BREAKING Multifactor raises $15M seed to make online accounts safe for AI agents YC F25 Vivek Nair joins Y Combinator's Fall 2025 batch RESEARCH Study identifies 50,000+ VR users from motion data alone MILESTONE UC Berkeley PhD in Computer Science, completed at age 22 AWARD Hertz Foundation entrepreneurship prize for AI cybersecurity BREAKING Multifactor raises $15M seed to make online accounts safe for AI agents YC F25 Vivek Nair joins Y Combinator's Fall 2025 batch RESEARCH Study identifies 50,000+ VR users from motion data alone MILESTONE UC Berkeley PhD in Computer Science, completed at age 22 AWARD Hertz Foundation entrepreneurship prize for AI cybersecurity
Profile / Founders

Vivek Nair Is Teaching AI Agents How to Log In

He finished a UC Berkeley PhD at 22, ran cyber operations inside the government, and captained a national-title VR team. Now he wants to redefine what "zero trust" means for machines that act on your behalf.

There is a quiet moment happening inside the software people use every day. An AI agent, given a task, reaches for a login. It types a password into a box that a human was supposed to fill. It clicks a button meant for a person. Most of the time nothing goes wrong. Vivek Nair spends his days on the times it does.

Nair is the co-founder and CEO of Multifactor, an applied cryptography company that joined Y Combinator's Fall 2025 batch and raised a $15 million seed round to make online accounts safe for AI agents. The pitch is narrow and specific, which is part of why it lands. Passwords, he argues, were designed for humans. When you hand them to autonomous software, the model starts to crack.

"Passwords were never built for the agentic era, and they're becoming the most fragile link in modern security." Vivek Nair

To understand why he is the person making this argument, it helps to look at how he got here, because the path is unusual even by the standards of people who start security companies.

The Fast Track

A degree, then another, then a doctorate

Nair was born in Phoenix, Arizona, and grew up across eight cities, including San Jose and Singapore. He attended an online high school program run through Stanford, which meant his classroom moved wherever his family did. He started studying cybersecurity in those years, launching small startups and taking a software job with a healthcare technology company in Singapore before most people finish secondary school.

The academic timeline reads like a typo. He earned a bachelor's degree in computer science from the University of Illinois Urbana-Champaign at 18, a master's from the same school at 19, and a PhD in computer science from UC Berkeley at 22. The doctorate came with support from three fellowships at once: the National Science Foundation, the National Physical Science Consortium, and the Fannie and John Hertz Foundation. Along the way he collected the 2022 Tong Leong Lim Pre-Doctoral Prize, given to the Berkeley electrical engineering and computer science student with the highest distinction on the pre-doctoral exam.

18
Bachelor's, UIUC
19
Master's, UIUC
22
PhD, UC Berkeley
6
Patents held

Speed is the easy story. The more interesting detail is what he did with the pace. His research at Berkeley focused on privacy in virtual reality, and it produced findings that were hard to unsee.

The Research That Stuck

You are how you move

Working within Berkeley's Center for Responsible Decentralized Intelligence, Nair and his collaborators studied what a VR headset actually reveals about the person wearing it. The answer unsettled people who assumed a virtual body was anonymous. Using head and hand motion alone, drawn from what was described as the largest dataset of VR user interactions ever analyzed for privacy risks, the team could re-identify more than 50,000 individual users. No camera. No name. Just the signature of how a body moves through space.

MOTION AS IDENTITY Re-identification from head + hand tracking unique peak — head trajectory - - hand trajectory 50,000+ users separated
The pattern is the person. Nair's work showed motion data behaves like a fingerprint you cannot take off.

That line of work earned recognition across the field: a Distinguished Artifact Award at USENIX Security 2023 for a key-derivation method called MFKDF, and a Best Paper Award at ACM UIST 2023 for "Going Incognito in the Metaverse," a project on hiding those movement signatures. His thesis carried the title "The Unprecedented Risks and Opportunities of Extended Reality Motion Data." The recurring theme was not fear of technology. It was a demand for proof. Show me the system is secure, do not tell me you hope it is.

"We're building solutions that enable the exact same functionality, just without the security risk." Vivek Nair, on securing AI agents
Government Years

Learning how things break

Between and after his research, Nair worked as a technical lead inside cyber units at the U.S. Department of Defense and later the Central Intelligence Agency. There he received the Directorate's Exceptional Performance Award for work on U.S. cyber operations. He does not dwell publicly on the specifics, and the nature of the work keeps most of it off the record. What carried over is a mindset. Someone who has spent years finding the seams in other people's systems tends to build differently when it is their turn.

The career, laid end to end, looks like this:

2015 — 2020
Authentication consultant; early startups and healthcare software
2020 — 2021
Cyber researcher, U.S. Department of Defense
2021 — 2023
Researcher at Berkeley's IC3 and RDI centers; VR privacy work
2023 — 2025
Technical lead, cyber unit at the CIA
2025 — now
Co-founder and CEO, Multifactor (YC F25)
The Company

A new pillar, on purpose

Multifactor, which Nair started with mathematician and cryptographer Colin Roberts, is built as a public benefit company with an open-source focus. That structure is unusual for a funded security startup, and it is deliberate. The bet is that trust is easier to earn when the code can be read.

The technical argument is clean. Most companies today are trying to bolt AI agents onto a security model designed for people. They make the agent behave like a human user, typing the same passwords and clicking the same buttons, and that is exactly where the vulnerabilities creep in. An attacker no longer has to fool a person into opening a bad email. They can fool the agent instead. Multifactor's answer is authentication, authorization, and auditing designed from scratch for software that acts on your behalf: credential-free access, fine-grained permissions, and a detailed log of every action an agent takes.

Nair frames the whole effort in terms of how the industry is organized. Cybersecurity has long been split into pillars, identity, web, network, with cloud security arriving later as its own category. He thinks the next pillar is already forming.

"We think agentic AI security is the next pillar of cybersecurity and we want to be the company that defines it." Vivek Nair

On the consumer side, the company launched what it calls the first password manager built for the AI era, with a feature that lets a user turn almost anything into a read-only link. The idea is to give everyday people a way to share access with an agent without handing over the keys to the whole account. As Nair puts it, a way to make daily life a little easier and a little safer at the same time.

Human keys vs. agent access OLD MODEL Agent gets the full password Same access as the human One trick breaks everything MULTIFACTOR Read-only, scoped links Fine-grained permissions Every action is logged
The design goal, in one picture: same functionality for the agent, far less blast radius when something goes wrong.
Off the Clock

The captain of the Beat Saber team

The detail that tends to surprise people comes from the same VR world he studied. While finishing his doctorate, Nair captained UC Berkeley's Beat Saber team and led it to a U.S. national collegiate championship in 2021. It is a rhythm game where players slice flying blocks in time with music, and being good at it demands exactly the kind of precise, repeatable motion his research later turned into a privacy problem. There is a neat symmetry there that he probably enjoys more than he lets on.

Research
peer-reviewed, award-winning
Operations
DoD + CIA cyber units
Building
Multifactor, $15M seed
VR sabers
national champion

The recognition has kept coming. The Fannie and John Hertz Foundation, which backed his PhD, gave him its Newman-Galas Entrepreneurial Initiative Award for the AI cybersecurity startup, along with mentoring from a community that included early supporters among fellow Hertz Fellows. His research has been covered by the Washington Post, Forbes, and Bloomberg, among others.

What He's After

Provable, not probable

Strip away the resume and a single question runs through all of it. How do you prove a system is safe instead of assuming it is? It shows up in the VR research, where he demonstrated that a supposedly anonymous headset was quietly broadcasting identity. It shows up in the government work, where the job was to find the assumptions that did not hold. And it shows up now at Multifactor, where the goal is authentication that can be checked rather than trusted on faith.

The AI agent reaching for that login is not going away. More of them arrive every month, wired into inboxes, calendars, and bank accounts, doing useful work and occasionally getting fooled. Nair's wager is that the companies racing to give agents access to everything have skipped a step, and that someone needs to build the layer underneath before the cracks get expensive. He would like that someone to be a small, open, public-benefit company run out of San Francisco, staffed by people who spent years learning precisely how these things break.

It is an ambitious place to plant a flag. Then again, this is a person who treated a PhD as something to finish early and a rhythm game as something to win nationally. Betting against the timeline has not worked out well so far.

#applied-cryptography #ai-agent-security #zero-trust #multifactor #yc-f25 #uc-berkeley #hertz-fellow #vr-privacy #authentication #founder