Operant AI is betting that the decisive moment in cybersecurity is no longer before software ships or after an alarm rings. It is the instant an AI agent decides to act.
ARMO gave away a Kubernetes scanner, watched 40,000 companies download it, then built a runtime-security business on top. This is the story of the open-source Trojan horse - and the eBPF sensor that made it work.
A firm run entirely by cybersecurity operators, backing the founders trying to defend everything from cloud workloads to synthetic media - one narrow thesis, executed at scale.
Silmaril is a San Francisco security startup building a runtime firewall for AI agents and AI-native applications. It intercepts prompt injections, context poisoning, and dangerous tool calls in real time - a self-healing classifier that hunts for new attacks against a customer's own environment and retrains itself continuously. Founded in 2026 by Aum Upadhyay (ex-AWS security) and Eduardo Velasco (whitehat who has found exploits in major AI systems), Silmaril is part of Y Combinator's 2026 batch.
Contrast Security is a Pleasanton, California-based cybersecurity company that secures software from the inside out. Founded in 2014 by OWASP veterans Jeff Williams and Arshan Dabirsiaghi, it pioneered an instrumentation-based approach that embeds security sensors directly into running applications to detect vulnerabilities and block live attacks in real time. Its runtime security platform spans Interactive Application Security Testing (IAST), Runtime Application Self-Protection (RASP), static analysis (SAST), software composition analysis (SCA), and Application Detection and Response (ADR), serving Fortune 500 enterprises and government agencies.
RAD Security is a San Francisco cloud-native security company that pairs runtime telemetry with agentic AI to help teams detect, investigate, and respond to threats across Kubernetes and cloud environments. Founded in 2021 as KSOC and rebranded RAD Security in 2024, it builds behavioral, eBPF-driven detection and a roster of AI 'RADBots' that triage alerts, generate compliance evidence, and automate security workflows. The company raised a $14M Series A in February 2025, bringing total funding to about $20M.
Upwind is a runtime-first Cloud Native Application Protection Platform (CNAPP) that unifies cloud and AI security across the full lifecycle. Founded in 2022 by the team behind Spot.io, the company uses eBPF-based runtime telemetry to give security teams real-time context on what's actually exploitable in production - cutting noise, surfacing real threats, and protecting cloud-native and AI workloads at the speed they run.