Compliant LLM (formerly FiddleCube, YC W23) is an AI security and compliance toolkit that helps infosec, compliance, and GenAI teams keep their AI agents, prompts, and MCP servers secure. It red-teams AI systems against attacks like prompt injection and jailbreaking, checks them against frameworks such as NIST, ISO, OWASP, GDPR, and HIPAA, and monitors employee use of third-party GenAI tools to catch data leaks and PII exposure across both approved and shadow AI workflows.
Baffle, Inc. is a Santa Clara data security company that builds a no-code data protection platform - combining encryption, tokenization and masking - so enterprises can protect sensitive data across databases, cloud data warehouses and GenAI pipelines without rewriting application code.
Theom is a San Jose-based data security company building what it calls an AI-native Data Operations Center - a platform that discovers, classifies, tracks and protects enterprise data across cloud data lakes, warehouses, SaaS and generative-AI environments. Rather than guarding infrastructure or access alone, Theom takes a data-first approach: it maps who can touch which data, scores the financial value and risk of that data, detects breach behavior mapped to MITRE ATT&CK, and enforces policy in real time. Founded in December 2020 by former Cisco/Tetration and Google engineers, it raised a $20M Series A in May 2025 led by Wing VC with strategic backers Snowflake Ventures, Databricks Ventures and SentinelOne's S Ventures, and counts Fiserv, Grammarly, Tradeweb and JetBlue among its customers.
Opsin is a San Jose-based enterprise AI security company that helps organizations adopt generative AI tools like Microsoft Copilot, ChatGPT Enterprise, Claude, and Google Gemini without leaking sensitive data. Its platform continuously maps AI agents across the enterprise, assesses what data those agents can surface, detects oversharing and policy violations in real time, and remediates misconfigurations - giving security, GRC, and legal teams visibility and control within about 24 hours of a one-click API integration.
SurePath AI is a Denver-based enterprise software company that helps organizations safely adopt generative AI. Its network-based platform discovers sanctioned and unsanctioned AI use (shadow AI) without app integrations, classifies the intent behind each interaction, redacts sensitive data in prompts, and enforces role-based policies with full audit trails. Founded in 2023 by Casey Bleeker and Randy Birdsall, the company raised $5.2M in seed funding in November 2024 and was acquired by F5 in June 2026 to power the F5 AI Security Platform.
Eric Chiu is the founder and CEO of SolidCore.ai, a Menlo Park startup that helps enterprises deploy generative AI with real-time monitoring, an immutable record of every LLM interaction, and built-in compliance. A veteran cybersecurity entrepreneur, he previously founded HyTrust, the cloud security company acquired by Entrust, whose technology protected the virtual infrastructure of Bank of America, United Healthcare, Honeywell, and U.S. Central Command. SolidCore emerged from stealth in September 2025 with $4M in seed funding led by Runtime Ventures, reuniting Chiu with his longtime collaborator and CTO Hemma Prafullchandra.
James Pham is the co-founder and CEO of Opsin, a San Francisco-area startup securing how enterprises adopt generative AI. After validating the problem through more than 300 conversations with industry leaders, he built Opsin to detect and remediate data oversharing in tools like Microsoft Copilot and Google Gemini, and has since expanded it into a full enterprise agent security platform. An immigrant from Vietnam with an MIT MBA and a machine-learning product background from Abnormal Security, Pham now leads a company in production at regulated healthcare, manufacturing, and financial-services organizations.
Obsidian Security is a Fortune 1000-focused cybersecurity company that secures business-critical SaaS applications, identities, and AI agents. Founded in 2017 by former Cylance and Carbon Black leaders, its platform unifies SaaS Security Posture Management (SSPM), Identity Threat Detection and Response (ITDR), and emerging AI agent and SaaS supply chain protection - giving enterprises visibility and control over the sprawling, interconnected SaaS ecosystems where modern breaches now begin.