Crosslayer Labs
A Princeton-spinout startup that monitors DNS, BGP, TLS certificates, and JavaScript dependencies to detect website and API impersonation attacks.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Crosslayer Labs builds “outside-in” monitoring that continuously discovers and correlates a company’s internet-facing dependencies, including DNS records, BGP routes, TLS certificate issuance, and third-party JavaScript, to detect when someone is impersonating a website or API through infrastructure-layer manipulation rather than obvious phishing or malware.
The founding team, Henry Birge-Lee, Grace Cimaszewski, and Prateek Mittal, came out of a Princeton network security research lab and are credited with inventing Multi-Perspective Issuance Corroboration (MPIC), a standard now used by major certificate authorities including Google, Apple, and Amazon to prevent fraudulent HTTPS certificate issuance. Crosslayer applies that same research lineage to commercial attack-surface monitoring, aiming at healthcare, banking, and cryptocurrency customers where certificate and routing-level attacks carry outsized impact.
Founded in 2025 and a Y Combinator Winter 2026 graduate, the three-person New York City team has raised approximately $500K in pre-seed funding backed by YC, AE Investments, and Long Journey Capital as of early 2026.
Innovation Matrix Assessment
The founders' prior invention (MPIC) was independently adopted as an internet-wide certificate authority standard before the company existed, an unusually strong technical track record for a pre-seed team.
Automating detection of infrastructure-layer impersonation (BGP/DNS/cert attacks) addresses a real gap most CISOs' teams cannot monitor manually, though the product is very early.
Three employees, ~$500K raised, and a YC W26 badge is early-stage traction, not yet market validation at scale.
Applying research-grade internet-infrastructure monitoring commercially is a genuinely underserved niche within attack surface management, but it is too early to call it category-redefining.
No customer case studies or independent efficacy evidence exist yet beyond the founders' prior academic research credibility.
Certificate, BGP, and DNS-layer attacks are a growing and persistent class of internet infrastructure abuse likely to matter over a multi-year horizon.
Why CISOs Should Care
Gives security teams visibility into infrastructure-layer impersonation risks (rogue certificates, BGP hijacks, JS supply chain) that traditional attack surface management tools typically miss.
What Makes It Different
Grounded in original, peer-reviewed internet security research (MPIC) already adopted as industry standard by major CAs, rather than repackaging existing ASM scanning techniques.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
An Emerging company: exceptional founder pedigree and a genuinely underserved technical niche, but with a three-person team and pre-seed funding, real-world evidence of impact is still to come.
Editorial Note: Claims vs. Verified Findings
The MPIC standard adoption by major certificate authorities is independently verifiable; product efficacy and customer traction claims are not yet independently evidenced.
Sources
Alternatives to Crosslayer Labs
CyCognito
Agentless attack surface management platform that maps organizations' entire external footprint, including subsidiaries and shadow assets, using graph-based…
Armis (a ServiceNow company)
Agentless asset intelligence platform discovering and assessing every connected IT, OT, IoT and medical device, now part of…
CybelAngel
External attack surface management and digital risk protection platform that scans the open, deep, and dark web for…
watchTowr
Singapore-based platform combining external attack surface management with continuous automated red teaming to validate whether exposures are actually…
Axonius
New York-based CAASM pioneer that aggregates data from hundreds of existing tools to build a unified, agentless asset…
Doppel
San Francisco AI-native digital risk protection platform that detects and automatically takes down phishing sites, impersonation accounts, and…