding tools and enterprise sales. Not a bootstrapper's game. However, it validates that the "security for AI-assisted development" wave is real — and a simpler, productized version of this insight could be bootstrapped (e.g., a simple code review service for AI-generated code, sold per repo).
4. Applying the DHH / Jason Fried Filter
The rules:
5. Categories to Skip
| Category | Why Skip |
|---|---|
| AI Pentesting | 8 VC-funded companies in an arms race. You cannot out-spend them. Skip. |
| AI Agent Security | Too early. Nobody knows if this market is real yet. Skip. |
| SIEM / Monitoring | Enterprise sales cycles, complex infrastructure to maintain. Skip. |
| Deepfake Detection | Requires massive ML/compute investment. Not a small-team play. Skip. |
| DLP / Data Protection | Enterprise-only buyers, long sales cycles. Skip. |
| AI-Native Code Security (Corridor) | VC-funded ($5.4M), elite team (ex-CISA, ex-Facebook CISO), enterprise customers (Cursor, Mercury). Genuinely differentiated from scanners, but requires deep integrations and enterprise sales. Skip as product. But: validates demand for "security for AI-generated code" — sellable as a service. |
6. What Survives the Filter
Option 1: Compliance Automation — the #1 pick
Why: Companies are legally required to buy this. SOC 2, ISO 27001, HIPAA — it is not optional. Vanta charges $10–25k/year. Drata, Secureframe, same range. 5 YC companies in this space = proven demand.
The DHH play:
- A self-serve, no-BS compliance tool at $200–500/month for small startups who cannot afford Vanta.
- No sales team. No enterprise features.
- Just "get SOC 2 done."
- People already search for "cheap Vanta alternative."
Option 2: Phishing Simulation / Security Training
Why: GhostEye does this at YC. KnowBe4 was acquired for $4.6 billion. Every company with >10 employees needs this for compliance.
The DHH play:
- Dead simple phishing simulation.
- Send fake phishing emails to your team, get a report.
- $50–100/month per company.
- No AI agents, no deepfake simulation. Just the basics that check the compliance box.
Option 3: Secrets Management (self-hosted)
Why: Infisical proved the model with open source.
Many companies want something even simpler — just a .env manager with audit logs and rotation.
The DHH play:
- Simple hosted secrets manager.
- $20/month per team.
- No enterprise bells and whistles.
Option 4: Pentesting-as-a-Service (productized)
Why: Not an AI platform. A productized service:
I will scan your app and send you a report for $500.
Use existing tools (Burp Suite, nuclei, etc.) + your own skill + AI to deliver fast.
The DHH play:
- No product to maintain. Pure margin.
- Sell on LinkedIn.
- Deliver in 24–48h.
- $500–2000 per engagement.
7. The Street-Smart Verdict
| Option | SNOLOC | TTFP | Recurring? | Bootstrap Score |
|---|---|---|---|---|
| Pentesting service | ~0 (it is a service) | Days | Per gig | |
| Compliance tool | Medium | Weeks | Monthly | |
| Phishing simulation | Low | Weeks | Monthly | |
| Secrets manager | Medium | Weeks | Monthly |