Silmaril
Silmaril builds runtime security for AI systems, aimed at prompt injection: the attack where the instructions come in through the data an agent was asked to read.
About Silmaril
Silmaril is runtime security for AI. Its subject is prompt injection, which is the attack that has no equivalent in ordinary software: an agent reads an email, a web page or a document, and something written in that content is treated as an instruction rather than as data. The defence sits between the agent and what it reads, and it retrains itself as new attacks appear rather than waiting for a rule to be written. That last part is the argument for it: a filter that only knows yesterday's attacks is a filter with a shelf life, and agents are being handed real permissions faster than any static list can keep up with. The company was founded in 2026 by Aum Upadhyay and Eduardo Velasco, went through Y Combinator's Spring 2026 batch, and is based in San Francisco.