Breaking
GOLF (YC X25) builds the security layer for AI agents and MCP servers DEPLOY TIME cut from 2-4 weeks to under 60 seconds SHADOW AI is the new shadow IT and Golf makes it visible SOC 2 TYPE II certified; 40+ SIEM & identity integrations FOUNDERS two dropouts building together since age 14 GOLF (YC X25) builds the security layer for AI agents and MCP servers DEPLOY TIME cut from 2-4 weeks to under 60 seconds SHADOW AI is the new shadow IT and Golf makes it visible SOC 2 TYPE II certified; 40+ SIEM & identity integrations FOUNDERS two dropouts building together since age 14
Company / AI Infrastructure

Golf Wants to Govern the AI Agents You Didn't Build

A Y Combinator (X25) startup started as an open-source framework for shipping MCP servers. Then it discovered a bigger, scarier problem: nobody could see what their AI agents were touching.

Ask a security team a simple question in 2026 and watch them squirm: how many AI agents are connected to your production systems right now, and what can each one actually do? Most cannot answer. Not because they are careless, but because the tools that keep the rest of the stack honest, the SIEMs and DLP scanners and identity providers, were built for humans and services. They were not built for a swarm of agents that a developer wired up over lunch with a copy-pasted config. That blind spot is the business Golf decided to build inside of.

Golf, a company in Y Combinator's Spring 2025 batch, sells a plain idea: if AI agents are going to act on your data, someone should be able to see them, govern them, and prove later what they did. The company runs its own one-line summary on the front page, and it lands harder than most marketing copy: "Your gateway has a blind spot. It's every agent you didn't build."

"Golf gave us governance for AI tools we don't control. That's the actual problem nobody else was solving." Head of AI, Enterprise Software Company

01 / THE WEDGEIt started as a favor to developers

Before Golf was a firewall it was a framework. The founders, Wojciech Blaszak and Antoni Gmitruk, noticed that building a production MCP server, the Model Context Protocol server that lets an AI agent call your tools, was a slog of undifferentiated plumbing. Routing. Auth. Telemetry. Error reporting. Deployment. So they wrote GolfMCP, an open-source Python framework with a file-based structure. You write the tools, prompts, and resources you want agents to call. Golf handles the rest. No decorators, no spec knowledge, no boilerplate.

The pitch that got attention was a number. What normally took a team two to four weeks to push into production, GolfMCP could do in under sixty seconds. That is the kind of before-and-after that spreads on its own, and the open-source traction became the company's way into rooms it could not have booked otherwise.

What makes the framework useful is what it refuses to make you think about. An MCP server needs authentication, observability, a debugger, telemetry, and a runtime, and each of those is a place where a hurried team ships something insecure and only finds out later. GolfMCP ships them as defaults. A developer defines a tool in a Python file, the way you would write any small function, and the server that goes to production already has the operational scaffolding a security reviewer would otherwise flag. The framework, in other words, was the first version of the security product. It just did not announce itself that way.

<60s
To ship a production MCP server
<1ms
Policy enforcement latency
40+
SIEM & identity integrations

02 / THE PROBLEMShadow AI, meet the audit team

Here is the shape of the problem Golf grew into. A company buys or tolerates a dozen agentic tools, Cursor, Claude Code, GitHub Copilot, ChatGPT Enterprise, Windsurf, and each one quietly opens MCP connections into codebases, databases, and internal systems. None of that traffic passes through the AI gateway the company bought to feel safe, because that gateway only governs the models the company itself deployed. The agents someone else built are invisible to it. Multiply that by every team and you have shadow AI: the same governance gap as shadow IT, except this time the software does not just read your data, it takes actions on your behalf.

WHERE GOLF SITS Cursor Claude / Copilot ChatGPT Ent. GOLF · MCP layer discover · enforce · audit Databases Codebases Internal APIs
The whole bet in one picture: Golf plants itself one layer below the model, where the actual connections live, so agents nobody deployed still have to pass through it.

03 / THE PRODUCTDiscover, enforce, audit

Golf's platform is organized around three verbs, in an order that matters. First it discovers every agent, MCP server, and data connection in the organization, including the shadow infrastructure nobody logged. Then it enforces granular policies per tool, per team, per data source, blocking PII exposure, credential leaks, and prompt injection before they reach an agent, all at sub-millisecond latency so it does not become the thing that slows everyone down. Finally it audits, keeping 90-day trails of prompts, actions, and data access, pre-mapped to SOC 2, ISO 27001, NIST AI RMF, and FINRA so a compliance team can export evidence instead of reconstructing it.

The three-pillar control plane
Step 01

Discover

Find every agent, MCP server, and data connection, including shadow AI that bypassed the gateway.

Step 02

Enforce

Granular policies per tool and team. Block PII, credentials, and injections in under a millisecond.

Step 03

Audit

90-day trails pre-mapped to SOC 2, ISO 27001, NIST AI RMF, and FINRA for one-click evidence.

The design choice underneath all of it is that Golf does not try to control the model. It does not change how a developer works or which assistant they open. It streams to the SIEM the company already runs, plugs into the identity provider already in place, Okta, Azure AD, Google Workspace, and governs at the protocol layer instead of picking a fight with the LLM. That is a quieter product than a flashy AI wrapper, and it is the reason a security team can say yes.

Traditional AI security bolts a dashboard onto the model. Golf went the other direction and secured the protocol underneath the agents.

04 / THE FOUNDERSTwo dropouts and a very long friendship

Golf is run by two people who have been building together since they were fourteen. Wojciech Blaszak, the CEO, scaled his first company to $200k in revenue as a teenager. Antoni Gmitruk, the CTO, built a fully automated 3D printer at fifteen. Both left university after a single semester to work on Golf full-time, and both had already spent time on AI products and agent infrastructure before it, an AI SDR here, agent plumbing there. The naming is on-brand in a way you either find charming or do not: the company is called Golf, and the founders were spotted networking at Topgolf during the batch.

Deploy time: before & after Golf
Hand-rolled
2-4 weeks
With GolfMCP
< 60 seconds
Not to scale, and it doesn't need to be. The gap between a month of plumbing and a minute is the entire reason developers tried GolfMCP in the first place.

05 / THE MARKETSelling to the people who can't sleep

Golf's business model reads like a textbook open-source-to-enterprise motion. The free framework wins developers and builds trust. The hosted gateway and the enterprise firewall are what companies pay for, sold through demos to the verticals that feel agent risk most acutely: financial services, fintech, healthcare, and enterprise software. The timing is not an accident. FINRA is drafting rules on prompt logging and human-in-the-loop for 2026. The EU AI Act threatens penalties up to 7% of global annual revenue for high-risk AI without oversight. Golf is, in effect, building the audit trail companies will be required to have before many of them realize they need it.

The company is small, roughly nine people, and young, with SOC 2 Type II already in hand and multiple enterprise customers live in its first year. It sits in a crowded neighborhood, AI gateways, LLM guardrail vendors, DLP and CASB tools stretched to cover AI, but Golf's answer to "why you" is consistent: those tools govern what you deployed, and Golf governs what you didn't.

Who actually buys this is worth being precise about, because "enterprise AI security" is a phrase that means everything and therefore nothing. Golf's users split into two groups that feed each other. On one side are the developers who pick up GolfMCP to ship a server without wiring plumbing, the people who file issues and star the repo. On the other are the buyers: a Head of AI, a security lead, a compliance owner at a bank or a hospital or a software company, someone who has been handed responsibility for a fleet of agents they did not choose and cannot fully see. The framework earns the first group's trust. The firewall answers the second group's fear. It is the same product told at two altitudes.

There is a version of the next few years where a typical knowledge worker runs a dozen agents that read, write, and act across internal systems without a human in the loop for most of it. If that world arrives, the question Golf is asking, who is connected, what are they allowed to do, and can you prove it afterward, stops being a niche security concern and becomes basic operating hygiene. Golf is making an early, specific bet on being the place that answer lives. It is a young company with a narrow wedge and a large adjacent problem, which is usually where the interesting outcomes start.

#mcp#ai-agent-security#agentic-ai#mcp-gateway #ai-governance#shadow-ai#developer-tools#open-source #yc-x25#enterprise-security#compliance#soc2