About
Silmaril builds self-healing, runtime prompt-injection defense for AI-native applications and agents. It sells to companies building agentic systems, including productivity, analytics, and legal organizations, and differentiates through application-context awareness, claims of blocking twice as many threats with one-tenth the latency of current leading defenses, and five-line framework integration.
Market
Silmaril competes in the enterprise AI-security market, specifically runtime security and prompt-injection protection for AI applications and agents. It positions itself against conventional guardrails by analyzing whether an execution leads to a harmful outcome rather than merely pattern-matching suspicious inputs, while claiming self-improvement, broader threat blocking, lower latency, and lightweight LangGraph/LangChain integration.
Silmaril targets enterprise companies building AI-native applications, agents, and LLM pipelines—especially productivity, analytics, and legal businesses whose systems ingest external data. Its likely buyers are Director-level and above security or AI leaders responsible for protecting agentic systems.
At a Glance
Problem
As AI agents gain access to email, documents, databases, calendars, and execution tools, ordinary user inputs and trusted context become attack surfaces. Silmaril focuses on indirect prompt injection, tool abuse, context poisoning, policy bypass, and multi-step attacks that can cause an agent to cross trust boundaries and exfiltrate sensitive information or execute unauthorized actions. The company specifically highlights financial institutions, where an agent processing treasury or client data could be induced to send cash reports, positions, credentials, or other confidential records to an attacker.
The economic pain is the potential for severe data loss, fraud, operational disruption, and regulatory exposure. Silmaril’s published case studies claim $68 million and $20 million in damages prevented, while its attack examples include data exfiltration, privilege abuse, credential theft, and remote code execution. A representative killer use case is protecting a financial-services agent that reads a malicious email, accesses internal systems, and attempts to run a command or transmit sensitive files: Silmaril aims to stop the harmful tool call before execution.
Product / Service
Silmaril combines autonomous red teaming with a real-time runtime security layer for AI agents. Its attack agents probe a product through the user interface, map trust boundaries, and chain prompt injection, tool abuse, and context poisoning into working exploits. Its firewall then evaluates user intent, application context, tool calls, and accumulated execution state together, rather than inspecting each input in isolation, and blocks risky actions before they materialize.
The product is delivered through a small SDK wrapper that works across major agent stacks, with managed or self-hosted controls and node-level blocking. Silmaril says discovered attacks are converted into synthetic training data, allowing defenses to be updated in under an hour and anonymized protections to be shared across deployments. The company reports 95.60% firewall accuracy at 20ms p90 latency in its comparison, and describes integration as five lines of code with no application overhead.
Market
Silmaril competes in the emerging AI-agent security, runtime protection, and AI application security market. Its positioning is broader than conventional input guardrails: it targets attacks that emerge from the interaction among an agent, its tools, and its context. In its published benchmark, it compares the Silmaril Firewall with Lakera Guard, Perplexity Browsesafe, GPT Safeguard, and Model Armor, while its red-teaming proposition also overlaps with AI security testing and threat-hunting products.
The company appears to be an early-stage, venture-backed startup rather than an established scale vendor. Its site identifies it as backed by Y Combinator, and YC lists it as founded in 2026 by Aum Upadhyay and Eduardo Velasco with two employees. Public traction signals include evaluation against 131 production attack techniques, 15 critical vulnerabilities disclosed to OpenAI, Anthropic, Google, and Microsoft in two weeks, and published customer-style damage-prevention case studies. Revenue and paying-customer status are not disclosed in the available evidence; the site instead emphasizes demos and early security research.
Founders & Leadership
Funding History
Y Combinator
Recent News
TLDL’s 2026 YC startup tracker lists Silmaril under runtime security for AI applications and agents, targeting prompt injection and other runtime attacks.
An Extruct overview of the YC batch describes Silmaril as a self-improving prompt-injection defense for AI applications that functions as a firewall for AI workloads.
TechCrunch included Silmaril among the standout YC Demo Day startups, highlighting its effort to protect AI agents from prompt-injection attacks.
Mezha’s YC Demo Day coverage reports that Silmaril detects threats and automatically retrains its defense systems to improve reliability against attacks on AI agents.
The YC Tier List profile describes Silmaril as self-healing prompt-injection defense for AI-native applications and agents.
Active Roles
0No active roles right now.
Get notified when they postBusiness Model
Silmaril appears to monetize as a B2B enterprise security-software vendor, selling runtime prompt-injection defense to companies building AI applications and agents. Public sources identify an enterprise, ROI-oriented sales motion but do not disclose whether pricing is subscription-, usage-, or services-based.