The problem sounds almost quaint in its simplicity. A sales rep asks the company chatbot for help drafting an email. The AI, trained on internal documents and hooked into a vector database stuffed with customer records, helpfully suggests language—along with a competitor's pricing structure that was never meant to leave the finance team's spreadsheets.
This isn't a breach in the traditional sense. No one hacked anything. The systems worked exactly as designed. And that, increasingly, is what keeps enterprise security teams up at night.
Velum Labs, a San Francisco startup barely out of its Y Combinator Winter 2026 cohort, believes it has spotted a fundamental gap in how companies think about AI security. Traditional access controls, the kind that have governed enterprise software for decades, operate at the perimeter. They know who can log into Salesforce, who can query the data warehouse. They don't, however, understand what's actually flowing through an AI system—the unstructured text, the retrieved documents, the generated responses that might contain anything.
"Enterprise AI has a leakage problem," the company argues, perhaps more bluntly than some of its prospective customers would like to admit.
Their answer? What they're calling a semantic firewall: middleware designed to sit between data sources and AI systems, analyzing not just metadata or patterns, but the actual meaning of information as it moves through prompts, database retrievals, and model responses. Write your security policies in natural language, they say. Enforce them consistently. Get an audit trail that compliance teams can actually use.
It's an ambitious pitch. Whether Velum can deliver remains an open question.
Reading the Fine Print (and Everything Else)
The company positions itself around open-source principles, though as of early February 2026, no code has appeared on GitHub. Early access requires filling out a form on their website—standard practice for startups still building in semi-stealth, but a detail worth noting for anyone excited by the "open-source" label.
The core concept centers on interception at the data layer. When an AI model retrieves a document, when a user exports a report from an enterprise system, when a large language model generates a response, Velum's firewall evaluates whether sensitive information should be exposed to that particular recipient at that particular moment.
According to the startup's Y Combinator profile, administrators define sensitivity and access rules using natural language rather than code. The system then enforces those policies across documents, databases, and major enterprise platforms—Salesforce, SAP, Workday, and others in the usual enterprise software constellation. It intercepts LLM prompts on the way in and screens generated responses on the way out, looking for information leakage in both directions.
For high-throughput data pipelines (the kind that choke when you add latency), Velum offers structure-preserving tokenization. Sensitive fields get encrypted in transit, then decrypted just-in-time if authorization rules permit. The result, in theory, is an audit-ready trail showing exactly what went where and why—particularly useful for compliance teams trying to prove they're not accidentally training models on regulated data.
The architecture, at least as described, emphasizes semantic understanding over pattern matching. Rather than flagging Social Security numbers with regular expressions—a brittle approach that misses context—Velum analyzes whether a piece of text contains the kind of information your policies say shouldn't be shared. A Social Security number in a help desk ticket about identity theft? Fine. The same number in a chatbot response to a random sales inquiry? Blocked.
Details beyond that remain frustratingly sparse. The company's documentation pages are mostly placeholders. There's no public SDK, no technical deep-dive, no GitHub repository to inspect. Deployment flexibility gets emphasized—multi-cloud support, configurable data residency per tenant—but whether that means an inline proxy, an API gateway, or something else entirely isn't clear from public materials.
Founders Benjamin Muñoz-Cerro and Alen Rubilar-Muñoz have hinted at more ambitious cryptographic goals in LinkedIn posts, mentioning fully homomorphic encryption and zero-trust architectures. Those capabilities don't appear in current product descriptions. Maybe they're coming. Maybe they were exploratory ideas that didn't pan out. Startups shift direction.
A Crowded Field, a Persistent Problem

Velum is hardly alone in spotting this gap. Meta's Purple Llama project released open models like Llama Guard specifically for content moderation. NVIDIA's NeMo Guardrails provides programmable safety rails for LLM applications. Microsoft's Presidio handles PII detection and redaction, albeit with a more traditional approach. Lakera Guard focuses on defending against prompt injection attacks—a different threat vector, but part of the same security conversation.
Academic researchers have explored similar concepts. LlamaFirewall and the recent Generative Application Firewall proposals tackle overlapping problems with varying degrees of rigor and production-readiness.
So what's different? Velum's bet is on unified enforcement. Instead of stitching together separate tools for input filtering, output scanning, data masking, and audit logging—each with its own API, its own policy language, its own gaps—they're proposing a single policy enforcement point. Think web application firewall, but for unstructured data flowing through AI workflows.
It's an appealing vision. The question is execution.
There's context here worth noting. OpenAI released its gpt-oss-safeguard reasoning models last October, accompanied by a quiet admission that safety checks were consuming roughly 16 percent of compute in some production deployments. Translation: securing AI systems isn't cheap, and organizations are starting to demand visibility into how it works and what it costs.
The industry is moving, haltingly, toward open-weight safety tooling. Partly that's philosophical—transparency and auditability in security systems. Partly it's practical. Enterprises are tired of black-box solutions they can't audit, can't customize, can't truly control.
Velum is accepting early-access requests through its website. The team, per LinkedIn, ranges between 2 and 10 employees—typical for a company this early. Y Combinator's backing provides credibility and connections, though as any veteran founder will tell you, getting into YC and building a sustainable business are separate challenges entirely.
Whether the promised open-source code materializes, and how Velum's approach compares to existing tools once people can actually test it, will determine if semantic firewalls become standard infrastructure or an interesting footnote. For now, the company has identified a real problem. Solving it at scale, with acceptable latency and reasonable costs? That's the hard part, and no amount of natural language policy writing makes it easier.
The enterprise AI security market is heating up, driven by one uncomfortable truth: the systems companies are deploying can't distinguish between helpful and catastrophic disclosure. They just generate text, retrieve documents, answer questions. Someone, or something, needs to read between the lines.
