When the founders list "open-source" twice on official profiles but the GitHub repository remains conspicuously absent, you learn to ask questions. For a startup still in beta, the absence of public code isn't unusual—but it does invite scrutiny.
Velum Labs—a San Francisco outfit that emerged from Y Combinator's Winter 2026 cohort—is working to solve one of the knottier problems in enterprise technology: keeping sensitive data away from the systems, human and machine, that shouldn't touch it. CEO Benjamin Muñoz-Cerro and CTO Alen Rubilar-Muñoz, the company's two-person founding team, describe their product as a firewall that enforces content-level access control across documents, databases, and applications. It's meant to work for both AI systems and the employees querying them—a dual mandate that, if executed, would set Velum apart in an increasingly glutted market.
The premise is straightforward enough: a runtime firewall intercepts requests as they flow between data sources and whoever (or whatever) is asking for them, redacting or tokenizing sensitive fields on the fly. Picture a sales rep querying Salesforce for customer records, with personally identifiable information stripped out before it hits their screen. Or a chatbot ingesting financial data, sanitized before the model ever sees it.
Straightforward in concept, perhaps. Less clear in execution.
What It Says It Does
Velum's pitch, according to its website, revolves around something called the "Dynamic Data Firewall"—a system that classifies sensitive information in real time as requests move through enterprise infrastructure. PII, protected health information, financial records, intellectual property: the firewall flags them all, the company claims, then enforces adaptive policies based on who's asking, when, where, and under what circumstances. Behavioral analytics layer on top to surface anomalies.
For large language models specifically, Velum says it sanitizes prompts, filters training data, and scrubs outputs. These protections have become baseline expectations as enterprises wake up to the reality that models can leak proprietary details or regurgitate customer data in unexpected ways. The company lists integrations with Salesforce, SAP, and Workday in its Y Combinator directory entry.
One feature gets particular emphasis: natural-language policy creation. Security teams could, in theory, write access rules in plain English rather than code. Policies apply at the request level, tailored to each recipient.
The promise is compelling. The details—harder to pin down.
Open Source in Name

"Open-source" appears prominently on Velum's YC profile and LinkedIn page. But a search for a public GitHub repository tied to the startup, conducted in late March, turned up nothing verifiable. The company's documentation portal requires VPN access. The firewall module page invites visitors to "Request Early Access / Join the beta"—language that confirms the product is still in early access, a phase where the absence of published code aligns with typical startup development practices.
There's also a product expansion underway. While Y Combinator's directory describes a standalone firewall, Velum's homepage currently leads with "Alma: The Data Quality Operating System," positioning the firewall as one module inside a larger platform—an extension of the product line rather than a pivot. The site claims Alma is "in production at regulated fintechs," though no customer logos or case studies appear publicly.
For a product marketed as open-source, the current opacity reflects its developmental stage, though the timeline for code publication remains unclear.
A Market Already at Capacity

Velum's timing is either brave or questionable, depending on your appetite for crowded categories. Fellow YC alum Superagent (Winter 2024 batch) calls itself "the AI Firewall." Lakera Guard built enough momentum to get acquired by Check Point last September. Levo AI launched its own enterprise AI firewall around February of this year.
Then there are the infrastructure incumbents. Akamai offers a "Firewall for AI" focused on edge protection. F5 markets "AI Guardrails." NVIDIA's open-source NeMo Guardrails toolkit—updated as recently as last October—provides programmable safeguards that have become something of an industry baseline.
Robust Intelligence, Acuvity, and Backflipt all stake claims in the space. Academic researchers have published open-source guardrail frameworks, including LlamaFirewall and OpenGuardrails, within the past year or so. The category is saturated, in other words.
What We Don't Know
Key details remain elusive. Velum has not disclosed funding beyond rough estimates from third-party aggregators suggesting around $500,000 raised—typical for early-stage startups at this phase, though unconfirmed. No press release or formal launch announcement could be located. Which parts of the code, if any, will ultimately be open-sourced, and under what license, is anyone's guess.
Architecture specifics are equally murky. Does the firewall operate as an in-line proxy? An SDK? Database middleware? What are the latency and throughput trade-offs? How exactly do the integrations with CRM and ERP systems work under the hood? The available materials don't say.
For a two-person team making promises about enforcing content-level policies across the unwieldy surface area of enterprise data and AI workflows, those aren't trivial omissions—though ambitious goals and small team sizes are hardly uncommon in early-stage software startups. The positioning is ambitious. Whether the execution can match it—and whether the "open-source" branding will materialize into actual published code as the product matures—remains to be seen.
In the meantime, the GitHub search box stays empty.
