Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 3, 2026

DesignVerse raises $5.5M to automate enterprise software

DesignVerse raises $5.5M to automate enterprise software
Ai AutomationEnterprise Software+3
SaaS iconSaaSOctober 3, 2026

OSCP raises $6M for GPS-free navigation sensors

OSCP raises $6M for GPS-free navigation sensors
PhotonicsSensor Tech+3
Healthtech & Biotech iconHealthtech & BiotechMay 29, 2026

Panacea Launches AI-Native Platform to Accelerate FDA Approvals

Panacea Launches AI-Native Platform to Accelerate FDA Approvals
YcBiotech+3
Fintech iconFintechMay 29, 2026

YC-Backed Klaimee Launches Liability Insurance for AI Agents

YC-Backed Klaimee Launches Liability Insurance for AI Agents
YcInsurtech+3

Founders Mentioned

Eric Levine

Clawvisor

saas icon
SaaS

Eric Levine

Clawvisor

saas icon
SaaS
SaaS iconSaaS
May 29, 2026
YcAi AgentsAi Access ControlApi InfrastructureEnterprise Security

YC-Backed Clawvisor Launches Authorization Layer for AI Agents

Post-exit founder Eric Levine's new startup solves the 'YOLO agent' problem with purpose-based authorization, letting companies deploy AI agents without surrendering full API access.

YC-Backed Clawvisor Launches Authorization Layer for AI Agents

Most entrepreneurs chase glamorous problems. Eric Levine builds plumbing.

His previous company, Berbix, automated identity verification—decidedly unsexy work that Socure nonetheless found compelling enough to acquire in 2023. Now, operating as a Visiting Partner at Y Combinator while running his latest venture, Levine has identified another problem that keeps infrastructure engineers up at night: AI agents with unfettered access to company systems.

"We call it the YOLO agent problem," Levine says, describing the current state of affairs where autonomous AI systems operate with full API permissions because nobody has figured out a better way.

Enter Clawvisor, which emerged from Y Combinator's Spring 2026 batch and went public in early May. The product occupies an unusual space in the technology stack—somewhere between skepticism about AI autonomy and grudging acceptance that these systems aren't going away. It sits as a gateway between AI agents and the downstream services they interact with, enforcing what Levine calls "purpose-based authorization."

The pitch is almost brutally simple: You approve what an agent should accomplish once. Clawvisor then ensures every subsequent API request aligns with that approved purpose, while keeping credentials locked in an encrypted vault that agents access only through the gateway.

"Approve a purpose, not a permission," Levine wrote in the company's February 26 launch post. It's a deliberate inversion of how authorization has worked since the web services era.

When OAuth Meets Chaos

The problem isn't exactly new, though its urgency has escalated. OAuth scopes were designed in an era of deterministic applications—software that did predictable things when humans clicked buttons. A scope like calendar.write grants blanket permission to modify calendar events, which works fine when there's a person in the loop making conscious decisions.

It works considerably less well when an autonomous agent is interpreting natural language instructions and deciding what to change on its own.

The alternatives most teams have tried aren't much better. Approving every individual action creates what Levine calls "approval fatigue"—that numbing effect where security becomes a speed bump people reflexively click through. Storing credentials in environment variables or configuration files creates sprawl and audit nightmares. So most teams building with AI agents default to what amounts to crossing their fingers and hoping nothing breaks spectacularly.

Hence: YOLO mode.

The Mechanics of Trust

Clawvisor operates as an intermediary, which is perhaps the only place it could operate given the constraints. When an agent wants to perform an action, it sends a request containing four pieces of information: which service, what action, the parameters, and a natural language explanation of why it needs to do this.

What happens next involves several layers of verification, some mandatory and others optional depending on how paranoid you are.

First, Clawvisor authenticates the agent itself and checks hard restrictions—essentially blacklists of certain actions or services that are never allowed. Second, it verifies the request matches a task scope that someone has previously approved. This is where the "purpose" model kicks in. Third, for edge cases or particularly sensitive operations, it can surface individual requests for human approval.

Task scopes come in two flavors. Session-based scopes expire when a task completes—something like "summarize my emails from this week" makes sense as a one-time operation. Standing scopes run indefinitely until someone revokes them, appropriate for ongoing monitoring tasks like "watch Stripe for failed payments and ping me in Slack."

Optional LLM-based verification adds another layer. Clawvisor can run inference to confirm that a request's parameters and reasoning genuinely align with the approved purpose, rather than representing some creative reinterpretation by the agent. According to self-reported evaluation results from mid-March, the system achieved roughly 95.6% accuracy across 249 test cases, catching all 42 attempted prompt injection attacks.

Those numbers are encouraging, though it's worth noting the evaluation framework is still evolving—as is everything else in this space.

A Growing Adapter Collection

Digital illustration for article section "A Growing Adapter Collection" in "YC-Backed Clawvisor Launches Authorization Layer for AI Agents" - Generate an image of diverse app icons (non-branded, abstract shapes) interconnected with subtle lin...

As of the documentation available in late May, Clawvisor supported 14 service adapters: the usual suspects like Gmail, Google Calendar, Google Drive, GitHub, Slack, Notion, and Linear, plus some less common integrations like iMessage (via a local bridge), Granola, and Perplexity. The documentation also lists Outlook and OneDrive as available. SendGrid, Jira, Salesforce, and Airtable are marked "coming soon," that perpetual state of startup roadmaps.

On the agent side, integration options include Claude Code, Claude Desktop (via Anthropic's Model Context Protocol), OpenClaw, and any HTTP-capable agent—which is to say, pretty much anything that can make a web request.

The Model Context Protocol integration deserves attention. MCP has become something of a common boundary layer for agent tooling, and Clawvisor offers a server implementation that plugs into that ecosystem. It's a savvy move, letting the product ride on infrastructure that Anthropic is pushing hard.

The most recent release, version 0.9.8 from May 21, includes improvements to something called "proxy-lite" runtime. This feature presents OpenAI and Anthropic-compatible endpoints that allow Clawvisor to observe model API calls, intercept tool usage, and attribute requests to specific registered agents. In other words, it wraps not just the downstream services but the language model itself.

Security by Design, With Caveats

Digital illustration for article section "Security by Design, With Caveats" in "YC-Backed Clawvisor Launches Authorization Layer for AI Agents" - Generate an image of a modern, abstract vault door slightly open, symbolizing the secure storage of ...

The security architecture centers on a straightforward principle: credentials never reach the agent. They're stored with AES-256-GCM encryption in Clawvisor's vault. Agent tokens are hashed with SHA-256 and displayed in plaintext exactly once during initial setup. For particularly sensitive routes—gateway requests, task management—the system enforces end-to-end encryption using X25519 key exchange and AES-256-GCM. Other routes rely on TLS in transit, which is standard but not immune to certain attack vectors.

Human-in-the-loop approvals can happen through multiple channels, depending on where you're working: a web dashboard, Telegram notifications, push notifications to mobile devices, or even a terminal UI for command-line workflows. Everything gets logged to a searchable audit trail.

The GitHub repository includes a prominent warning that's refreshingly direct: "Clawvisor is experimental and unaudited. Don't use it as the sole safeguard for critical systems."

That's probably wise. Building security infrastructure for unpredictable AI systems is hard enough without overpromising.

Cloud or Self-Hosted

Companies can deploy Clawvisor in two configurations. The cloud option offers a free trial without requiring a credit card upfront, though pricing for paid tiers isn't published on the website. An enterprise track promises single sign-on, SAML integration, compliance features, and dedicated support, available through the standard "contact sales" dance.

The self-hosted option ships under the Elastic License 2.0—a licensing choice that keeps the code visible while maintaining some commercial control. Installation options include a curl script, Docker container, or Cloud Run deployment. Documentation covers integration with specific agents and includes architecture deep-dives for teams that need to understand exactly what's happening under the hood.

Funding details are sparse but traceable. Third-party directories list $125,000 from Y Combinator in March 2026, which aligns with YC's standard deal structure. The Y Combinator directory lists team size as one person, though that information may not reflect current staffing given how much has shipped since the Spring 2026 batch concluded.

A Market Still Taking Shape

Digital illustration for article section "A Market Still Taking Shape" in "YC-Backed Clawvisor Launches Authorization Layer for AI Agents" - Generate an image of a wide, empty terrain with a single road leading towards the horizon, represent...

Clawvisor is entering territory that didn't really exist two years ago and is still poorly defined today. AI gateway vendors like Palo Alto Networks published analysis in late April discussing unified gateways for agent traffic. Other security vendors are circling the same problem. Meanwhile, agent frameworks themselves are adding authorization primitives, and identity and access management platforms are eyeing extensions into this space.

There's a plausible future where agent frameworks or IAM systems build native authorization into their stacks, potentially obviating the need for a separate gateway layer entirely.

Levine's bet seems to be that the gateway pattern wins precisely because it sits outside any particular agent runtime. Whether you're running Claude, OpenAI's swarm framework, or some custom LangChain setup, Clawvisor enforces policy consistently across all of them. That's considerably harder to replicate if every framework builds its own solution.

The company amplified its launch through Y Combinator's distribution channels in early May, hitting LinkedIn and developer aggregators. GitHub engagement stood at 206 stars and 28 forks when checked in late May—modest traction for an infrastructure tool at this stage, though these things can move quickly when adoption hits.

The Practical Middle Ground

For engineering teams actually deploying AI agents in production environments—and there are more of them than you might think—Clawvisor represents something like a pragmatic compromise. Full autonomy is too risky for most organizations to stomach. Approving every individual action is too slow to be useful. Purpose-based authorization gives agents enough operational freedom to be genuinely helpful without enough to cause catastrophic damage.

The vault architecture also solves a mundane problem that nonetheless trips up real deployments: where exactly do you store the API keys your agent needs? Not in the agent's configuration files. Not in some scattered key management system the agent queries directly. Clawvisor centralizes credential storage, injects them server-side as needed, and ensures they never appear in the agent process itself.

That's useful, perhaps even necessary. Whether it's enough to build a standalone business, or whether this kind of authorization becomes table stakes in agent frameworks over the next year or two, remains an open question.

For now, Levine is shipping code and signing early customers. The "experimental" label gives him space to iterate without overpromising. The open source license keeps the developer community engaged without giving away the entire business model. And the founder's track record—exit from Berbix, YC partnership, deep infrastructure experience—suggests someone who knows how to navigate the gap between early traction and eventual exit.

Building plumbing isn't glamorous. But when the pipes break, everyone notices.

More stories

  • DesignVerse raises $5.5M to automate enterprise software
  • OSCP raises $6M for GPS-free navigation sensors
  • Panacea Launches AI-Native Platform to Accelerate FDA Approvals
  • YC-Backed Klaimee Launches Liability Insurance for AI Agents
  • Kubera Health Raises $6.5M Seed to Fix Healthcare's Payment Crisis
  • YC-Backed Hyper Launches AI 'Company Brain' for Startups
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.