Companies

Silmaril

silmaril.dev

Silmaril provides self-healing, context-aware prompt-injection defense for AI-native applications and agents.

HQSan Francisco, California, United States
Employees1-50
Jobs checked 18h ago
CybersecurityAI InfrastructureB2B SaaS

About

Silmaril builds self-healing, runtime prompt-injection defense for AI-native applications and agents. It sells to companies building agentic systems, including productivity, analytics, and legal organizations, and differentiates through application-context awareness, claims of blocking twice as many threats with one-tenth the latency of current leading defenses, and five-line framework integration.

Market

Silmaril competes in the enterprise AI-security market, specifically runtime security and prompt-injection protection for AI applications and agents. It positions itself against conventional guardrails by analyzing whether an execution leads to a harmful outcome rather than merely pattern-matching suspicious inputs, while claiming self-improvement, broader threat blocking, lower latency, and lightweight LangGraph/LangChain integration.

Target Customers

Silmaril targets enterprise companies building AI-native applications, agents, and LLM pipelines—especially productivity, analytics, and legal businesses whose systems ingest external data. Its likely buyers are Director-level and above security or AI leaders responsible for protecting agentic systems.

At a Glance

Problem

As AI agents gain access to email, documents, databases, calendars, and execution tools, ordinary user inputs and trusted context become attack surfaces. Silmaril focuses on indirect prompt injection, tool abuse, context poisoning, policy bypass, and multi-step attacks that can cause an agent to cross trust boundaries and exfiltrate sensitive information or execute unauthorized actions. The company specifically highlights financial institutions, where an agent processing treasury or client data could be induced to send cash reports, positions, credentials, or other confidential records to an attacker.

The economic pain is the potential for severe data loss, fraud, operational disruption, and regulatory exposure. Silmaril’s published case studies claim $68 million and $20 million in damages prevented, while its attack examples include data exfiltration, privilege abuse, credential theft, and remote code execution. A representative killer use case is protecting a financial-services agent that reads a malicious email, accesses internal systems, and attempts to run a command or transmit sensitive files: Silmaril aims to stop the harmful tool call before execution.

Product / Service

Silmaril combines autonomous red teaming with a real-time runtime security layer for AI agents. Its attack agents probe a product through the user interface, map trust boundaries, and chain prompt injection, tool abuse, and context poisoning into working exploits. Its firewall then evaluates user intent, application context, tool calls, and accumulated execution state together, rather than inspecting each input in isolation, and blocks risky actions before they materialize.

The product is delivered through a small SDK wrapper that works across major agent stacks, with managed or self-hosted controls and node-level blocking. Silmaril says discovered attacks are converted into synthetic training data, allowing defenses to be updated in under an hour and anonymized protections to be shared across deployments. The company reports 95.60% firewall accuracy at 20ms p90 latency in its comparison, and describes integration as five lines of code with no application overhead.

Market

Silmaril competes in the emerging AI-agent security, runtime protection, and AI application security market. Its positioning is broader than conventional input guardrails: it targets attacks that emerge from the interaction among an agent, its tools, and its context. In its published benchmark, it compares the Silmaril Firewall with Lakera Guard, Perplexity Browsesafe, GPT Safeguard, and Model Armor, while its red-teaming proposition also overlaps with AI security testing and threat-hunting products.

The company appears to be an early-stage, venture-backed startup rather than an established scale vendor. Its site identifies it as backed by Y Combinator, and YC lists it as founded in 2026 by Aum Upadhyay and Eduardo Velasco with two employees. Public traction signals include evaluation against 131 production attack techniques, 15 critical vulnerabilities disclosed to OpenAI, Anthropic, Google, and Microsoft in two weeks, and published customer-style damage-prevention case studies. Revenue and paying-customer status are not disclosed in the available evidence; the site instead emphasizes demos and early security research.

Founders & Leadership

Aum UpadhyayFounder
Co-Founder & CEO
Eduardo VelascoFounder
Co-Founder & CTO

Funding History

2026-06
Pre-Seed$500K

Y Combinator

Recent News

2026-07-13
YC AI Startups 2026: W26, Spring & Summer Tracker - TLDL

TLDL’s 2026 YC startup tracker lists Silmaril under runtime security for AI applications and agents, targeting prompt injection and other runtime attacks.

2026-06-19product
Y Combinator P26 (formerly X26) Batch Companies

An Extruct overview of the YC batch describes Silmaril as a self-improving prompt-injection defense for AI applications that functions as a firewall for AI workloads.

2026-06-18
The 11 standout startups from YC's Demo Day, according to VCs

TechCrunch included Silmaril among the standout YC Demo Day startups, highlighting its effort to protect AI agents from prompt-injection attacks.

2026-06-18
YC Demo Day spotlights startups driving AI agents defense ...

Mezha’s YC Demo Day coverage reports that Silmaril detects threats and automatically retrains its defense systems to improve reliability against attacks on AI agents.

2026-06-03product
Silmaril - The YC Tier List

The YC Tier List profile describes Silmaril as self-healing prompt-injection defense for AI-native applications and agents.

Active Roles

0

No active roles right now.

Get notified when they post

Business Model

Silmaril appears to monetize as a B2B enterprise security-software vendor, selling runtime prompt-injection defense to companies building AI applications and agents. Public sources identify an enterprise, ROI-oriented sales motion but do not disclose whether pricing is subscription-, usage-, or services-based.

Products

Silmaril runtime security for AISelf-healing prompt-injection defenseContext-aware execution and harmful-outcome detection for AI agentsAgent-generated threat intelligence and self-improving security

Tech Stack

AI/LLM applications and agentsRuntime AI securityContext-aware threat detectionPrompt-injection defenseLangGraph/LangChain agentic-framework integrationsSelf-improving threat intelligence

Competitors

Rebuff
LLM Guard
Lakera Guard
Protect AI
HiddenLayer