Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
Healthtech & Biotech iconHealthtech & BiotechJune 27, 2026

The Race to Reinvent MRI: How Startups Are Making Cancer Screening Affordable

The Race to Reinvent MRI: How Startups Are Making Cancer Screening Affordable
Portable MriDiagnostic Imaging+3
SaaS iconSaaSJune 27, 2026

The Semantic Web Returns: AI Agents Force Infrastructure Rethink

The Semantic Web Returns: AI Agents Force Infrastructure Rethink
Ai AgentsAi Infrastructure+3

Founders Mentioned

Aum Upadhyay

Silmaril

saas icon
SaaS

Eduardo Velasco

Silmaril

saas icon
SaaS

Aum Upadhyay

Silmaril

saas icon
SaaS

Eduardo Velasco

Silmaril

saas icon
SaaS
SaaS iconSaaS
June 27, 2026
YcAi AgentsCybersecurityEnterprise SecurityRuntime Security

Self-Improving AI Security Firewall Tackles Runtime Threats

YC-backed Silmaril launches runtime security platform that learns from attacks, claiming 2x better threat blocking as enterprises race to secure AI agents.

Self-Improving AI Security Firewall Tackles Runtime Threats

Eduardo Velasco didn't set out to terrify the AI industry. But when he demonstrated how to chain a prompt injection into root access inside ChatGPT, the exercise landed less like a researcher's curiosity and more like a fire alarm going off in a crowded theater.

For enterprises now racing to deploy AI agents—systems with the authority to execute code, shuttle data between applications, and make decisions that matter—Velasco's exploit highlighted what security researchers have been warning: the traditional security perimeter has fundamentally changed. It's not just about filtering bad prompts anymore. It's about what happens when those prompts effectively become shells, capable of commanding an agent to do precisely what you hoped it never would.

Enter Silmaril, a two-person startup that emerged from Y Combinator's recent cohort with a pitch that sounds almost too good to be true. The company claims its runtime security platform wraps AI agent execution at the inference layer, inspecting user intent, application context, tool calls, and accumulated conversational state before blocking harmful outcomes. The kicker? According to the company, when the system discovers a new attack, it retrains itself and pushes updated defenses into production—reportedly within an hour.

According to materials the company has shared, Silmaril claims to achieve 95.6% accuracy at 20-millisecond p90 latency, blocking twice as many threats as current leaders with one-tenth the delay. Those benchmarks position the startup against established players: Lakera Guard (which Silmaril pegs at 74.3% accuracy, 114ms latency) and Google's Model Armor (61.4%, 220ms).

Here's the catch. These are vendor-reported figures. No independent validation has emerged, which means enterprises evaluating the platform should demand proof beyond marketing collateral. And they should probably ask pointed questions about how "damages prevented"—a metric Silmaril cites at $28 million across client engagements—gets calculated in the first place.

The Vulnerability Surface Just Got Personal

The abstract nature of AI security threats became visceral earlier this year when researchers disclosed CVE-2026-21520, a prompt injection vulnerability in Microsoft Copilot Studio they dubbed "ShareLeak." Microsoft patched it in January. The patch proved insufficient. Attackers could still exfiltrate data through legitimate Outlook action chains, exploiting what security researchers call the "confused deputy" pattern—where an agent, dutifully following instructions, becomes an unwitting accomplice in data theft.

Salesforce's Agentforce platform showed similar weaknesses through a flaw called "PipeLeak," disclosed around the same time. Google's security team, in reports from earlier this year, documented what many had suspected: indirect prompt injection payloads detected on the public web increased by 32% over a four-month period. This class of attack has moved out of academic papers and into active exploitation.

The speed at which these intrusions unfold has compressed in ways that render traditional incident response obsolete. One threat intelligence report documented AI-assisted breaches achieving full data exfiltration in as little as 25 minutes. When a malicious payload buried in an email can trigger an agent to extract credentials and ship them off before your security operations center finishes its morning standup, prevention at runtime stops being optional.

Microsoft's analysis, published in May, put the problem bluntly: "Prompts become shells" when tools are wired directly to model outputs, making runtime the true security boundary. Forcepoint X-Labs catalogued ten real-world payloads targeting API-key theft, fraud, and destructive actions. This isn't hypothetical anymore.

A Firewall That Teaches Itself

Silmaril's approach—at least as described—centers on what the founders call "outcome-centric classification." Rather than simply filtering prompts at the input layer, the platform intercepts tool calls at the moment of execution, evaluating whether a proposed action represents a harmful outcome given the full context: user intent, prior conversation state, available tools.

When a threat slips through? The system generates synthetic training data from the discovered attack, retrains a ModernBERT variant optimized with Flash Attention, and pushes the updated model into production. It's a firewall that ostensibly learns from its mistakes faster than attackers can iterate.

The company claims to have disclosed 15 critical vulnerabilities to OpenAI, Anthropic, Google, and Microsoft within a two-week span. Case studies on the company's materials cite $68 million and $20 million in prevented damages for specific clients. None of these claims have been independently verified, and the methodology behind damage-prevention calculations remains, shall we say, opaque.

Founder Aum Upadhyay comes from AWS, where he says he worked on security frameworks that prevented over $1.8 billion in damages during his tenure. Co-founder Eduardo Velasco—yes, the same one who rattled the industry with that ChatGPT exploit—brings experience from Amazon's low-latency machine learning systems. Together, they've built SDKs spanning TypeScript, Python, Go, and Java, with integrations for LangGraph, LiteLLM, and common API gateways.

The platform isn't self-serve yet; provisioning runs through Silmaril directly. SDK versions hit 0.4.2 in early June, suggesting active development but also relative immaturity.

The Giants Are Already Here

Digital illustration for article section "The Giants Are Already Here" in "Self-Improving AI Security Firewall Tackles Runtime Threats" - A conceptual, modern 3D illustration representing a professionalized landscape of tech giants and pr...

Silmaril isn't entering an empty market. The landscape has professionalized remarkably fast.

Google Cloud's Model Armor, initially previewed as an Apigee add-on last summer, reached general availability with agent-aware controls by mid-2026. The platform now offers prompt injection detection, sensitive data leak prevention, and unsafe content filtering across applications and agents. Google's positioning signals a shift: runtime guardrails are becoming default infrastructure, not optional extras.

Cisco announced an expansion of its AI Defense suite in February, adding runtime protections for agentic tool use and what it calls "Live Protect"—temporary shields activated during patch windows, addressing the reality that enterprises can't always upgrade immediately when vulnerabilities surface. At Cisco Live in June, executives emphasized "AI-aware SASE" and agent identity controls. Jeetu Patel, the company's executive vice president, framed the challenge clearly: "In the age of AI, safety and security are prerequisites for adoption. AI agents bring a whole new set of challenges."

Palo Alto Networks' Prisma AIRS (AI Runtime Security) includes an AI Runtime Firewall, Agent Security module, and integrated red teaming. Documentation for these products has been refreshed throughout the first half of the year, suggesting active development and customer feedback loops.

Then there's the acquisition wave. F5 closed a deal for CalypsoAI last September—estimates peg the price between $145 million and $180 million—bringing runtime guardrails and red teaming capabilities into F5's portfolio. Check Point acquired Lakera around the same time. The pattern is clear: platform vendors are absorbing point solutions to bundle runtime controls with broader security offerings.

Dell'Oro Group's May forecast projects roughly 60 vendors across posture management, validation, runtime guardrails, and agent security. Dell'Oro projects the AI Systems Security market will grow from nearly nothing in 2024 to $8 billion by 2030. IT-Harvest estimated the narrower AI firewall segment at approximately $30 million last year, with expectations of 100% growth this year—a small base, certainly, but one that's doubling.

Money Follows Fear

Enterprise Trends Research found in May that 59% of security and IT leaders plan to increase GenAI security spending—a figure that surpasses cloud security at 54% and detection-and-response at 45%. Gartner's analysis from June warned that "Agent and LLM Security Spend Grows Exponentially," predicting many vendors will be left behind as the market consolidates around integrated platforms.

McKinsey's research shows 88% of organizations using AI in at least one function, with roughly 39% experimenting with agents and 23% scaling agentic AI deployments. Governance, however, lags badly behind adoption. Multiple surveys report that 57% of employees use personal GenAI accounts, and 33% input sensitive data into those systems—creating what the industry now calls "shadow AI" risk that traditional perimeter controls can't touch.

The regulatory environment is tightening, too. The EU AI Act's general application date—August 2, 2026, for those keeping track—brings post-market monitoring requirements for high-risk systems. Colorado signed legislation in May imposing transparency and risk obligations for automated decision-making technology, with state rulemaking due by early next year. NIST commentary from June advocated for a continuous monitor-and-update model, noting that "robust AI security and alignment is Sisyphean without ongoing adaptation." That's essentially a philosophical endorsement of self-improving approaches, though whether from a government standards body or private vendors remains an open question.

The Deterministic Rebellion

Digital illustration for article section "The Deterministic Rebellion" in "Self-Improving AI Security Firewall Tackles Runtime Threats" - A clean, minimalist conceptual composition featuring a prominent, oversized, soft-edged confirmation...

Not everyone believes machine learning classifiers are the answer.

Academic research published in April under the ClawGuard framework demonstrates robust protection against indirect prompt injection through deterministic capability-based enforcement. ClawGuard requires user confirmation at every tool-call boundary, enforcing rules that—in theory—no amount of prompt manipulation can bypass. Testing across benchmarks like AgentDojo, SkillInject, and MCPSafeBench showed strong mitigation without fine-tuning or retraining.

Capframe, a commercial implementation of capability-token runtime controls, offers microsecond-level policy checks where every agent action requires an explicit grant. It trades ML flexibility for deterministic guarantees—appealing to risk-averse enterprises that want mathematical proof rather than probabilistic defense.

Research from June examining which defenses close which threats found that many guardrail systems exhibit brittleness under paraphrasing attacks. The implication? Multi-layer controls combining input filtering, runtime enforcement, and tool-boundary gating probably matter more than any single technique. Microsoft's May analysis reinforced this—when tools are wired to model outputs, no single layer suffices.

What Buyers Should Actually Ask For

The proliferation of vendor claims without independent benchmarks creates a due diligence nightmare. Enterprises evaluating runtime security platforms should request testing against public datasets—AgentDojo, MCPSafeBench, SkillInject—with clear cost and latency trade-offs documented at production scale. Silmaril's comparative charts show performance against competitors, but these remain vendor-supplied numbers. Independent validation would strengthen the case considerably.

The "damages prevented" metric that multiple vendors cite—Silmaril's $28 million figure, HiddenLayer's claim that one in eight AI breaches link to agentic systems—lacks standardized methodology. Without common frameworks for calculating exposure, these numbers function more as marketing differentiation than risk quantification. Perhaps that's fine for a sales pitch. For a procurement decision? Less so.

One industry analysis from May argued that runtime represents "the weakest link" where decrypted data, model weights, and API keys exist simultaneously in memory. The framing is directional, but it oversimplifies. Runtime controls matter most when paired with identity management, least-privilege tool access, and continuous monitoring. Silmaril's integration points across LangGraph, LiteLLM, and API gateways suggest the founders understand that runtime protection is one layer in a defense-in-depth stack, not a silver bullet.

Consolidation Is Coming

Digital illustration for article section "Consolidation Is Coming" in "Self-Improving AI Security Firewall Tackles Runtime Threats" - A clean, minimalist 3D conceptual illustration representing business consolidation and the integrati...

The F5-CalypsoAI and Check Point-Lakera deals established a pattern worth watching: platform vendors absorbing point solutions to bundle runtime controls with broader security portfolios. Enterprises increasingly prefer integrated stacks over stitching together ten separate tools, which means standalone runtime vendors face a compressed window to achieve scale or get acquired.

Google's evolution of Model Armor from API gateway add-on to platform-embedded guardrail with agent identity integration demonstrates how quickly "optional extras" become table stakes. Cisco's Live Protect—those temporary runtime shields activated during patch windows—addresses a reality that security teams live with daily: you can't always upgrade immediately when vulnerabilities surface.

Gartner's guidance from June urged CISOs to "embrace continuous improvement and resilience amid AI chaos"—a tacit acknowledgment that the threat landscape evolves faster than procurement cycles allow. Self-improving systems like Silmaril's offer one answer, though NIST's call for continuous monitoring applies equally to deterministic frameworks that adapt policy rather than model weights.

The market will likely support multiple approaches. ML-based classifiers for speed and adaptability. Deterministic frameworks for high-assurance use cases. Platform-embedded defaults for broad enterprise adoption. Silmaril's bet on self-improvement assumes attacks will continue to evolve through paraphrasing, novel payload construction, and creative tool chaining. Spring's vulnerability disclosures validated those assumptions, at least so far.

---

For CTOs and CISOs deploying AI agents, the question isn't whether to implement runtime controls anymore. It's which combination of defenses matches your risk profile, how quickly you can adapt when new attacks emerge, and whether your vendors can prove their claims under fire.

The research labs, after all, have already moved on to the next exploit. Your runtime defenses need to learn at least as fast. Maybe faster.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • The Race to Reinvent MRI: How Startups Are Making Cancer Screening Affordable
  • The Semantic Web Returns: AI Agents Force Infrastructure Rethink
  • From Words to Workflows: AI's Push to Automate Lab Instruments
  • OpenProse Launches Open-Source 'OS' for Long-Running AI Agents
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.