Most AI security products were built for the chatbot era. They scan prompts before they hit the model, flag sensitive outputs, and call it a day. That worked fine when the worst a model could do was say something embarrassing. It doesn't work when the model has a calendar invite, an SSH key, and write access to your CRM.
Clam is a YC W2026 company that builds what it calls a Semantic Firewall: a network-layer security checkpoint that sits between AI agents and everything they touch. Every message in and every message out gets scanned for PII leaks, prompt injection attempts, and malicious code. The agent runs in an isolated VM. API keys never enter the model's context. The approach is less "add security to the prompt" and more "treat the agent like untrusted code and put it in a sandbox."
That's the right framing. And it's arriving at exactly the right moment.
What They Do
Clam started as Baseframe, a tool that analyzed work patterns to identify automation opportunities inside organizations. The founders pivoted mid-YC, roughly 2.5 weeks before Demo Day. That pivot - from spotting automation opportunities to securing the agents that execute them - tells you something about how fast the market is moving. The problem they discovered wasn't that companies didn't want to automate. It was that they couldn't deploy agents in production without a security architecture that didn't exist yet.
The product today is a secure hosting platform for AI agents, starting with OpenClaw integration. You run your agent through Clam's infrastructure instead of directly on your own stack. Clam handles three things:
