# Silmaril

> Silmaril is a San Francisco security startup building a runtime firewall for AI agents and AI-native applications. It intercepts prompt injections, context poisoning, and dangerous tool calls in real time - a self-healing classifier that hunts for new attacks against a customer's own environment and retrains itself continuously. Founded in 2026 by Aum Upadhyay (ex-AWS security) and Eduardo Velasco (whitehat who has found exploits in major AI systems), Silmaril is part of Y Combinator's 2026 batch.

- **Founded:** 2026
- **Headquarters:** San Francisco, United States
- **Founders:** Aum Upadhyay (Co-Founder & CEO), Eduardo Velasco (Co-Founder & CTO)
- **Team size:** 2-3
- **Products:** Silmaril Runtime Firewall, Autonomous Threat-Hunting Agents, Adaptive Self-Retraining, Integrations & SDKs
- **Notable:** Launched as, per YC, the first self-healing prompt injection defense (YC 2026 batch)., Reports blocking tens of millions of dollars in potential damages, including a self-replicating worm, supply-chain compromise, sandbox credential theft and zero-click exfiltration., Disclosed critical vulnerabilities to OpenAI, Anthropic, Google and Microsoft; Microsoft reportedly patched issues affecting millions of users.

## Products & services

- **Silmaril Runtime Firewall** — A real-time classifier that wraps inference and tool calls, analyzing user intent, application context and execution state together to block prompt injections, context poisoning and dangerous tool calls. Roughly 20ms p90 latency and a claimed 95.6% accuracy across 131 attack techniques.
- **Autonomous Threat-Hunting Agents** — Agents that continuously probe a customer's own application to discover multi-step attack chains, so defenses are trained on real, environment-specific threats rather than generic rules.
- **Adaptive Self-Retraining** — When a new attack technique is discovered, Silmaril updates its defenses in under 60 minutes and anonymously shares the learning so every deployment is protected.
- **Integrations & SDKs** — Language SDKs, agent plugins (Claude Code, OpenClaw, OpenCode), and AI-gateway support (LiteLLM). Available self-hosted or as SaaS, integrated in about five lines of code.

## Achievements

- Launched as, per YC, the first self-healing prompt injection defense (YC 2026 batch).
- Reports blocking tens of millions of dollars in potential damages, including a self-replicating worm, supply-chain compromise, sandbox credential theft and zero-click exfiltration.
- Disclosed critical vulnerabilities to OpenAI, Anthropic, Google and Microsoft; Microsoft reportedly patched issues affecting millions of users.
- Reported benchmarks of 95.6% accuracy at ~20ms p90 latency across 131 attack techniques, ahead of cited alternatives.
- Holds/cites AICPA SOC and ISO 27001 certifications and CSA membership.

## Latest updates

- **2026-03** — Silmaril raised a seed round and joined Y Combinator's 2026 batch.
- **2026-03** — Public launch as a self-healing prompt injection defense, promoted by Y Combinator across X and LinkedIn.

## Links

- Website: https://silmaril.dev
- LinkedIn: https://www.linkedin.com/company/silmarilsecurity
- Twitter/X: https://x.com/Silmarildev

---

Profile page: https://yespress.io/silmaril-yc-p26
Published by YesPress — https://yespress.io
Last updated: 2026-07-30
