Skip to content

Candor Security

A San Francisco YC startup (formerly branded Haleum) building agentic AI that monitors internal communications to catch insider data leaks and threats before damage occurs.

Visit Website ↗ + Add to Compare Claim This Company
43/100Emerging / Unranked

Overview

Candor Security (previously operating under the name Haleum) builds agentic data-loss-prevention and insider-risk software. Rather than relying on static keyword or pattern-matching rules, its AI agents analyze security logs and communications context to identify signs of financial fraud, IP theft, compliance violations, and other insider threats across an organization’s platforms, aiming to reduce the noisy false-positive rates typical of legacy DLP tools.

Founded in San Francisco in 2024 by Adarsh Ambati, Ansh Gupta, and Aditya Iyengar, the company went through Y Combinator’s Winter 2025 batch and subsequently rebranded from Haleum to Candor Security; the company’s original haleum.ai domain now redirects to its current candor.security site.

As a three-person, YC-backed early-stage company, Candor Security has disclosed limited public funding details beyond its YC investment, and has not published named enterprise customers or independent efficacy data as of this research.

Innovation Matrix Assessment

Innovation Velocity 5/10

Shipped a working agentic DLP product and iterated on positioning and branding (Haleum to Candor Security) within roughly two years of founding.

Operational Value 5/10

Targets a real problem, insider risk and DLP false-positive fatigue, though at three employees the operational maturity of the product is unproven.

Market Momentum 3/10

YC W25 backing is a real but early signal; no disclosed funding amount, enterprise customers, or growth metrics were found.

Category Disruption 4/10

Agentic, context-aware insider-risk detection is a genuinely active reframing of DLP, but the space has multiple competing entrants and no independent evidence yet of a defensible edge.

Real-World Efficacy 3/10

No independent results, benchmarks, or named customer deployments were found; effectiveness claims are entirely vendor-sourced.

Enduring Relevance 6/10

Insider risk and data-leak prevention remain durable, multi-year security priorities regardless of how any individual vendor fares.

Why CISOs Should Care

Offers a potentially lower-noise alternative to legacy insider-risk and DLP tooling by using AI agents to add context to log and communications monitoring rather than static rule matching.

What Makes It Different

Applies agentic AI reasoning to insider-risk and DLP monitoring rather than the rule- or pattern-matching approach of legacy DLP tools.

The Matrix Verdict

43/100 — EMERGING / UNRANKED

An Emerging company: an interesting agentic reframing of a well-understood problem from a YC-backed team, but with only three employees and no disclosed traction, it is far too early to assess real-world impact.

Editorial Note: Claims vs. Verified Findings

The company's YC batch participation and rebrand from Haleum are independently confirmed via Y Combinator's own listings; specific detection-accuracy and false-positive-reduction claims are vendor-sourced only.

Sources