Skip to content

Crosslayer Labs

A Princeton-spinout startup that monitors DNS, BGP, TLS certificates, and JavaScript dependencies to detect website and API impersonation attacks.

Visit Website ↗ + Add to Compare Claim This Company
45/100Emerging / Unranked

Overview

Crosslayer Labs builds “outside-in” monitoring that continuously discovers and correlates a company’s internet-facing dependencies, including DNS records, BGP routes, TLS certificate issuance, and third-party JavaScript, to detect when someone is impersonating a website or API through infrastructure-layer manipulation rather than obvious phishing or malware.

The founding team, Henry Birge-Lee, Grace Cimaszewski, and Prateek Mittal, came out of a Princeton network security research lab and are credited with inventing Multi-Perspective Issuance Corroboration (MPIC), a standard now used by major certificate authorities including Google, Apple, and Amazon to prevent fraudulent HTTPS certificate issuance. Crosslayer applies that same research lineage to commercial attack-surface monitoring, aiming at healthcare, banking, and cryptocurrency customers where certificate and routing-level attacks carry outsized impact.

Founded in 2025 and a Y Combinator Winter 2026 graduate, the three-person New York City team has raised approximately $500K in pre-seed funding backed by YC, AE Investments, and Long Journey Capital as of early 2026.

Innovation Matrix Assessment

Innovation Velocity 6/10

The founders' prior invention (MPIC) was independently adopted as an internet-wide certificate authority standard before the company existed, an unusually strong technical track record for a pre-seed team.

Operational Value 5/10

Automating detection of infrastructure-layer impersonation (BGP/DNS/cert attacks) addresses a real gap most CISOs' teams cannot monitor manually, though the product is very early.

Market Momentum 3/10

Three employees, ~$500K raised, and a YC W26 badge is early-stage traction, not yet market validation at scale.

Category Disruption 4/10

Applying research-grade internet-infrastructure monitoring commercially is a genuinely underserved niche within attack surface management, but it is too early to call it category-redefining.

Real-World Efficacy 3/10

No customer case studies or independent efficacy evidence exist yet beyond the founders' prior academic research credibility.

Enduring Relevance 6/10

Certificate, BGP, and DNS-layer attacks are a growing and persistent class of internet infrastructure abuse likely to matter over a multi-year horizon.

Why CISOs Should Care

Gives security teams visibility into infrastructure-layer impersonation risks (rogue certificates, BGP hijacks, JS supply chain) that traditional attack surface management tools typically miss.

What Makes It Different

Grounded in original, peer-reviewed internet security research (MPIC) already adopted as industry standard by major CAs, rather than repackaging existing ASM scanning techniques.

The Matrix Verdict

45/100 — EMERGING / UNRANKED

An Emerging company: exceptional founder pedigree and a genuinely underserved technical niche, but with a three-person team and pre-seed funding, real-world evidence of impact is still to come.

Editorial Note: Claims vs. Verified Findings

The MPIC standard adoption by major certificate authorities is independently verifiable; product efficacy and customer traction claims are not yet independently evidenced.

Sources