When Benjamin Muñoz-Cerro and Alen Rubilar-Muñoz pitched their idea to Y Combinator this winter, they weren't selling the usual story of rapid growth and network effects. They were selling paranoia—the kind that keeps enterprise security chiefs awake at night.
Their concern? Every company racing to deploy AI agents is essentially handing powerful new tools access to vast troves of internal data, often without the guardrails that govern human employees. An HR manager blocked from viewing payroll records has no business feeding those same records into ChatGPT, yet most companies lack any systematic way to prevent exactly that.
Velum Labs, which the two founders are running out of San Francisco as part of Y Combinator's Winter 2026 cohort, has built what it describes as a semantic firewall—one that governs both AI systems and human users with the same policy engine. It's an ambitious framing for a company that consists of exactly two people. Whether it's premature remains one of the more interesting questions hanging over the startup.
Content-Level Surveillance
The architecture is more sophisticated than a traditional network firewall. Velum's Dynamic Data Firewall doesn't just monitor traffic at the perimeter; it intercepts every API call, database query, file upload, and LLM prompt before anything reaches its destination. Then it makes a decision: allow, redact, or block.
When an AI agent queries a customer database, Velum's system classifies the data in real time and applies preset policies. Social Security numbers might get stripped from a document. Personally identifiable information could be blocked from reaching a third-party API. Training datasets get sanitized before entering a model. At least, that's the theory.
The company claims compatibility with more than 50 enterprise platforms—SAP, Oracle, Salesforce, ServiceNow among them—and logs every decision for audit trails. The pitch positions this as a compliance play: GDPR's purpose limitation requirements, HIPAA's minimum necessary standard, SOC2 frameworks. All the acronyms enterprises care about, bundled into a single chokepoint.
Velum's second module adds what the founders call Purpose/Role Based Access Control, which sounds like standard role-based access control until you read the fine print. Users don't just declare their role; they declare their intent. A finance analyst investigating fraud might get temporary access to transaction records, but only for that stated purpose, with an automatic expiration and approval workflow baked in. It's an intriguing twist on zero-trust architecture, though one that assumes employees will truthfully declare why they need data—a premise that doesn't always survive contact with reality.
The FHE Gambit

The technical foundation, according to Rubilar-Muñoz's LinkedIn posts and scattered references on the company website, relies on fully homomorphic encryption. That's a signal of serious ambition. FHE allows computations on encrypted data without ever decrypting it—a holy grail in privacy-preserving systems, but notoriously difficult to implement at scale.
Rubilar-Muñoz, a recent Minerva University graduate with research experience in AI and machine learning, announced the Y Combinator acceptance by describing the company's mission as building "zero-trust infrastructure for AI privacy using fully homomorphic encryption." His co-founder Muñoz-Cerro brings credentials from Stanford and Harvard in quantum computing and physics. On paper, they have the technical chops. Executing at enterprise scale with a two-person team is another matter entirely.
The Open Source Puzzle
Here's where things get murky. Velum describes itself as "open-source" on its Y Combinator profile and LinkedIn page. An "Open Source" tag appears on the company website. But as of early March, no public GitHub repository exists for the firewall. No license document has surfaced. The company blog sits empty with a placeholder message: "No blog posts yet."
It's possible the open-source release is timed to general availability, which hasn't happened yet. The site is dotted with "Request Early Access" and "Design Partner" prompts, suggesting the product remains in beta. But the discrepancy raises questions about positioning. Are they open-source in intent, or is this marketing language that got ahead of the engineering roadmap?
The ambiguity matters because open source would be a significant differentiator in this market. Enterprises evaluating AI security tools tend to prefer transparency, especially when those tools sit in the critical path of every data request. A proprietary black box is a harder sell.
Already Crowded

Velum is hardly alone in chasing this problem. ProofHelm built a vendor-neutral runtime firewall for LLMs and agents. Radware, Robust Intelligence, and Securiti all have enterprise LLM firewall products already deployed. Open-source alternatives have proliferated: OpenGuardrails, Guardrails AI's library, Octelium's AI gateway with policy-as-code.
What Velum seems to be betting on is unified control—the same policy engine governing whether sensitive data reaches an employee's laptop or an AI model's context window. That dual-purpose approach, layered with FHE and content-level filtering, represents the startup's angle of attack. Whether that's differentiation enough in a market filling up fast is unclear.
The company's messaging itself appears unsettled. Y Combinator's directory currently describes Velum as "The OS for data quality across any stack," which is a notably different pitch than the firewall and ontology framing on Velum's own website. Early-stage startups often iterate on positioning, but the gap suggests the founders are still figuring out exactly what story resonates.
The Execution Question

Most specifics remain provisional. A third-party funding aggregator mentions a $500,000 figure, though the company hasn't disclosed financing publicly and this remains unverified by primary sources. There are no customer case studies. No deployment examples. No technical benchmarks showing how the FHE implementation performs under load, or what latency penalty it introduces.
For security teams evaluating AI rollout strategies, Velum represents one emerging answer to a real and growing concern. AI tools have expanded the attack surface for data leakage in ways most enterprises haven't fully accounted for. The question isn't whether the problem exists. It does.
The question is whether two founders, however technically credentialed, can build the infrastructure to solve it at enterprise scale—deliver the open-source code they've alluded to, carve out market share against better-funded competitors, and sustain a business model that works. Y Combinator's bet suggests at least one set of experienced investors thinks the odds aren't terrible.
But this early, with this little public evidence, calling it more than a promising hypothesis would be generous.
