Candor (YC W25) is a San Francisco cybersecurity startup building agentic data loss prevention and insider risk management. Instead of drowning security teams in false positives like legacy DLP tools, Candor's AI agents watch both the data movement and the person behind it - stitching together the story of who is about to leak source code, exfiltrate IP, or misuse AI tools - so lean teams know exactly who to watch before damage is done.
ORION Security is an AI-native data loss prevention (DLP) company that protects enterprises from data leaks without relying on manually written policies. Founded in 2024 by Nitay Milner and Jonathan Kreiner, ORION uses large language models and specialized AI agents to map how data normally flows across SaaS, email, cloud, endpoints, and AI tools, then analyzes content sensitivity, user identity, behavioral intent, and data lineage to catch exfiltration and insider threats in real time. The platform targets the three core sources of data loss - human error, malicious insiders, and external attackers - while cutting the false positives and maintenance burden that plague legacy DLP.
PixieBrix is a New York-based software company that started as a low-code browser extension for customizing and automating web apps, and has evolved into a browser-native platform for monitoring, guiding, and securing the actions people and AI agents take inside their web applications. Deployed as a lightweight Chrome/Edge extension, it lets teams add context-aware automations, AI assistance, and real-time policy enforcement on top of any website - originally aimed at customer support and contact-center productivity, and more recently at agent oversight, compliance, and safe AI-agent browsing.
Cyberhaven is a data security company that protects enterprises from data exfiltration and insider risk by tracing how information moves rather than just where it sits. Founded in 2016 by five PhD researchers with roots in the DARPA Cyber Grand Challenge, the company built a proprietary 'data lineage' engine and an AI layer, Linea AI, that combines Data Loss Prevention (DLP), Data Security Posture Management (DSPM), Insider Risk Management, and AI security into one platform. Reaching a $1 billion valuation in April 2025 after a $100M Series D, Cyberhaven serves customers such as Snowflake, Motorola, Reddit, and major law firms.
Credal.ai is a New York-based enterprise AI startup building a control plane for company AI agents. Founded in 2022 by two former Palantir engineers, its platform connects internal company data - from Google Drive and Slack to Salesforce - to large language models while strictly enforcing existing user permissions, redacting sensitive data, and logging every prompt and action. Credal lets regulated enterprises build, govern, and deploy AI agents and MCP servers without leaking data or breaking compliance rules.
SurePath AI is a Denver-based enterprise software company that helps organizations safely adopt generative AI. Its network-based platform discovers sanctioned and unsanctioned AI use (shadow AI) without app integrations, classifies the intent behind each interaction, redacts sensitive data in prompts, and enforces role-based policies with full audit trails. Founded in 2023 by Casey Bleeker and Randy Birdsall, the company raised $5.2M in seed funding in November 2024 and was acquired by F5 in June 2026 to power the F5 AI Security Platform.
Proofpoint is a cybersecurity and compliance company that protects organizations against the threats that target people - email attacks, data loss, and insider risk. Founded in 2002, it became the first SaaS-based cybersecurity vendor to cross $1B in annual revenue, was taken private by Thoma Bravo for $12.3B in 2021, and today runs a 'human-centric' security platform spanning email defense, data security, and identity threat protection used by a majority of the Fortune 100.
Seclore is a data-centric security company that protects sensitive files and emails wherever they travel - across any user, device, app, or cloud. Its browser-based ARMOR platform unifies Data Security Posture Management, AI-powered Data Loss Prevention, data classification, and Enterprise Digital Rights Management so organizations keep persistent, granular control over data even after it leaves their walls. Founded in India in 2008 and headquartered in Santa Clara, California, Seclore serves more than 2,000 enterprises and government bodies across roughly 29 countries.
dope.security is a Mountain View cybersecurity startup that rebuilt the Secure Web Gateway (SWG) so it runs directly on the endpoint instead of routing traffic through a vendor's cloud datacenter. Founded in 2021 by ex-Symantec and Forcepoint product leader Kunal Agarwal, its 'fly-direct' architecture inspects web traffic on-device, claiming faster performance, fewer outages, and better privacy than legacy cloud proxies. The company has expanded from its core dope.swg product into AI-powered data protection with CASB Neural and DOPAMINE DLP, backed by roughly $20M from GV (Google Ventures) and Boldstart Ventures.
Trustifi is a cloud-based, AI-driven email security company that protects organizations from phishing, business email compromise, data leaks and compliance failures. Its one-stack platform pairs Inbound Shield threat detection with Outbound Shield one-click encryption and One-Click Compliance, making enterprise-grade email protection simple enough for small businesses and the managed service providers that serve them. Founded by Rom Hendler and Idan Udi Edry, the company raised a $25M Series A in 2025 to scale its channel-first, AI-powered platform.
Venn is a New York cybersecurity company that secures remote and hybrid work on personal, unmanaged, or contractor-owned computers. Its patented Blue Border technology installs a lightweight agent that creates a company-controlled Secure Enclave on any Windows or Mac machine - work apps run locally inside a literal blue border where data is encrypted and isolated from personal use, with no virtual desktop, no remote session, and no shipped laptop required.
Harmonic Security helps enterprises adopt generative AI without leaking sensitive data. Using small, purpose-built language models, its AI Governance and Control platform spots risky prompts, enforces policy across browsers and desktops, and gives security teams visibility into the thousands of AI tools employees quietly use every day.
Material Security is a San Francisco cloud workspace security company that protects email, files, and accounts inside Google Workspace and Microsoft 365. Founded in 2017 by three ex-Dropbox engineers, it assumes attackers will eventually get in - and locks down the sensitive data they came for, instead of stacking yet another perimeter.
Nightfall AI is a San Francisco-based data security company that uses AI-native detection to find and protect sensitive data across SaaS applications, AI tools, and endpoints. It pitches itself as the first DLP and insider risk platform purpose-built for the AI era.