When a financial services firm deploys ChatGPT for its customer support team, what stops the system from inadvertently surfacing account balances from one customer's query in another's? Or consider the healthcare provider whose retrieval-augmented generation tool pulls patient records—but can't distinguish between which doctor should see what.
These aren't hypothetical scenarios. They're playing out in enterprise IT departments right now, and the traditional security perimeter—firewalls, VPNs, role-based access controls—wasn't designed for a world where language models act as data consumers alongside humans.
Velum Labs thinks it has an answer. The Y Combinator-backed startup, fresh from the Winter 2026 batch, has launched what it calls an open-source data firewall. The pitch: enforce granular access policies in real time, treating AI systems and human users as equivalent threats—or, perhaps more generously, as equivalent risks requiring equivalent oversight.
It's an ambitious frame. Whether Velum can deliver on it, particularly the "open-source" part, remains an open question.
Intercepting Data Before It Escapes
Velum's approach differs from the growing cohort of AI guardrail products. Rather than sitting at the application edge or wrapping around a specific LLM API, the company positions its firewall at the data layer itself—between sources and consumers, wherever those consumers might be.
According to Velum's Y Combinator profile, the system intercepts requests "across documents, databases, and applications." The policy engine accepts natural-language rules (think: "marketing interns can't see revenue figures from Q4" or "contractors based in the EU can only access EU-resident data"). Those rules adapt based on context—user role, yes, but also data sensitivity, location, time of day, even real-time threat assessment.
The enforcement mechanism ranges from straightforward allow-deny gates to what the company calls "structure-preserving tokenization." In practice, that means redacting sensitive fields on the fly while keeping the rest of the document intact. Change someone's authorization mid-session? Velum claims it can reveal previously masked data just-in-time, a feature detailed in the company's technical documentation.
For AI workloads specifically, Velum intercepts three critical points: prompts going in, model responses coming out, and retrieval operations pulling from vector databases or knowledge stores. The goal is preventing personally identifiable information from slipping into training sets, sanitizing outputs before they're logged, and stopping RAG systems from becoming inadvertent data leak machines.
Beyond the LLM
What distinguishes Velum—at least on paper—is scope. Many startups have rushed into the "AI security" space with products narrowly focused on prompt injection or jailbreak attempts. Velum is making a broader argument: that enterprises need unified controls across human and machine consumers, and that those controls should span both AI-native systems and legacy platforms.
To that end, the company has built integrations with Salesforce, SAP, and Workday. The same policy engine that governs LLM access, Velum says, can also govern exports, reports, and syncs from these enterprise workhorses. A Salesforce admin pulling customer data for a marketing campaign? Subject to the same real-time policies as a GPT-4 instance querying that same database.
The compliance angle is front and center. Velum's system supports encryption and tokenization for high-throughput pipelines, multi-cloud deployments, and data residency controls—table stakes for any tool pitching itself to regulated industries. Audit trails come baked in, aligned to GDPR, HIPAA, and SOC 2 requirements, per the company's product documentation.
It's a bet that the next generation of data governance won't distinguish between flesh-and-blood employees and silicon-based agents. Both pose risks. Both need guardrails.
The Open-Source Asterisk

Here's where things get murky.
Velum positions itself prominently as an "open-source firewall" across its Y Combinator profile, LinkedIn page, and marketing materials. But at the time of this writing, no public GitHub repository exists. No license file. No code.
The company did not immediately respond to requests for comment about when the code would be published or under which open-source license it would be released. That's not necessarily damning—plenty of startups announce open-source intentions before the repository goes live. But it does raise eyebrows in a landscape where "open source" has become as much marketing language as technical reality.
This matters because alternatives already exist. Rampart, for instance, offers microsecond policy evaluation for AI agents with YAML-based rules and tamper-proof audit chains—and its code is on GitHub. Trylon Gateway provides a self-hosted LLM proxy with prompt injection and PII redaction, also fully open. VibraniumDome operates as an open-source web application firewall specifically for AI agents.
On the commercial side, Cloudflare and Akamai each launched AI firewall products in 2024, focused on protecting model inference at the edge and API layers. So Velum enters a market that's neither empty nor under-served.
The company's edge, if it has one, lies in that broader data-layer architecture—and in the enterprise integrations that extend beyond the AI stack. Whether that's enough will depend on execution, pricing (currently undisclosed), and whether the "open source" promise materializes into something developers can actually fork and deploy.
Who's Building This
Velum was founded in 2025 by CEO Benjamin Muñoz-Cerro and CTO Alen Rubilar-Muñoz, both based in San Francisco. The Y Combinator profile lists a two-person team, though the founders have hinted at grander cryptographic ambitions in social media posts. Fully homomorphic encryption for AI privacy infrastructure has come up in those discussions, though such details are conspicuously absent from current product positioning. Perhaps that's Phase Two.
For now, Velum is operating an early-access program. Organizations can request access to what the company describes as a "semantic firewall for unstructured data." There's a design-partner program listed on the website, but no public pricing information and no general availability timeline.
Which means prospective customers are being asked to bet on a vision—and on the delivery capacity of a two-person team.
The Bigger Question

Velum's central thesis is compelling: that enterprises need a single control plane for governing data access, one that doesn't distinguish between carbon-based and silicon-based consumers. Language models, after all, are just another type of user—albeit users that make thousands of queries per second and lack the social guardrails that prevent most employees from mass-exfiltrating customer records.
But the thesis only works if the technology delivers. And if it's truly open source, that delivery will be subject to scrutiny from a developer community that's increasingly skeptical of startups slapping the label on products that remain closed for months—or indefinitely.
For security teams navigating the AI data governance problem, Velum represents one possible path forward. Whether it's the right path will hinge on transparency, both technical and commercial. The code needs to ship. The pricing needs to make sense. And the architecture needs to prove it can scale beyond pilot programs and design partnerships.
Until then, it's a compelling deck—and little else.
