Breaking
$15M SEED Nexus Venture Partners leads Multifactor's round, Dec 2025 YC F25 Backed by Y Combinator's Fall 2025 batch LAUNCH Free account manager live at multifactor.com PROOF $1M corporate account behind a public read-only link FOUNDERS Ex-CIA cyber officer + former NASA cryptographer $15M SEED Nexus Venture Partners leads Multifactor's round, Dec 2025 YC F25 Backed by Y Combinator's Fall 2025 batch LAUNCH Free account manager live at multifactor.com PROOF $1M corporate account behind a public read-only link FOUNDERS Ex-CIA cyber officer + former NASA cryptographer
Company Security · AI Agents · YC F25

Multifactor Wants to Share Your Bank Login Without the Password

A former CIA cyber officer and an ex-NASA cryptographer built an account manager for the age of AI agents. Their bet: the safest secret to hand over is the one that never leaves your hands.

The pitch sounds like a security breach waiting to happen. Sometime late in 2025, the founders of Multifactor put their company's own corporate bank account - roughly a million dollars - behind a link, made it public, and rented a billboard in Times Square to point people toward it. The link was read-only. Anyone could look. Nobody could touch. That distinction is the entire company.

Multifactor, a San Francisco startup in Y Combinator's Fall 2025 batch, is built on a stubborn observation: the password was designed for a world where only humans logged in, and that world is quietly ending. AI agents now book travel, move money, file expenses, and read inboxes. The instant you give one of them a password, you have handed over everything the password unlocks, forever, with no way to watch what it does or take it back. Multifactor's answer is to stop sharing the secret at all.

The Idea

A login that works like a Google Doc

The company's core move is easy to describe and harder to build. Instead of copying a password from one person - or one agent - to another, Multifactor turns any online account into a shareable link with granular permissions attached. You can grant read-only access. You can restrict a share to a single feature. You can cap it to a dollar amount. And you can revoke the whole thing in one click, no password reset required.

If that mechanic feels familiar, it should. It is the way Google Docs has worked for years: you send someone a view-only link, and they never learn your Google password. Multifactor extends that same logic to a bank account, an email inbox, a calendar, a social profile, an internal business tool. The credential stays put. What travels is permission.

Old way vs. Multifactor
🔑
You share the password
👀
They can do anything, forever
No log, no easy revoke
🔗
You share a link
👁
Read-only, feature, or dollar limits
Signed audit log, one-click revoke
Same button, different physics. The password model hands over the keys. Multifactor hands over a view, and keeps a receipt of everything that happens on the other side.

"Passwords were never built for the agentic era. Multifactor is the easiest, safest, and most verifiable way to collaborate."Vivek Nair, Co-Founder & CEO

The Founders

From the CIA and NASA to your inbox

The people behind this are not typical consumer-app founders. Vivek Nair, the CEO, served in elite cyber units at the Department of Defense and the CIA, where he received an Exceptional Performance Award. He is also the youngest-ever recipient of a Ph.D. in computer science from UC Berkeley. His co-founder and CTO, Colin Roberts, is an applied cryptographer with a doctorate in mathematics who previously did research at NASA - his prior work touched the so-called solar system internet, the problem of moving data reliably across interplanetary distances.

That background matters less as a resume flex than as a hint about the product's shape. People who have spent a decade inside national-security cryptography tend to distrust workarounds. A password manager, in that light, is a workaround: it stores the secret more carefully, but it still hands the secret over. Multifactor's design starts from a different question - what if the secret never has to leave? - and that reframe is the thing worth stealing from this company.

The gap the two of them are pointing at is not hypothetical. For most of the web's life, the only thing typing your password was you, sitting at a keyboard, doing one thing at a time. An agent is different in kind: it can act in parallel, at machine speed, following instructions that may have been slipped into a web page or an email it read along the way. Hand that agent a password and you have given it standing permission to do anything the account allows, with none of the hesitation a person would feel. The credential model has no concept of "only this much." Multifactor's founders spent their careers in environments where "only this much" was the whole job.

$15M
Seed round, Dec 2025
8
Patents cited
Free
Core product, forever
The Money

A $15M bet on agent security

In December 2025, Multifactor raised a $15 million seed round led by Nexus Venture Partners, with participation from Y Combinator, Taurus Ventures, Honeystone Ventures, Flex Capital, Pioneer Fund, Ritual Capital, and Liquid2 Ventures. The list of individual backers is its own signal: Mohan and Padma Warrior, Gokul Rajaram, and Mathilde Collin, the founder of Front, among them. A seed round of that size for a roughly five-person team says the investors are pricing in a market that barely exists yet - the problem of letting AI agents act on your behalf without becoming a liability.

The technical claims underneath are ambitious. Multifactor describes its access layer as protected by patented post-quantum cryptography, and for agents specifically it markets what it calls a provably safe execution environment - one meant to head off prompt injection, credential theft, confused-deputy attacks, and cross-agent hijacking. Those are the failure modes that keep security teams up at night as agents start touching real systems. Whether the guarantees hold up under adversarial pressure is the kind of thing the market will decide, but the framing is clear: treat access as math, not as a shared string of characters.

Read-only
view
Feature-limited
scoped
Dollar-capped
spend limit
Full access
owner
Trust, sliced thin. Instead of the password's all-or-nothing deal, a Multifactor link can be dialed to exactly the access a person or agent needs - and no more.
The Products

Checkpoint, Multi, and the free tier

The consumer product launched publicly on November 12, 2025, and it is free - unlimited accounts, unlimited sharing with friends and family, across platforms. The mechanism that turns an account into a shareable link is called Checkpoint. It carries the pieces that make sharing safe to actually use: instant revocation, fine-grained permissions, and a detailed event history where every action is recorded with a cryptographic signature. If a shared credential is ever misused, the question of who did what stops being a guess.

On top of that sits Multi, an AI assistant that can act inside your accounts through the same permissioned, audited channel rather than by holding raw passwords. For organizations, an Enterprise tier adds advanced compliance auditing, priority support with SLAs, cloud role-based access control, and SSO integrations. The business model is the familiar freemium funnel - free for individuals, custom pricing for teams - with API access flagged as coming for developers who want to build agents on the same rails.

The audit trail is the quiet part of the pitch that security buyers tend to fixate on. Every shared password ever leaked has produced the same miserable morning-after question: who used it, when, and to do what. Because the credential itself is the only thing that moves, the honest answer is usually a shrug. Multifactor signs each action cryptographically, so the log is not a best-effort record kept by whoever happened to be watching - it is evidence. For a compliance team, that difference is the whole reason to pay, and it is why the free consumer tier and the enterprise tier are really the same product seen from two distances.

"We created Multifactor to make it effortless to collaborate securely with humans and AI alike."Vivek Nair, Co-Founder & CEO

The Market

Not quite a password manager

The obvious comparison is to 1Password, Bitwarden, Dashlane, and the rest of the vault category. Multifactor's own tagline - "so much more than a password manager" - is a deliberate attempt to step outside that box. The distinction is real: a vault protects and autofills a secret you still have to share to collaborate. Multifactor's premise is that the sharing itself is the vulnerability, so it removes the need to share the secret in the first place.

That puts the company in a newer, thinner slice of the market: authentication and delegated access for AI agents. It is a slice that did not need to exist two years ago, when the only thing logging into your bank was you. The risk is the usual one for category-creators - customers have to feel the pain before they buy the cure, and plenty of people are still comfortable pasting a password into an agent. The opportunity is that if agents become as routine as browser tabs, the all-or-nothing password starts to look like the obviously broken thing it is.

There is also a consumer wedge hiding inside the enterprise story, and it is the part most people will meet first. Sharing a Netflix login with a roommate, handing a bookkeeper access to a bank, letting a partner manage a shared bill - all of it runs today on the same crude tool, a password typed into a text message. Multifactor's free tier is a bet that if you give people a cleaner way to do the thing they are already doing, the habit forms before the AI-agent future fully arrives. Get the sharing primitive into enough hands, the logic goes, and the agents will meet users on rails that already exist.

Founded2025, San Francisco
BatchY Combinator F25
FoundersVivek Nair (CEO), Colin Roberts (CTO)
Seed$15M, led by Nexus Venture Partners (Dec 2025)
Core productFree account manager + Checkpoint sharing
For agentsPermissioned, audited access without raw credentials
The one-page version. A small team, a big claim, and a product you can try before you finish reading this sentence.
The Takeaway

Why the billboard made sense

The Times Square stunt reads as marketing, and it is. But it is also the cleanest possible statement of the product. A security company usually sells you locks; Multifactor bought a billboard telling strangers to go look at its bank account. The message underneath is that a read-only link is a genuinely different object than a password - safe to expose precisely because it grants nothing you did not choose to grant. Confidence, in this case, is the demo.

What people can actually do with it today is modest and useful: give an accountant a view of the books without handing over the banking login, let a family member manage a shared account without a shared password, or point an AI agent at an inbox with limits it cannot exceed. Where Multifactor goes from there depends on whether the agentic web arrives on schedule. The company is betting it will, and that when it does, the safest secret to share will be the one you never shared at all.

Post-QuantumZero-TrustAI AgentsAccount SecurityYC F25Read-Only LinkCryptographyIdentity