Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

Fintech iconFintechOctober 4, 2026

HIFI raises $37M for tokenized money infrastructure

HIFI raises $37M for tokenized money infrastructure
StablecoinsPayment Processing+3
Fintech iconFintechOctober 3, 2026

Pivot57 launches Africa's first institutional intelligence platform

Pivot57 launches Africa's first institutional intelligence platform
Africa TechInstitutional Finance+3
Fintech iconFintechJune 27, 2026

Allowance Gives AI Agents Payment Cards with Built-In Guardrails

Allowance Gives AI Agents Payment Cards with Built-In Guardrails
YcAi Agents+3
Fintech iconFintechJune 27, 2026

PLAN0 AI Debuts Bloomberg-Style Platform for Construction Costs

PLAN0 AI Debuts Bloomberg-Style Platform for Construction Costs
YcConstruction Tech+3

Founders Mentioned

Kareem Selim

RASPIRE

saas icon
SaaS

Hassan Mostafa

RASPIRE

saas icon
SaaS

Kareem Selim

RASPIRE

saas icon
SaaS

Hassan Mostafa

RASPIRE

saas icon
SaaS
Fintech iconFintech
June 27, 2026
YcCybersecurityFraud DetectionMobile App DevelopmentEnterprise Security

YC-Backed RASPIRE Unveils Runtime Defense for AI-Era Mobile Threats

The post-compile security platform claims to protect 20M+ mobile users from AI-powered fraud without code changes—positioning against legacy RASP vendors and emerging enterprise rivals.

YC-Backed RASPIRE Unveils Runtime Defense for AI-Era Mobile Threats

The pitch is elegantly simple, almost suspiciously so: upload your finished mobile app, wait less than an hour, and download a hardened version shielded against runtime attacks. No SDK integration. No code refactoring. No developer friction whatsoever.

That's the promise from RASPIRE, a San Francisco startup that surfaced from Y Combinator earlier this year with a post-compile approach to mobile application security. The company's core argument? That the very apps protecting sensitive financial data are themselves vulnerable the moment they hit a user's device—and that traditional security tools create too much friction for time-strapped development teams to bother with.

On June 1, 2026, RASPIRE unveiled its SHIELD 2.0 platform, then followed up roughly a week later with a Y Combinator launch post claiming the technology already safeguards "apps used by 20M+ end users" across banking, fintech, healthcare, and e-commerce. It's an audacious figure for a company founded just last year. It's also one the startup offers no way to independently verify.

The Workflow Problem

Runtime Application Self-Protection—RASP, in industry shorthand—has been around for years. The idea is straightforward: embed defenses directly into an application so it can detect and respond to attacks while running on a user's device. Sounds good in theory. In practice, it usually means integrating third-party SDKs into your codebase, managing new dependencies, and maintaining those integrations across every release cycle.

RASPIRE's founders, Kareem Selim and Hassan Mostafa, both emphasize backgrounds in offensive security work for banks and financial institutions. They clearly believe that friction is the real enemy. Their solution bypasses the integration step entirely. Developers upload a compiled APK, IPA, or xcarchive file to RASPIRE's platform. The system applies what it calls "AI-configured" runtime defenses, then returns a production-ready binary. The company's materials claim the entire process takes under an hour and slots neatly into existing CI/CD pipelines.

Once deployed, protected apps stream telemetry to a centralized dashboard—or pipe it into third-party monitoring systems like Sentry and Datadog. The platform flags code tampering, hooking attempts, man-in-the-middle attacks, jailbroken devices. Automated responses are granular: block a suspicious session outright, redirect the user to a warning screen, or just log the behavior quietly for forensic review later.

The platform supports native Android and iOS builds, plus the usual cross-platform suspects: Flutter, React Native, Unity, Xamarin. It's a broad compatibility net, assuming it all works as advertised.

SHIELD 2.0 and the AI Anxiety

The SHIELD 2.0 update, detailed in a June blog post by CTO Hassan Mostafa, emphasizes stronger runtime protections against tampering, instrumentation, and debugging. It also expands telemetry and risk-scoring features—perhaps more important than it sounds, given how sophisticated mobile fraud schemes have become.

The timing isn't accidental. A February report from Wallarm flagged APIs as the "single most exploited attack surface" in modern application stacks. Kaspersky's first-quarter mobile threat data showed Android banking Trojans continuing their steady climb. LexisNexis documented an 8% uptick in global fraud rates last year, driven partly by synthetic identities and automated bot attacks.

Digital illustration for article section "Content Section 3" in "YC-Backed RASPIRE Unveils Runtime Defense for AI-Era Mobile Threats" - A clean, minimal, and conceptual 3D illustration representing API vulnerabilities and mobile threats...

RASPIRE positions itself as "the first line of defense for applications against AI-powered fraud attacks, API abuse, and runtime threats," according to its Y Combinator profile. That language puts the startup in implicit conversation with a wave of enterprise security vendors rolling out "agentic AI protection" products earlier this year—Palo Alto Networks' Prisma AI Runtime Security, Radware's Agentic AI Protection, HiddenLayer's runtime module. Those focus on AI agents and multi-step autonomous threats, not traditional mobile apps, but the terminology overlap is hard to miss.

A Crowded Field

Mobile RASP isn't exactly virgin territory. Guardsquare, Appdome, Promon, Digital.ai—all have been selling runtime protection and app shielding for years, often with deep hooks into developer workflows and compliance frameworks. Appdome, for instance, also markets a no-code security model, applying protections at build time without requiring SDK integration.

RASPIRE's claimed differentiator is the combination of post-compile convenience and those "AI-configured" defenses supposedly tuned to each individual binary. The company's website features illustrative metrics—"attacks blocked," "top threats this week"—though these read more like marketing displays than audited figures.

Customer testimonials are there, but anonymized: quotes from a "regional e-commerce CTO" and various bank chief information security officers. No names. No logos. The site lists compliance mappings for OWASP MASVS, PCI DSS, GDPR, HIPAA, and SOC 2, but doesn't publish third-party certifications or penetration test results. Pricing? Not public.

The Verification Gap

That "20M+ end users" claim—repeated in RASPIRE's Y Combinator launch materials and subsequently picked up by several secondary news outlets—lacks any substantiation. A separate marketing page on AngelsRound, dated June 24, lists "16 customers," "25+ production apps," and "50k+ attacks blocked." The site itself describes these figures as unverified.

There's also a headcount mystery. LinkedIn lists "11–50 employees," though neither it nor Y Combinator's company profile carries a timestamp, so it's unclear which is accurate or whether the LinkedIn range includes contractors, advisors, or just outdated data sitting in a profile field someone forgot to update.

For a platform claiming to protect millions of users across high-stakes verticals like banking and healthcare, the absence of verifiable deployment data stands out. Security leaders at financial institutions—the very buyers RASPIRE is courting—would typically be expected to demand proof. Reference customers. Penetration tests. Performance benchmarks. False-positive rates. The works.

Simplicity Versus Scrutiny

RASPIRE is entering a market where workflow elegance matters nearly as much as technical capability, maybe more. Security teams at banks and fintech companies are chronically overstretched; a solution promising protection without upending build pipelines has real appeal. But those same teams don't typically sign contracts based on slick demo videos and unverified user counts.

The company's June launch materials and demo links suggest product confidence, and Y Combinator's backing signals that at least some investors see a viable path forward. Whether that's enough to carve out market share against entrenched incumbents—or capture a new segment as AI-accelerated fraud grows—depends largely on what happens when the marketing claims meet real-world due diligence.

Digital illustration for article section "Content Section 6" in "YC-Backed RASPIRE Unveils Runtime Defense for AI-Era Mobile Threats" - A minimalist and conceptual 3D pop art toy style scene featuring a glossy, vibrant orange geometric ...

For now, RASPIRE is placing a bet that simplicity and speed can win in a category that's historically rewarded neither. The founders' offensive security backgrounds may resonate with their target buyers. But in enterprise security, trust comes from verification, not pitch decks. And on that front, the startup still has considerable ground to cover.

More stories

  • HIFI raises $37M for tokenized money infrastructure
  • Pivot57 launches Africa's first institutional intelligence platform
  • Allowance Gives AI Agents Payment Cards with Built-In Guardrails
  • PLAN0 AI Debuts Bloomberg-Style Platform for Construction Costs
  • YC's Uno Wallet Claims First Third-Party iPhone Default Wallet Status
  • Hyper Launches Self-Maintaining Knowledge Graph for AI Agents
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.