Seven days before Y Combinator's Winter 2026 Demo Day, Velum Labs has a problem that's easy to miss: The San Francisco startup calls itself open-source, but the code's public availability remains unclear.
Not on GitHub. Not in any public repository that a determined search can surface. The company's documentation console sits behind a VPN wall. For a two-person team pitching what it describes as a "Dynamic Data Firewall" to govern data access across both AI systems and human users, the absence is notable—particularly when the YC directory explicitly labels the venture as open-source.
The discrepancy may simply be a matter of timing. Demo Day lands on Tuesday, March 24. Perhaps the code arrives then, a perfectly choreographed reveal for the cohort's culminating pitch session. Or perhaps the founders, Benjamin Muñoz-Cerro and Alen Rubilar-Muñoz, are still refining what open-source means in their context. Either way, the gap illustrates something about this moment in enterprise software: everyone wants to claim the legitimacy of open-source without always committing to the exposure it demands.
What Velum Says It Does
Strip away the marketing copy, and Velum is pitching content-level access control. Not the prompt-filtering that most so-called AI firewalls handle, but something more ambitious. According to the company's YC profile, administrators write policies in natural language—"no engineers with less than three years tenure can see customer payment histories," say—and those rules apply in real time across databases, documents, and API calls. Whether the requester is an employee, a third-party vendor, or a large language model.
The claim is that Velum's firewall intercepts everything: database queries, file uploads, LLM prompts. It classifies data on the fly, redacts what shouldn't pass through (while preserving structure, the company says), and escalates when behavior looks anomalous. For AI workflows specifically, that means blocking personally identifiable information before it reaches a model, sanitizing training datasets, filtering outputs.
It's a sweeping vision. The product pages name-drop integrations with Salesforce, SAP, Workday. Multi-cloud deployment. Configurable data residency. Enterprise checkboxes that suggest Muñoz-Cerro and Rubilar-Muñoz aren't gunning for developers alone—they want compliance officers, CISOs, the buyers who green-light procurement in healthcare and finance.
There's also something called "Alma," described as a semantic control plane for data quality. Alma supposedly learns from query traffic, generates contracts, detects drift. Whether that's a separate product, a module, or just another name for the firewall's backend isn't clear. The website doesn't spell it out.
The Problem They're Chasing

The timing, at least, makes sense. Enterprise anxiety around AI data leakage has gone from simmer to boil over the past year. A report from Concentric AI—covered by TechRadar Pro last October—found that Microsoft Copilot had access to nearly three million sensitive records per organization in the first half of 2025. Gartner warned in November that 40% of enterprises would experience shadow AI breaches by 2030. Just this January, an ISACA survey showed 26% of privacy professionals expecting a material privacy breach within the year.
The core challenge is architectural. Most enterprises bolt AI capabilities onto systems designed decades ago, long before anyone imagined LLMs ingesting company data at scale. Access controls were built for humans, not probabilistic reasoning engines that can inadvertently leak PII, financial details, or IP in ways traditional DLP tools struggle to catch.
Velum's pitch is that you need a layer that understands content semantically—not just pattern-matching for Social Security numbers, but grasping context. Role. Sensitivity. Time of day, location, threat level. And then enforcing policy across both sides of the firewall: the humans querying data and the models consuming it.
Whether that's technically feasible at enterprise scale for a two-person startup is, well, an open question. But the market is clearly listening. Or at least nervous enough to consider new answers.
A Landscape Already Crowded

Velum isn't stepping into a vacuum. Cloudflare's Firewall for AI inspects prompts and responses at the network edge. Superagent, another YC alum from the Winter 2024 batch, runs a small security-tuned LLM inline to catch threats. Lakera Guard, which Check Point acquired last September, offered prompt-injection defense and leakage prevention before it got absorbed. NVIDIA open-sourced NeMo Guardrails for programmable LLM controls. And traditional authorization engines—Open Policy Agent, Cerbos, OpenFGA—handle fine-grained access but weren't designed with LLM traffic in mind.
So Velum is threading a needle: more comprehensive than prompt filters, more AI-aware than legacy DLP, but trying to avoid the complexity that sinks ambitious platforms before they find traction. If the founders pull it off, they occupy that middle territory between classic data loss prevention and the new generation of LLM guardrails. A useful place to be, maybe, for enterprises racing to deploy Copilot and ChatGPT integrations while keeping compliance teams from revolting.
The founders bring academic pedigrees—Stanford, Harvard, other research institutions according to their team page. An old LinkedIn post from five months back mentioned zero-trust architecture and fully homomorphic encryption for encrypted machine learning. The current marketing, though, has pivoted away from cryptographic exotica toward something more digestible: policy enforcement, redaction, real-time controls. Perhaps a necessary concession to what enterprises actually want to buy versus what sounds impressive in a whitepaper.
What Happens Next

Demo Day will offer the first real test. YC batches live or die on that initial momentum—the deals struck in the days after, the follow-on interest from VCs who missed the SAFE round, the enterprise pilots that convert (or don't) into design partnerships.
For Velum, the open-source question looms larger than it might for other startups. Declaring yourself open-source in the YC directory creates expectations. Developers will want to kick the tires, file issues, fork the repo. Security engineers will want to audit the code before they'd dream of running it in production. Compliance teams—Velum's ostensible buyers—will want proof that the firewall works as advertised, and nothing builds trust faster than public, auditable code.
If the repository materializes next week alongside the Demo Day presentation, the gap gets explained away. Launch choreography. If it doesn't? The claim starts to look like aspiration rather than fact, and that's a harder story to walk back.
Whether two people can execute the full scope of what Velum's product pages describe—semantic understanding, real-time policy enforcement, integrations with half the enterprise software stack—is the other question. Ambitious visions are cheap. Shipping something that works at scale, that doesn't collapse under edge cases or drown in technical debt, that's the grind most YC companies face after the Demo Day applause fades.
For now, Velum exists in that liminal space occupied by many early-stage startups: more promise than proof, more architecture than adoption. A week from now, we'll know a little more. The code might appear. The pitch might land. Or it might become another case study in the distance between what a startup says it's building and what it can actually deliver.
The enterprise AI exposure problem, though—that's real enough. Someone will solve it. The question is whether Velum gets there first, or just becomes a footnote in someone else's origin story.
