Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
Climate / Social Tech iconClimate / Social TechFebruary 7, 2026

Ecovia Bio Lands Series B for Biodegradable Plastic Alternative

Ecovia Bio Lands Series B for Biodegradable Plastic Alternative
BiomaterialsClean Tech+2
Climate / Social Tech iconClimate / Social TechFebruary 7, 2026

TWAICE Secures €24M EIB Venture Debt for Battery Analytics

TWAICE Secures €24M EIB Venture Debt for Battery Analytics
Energy StorageClean Tech+2

Founders Mentioned

Benjamin Muñoz-Cerro

Velum Labs

saas icon
SaaS

Alen Rubilar-Muñoz

Velum Labs

saas icon
SaaS

Benjamin Muñoz-Cerro

Velum Labs

saas icon
SaaS

Alen Rubilar-Muñoz

Velum Labs

saas icon
SaaS
SaaS iconSaaS
February 7, 2026
YcEnterprise SecurityAi AgentsOpen SourceCloud Security

Velum Labs Launches Open-Source Firewall for AI and Human Access Control

YC-backed startup debuts unified security infrastructure to enforce content-level policies across AI agents and human users as enterprises race to govern GenAI deployments.

Velum Labs Launches Open-Source Firewall for AI and Human Access Control

The chief information security officer at a Fortune 500 financial services firm—let's call him David, because he asked not to be named—has a problem that didn't exist two years ago. His company deployed AI agents last quarter to handle customer service inquiries. Thousands of them, operating around the clock. They're remarkably effective. They're also, in his words, "basically uncontrollable."

"We built access controls for humans," David told me during a brief call between meetings. "Role-based permissions. Audit logs. The whole nine yards. But these agents? They're querying databases, pulling from document stores, synthesizing answers from a dozen different sources—all in milliseconds. By the time we log what happened, it's ancient history."

He's not alone. According to McKinsey's latest survey, 65% of enterprises now use generative AI regularly in their operations. Cisco's 2025 Cybersecurity Readiness Index puts a finer point on it: 86% of organizations experienced some form of AI-related security incident last year. The gap between how fast companies are deploying AI and how well they can govern it isn't closing. If anything, it's widening.

The question corporate security teams face isn't whether this creates risk—that debate is over. The question is more fundamental: How do you enforce consistent policies when your attack surface now includes not just fallible humans but autonomous agents making thousands of decisions every minute, often with minimal oversight?

When Access Control Meets Its Match

Traditional security architecture makes a simple assumption: there's a person at the keyboard. Someone who logs in, clicks through an interface, occasionally makes a mistake. The entire edifice of enterprise security—least privilege principles, role-based permissions, audit trails—rests on that foundation.

AI agents shatter it.

They don't log in through a browser. They traverse APIs. They query vector databases most security teams don't even know exist. They synthesize outputs from multiple sources and act on their own judgment within milliseconds. Deloitte estimates that 25% of enterprises using generative AI will deploy agents this year, a figure expected to hit 50% by 2027. Each one represents what security professionals awkwardly call a "non-human identity"—an actor that needs governance but doesn't fit into any existing playbook.

The OWASP Top 10 for LLM Applications, a widely referenced framework, catalogs the core vulnerabilities: prompt injection, sensitive information disclosure, excessive agency. These aren't theoretical. Last December, the UK's National Cyber Security Centre issued guidance that reads almost like a concession speech. Prompt injection attacks, the agency warned, may never be fully mitigated at the model layer. The only viable defense? Layered runtime controls that sit between data sources and whoever—or whatever—is consuming them.

IBM's 2025 Cost of a Data Breach report quantifies the stakes. The average breach now runs $4.44 million. When shadow AI is involved and access controls are inadequate, that figure climbs by roughly $670,000. Most breached organizations, IBM found, lacked proper AI oversight. The gap becomes particularly acute as companies move beyond experimental pilots (95% of which show no measurable profit-and-loss impact, per MIT research) into scaled production deployments where the data is more sensitive and the consequences more severe.

A Market Scrambling to Respond

Digital illustration for article section "A Market Scrambling to Respond" in "Velum Labs Launches Open-Source Firewall for AI and Human Access Control" - A dynamic and expressive hand-drawn sketch illustration visualizing a frantic tech market scene wher...

The security industry has noticed. Perhaps too enthusiastically.

Amazon Web Services launched Bedrock Guardrails with PII redaction, hallucination detection, and scanning for prompt attacks—then, in a telling move, slashed pricing by up to 85% in December to spur adoption. Microsoft integrated Prompt Shields into Azure AI Content Safety and ran what it called the LLMail-Inject challenge, subjecting its defenses to 370,000-plus adversarial attempts. Akamai built a firewall for AI that operates at the network edge. Check Point announced plans to acquire Lakera, billing the deal as end-to-end AI security. Startups like WitnessAI and Robust Intelligence are carving out niches in behavioral runtime defense and automated red-teaming.

Identity vendors are approaching the problem from a different direction entirely. Okta introduced something called Cross App Access, an OAuth extension meant to govern how AI agents interact with applications at the identity layer. Delinea is acquiring StrongDM to merge privileged access management with just-in-time authorization for non-human identities. Teleport rolled out an Agentic Identity Framework. The thesis underlying all of this: if agents are actors with permissions, treat them like any other principal in your identity infrastructure.

Open-source tools, meanwhile, have proliferated. NVIDIA's NeMo Guardrails offers programmable rails for LLM applications. Microsoft's Presidio handles PII detection and anonymization. Open Policy Agent, a Cloud Native Computing Foundation project that graduated in 2021, provides policy-as-code that many enterprises already deploy across Kubernetes and service meshes—and now, increasingly, AI workloads. Academic researchers are publishing frameworks like OpenGuardrails and LlamaFirewall, complete with Apache 2.0 licenses and benchmarks against real-world jailbreak datasets.

The result, predictably, is fragmentation. Security teams need prompt-injection defenses and data redaction and policy enforcement and identity governance and audit trails. Often from four different vendors. With four different integration paths. Four separate management consoles.

What's missing isn't more point solutions. It's a unified control plane that enforces content-level policies consistently, whether the entity making a request is a human analyst or an agent orchestrating a chain of API calls.

The Two-Person Bet on Unification

Digital illustration for article section "The Two-Person Bet on Unification" in "Velum Labs Launches Open-Source Firewall for AI and Human Access Control" - A conceptual technical illustration rendered in a hand-drawn sketch style depicting a unified open-s...

Velum Labs thinks unification might matter more than feature proliferation. A bold thesis for a two-person startup fresh out of Y Combinator's Winter 2026 batch.

The company describes its core product as an open-source firewall that enforces content-level access policies across AI agents and human users alike—a positioning that deliberately collapses the distinction between the two into a single enforcement layer.

Founders Benjamin Muñoz-Cerro and Alen Rubilar-Muñoz launched Velum in 2025. Muñoz-Cerro studied quantum computing at Stanford and physics at Harvard; Rubilar-Muñoz comes from machine learning engineering. Their initial vision leaned heavily on zero-trust architecture and, somewhat ambitiously, fully homomorphic encryption—the idea that AI agents could operate on sensitive data they "mathematically cannot see."

That messaging has since evolved. The YC profile and company website now emphasize something more pragmatic: real-time redaction and tokenization, semantic detection that understands context rather than just pattern-matching for Social Security numbers, and natural-language policy authoring that lets security teams write rules in plain English instead of wrestling with custom code.

The firewall sits inline across prompts, responses, and retrieval-augmented generation pipelines, scanning for sensitive content before it reaches a model or end user. Velum claims it generates audit-ready evidence of every policy decision—increasingly a requirement as the EU AI Act phases in robustness and logging mandates through 2027. The company also touts multi-cloud and data residency support, which resonates with enterprises managing hybrid deployments and navigating a patchwork of regional compliance obligations.

The open-source angle is deliberate, not ideological. Enterprises increasingly favor inspectable, self-hostable guardrails for security-critical infrastructure. Open Policy Agent's trajectory—now a graduated CNCF project with broad adoption—demonstrates that policy-as-code resonates when teams can audit the logic and contribute improvements themselves. If Velum can deliver semantic detection and tokenization under an open license, it slots naturally into existing DevOps pipelines alongside tools like Presidio and NeMo Guardrails. Potentially becoming a default layer in the stack rather than yet another proprietary black box.

The timing may be instructive. Anthropic donated the Model Context Protocol to the Linux Foundation–backed Agentic AI Foundation last December, and MCP adoption is spreading rapidly. Security researchers are already raising concerns about tool orchestration, server vulnerabilities, and data poisoning in MCP-mediated workflows. A firewall that can mediate agent-tool-data interactions at the content level—enforcing granular policies about who or what can access which information, regardless of protocol—addresses a gap that identity controls and application-layer security can't fully close on their own.

What Happens Next

Digital illustration for article section "What Happens Next" in "Velum Labs Launches Open-Source Firewall for AI and Human Access Control" - A conceptual illustration depicting a timeline stretching forward over the next 18 months, visualizi...

The next 18 months will separate infrastructure that endures from tactical patches that fade. The regulatory environment is tightening on multiple fronts. The EU AI Act's high-risk system requirements take full effect in August 2026. U.S. federal mandates—particularly OMB memorandum M-24-10—are pushing Chief AI Officers to implement minimum practices for safety-impacting AI systems. Organizations treating governance as an afterthought, bolting on guardrails only when auditors or regulators demand evidence, will accumulate the kind of technical debt that's expensive and time-consuming to unwind.

The more interesting question, though, is architectural. Will content-level firewalls emerge as a distinct layer in the enterprise stack? Or will they get absorbed into broader platforms before independent vendors can establish beachheads?

Check Point's move to acquire Lakera suggests the latter. Cloud providers are rapidly expanding native guardrails—AWS's ApplyGuardrail API now works across non-Bedrock models; Azure's Content Safety integrates with every Azure AI service. Identity vendors are building agent governance directly into their control planes. For startups like Velum, the risk is commoditization before they achieve what Silicon Valley calls "escape velocity."

Open source might be the hedge. If Velum's firewall becomes widely adopted infrastructure—something teams deploy by default, contribute to, extend for their own needs—it could achieve distribution that pure commercial plays struggle to match. There's precedent. Kubernetes didn't win because it was technically superior to every competitor. It won because it became the standard around which an ecosystem coalesced.

Whether a two-person team can execute that playbook while simultaneously building a sustainable business remains very much an open question. But the market need is undeniable, and the window hasn't closed. Enterprises won't wait around for perfect solutions. They'll adopt what's available, what they can inspect, and what's good enough to satisfy the next audit.

In an industry moving as fast as AI governance—maybe faster than the technology it's trying to govern—that calculus might be all that matters. David, the CISO who asked not to be named, put it more bluntly: "We need something that works next quarter, not next year. Even if it's not elegant."

Elegant or not, the firewalls are coming. The only question is whose.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • Ecovia Bio Lands Series B for Biodegradable Plastic Alternative
  • TWAICE Secures €24M EIB Venture Debt for Battery Analytics
  • The Infrastructure Race Behind Medicine's Digital Twin Revolution
  • AI Finds 500 Zero-Days: How Claude Opus 4.6 Is Rewriting Security
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.