Candor (YC W25) is a San Francisco cybersecurity startup building agentic data loss prevention and insider risk management. Instead of drowning security teams in false positives like legacy DLP tools, Candor's AI agents watch both the data movement and the person behind it - stitching together the story of who is about to leak source code, exfiltrate IP, or misuse AI tools - so lean teams know exactly who to watch before damage is done.
Tarique Mustafa is a Silicon Valley cybersecurity founder, engineer and AI researcher who serves as CEO, CTO and founder of Chorology, Inc., a San Jose company applying deep AI to automate data discovery, classification, mapping and compliance enforcement for enterprises. A serial entrepreneur with two prior startups that ended in acquisitions, he previously founded GhangorCloud, a pioneer of fourth-generation data leak prevention, and held senior roles at Symantec, MCI WorldCom and others. He holds dual master's degrees and did PhD research in AI at USC, and holds multiple patents in deep AI.
ORION Security is an AI-native data loss prevention (DLP) company that protects enterprises from data leaks without relying on manually written policies. Founded in 2024 by Nitay Milner and Jonathan Kreiner, ORION uses large language models and specialized AI agents to map how data normally flows across SaaS, email, cloud, endpoints, and AI tools, then analyzes content sensitivity, user identity, behavioral intent, and data lineage to catch exfiltration and insider threats in real time. The platform targets the three core sources of data loss - human error, malicious insiders, and external attackers - while cutting the false positives and maintenance burden that plague legacy DLP.
PixieBrix is a New York-based software company that started as a low-code browser extension for customizing and automating web apps, and has evolved into a browser-native platform for monitoring, guiding, and securing the actions people and AI agents take inside their web applications. Deployed as a lightweight Chrome/Edge extension, it lets teams add context-aware automations, AI assistance, and real-time policy enforcement on top of any website - originally aimed at customer support and contact-center productivity, and more recently at agent oversight, compliance, and safe AI-agent browsing.
Cyberhaven is a data security company that protects enterprises from data exfiltration and insider risk by tracing how information moves rather than just where it sits. Founded in 2016 by five PhD researchers with roots in the DARPA Cyber Grand Challenge, the company built a proprietary 'data lineage' engine and an AI layer, Linea AI, that combines Data Loss Prevention (DLP), Data Security Posture Management (DSPM), Insider Risk Management, and AI security into one platform. Reaching a $1 billion valuation in April 2025 after a $100M Series D, Cyberhaven serves customers such as Snowflake, Motorola, Reddit, and major law firms.
Nitay Milner is co-founder and CEO of ORION Security, a New York and Tel Aviv-based startup rebuilding data loss prevention around AI that learns how data actually moves inside a company. He raised a $32M Series A led by Norwest in February 2026, with IBM participating, less than a year after a $6M seed. Before ORION he was a senior product leader at Epsagon (acquired by Cisco for around $500M) and previously co-founded DatsMi, an event-media startup.
Credal.ai is a New York-based enterprise AI startup building a control plane for company AI agents. Founded in 2022 by two former Palantir engineers, its platform connects internal company data - from Google Drive and Slack to Salesforce - to large language models while strictly enforcing existing user permissions, redacting sensitive data, and logging every prompt and action. Credal lets regulated enterprises build, govern, and deploy AI agents and MCP servers without leaking data or breaking compliance rules.
SurePath AI is a Denver-based enterprise software company that helps organizations safely adopt generative AI. Its network-based platform discovers sanctioned and unsanctioned AI use (shadow AI) without app integrations, classifies the intent behind each interaction, redacts sensitive data in prompts, and enforces role-based policies with full audit trails. Founded in 2023 by Casey Bleeker and Randy Birdsall, the company raised $5.2M in seed funding in November 2024 and was acquired by F5 in June 2026 to power the F5 AI Security Platform.
Casey Bleeker is the co-founder and CEO of SurePath AI, a Denver-based startup that helps enterprises adopt generative AI without leaking their secrets to it. He built the company in 2023 around a simple bet: companies will not choose between banning AI and losing control of their data, so SurePath sits at the network edge, governing what employees send to public models and redacting what they should not. Before founding SurePath, Casey ran CDW's $2B+ Cloud and Cloud Native business and held senior roles at Cisco in AI/ML, IoT, and developer advocacy. He is a computational-biology major turned go-to-market operator who codes his own prototypes, and online he is better known as 'geekbleek.'
Vinay Goel is the CEO and co-founder of Wald.ai, a Palo Alto startup building contextual data-loss protection for the age of generative AI. After more than 30 years in product and technology - a decade at Google leading Maps and Local, then top product roles at JLL, Kiavi, Check Point and Webroot - he co-founded Wald.ai in 2024 to solve the 'shadow AI' problem: employees feeding sensitive company data into ChatGPT, Claude and Gemini. Wald.ai redacts sensitive data inline, lets the AI answer, then restores the original context before the user sees it. He raised a $4M seed round in December 2024 and sits on the Forbes Technology Council.
Proofpoint is a cybersecurity and compliance company that protects organizations against the threats that target people - email attacks, data loss, and insider risk. Founded in 2002, it became the first SaaS-based cybersecurity vendor to cross $1B in annual revenue, was taken private by Thoma Bravo for $12.3B in 2021, and today runs a 'human-centric' security platform spanning email defense, data security, and identity threat protection used by a majority of the Fortune 100.
Seclore is a data-centric security company that protects sensitive files and emails wherever they travel - across any user, device, app, or cloud. Its browser-based ARMOR platform unifies Data Security Posture Management, AI-powered Data Loss Prevention, data classification, and Enterprise Digital Rights Management so organizations keep persistent, granular control over data even after it leaves their walls. Founded in India in 2008 and headquartered in Santa Clara, California, Seclore serves more than 2,000 enterprises and government bodies across roughly 29 countries.
dope.security is a Mountain View cybersecurity startup that rebuilt the Secure Web Gateway (SWG) so it runs directly on the endpoint instead of routing traffic through a vendor's cloud datacenter. Founded in 2021 by ex-Symantec and Forcepoint product leader Kunal Agarwal, its 'fly-direct' architecture inspects web traffic on-device, claiming faster performance, fewer outages, and better privacy than legacy cloud proxies. The company has expanded from its core dope.swg product into AI-powered data protection with CASB Neural and DOPAMINE DLP, backed by roughly $20M from GV (Google Ventures) and Boldstart Ventures.

Kunal Agarwal is the founder and CEO of dope.security, the 'Fly Direct' Secure Web Gateway that runs security on the endpoint instead of routing all traffic through a distant cloud data center. A self-described hacker since age 8 who once talked his way out of juvenile detention after breaking into his high school's grading system, he spent roughly a decade at Symantec and Forcepoint - rising from engineer to running Symantec's IoT business and leading product at Forcepoint - before launching dope.security in 2022. The company raised a $16M Series A led by GV (Google Ventures), and Agarwal was named SC Awards 2025 Innovator of the Year.
Trustifi is a cloud-based, AI-driven email security company that protects organizations from phishing, business email compromise, data leaks and compliance failures. Its one-stack platform pairs Inbound Shield threat detection with Outbound Shield one-click encryption and One-Click Compliance, making enterprise-grade email protection simple enough for small businesses and the managed service providers that serve them. Founded by Rom Hendler and Idan Udi Edry, the company raised a $25M Series A in 2025 to scale its channel-first, AI-powered platform.

Rom Hendler is the CEO and co-founder of Trustifi, an AI-driven email security platform that wraps encryption, data loss prevention, and security awareness training into one product built for managed service providers and mid-sized businesses. He took an unlikely path to cybersecurity, spending more than a decade as a marketing and operations executive in the casino and hospitality world (CMO at Las Vegas Sands, leadership roles at The Venetian and The Palazzo) before building a travel-tech startup and then turning his attention to the most-attacked surface in the enterprise: the inbox. Under his leadership Trustifi raised a $25M Series A in June 2025 led by Camber Partners and Hendler has been named a CRN Channel Chief four years running.
Venn is a New York cybersecurity company that secures remote and hybrid work on personal, unmanaged, or contractor-owned computers. Its patented Blue Border technology installs a lightweight agent that creates a company-controlled Secure Enclave on any Windows or Mac machine - work apps run locally inside a literal blue border where data is encrypted and isolated from personal use, with no virtual desktop, no remote session, and no shipped laptop required.
Harmonic Security helps enterprises adopt generative AI without leaking sensitive data. Using small, purpose-built language models, its AI Governance and Control platform spots risky prompts, enforces policy across browsers and desktops, and gives security teams visibility into the thousands of AI tools employees quietly use every day.
Material Security is a San Francisco cloud workspace security company that protects email, files, and accounts inside Google Workspace and Microsoft 365. Founded in 2017 by three ex-Dropbox engineers, it assumes attackers will eventually get in - and locks down the sensitive data they came for, instead of stacking yet another perimeter.
Nightfall AI is a San Francisco-based data security company that uses AI-native detection to find and protect sensitive data across SaaS applications, AI tools, and endpoints. It pitches itself as the first DLP and insider risk platform purpose-built for the AI era.
Rohit Dixit is the Executive Vice President and Chief Customer Officer at Proofpoint, the human-centric cybersecurity company headquartered in Sunnyvale, California. With over 30 years of experience spanning SaaS, technology, and technology-enabled services, Dixit oversees Proofpoint's global customer success, professional services, managed services, and technical support teams. He joined Proofpoint in February 2024 from Hewlett Packard Enterprise, where he transformed a $1 billion advisory and professional services business into a record profit-generating unit. His career arc spans continents - from ESSEN Computers in India to oil fields in Kuwait, Egypt, and Turkmenistan with Halliburton, to strategy consulting at A.T. Kearney, to the C-suite of one of the world's leading cybersecurity firms.

Rohan Sathe is the Co-Founder and CEO of Nightfall AI, the AI-native data loss prevention platform built for the modern enterprise. A Forbes 30 Under 30 honoree and nationally ranked chess player, Sathe co-founded Nightfall in 2018 after leading backend engineering at Uber Eats, where managing petabytes of sensitive data across fragmented SaaS systems exposed the deep inadequacy of legacy DLP tools. Nightfall has raised $60.3M in total funding and is redefining how enterprises protect sensitive data across SaaS apps, endpoints, browsers, and AI workflows.