Somewhere in a mid-sized company right now, an engineer is emailing a chunk of source code to a personal Gmail address. Maybe they want to work over the weekend. Maybe they are three weeks from resigning and quietly building a leaving present for a competitor. To the average data loss prevention tool, both actions look identical - a file crossing a boundary - and both get logged into the same overflowing queue of alerts nobody has time to read. That gap, between what a tool sees and what actually matters, is the entire reason Candor exists.
Candor is a San Francisco cybersecurity startup in Y Combinator's Winter 2025 batch. It builds what the founders call agentic data loss prevention and insider risk management. The short version: its AI agents don't just watch the data move, they try to understand the person doing the moving, and then hand security teams a single useful answer - here is who you should be watching, and here is why.
01 / THE PROBLEMThe alert that everyone ignores
Legacy data loss prevention has a reputation problem inside security teams. It is very good at one thing - satisfying an auditor. It can cross off a compliance checkbox and produce a tidy report. What it is bad at is the actual job. Because it works off static rules and pattern matching, it flags an enormous number of things that turn out to be nothing: the finance analyst legitimately exporting a spreadsheet, the designer sharing a mockup with an agency, the developer pushing to a repo. Each false alarm is cheap on its own. Multiply it across a company and you get alert fatigue, a state where the signal that matters is buried under thousands that don't.
Legacy DLP tools can cross off compliance checkboxes but flood security teams with false positives.Candor, on the tools it wants to replace
The founders arrived at this the unglamorous way. Before writing much product, they embedded themselves as investigators inside medium and large companies, sitting with the analysts who chase these alerts. The lesson they took away was that the missing ingredient was almost always context. A file leaving the building means nothing without knowing who is carrying it, what they normally do, and whether anything about the situation has changed.
02 / THE APPROACHWatch the person, not just the file
Candor's bet is that the interesting unit of security is not the document, it is the human. Its agents fuse two signals that most tools keep in separate silos: the movement of sensitive data, and the identity and behavior of the person behind it. A contractor quietly staging files in a folder before their engagement ends reads very differently than the same files touched by a full-time employee mid-project. An account suddenly feeding confidential material into an AI copilot is a different story than routine use. Candor is built to stitch those threads into something a human can act on.
How Candor reframes an alert
Two words the company keeps repeating are worth pausing on: zero tuning. Traditional enterprise security tools often need months of configuration before they earn their keep - policies written, thresholds set, exceptions carved out. Candor's pitch is that detection should work on day one and get sharper on its own, learning from the feedback analysts give it rather than from a rulebook a human has to maintain. Whether that holds at large scale is the kind of claim that gets tested in production, but it is a clear philosophical line: if a security tool needs a quarter of babysitting before it works, it has already failed the team.
The false-positive problem, illustrated
03 / THE PEOPLEThree founders, a lot of logos
Candor is small - three to five people - and young. The founding team's resumes read like a tour of places that care about not leaking things: NASA, Uber, JPMorgan, AMD, and the low-code startup Flutterflow. CEO Adarsh Ambati is a Stanford class of 2025 founder who left to build the company. Ansh Gupta is the CTO. Aditya Iyengar, the third co-founder, did engineering stints at Flutterflow, Uber, and NASA.
There is a small detail that tells you something about the company's willingness to change its mind. Candor did not start as Candor. Its earliest identity was Haleum - a name that still lives on in the company's original LinkedIn handle. Somewhere between founding in 2024 and the W25 batch, the team renamed and narrowed its focus onto insider risk. Startups often treat a rename as a scar to hide. Here it reads more like a decision: pick the sharper name for the sharper problem.
Candor's AI agents understand both the data movement and the person behind it, giving lean security teams broad coverage without the noise.The company's core promise
04 / THE MARKETWhere Candor sits
Data loss prevention and insider risk is a crowded, well-funded corner of security. The incumbents range from Microsoft's Purview to Forcepoint, Broadcom's Symantec line, Code42's Incydr, DTEX, Cyberhaven, and Nightfall. Most of them are either heavyweight compliance platforms or point tools. Candor's wedge is not to out-feature them, it is to change the question - from "what should I block?" to "who should I watch?" For a lean security team that cannot afford a dedicated tuning engineer, an answer shaped like a name is more useful than a dashboard shaped like a firehose.
The early customer picture points at high-stakes industries - defense, energy, and biotech - where protecting intellectual property and customer trust is not a nice-to-have but a condition of doing business. These are companies where a single leaked design or dataset can cost a contract, which makes them natural first buyers for a tool that promises to surface the real threat early. Candor has not published a customer roster, which is normal for a company at this stage.
05 / THE STAKESWhy any of this matters
The numbers Candor points to are the ones that keep security leaders up at night. Insider incidents are expensive, roughly $17.4M a year for the average large enterprise by the figure the company cites, and slow, often taking around three months to contain. The reason they are slow is precisely the reason Candor thinks it has an opening: the threat is already inside, already trusted, and already generating log entries that look like everyone else's. Finding it is less about building a taller wall and more about reading the room.
That is the whole thesis in a sentence. Context beats baselines. Candor is early, unproven at scale, and competing in a category full of well-resourced names. But the framing is clean, the problem is real, and the founding team went and lived inside the problem before deciding what to build. In a field that often sells fear, a company selling better signal is at least aiming at the right target.