Candor Security
A San Francisco YC startup (formerly branded Haleum) building agentic AI that monitors internal communications to catch insider data leaks and threats before damage occurs.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Candor Security (previously operating under the name Haleum) builds agentic data-loss-prevention and insider-risk software. Rather than relying on static keyword or pattern-matching rules, its AI agents analyze security logs and communications context to identify signs of financial fraud, IP theft, compliance violations, and other insider threats across an organization’s platforms, aiming to reduce the noisy false-positive rates typical of legacy DLP tools.
Founded in San Francisco in 2024 by Adarsh Ambati, Ansh Gupta, and Aditya Iyengar, the company went through Y Combinator’s Winter 2025 batch and subsequently rebranded from Haleum to Candor Security; the company’s original haleum.ai domain now redirects to its current candor.security site.
As a three-person, YC-backed early-stage company, Candor Security has disclosed limited public funding details beyond its YC investment, and has not published named enterprise customers or independent efficacy data as of this research.
Innovation Matrix Assessment
Shipped a working agentic DLP product and iterated on positioning and branding (Haleum to Candor Security) within roughly two years of founding.
Targets a real problem, insider risk and DLP false-positive fatigue, though at three employees the operational maturity of the product is unproven.
YC W25 backing is a real but early signal; no disclosed funding amount, enterprise customers, or growth metrics were found.
Agentic, context-aware insider-risk detection is a genuinely active reframing of DLP, but the space has multiple competing entrants and no independent evidence yet of a defensible edge.
No independent results, benchmarks, or named customer deployments were found; effectiveness claims are entirely vendor-sourced.
Insider risk and data-leak prevention remain durable, multi-year security priorities regardless of how any individual vendor fares.
Why CISOs Should Care
Offers a potentially lower-noise alternative to legacy insider-risk and DLP tooling by using AI agents to add context to log and communications monitoring rather than static rule matching.
What Makes It Different
Applies agentic AI reasoning to insider-risk and DLP monitoring rather than the rule- or pattern-matching approach of legacy DLP tools.
The Matrix Verdict
43/100 — EMERGING / UNRANKED
An Emerging company: an interesting agentic reframing of a well-understood problem from a YC-backed team, but with only three employees and no disclosed traction, it is far too early to assess real-world impact.
Editorial Note: Claims vs. Verified Findings
The company's YC batch participation and rebrand from Haleum are independently confirmed via Y Combinator's own listings; specific detection-accuracy and false-positive-reduction claims are vendor-sourced only.
Sources
Alternatives to Candor Security
Fireblocks
Fireblocks is the category-defining institutional digital-asset infrastructure provider, with roughly $2 trillion transferred and the industry's highest valuation…
Cyera
AI-powered, agentless data security platform combining DSPM, DLP, and AI-activity monitoring, and one of the fastest-funded startups in…
Varonis
Data-centric security platform that monitors file, email, and cloud activity to detect insider threats and ransomware before data…
Bedrock Data
AI-native data security posture management (DSPM) platform using a Metadata Lake to discover, classify, and contextualize data across…
Halcyon
Ransomware-focused cyber resilience platform combining endpoint prevention, automated recovery, and data exfiltration protection.
CyberRidge
Photonic-layer encryption that converts transmitted data into optical noise, defending fiber communications against quantum-era decryption.