Skip to content

ContextFort

Y Combinator-backed startup whose Chrome extension gives security teams visibility and rule-based controls over AI browser agents.

Visit Website ↗ + Add to Compare Claim This Company
38/100Emerging / Unranked

Overview

ContextFort is a Chrome extension that detects when an AI browser agent (an autonomous copilot navigating and clicking on a user’s behalf) takes control of a browser session, records every action taken — pages visited, clicks, text entered — and lets teams set rules to block risky actions or cross-site data leakage. The company frames the problem as an auditing gap distinct from traditional malware detection: rather than asking “is this malicious?” the way an EDR tool does, ContextFort asks “what did this agent actually do?” and builds an independent, agent-tamper-resistant activity log.

Under the hood, the company (and its related open-source project) uses OS-level telemetry — eBPF on Linux, the Endpoint Security Framework on macOS, and ETW/Minifilter on Windows — to monitor file access, network connections, and process activity independently of the agent itself, alongside the browser-extension layer for browser-specific agent monitoring. Its differentiator is a local-first architecture: session data and screenshots are stored on-device with no transmission to external servers, and the codebase is open source on GitHub. ContextFort was founded in 2025 by Ashwin Ramachandran and Harshvardhan Agarwal, is part of Y Combinator’s Summer 2025 batch, and remains a very early, two-person team based in San Francisco with an undisclosed pre-seed round.

Innovation Matrix Assessment

Innovation Velocity 5/10

A two-person team shipped a working Chrome extension plus a multi-OS kernel-level telemetry stack (eBPF/ESF/ETW+Minifilter) and open-sourced it within roughly a year of founding — solid technical output for the team size, though still an early product.

Operational Value 4/10

Addresses a real and growing blind spot (auditing what autonomous browser/coding agents actually do), but the local-only, rule-based architecture lacks the fleet management, policy orchestration, and reporting maturity enterprise security teams typically need.

Market Momentum 2/10

Pre-seed with an undisclosed (reportedly small) raise, a two-person team, no named enterprise customers found, and a GitHub repo with only a handful of stars as of research — very early-stage traction.

Category Disruption 4/10

The agent-specific audit-trail angle is a genuinely different framing from conventional EDR, but it is one of several new entrants (multiple "AI agent monitoring" browser extensions surfaced in the same search) rather than a clear category leader.

Real-World Efficacy 2/10

No independent testing, named customer deployment, or third-party validation was found; efficacy claims are entirely vendor- and documentation-sourced at this stage.

Enduring Relevance 6/10

Visibility into autonomous AI agent actions in the browser and on the endpoint is likely to become a standard security requirement as agentic AI adoption grows, giving the underlying problem strong durability even if this specific vendor does not scale.

Why CISOs Should Care

Provides a tamper-resistant record of exactly what an AI browser or coding agent clicked, typed, or accessed during a session — closing a visibility gap that conventional EDR and browser security tools do not cover.

What Makes It Different

Monitors AI agent behavior independently from the agent itself, using kernel/OS-level telemetry and local-only data storage rather than relying on the agent's own self-reported logs or a cloud-hosted proxy.

The Matrix Verdict

38/100 — EMERGING / UNRANKED

ContextFort falls into the Emerging/Unranked tier: the problem it targets is real and forward-looking, but with a two-person team, an undisclosed pre-seed round, and no independently verified customer or efficacy evidence, it is too early to score as more than a promising early signal.

Editorial Note: Claims vs. Verified Findings

Product functionality descriptions come from the company's own site, GitHub repo, and Y Combinator listing (all vendor-controlled); a $500K funding figure appearing on a third-party aggregator could not be independently corroborated and is not treated as fact — Crunchbase lists the pre-seed amount as undisclosed.

Sources