The YC directory says one thing. The website says another. And somewhere between Demo Day and now, Velum Labs became a completely different company.
Check the startup's Y Combinator profile—still live, three days past the Winter 2026 batch presentation—and you'll find a description of an "open-source firewall" designed to enforce content-level access control across AI systems. Click through to the actual company website, though, and that narrative vanishes. In its place: a data quality platform focused on monitoring database tables, tracing metric lineage, and automatically patching inconsistencies.
It's the kind of whiplash-inducing disconnect that happens more often than the startup mythology suggests. Pivots at this stage aren't just common—they're expected. What's unusual is catching one this cleanly, frozen mid-turn in the public record.
The Firewall That Was
The pitch, at least as it appears in YC's company directory, centered on AI access control. Velum's system would sit between data sources and whoever—or whatever—needed to access them: large language models, human analysts, third-party vendors. Administrators could write policies in natural language. The firewall would apply semantic understanding to detect sensitive information in real time, then enforce recipient-specific rules across documents, databases, even live applications.
The feature list was ambitious. Integrations with enterprise mainstays like Salesforce, SAP, and Workday. Hooks into AI workflows to intercept prompts and responses. Encryption paired with structure-preserving tokenization. Configurable data residency for deployments spanning multiple clouds.
Open-source, the description said. But there's no public GitHub repository to be found. If the code exists, it's behind closed doors.
The Platform That Is

Visit Velum's website now and the story shifts entirely. The company describes itself as "the operating system for data quality"—a platform that spots divergent metrics, traces their origins through query lineage, suggests corrections, and deploys them automatically. It generates data contracts. It plugs into the usual suspects in the modern data stack: Snowflake, BigQuery, Databricks, Redshift, Postgres. Plus the orchestration layer—Airflow, Dagster, Prefect—and BI tools like Looker, Tableau, Metabase.
There's a claim about production deployments at "regulated fintechs," accompanied by a testimonial from a design partner identified only as a "Leading LatAm Fintech, YC W18, BigQuery." The metrics sound impressive: over 200 tables monitored, more than $1 billion in assets under management. But there are no dates attached, no way to verify them independently.
The founders, Benjamin Muñoz-Cerro (CEO) and Alen Rubilar-Muñoz (CTO), both have backgrounds in mathematics and machine learning. A two-person operation that appears to have changed direction during—or shortly after—their batch wrapped. Scroll back through LinkedIn, roughly five months ago, and there's a post referencing the Fall 2025 cohort and describing a zero-trust AI privacy approach built on fully homomorphic encryption. Yet another positioning, it seems.
The trail of breadcrumbs doesn't quite line up.
The Market They Abandoned

Had they stuck with AI firewalls, Velum would have landed in a neighborhood already getting crowded. Levo AI unveiled its own AI Firewall in February 2026, promising defenses against prompt injection, system prompt leakage, and personally identifiable information redaction. Radware shipped an LLM Firewall last November. Arthur Shield bills itself as "the first firewall for LLMs"—a claim that invites scrutiny, given how many others are staking similar ground.
Superagent, a YC Winter 2024 alum, calls its product "the AI Firewall" and emphasizes an open-source model. OnGarde offers an MIT-licensed "Firewall for Autonomy" aimed at AI agents. Trylon's open-source Gateway repo has picked up north of 100 stars on GitHub. The space isn't exactly barren.
Which raises a question: did Velum's founders see that landscape and decide the path forward was too narrow? Or did they simply find something more compelling—or more tractable—in data observability?
When the Pitch Outlives the Product

Repositioning this fast isn't unheard of. Startups at this stage are supposed to iterate, to hunt for product-market fit with whatever works. But the public accounting of the shift is almost nonexistent. No blog post walking through the logic. No announcement framing the new direction. The YC directory still points to the firewall. LinkedIn holds onto the old narrative. The website has already moved on.
For anyone tracking the Winter 2026 batch—investors sizing up opportunities, operators benchmarking their own progress—it's a useful reminder. What gets presented at Demo Day may not survive contact with reality. Sometimes the product evolves within months. Other times it doesn't make it through the week.
Muñoz-Cerro and Rubilar-Muñoz, who've toggled between quantum computing reinforcement learning and protein design in past work, may have concluded that data quality offered a clearer path than semantic access control for AI. Perhaps they saw faster traction with early customers. Perhaps the technical challenges were more solvable. Or perhaps—and this feels like the most honest read—they're still figuring it out.
At two people and barely a few months past their batch, there's still plenty of room to pivot again. Nothing about this trajectory suggests they're done searching.
