Wojciech Blaszak is the co-founder and CEO of Golf (YC X25), a San Francisco company building a security and governance control plane for the Model Context Protocol (MCP), the layer where AI agents connect to company data. He started his first business at 14, grew it to around $200k in revenue, and left university after a single semester to build full-time with his longtime collaborator Antoni Gmitruk. Golf began as an open-source framework for shipping production MCP servers and grew into an enterprise product that discovers shadow AI, enforces per-tool policies, and produces compliance-ready audit trails.
BaseFrame is a San Francisco AI startup from Y Combinator's Winter 2026 batch, founded by UC Berkeley classmates Anshul Paul and Vaibhav Agrawal. The company has iterated quickly across the AI stack - launching first as an AI copilot that catches hardware design flaws before boards are built, then as a desktop app that scans a team's own work history to find what AI can automate, and most recently pivoting to Clam, a 'Semantic Firewall' that adds enterprise-grade security around broad-access AI agents. Across all three, the thread is the same: make powerful AI safe, useful, and grounded in real work.
Compliant LLM (formerly FiddleCube, YC W23) is an AI security and compliance toolkit that helps infosec, compliance, and GenAI teams keep their AI agents, prompts, and MCP servers secure. It red-teams AI systems against attacks like prompt injection and jailbreaking, checks them against frameworks such as NIST, ISO, OWASP, GDPR, and HIPAA, and monitors employee use of third-party GenAI tools to catch data leaks and PII exposure across both approved and shadow AI workflows.
Golf is a Y Combinator (X25) startup building the security and governance layer for AI agents and Model Context Protocol (MCP) servers. It began as GolfMCP, an open-source Python framework for shipping production MCP servers without boilerplate, and grew into an enterprise control plane that discovers every AI agent and MCP connection in an organization (including shadow AI), enforces granular policies with sub-millisecond latency, and maintains compliance-ready audit trails. Founded by high-school friends Wojciech Blaszak and Antoni Gmitruk, who both dropped out of university to build it full-time.
Silmaril is a San Francisco security startup building a runtime firewall for AI agents and AI-native applications. It intercepts prompt injections, context poisoning, and dangerous tool calls in real time - a self-healing classifier that hunts for new attacks against a customer's own environment and retrains itself continuously. Founded in 2026 by Aum Upadhyay (ex-AWS security) and Eduardo Velasco (whitehat who has found exploits in major AI systems), Silmaril is part of Y Combinator's 2026 batch.
Alice, formerly ActiveFence, is an Israeli-American AI safety and security company that acts as a protective layer for online platforms and AI systems. Founded in 2018, it uses a decade of real-world abuse intelligence to detect and stop harms such as fraud, deepfakes, child exploitation, disinformation, prompt-injection attacks, and jailbreaks. Its technology helps protect roughly 3 billion people and secures 7 of the 10 largest AI foundation models, serving customers including Amazon, TikTok, Nvidia, and Cohere.
Arthur is a New York-based AI governance and observability company that gives enterprises a single control plane to discover, monitor, evaluate, and govern the AI models and autonomous agents running across their organization. Founded in 2018 by a team out of Capital One and academia, Arthur started with machine-learning monitoring - catching model drift, bias, and performance decay in production - and has since expanded into real-time guardrails, LLM evaluation, and agentic AI governance. Its open-source Arthur Engine and its Agent Discovery & Governance platform help security, compliance, and ML teams ship AI they can trust in regulated industries like finance, insurance, healthcare, and government.
PixieBrix is a New York-based software company that started as a low-code browser extension for customizing and automating web apps, and has evolved into a browser-native platform for monitoring, guiding, and securing the actions people and AI agents take inside their web applications. Deployed as a lightweight Chrome/Edge extension, it lets teams add context-aware automations, AI assistance, and real-time policy enforcement on top of any website - originally aimed at customer support and contact-center productivity, and more recently at agent oversight, compliance, and safe AI-agent browsing.
Zenity is a cybersecurity company that builds an end-to-end security and governance platform purpose-built for AI agents. Founded in 2021 by Ben Kliger and Michael Bargury, it gives enterprises visibility and control over what AI agents - from Microsoft Copilot and Salesforce Agentforce to home-grown builds on AWS Bedrock - can access, do, and invoke. Zenity covers the full agent lifecycle with discovery, posture management, real-time threat detection, and response across SaaS, cloud, and endpoint environments, closing the blind spots that traditional model-focused security tools miss.
Straiker is a Sunnyvale-based agentic AI security company that helps enterprises deploy AI agents without handing attackers the keys. Its platform spans three jobs - Discover AI maps the agents, MCP servers, and workflows running across a company; Ascend AI red-teams them before deployment to surface prompt injection, goal hijacking, and tool misuse; and Defend AI blocks identity abuse, memory poisoning, and data exfiltration at runtime. Founded by former Palo Alto Networks and Akamai security leaders, Straiker raised a $64M Series A in June 2026, bringing total funding to $85M.
Vijil is a Menlo Park-based AI company building trust infrastructure for enterprise AI agents. Founded in 2023 by senior AWS leaders, its modular platform tests, defends, and continuously hardens agents so they are verifiably reliable, secure, and safe - cutting the time it takes enterprises to trust an agent from about six months to six weeks. Vijil raised $17 million in 2025 (total $23 million) and was named a Gartner Cool Vendor.
Virtue AI is a San Francisco-based enterprise AI security company that helps organizations deploy generative AI and AI agents safely. Founded in 2024 by AI-safety researchers from Berkeley, Stanford, and Chicago, its platform combines automated red-teaming (VirtueRed), real-time multimodal guardrails (VirtueGuard), and an end-to-end agent security suite (AgentSuite) to catch prompt injections, jailbreaks, data poisoning, and policy violations before they reach production. The company raised $30 million in seed and Series A funding and counts frontier AI labs and enterprises in finance, healthcare, and IT among its customers.
Enkrypt AI is a Boston-based AI security company that builds a control layer between enterprises and the large language models and AI agents they deploy. Founded in 2022 by Yale PhDs Sahil Agarwal and Prashanth Harshangi, its Sentry platform combines automated red teaming, runtime guardrails, and compliance monitoring to detect vulnerabilities like prompt injection, jailbreaks, bias, and data leakage before and after models reach production. The company also publishes a free LLM Safety Leaderboard and widely cited red-team research, including a January 2025 report finding DeepSeek-R1 far more likely than rivals to produce harmful content.
Dynamo AI is a San Francisco-based enterprise AI security and governance company that helps regulated organizations deploy generative and agentic AI safely. Born out of MIT CSAIL research, its platform - spanning DynamoEval, DynamoGuard, and AgentWarden - tests AI systems for vulnerabilities, applies real-time, customizable guardrails against threats like prompt injection, data leakage, and hallucinations, and produces the compliance documentation enterprises need to meet regulations such as the EU AI Act.
WitnessAI is an enterprise AI security and governance platform that helps organizations safely deploy AI at scale. Built on three pillars - Observe, Protect, and Control - its platform provides real-time visibility into all AI interactions (employee tools, internal models, AI agents, MCP servers), detects and blocks prompt injections and jailbreaks with over 99% accuracy using intent-based ML models, and enforces behavioral policies without code changes. With $85.5M in total funding, 500% ARR growth in 2025, and customers across financial services, telecom, airlines, and automotive, WitnessAI is positioning itself as the confidence layer enterprises need to move from AI experimentation to production deployment.

Simon Willison is a British software engineer, open source creator, and AI commentator best known for co-creating the Django web framework and building Datasette, the open-source data exploration tool. He coined the term 'prompt injection' in 2022 and popularized 'AI slop' in 2024 - a word later named Merriam-Webster's 2025 Word of the Year. Through his prolific blog (active since 2002), newsletter with 54,000+ subscribers, and 100+ open source tools, he is one of the most influential independent voices at the intersection of LLMs and open source software.