Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

Subvocal launches under-chin wearable for silent computer control

Subvocal launches under-chin wearable for silent computer control
YcBrain Computer Interface+3
SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
Healthtech & Biotech iconHealthtech & BiotechFebruary 28, 2026

Ex-Tesla Engineers Launch Fort: Auto-Tracking Strength Wearable

Ex-Tesla Engineers Launch Fort: Auto-Tracking Strength Wearable
YcWearable Tech+2
SaaS iconSaaSFebruary 28, 2026

YC-Backed Bubble Lab Launches Pearl AI Automation for Ops Teams

YC-Backed Bubble Lab Launches Pearl AI Automation for Ops Teams
YcAi Agents+3

Founders Mentioned

Kevin Pan

Salus

saas icon
SaaS

Ankit Gupta

Y Combinator

saas icon
SaaS

Kevin Pan

Salus

saas icon
SaaS

Ankit Gupta

Y Combinator

saas icon
SaaS
SaaS iconSaaS
February 28, 2026
YcAi AgentsEnterprise AiAi Observability

YC-Backed Salus Launches Guardrails to Stop AI Agents from Costly Errors

Runtime validation platform intercepts AI agent actions before execution, claiming 60% cost cuts and 52% fewer policy violations in benchmarks. Targets growing enterprise agent safety gap.

YC-Backed Salus Launches Guardrails to Stop AI Agents from Costly Errors

Last month, during a test of an AI-powered customer service agent, the system nearly approved a $60,000 refund—for a ticket that cost $400.

The agent had misread booking codes, hallucinated a policy exception that didn't exist, and was seconds away from executing a transaction that would have sailed through most companies' approval workflows. It's the kind of mistake that keeps enterprise architects up at night as they contemplate handing more autonomy to AI systems.

This wasn't a hypothetical scenario. It was a demonstration run by Salus, a two-person startup out of Y Combinator's Winter 2026 batch, built precisely to stop these moments before they become expensive reality.

The pitch: intercept every action an AI agent wants to take, validate it against evidence and policy, then either let it proceed or force a do-over with structured feedback. Think of it as a bouncer for autonomous systems—one that doesn't just throw out bad actors but explains why they can't come in and gives them a chance to fix their credentials.

Whether that proves more than a well-marketed middleware layer remains an open question. But the underlying problem Salus is targeting? That one's undeniably real.

When Guardrails Meet Execution

AI agents are making decisions at a pace that outstrips human oversight. They're approving refunds, updating databases, routing support tickets, and occasionally—often enough to matter—doing things spectacularly wrong.

The hallucination problem that plagued chatbots hasn't disappeared just because we gave AI access to tools. If anything, it's gotten more dangerous. A chatbot that invents a fact wastes your time. An agent that invents a fact and then acts on it can waste your money.

Salus, which launched publicly last month, positions itself as runtime validation infrastructure. Co-founders Kevin Pan and Vedant Singh—Stanford computer science graduates and former roommates who are now working with YC partner Ankit Gupta—describe their system as sitting between an AI agent and its available functions.

Here's the mechanics: when an agent decides to execute a function call—approving that refund, say, or updating customer records—Salus intercepts it and runs two layers of checks before allowing anything through.

First, evidence grounding. The platform maintains a running cache of everything the agent has actually seen: conversation history, tool outputs, retrieved documents. If an agent tries to act on information that doesn't exist in that cache, Salus blocks the call outright. No hallucinated customer service policies. No invented discount codes.

Second, explicit policy enforcement. Companies write constraints—budget caps, regulatory requirements, approval thresholds—in formats as simple as YAML or plain English. Those constraints compile into runtime checks. Salus can catch budget overruns, regulatory violations, or business logic failures before they execute.

When something gets blocked, the agent doesn't just hit a wall. It receives structured feedback: here's why your action failed, here's what policy you violated, here's what evidence you're missing. According to Salus, 58% of initially blocked actions succeed after the agent adjusts and retries.

That self-correction rate feels optimistic—perhaps more than the founders expected when they started building—but if it holds up in production environments, it's the kind of number that could shift the economics of agent deployment.

The Benchmark Results (With Caveats)

Digital illustration for article section "The Benchmark Results (With Caveats)" in "YC-Backed Salus Launches Guardrails to Stop AI Agents from Costly Errors" - A conceptual visualization of AI validation benchmarks rendered in a sophisticated neo-cyberpunk aes...

Salus has run its validation system against two academic benchmarks designed to stress-test agent reliability under realistic constraints.

On ODCV-Bench, which measures whether agents violate ethical and safety rules when pressured to hit performance targets, Salus reduced policy violations by 52% on average across 12 frontier models. The benchmark, published in 2025, documented baseline misalignment rates between 30-50% across many leading models—a sobering reminder that even state-of-the-art systems routinely break rules under pressure.

On τ²-bench, a 2025 benchmark for dual-control customer service scenarios, agents using Salus followed policies more reliably while cutting costs by up to 60%.

Those are vendor-reported numbers. No independent replication has been published yet, which means they should be read with the appropriate grain of salt.

Still, the cost reduction claim is notable if it proves out. Much of the expense in agent systems comes from wasted API calls—agents spinning in loops, retrying failed actions without learning from mistakes, or executing redundant operations. If Salus can short-circuit those patterns, the savings could be material.

In internal benchmarks, the company claims a 26% improvement in correctness and double the consistency for customer service workflows. The airline refund demo that nearly approved $60,000? Salus blocked it, cited the specific policy violation and the missing booking evidence, then escalated to a human supervisor.

Whether these gains translate beyond controlled test environments is another matter entirely. Enterprise workloads have a way of looking nothing like academic benchmarks.

Implementation: One Decorator, Multiple Concerns

For developers, the integration is intentionally lightweight. After installing the SDK with pip install salus-ai, engineers wrap their tool functions with a @session.protect decorator. That's it—at least for the basic setup.

The decorator can mark which actions constitute "commits" versus read-only operations, and specify dependencies between tools. The platform integrates with OpenAI, Anthropic, LangChain, LangGraph, and CrewAI out of the box.

Salus also bundles a suite of built-in protections that feel almost table-stakes at this point: PII detection, budget enforcement, infinite loop prevention, idempotency checks, content moderation. Human-in-the-loop escalation triggers are configurable, which matters when you're trying to balance autonomy against risk tolerance.

Real-time observability comes standard, with streaming traces that break down token usage and latency by operation. The same runtime checks used in production can feed an evaluation module that generates adversarial test cases using domain-specific context.

It's a clean developer experience, assuming the underlying validation logic holds up under production traffic. The real test will be whether a single decorator can truly capture the complexity of enterprise policy enforcement—or whether companies end up writing so many custom constraints that the simplicity advantage evaporates.

Crowded Space, Shifting Strategy

Digital illustration for article section "Crowded Space, Shifting Strategy" in "YC-Backed Salus Launches Guardrails to Stop AI Agents from Costly Errors" - A conceptual visualization of a densely packed, high-tech ecosystem representing a crowded market of...

Salus isn't entering a vacuum.

NVIDIA expanded its NeMo Guardrails toolkit with production microservices in 2024. AWS Bedrock launched enhanced guardrails with hallucination detection capabilities in 2025. A wave of academic work in 2025-2026—AgentSpec, Agent-C, VeriGuard—formalized approaches to constraint enforcement for autonomous systems.

On the startup side, Guardrails AI focuses on output validation with corrective actions. Lakera Guard emphasizes prompt injection defense and PII protection. Akto AgentGuard and HaliosAI both market runtime agent guardrails with positioning that overlaps heavily with Salus.

What's shifting across the space is the move from reactive to proactive. Earlier guardrail tools tended to evaluate agent outputs after the fact—useful for logging and analysis, less useful for preventing damage. Runtime validation tries to catch problems before execution and give agents a chance to self-correct.

One critique that's circulated in the agent safety community: too many guardrail products treat all AI outputs the same, applying generic content moderation to problems that are fundamentally about tool use and state changes. Salus positions its evidence-grounding mechanism as specifically designed for function-calling agents, not general LLM outputs.

Whether that distinction matters in practice depends on how different tool-calling risks actually are from other failure modes. The jury's still out.

The Go-to-Market Gamble

Digital illustration for article section "The Go-to-Market Gamble" in "YC-Backed Salus Launches Guardrails to Stop AI Agents from Costly Errors" - A conceptual, high-tech visualization representing a high-stakes go-to-market strategy, featuring an...

Pan and Singh are running a sales-led strategy through demo bookings. No public pricing. No published SLAs. The SDK and documentation aren't prominently listed in public package indexes yet, suggesting distribution is still early and controlled.

The company hasn't disclosed customer names or deployment scale—standard practice for a stealth-to-launch transition, but it makes assessing real-world traction difficult.

With a two-person team at launch, Salus appears focused on proving the core validation engine works reliably before expanding the surface area. That's a reasonable approach, though it raises questions about how much support capacity they have if adoption accelerates faster than headcount.

For engineering leaders evaluating agent deployments, the value proposition is straightforward enough: stop expensive mistakes before they execute, reduce the blast radius of hallucinations, build audit trails that explain why actions were blocked.

Whether Salus captures meaningful market share depends on execution that matches the pitch—and whether benchmark gains hold up when applied to messy, real-world workflows that bear little resemblance to academic test scenarios.

The broader bet is that enterprises will pay for an additional validation layer rather than building it themselves or trusting foundation model providers to solve reliability at the model level. Given how often AI systems still fail in surprising ways, that bet might not be as risky as it sounds.

Then again, every middleware layer introduces latency, complexity, and another potential point of failure. The companies that adopt Salus will be wagering that the cost of prevention beats the cost of cleanup.

In an industry racing toward autonomous everything, that might be the most expensive calculation of all.

More stories

  • Subvocal launches under-chin wearable for silent computer control
  • DoD Solution raises $2M for AI drone navigation in war zones
  • Ex-Tesla Engineers Launch Fort: Auto-Tracking Strength Wearable
  • YC-Backed Bubble Lab Launches Pearl AI Automation for Ops Teams
  • YC-Backed BeeSafe AI Launches Platform to Combat Trust-Based Fraud
  • Ex-Casetext Team Launches $500 Flat-Fee AI Law Firm for Startups
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.