Breaking
BASEFRAME (YC W26) — San Francisco, 2 founders, backed by Y Combinator PIVOT: from hardware copilot to Clam, a Semantic Firewall for AI agents SEED: $130K raised via YC Winter 2026 FOUNDERS: Anshul Paul & Vaibhav Agrawal, Berkeley roommates CLAM: scans every AI message for leaks, injections & malicious code BASEFRAME (YC W26) — San Francisco, 2 founders, backed by Y Combinator PIVOT: from hardware copilot to Clam, a Semantic Firewall for AI agents SEED: $130K raised via YC Winter 2026 FOUNDERS: Anshul Paul & Vaibhav Agrawal, Berkeley roommates CLAM: scans every AI message for leaks, injections & malicious code
Company Profile ·Y Combinator W26 ·Artificial Intelligence

BaseFrame Built Three Products in One Batch. The Winner Was a Firewall for AI.

Two Berkeley roommates started with an AI copilot for hardware engineers. They ended the batch with Clam - a security checkpoint that stands between broad-access AI agents and your data. This is the story of shipping until the market answers.

The pitch that got BaseFrame into Y Combinator was about circuit boards. The company that walked out of the Winter 2026 batch was about something else entirely - keeping AI agents from leaking your data. In between, there were three products. That churn is not a footnote to the story. It is the story.

BaseFrame was started in San Francisco by Anshul Paul and Vaibhav Agrawal, who met in their first week of college at UC Berkeley and became roommates. Before founding the company, Paul was a founding engineer at HappyRobot, where he worked on AI evaluations, observability, and enterprise integrations as the company grew from Seed to Series B. Agrawal worked on data-ingestion infrastructure at Sigma Computing and on remote-agent orchestration at Augment Code, after a fellowship at Sutter Hill Ventures. Two engineers who had spent their careers making AI work inside real companies decided to build one of their own.

2
Founders / full team
W26
Y Combinator batch
$130K
Seed raised
3
Products shipped in one batch

Where it startedCatching the mistake before the board

The first version of BaseFrame aimed at hardware teams. The founders had noticed that hardware development runs on a sequence of handoffs that can go quietly wrong: a team finalizes a design, sends it to procurement, and finds out weeks later that there was an oversight, or that a critical component carries a long lead time. By then the mistake is expensive.

BaseFrame put AI agents on the front of that process. Specialized agents would scope a project by asking questions and drilling down when answers were thin, then run validations in parallel to surface contradictions and gaps. From there the system generated a Bill of Materials - parsing datasheets, pulling pricing and lead-time data from vendors, and letting engineers branch designs to compare architectures on cost and timing. The tagline was plain: bring confidence and clarity to hardware designs, and catch fatal mistakes while they are still cheap to fix.

The current hardware workflow is a broken sequence of handoffs. - BaseFrame launch note

The second swingReading the work to find the automation

The next incarnation of BaseFrame moved away from hardware and toward a problem nearly every team has: they want to use AI but do not know where to point it. BaseFrame's answer was to stop guessing and start reading. A desktop app analyzed a team's own history - email, documents, Slack, calendar, browser activity, files - and used that record of how work actually got done to recommend the highest-value automations, which could then be exported to whatever automation tool a team already used.

One design choice stood out. Rather than screen-recording employees or relying on generic demos, BaseFrame ran local AI models, so sensitive data did not have to leave the machine it lived on. That instinct - powerful AI, but kept close to the data - would become the whole company in the third act.

Most teams want to plug in AI but don't know where to get started. - BaseFrame

Where it landedClam, and a firewall for meaning

In February 2026, the company launched Clam. The framing is direct: broad-access AI agents - the kind that can touch your accounts, your files, and the open internet - are useful precisely because they can do a lot, which is also exactly why they are frightening. Data leaks tied to such agents have already happened. Enterprises and individuals alike hesitate to hand over the keys.

Clam calls its approach a Semantic Firewall: a security checkpoint that sits around the AI's environment at the network level, rather than trying to police the model from the inside. Everything an agent sends out and everything that comes back gets scanned for trouble before it can turn into a problem.

AI AGENT broad access CLAM SEMANTIC FIREWALL THE WORLD apps · data · web every message in and out is scanned before it passes
Standing at the door. Clam does not live inside the model. It wraps the agent's environment, checking traffic in both directions - the bouncer who reads every note before it leaves the building.

The scans look for three families of trouble. Personal-information leaks, like Social Security numbers, credit-card numbers, and private keys. Prompt-injection attempts, like jailbreaks and instruction overrides. And malicious code, like reverse shells and encoded execution. To keep credentials out of harm's way entirely, Clam injects API keys and secrets at the network level, so the AI never sees or stores them.

Personal info leaksSSN · cards · keys
Prompt injectionjailbreaks · overrides
Malicious codereverse shells · exec
Credential exposurekeys injected at network
Illustrative view of the threat categories Clam's Semantic Firewall inspects on each message. Bars are for illustration, not measured benchmarks.

Who it's forPeople holding the keys they don't want to hand over

The customer for Clam is anyone standing at that hesitation point: an enterprise that wants agents doing real work across its systems but cannot accept the leak risk, or an individual who has heard the horror stories and has not yet connected an agent to their accounts. The founders have said, plainly, that they want to talk to people who have already set up broad-access agents and to those who have held back because of the security questions.

The through-lineThree products, one obsession

It would be easy to read BaseFrame's path as indecision. Read it more carefully and a single thread runs through all three products: make powerful AI safe and useful in the messy conditions of real work. The hardware copilot caught costly mistakes before they shipped. The automation finder kept sensitive data on local machines while pointing AI at real tasks. Clam sits between an agent and the world so the agent can act without becoming a liability. Different surfaces, same instinct.

2025
BaseFrame is foundedBerkeley classmates Anshul Paul and Vaibhav Agrawal start the company in San Francisco.
Jan 2026
Into YC Winter 2026Backed by Y Combinator with a $130K seed; partner Gustaf Alstromer.
Jan 2026
Hardware copilot launchAI agents scope designs, run validations, and generate Bills of Materials.
Early 2026
Automation-discovery pivotA desktop app finds what AI can automate from a team's own work history, using local models.
Feb 2026
Clam and the Semantic FirewallEnterprise-grade security for broad-access AI agents, launched at tryclam.com.

There is a small irony worth noting. Paul and Vaibhav were lab partners in a Computer Security course at Berkeley years before any of this. The company they eventually built - after a hardware copilot and an automation finder - is a security company. Sometimes the market takes a while to route you back to the thing you already knew.

A security checkpoint that sits around the AI's environment at the network level. - How Clam describes the Semantic Firewall

Where it fitsThe new market for agent guardrails

Clam is early, and it is entering a category that is forming in real time: guardrails and governance for AI agents. As agents get more autonomy and more access, the question of what stands between them and the systems they touch becomes a product in its own right. BaseFrame's wager is that the answer belongs at the network layer, watching meaning move in and out, rather than trusting a model to police itself. For a two-person team, it is a large bet. It is also, by their own account, the one the market pulled hardest on.

The Fast Facts
  • CompanyBaseFrame (now building Clam)
  • BatchY Combinator, Winter 2026
  • HQSan Francisco, California
  • Founded2025
  • Team2 (Anshul Paul, Vaibhav Agrawal)
  • Seed$130,000
  • NowClam - Semantic Firewall for AI agents

Go deeperLinks & sources

AIYC W26AI Security AI AgentsSemantic FirewallOpenClaw Developer ToolsEnterpriseSan Francisco StartupY Combinator