New startup ideas · AI and software · Developer tools
startup idea
Sovern
Air-gapped coding agent infrastructure for defense and banks; the code graph never leaves.
Sovern is an on-premise runtime and API that lets a defense program office or a bank run coding agents against its entire repository history without a single token crossing the network boundary.
- Infrastructure and APIs
- Enterprise
- $10-100B market
- Creates a new category
- Global from day one
4/5
venture judge
35
similar startups, last 2 years (101 all-time)
95%
of 4 nearest real companies still alive
yes
8 matching federal grants and programs
Direction supported by government programs and grants
Test it before you build it
$1,500 · 6 weeks · 12 prospects
For $1,500 and 6 weeks, prove software factory leads at defense primes will sign dated $15,000 evaluation LOIs now rather than wait for a certified air-gapped offering from a frontier model vendor.
Riskiest assumption · Software factory leads at defense primes banned from hosted models will commit money and a dated start to a third-party on-premise evaluation now, rather than wait for a certified air-gapped deployment from a frontier model vendor
1Focus group: who and where
Senior director of software engineering or chief engineer of a software factory at a US defense prime or tier-one supplier, running programs where CUI or classification rules ban hosted LLMs, with hundreds of developers and a standing mandate from above to adopt AI tooling anyway
where to find 12 · AFCEA local chapter events in DC, Huntsville and San Diego; the Washington Technology Top 100 federal contractor list worked through warm intros from veteran advisors and former colleagues; the AUSA Annual Meeting expo floor in Washington DC this October, where every prime's software organization exhibits
2Sell first, build later
A 90-day read-only code intelligence evaluation inside one accredited facility: a resident code and dependency graph over the full repository history, agent-compatible query endpoints, a complete audit record for the ISSM, engineers on site for install, starting Q1 2027 - no write access, no token leaving the boundary
the ask · $15,000 per 90-day evaluation, payable by purchase order; production license quoted only after the evaluation
a real yes · A real yes is a signed LOI naming the facility, program and start quarter plus a purchase requisition in their procurement system; a purchase order is the gold standard. 'The mission needs this', badge scans at AUSA, and unpaid sandbox requests are noes
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Ban-and-roadmap interviews
$1,200 · 14 days
Book 12 twenty-minute calls with software factory leads via AFCEA chapters, advisor intros into the Top 100 list, and the AUSA floor. Confirm two facts: hosted coding models are banned on their programs today, and no certified hosted alternative is approved on their 12-month roadmap. Log verbatim what they are waiting for - this is the direct test of the frontier-vendor risk.
keep going if · 7 of 12 confirm the ban applies to their programs and name no approved alternative arriving within 12 months
2. Security-gate dry run
$100 · 14 days
Write a 6-page draft deployment and security package for a read-only code intelligence appliance - data flows, audit record, no egress - and review it with 5 ISSMs or program security officers reached through the same AFCEA chapters. Ask what would block approval and how long approval takes.
keep going if · 3 of 5 security reviewers say the package is approvable within one quarter, with conditions listed rather than refusals
3. LOI and slot commitment
$200 · 21 days
Return to the 12 interviewed leads with a 2-page spec sheet: a 90-day read-only evaluation inside one accredited facility, resident code graph over their repo history, full audit record, scoped at $15,000 by purchase order, three Q1 2027 install slots. Ask each to sign an LOI naming the facility, the program office and the start quarter, and to open a purchase requisition.
keep going if · 3 of 12 sign the LOI with a named facility and start quarter; at least 1 purchase requisition enters procurement
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$0
no cash yet: take a signed commitment
how · No money can credibly move before the prime's security review and PO cycle, so collect a signed LOI on the prime's letterhead instead: it names the facility, the program office, the $15,000 evaluation scope and the start quarter, is signed by the software factory lead, and is paired with a purchase requisition submitted to their procurement
what it reserves · One of three Q1 2027 install slots, priority on the security package review for their facility, and the $15,000 evaluation price held through the start quarter
refund · The LOI is non-binding on award; either side may withdraw in writing before the purchase order issues, and a missed start quarter rolls the slot forward or lapses the LOI at the prime's option
target · 3 signed LOIs with dated start quarters from 12 conversations within 45 days, with at least 1 purchase requisition in procurement
before taking money · Take no CUI, classified or export-controlled source code during the test - interviews and the security dry run use only the spec sheet, and ITAR counsel reviews anything before it enters a facility.
Go: build it if
3 signed LOIs with named facilities and start quarters, 1+ purchase requisition in procurement, and 3 of 5 security reviewers calling the package approvable within a quarter - start the build and the first install
Kill: stop if
7 or more of 12 leads say they are waiting on a certified hosted offering from a frontier vendor already on their roadmap, or 0 LOIs after 12 asks, or security reviewers unanimously put approval beyond two quarters
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
Your software factory can't send source to a hosted model, so your developers are watching the coding-agent wave from behind the boundary. I'm scoping a read-only code intelligence appliance that runs entirely inside your enclave: a resident code graph over your full repo history, agent-compatible endpoints, a complete audit record for your ISSM, and no token crossing the network. I'm signing three primes for 90-day evaluations at $15,000 each, installing Q1 2027. Would you give me 20 minutes to walk the spec against your security gates?
landing page
Coding agents inside your enclave - nothing crosses the boundary $15,000 for a 90-day read-only evaluation in one accredited facility, by purchase order Sign the LOI to hold one of three Q1 2027 install slots
deposit terms
This letter of intent reserves one of three Q1 2027 evaluation slots: a 90-day read-only install at the facility you name, scoped at $15,000 and payable by purchase order after your security review. No money moves until the PO issues, and either side may withdraw in writing before then. If we miss your named start quarter, the slot rolls forward or the LOI lapses at your option.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
One score that balances how trendy the idea is, the demand for it and its potential for 100x, with competition measured relative to every other idea in the catalog. Recent startup trends first, government priorities second.
57
Idea Score, 0-100 · raw 35.7 x 1.61
Crowded
competition: more crowded than 96% of ideas · headwind x0.52
+3.8
government priorities, secondary (39 matching grants)
Trend
43
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)56
- Rounds announced 2025+ in the sector16
- Sector direction (live batch)50
- 2026 trend analyst50
Demand
68
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)100
- Operator judge: real pain75
100x potential
79
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- Venture judge75
- Market size axis67
- Moat axis100
- Neighbours still alive59
- Technologist judge100
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 272 ideas in the catalog; the terms matched were air-gapped, coding, infrastructure, defense, banks, code, graph, on-premise.
The idea in full
- What
- Sovern is an on-premise runtime and API that lets a defense program office or a bank run coding agents against its entire repository history without a single token crossing the network boundary. It builds a resident code and dependency graph inside the enclave, distills a small model against that graph, and exposes the same endpoints an agent harness expects, plus a full record of every proposed and rejected change for the auditor. Deployment involves engineers on site inside accredited facilities, which is why the sales motion is founder-led and the install takes months.
- Why now
- Two companies in the yc S26 batch alone attack the pieces separately: Graphify Labs with an on-device knowledge graph engine for enterprises and Hoplite with deploying cloud software factories; meanwhile only 85% of the 798 tracked companies in this cluster are still alive and average AI-visibility sits at 47/100, so the buyers with the strictest data rules have the fewest credible vendors.
- Wedge: first customer and entry point
- One software factory at a single prime contractor that is banned from sending source to a hosted model, sold as a read-only code intelligence appliance before any write access is granted.
- Path to 100x
- Enterprise development tooling plus regulated and defense IT is a $10-100B market where the strictest buyers currently cannot use agents at all, so the category being created is the sovereign coding substrate rather than another assistant. Every rejected and accepted change inside every enclave feeds a cross-customer model of what regulated reviewers refuse, a data moat that hosted vendors structurally cannot assemble because they never see inside the boundary.
- Ceiling
- Air-gapped deals are few, slow and lumpy; if the customer count stalls in the low hundreds the business looks like a high-margin government contractor rather than infrastructure.
- Closest real companies, as the generator saw them
- Graphify Labs sells an on-device knowledge graph but not an agent runtime, Hoplite deploys software factories in the cloud, Jcode builds the harness and Mentlio measures token spend; none of them holds the accreditation-facing evidence record that lets a regulated program approve agent-written commits.
- Main risk
- Frontier model vendors ship a certified air-gapped deployment and Sovern degrades into an integration layer on top of it.
Five judges
Each judge scores every idea in the catalog with a named rubric; the venture judge decides whether a card is shown at all (4-5 is venture-grade).
Venture investor
4/5
Sovereign coding substrate for banks and defense in a $10-100B market with an inside-the-enclave data moat hosted vendors cannot replicate.
Bootstrapper
2/5
Defense enclave installs take months with engineers on site, so revenue is lumpy six-figure deals gated by accreditation calendars.
Operator
4/5
A prime contractor banned from sending source to a hosted model has a hard blocker, and read-only code intelligence lands before any trust is needed.
Technologist
5/5
A resident code graph plus a model distilled inside the enclave is hard engineering, and the rejected-change corpus is data hosted vendors structurally cannot see.
Risk
3/5
On-premise enclaves and an auditor-facing evidence record fit regulated buyers, but revenue rests on a few lumpy prime contractor deals in the low hundreds.
trends
3/5
Working coding agents are a real 2025 shift and defense fits the RFS, but frontier vendors shipping certified air-gapped deployments is already closing this window.
Similar startups in the directory
Companies whose pitch matches most of the idea's terms (air-gapped, coding, infrastructure, defense, banks, code, graph, on-premise): 101 all-time, 35 from the last two years. Same matching as Idea Check.
On-device Knowledge Graph engine for Enterprise Software
Frontier AI Defenses for Social Engineering Attacks
Financial infrastructure for the agent economy
Dynamic access controls for all data and databases
Prevent Fraud and Onboard Users Faster
Secure Collaboration for Technical Teams
Use Radiant's control plane to easily deploy, manage, and scale generative AI features for critical workflows
Persistent sandboxes for agents like hermes, openclaw, claude code
The infrastructure to run coding agents for your team
Build-your-own compliance AI workflows for sanctions screening, regulatory monitoring and due diligence, with audit trails built in.
Databricks for Enterprise Codebases
Your software, improving itself: An autonomous product, run entirely by agents
The generator's reference companies
Real companies the model named as closest when it wrote the card, with their fate. A check mark is a company the radar could verify in its directory.
Public money in this direction
US federal grants, SBIR/STTR awards and open opportunities from the radar's public-money feed, matched to the idea's terms; the sector totals give the context.
8
grants and programs matching the idea
122
startup-relevant grants in Developer tools
$70M
awarded in the sector, tracked
1
opportunities open now in the sector
- CAREER: Towards Automated Vulnerability Management: Vulnerability Discovery, Localization, and Continuous Monitoringawardhigh relevance
National Science Foundation · Secure &Trustworthy Cyberspace · $625K · posted 2026-03-26
- VINES: Track 2: OMNISCIENT: Enabling BVLOS for On-demand Mission Critical Aerial Networks through Self-adapting NextG IAB Meshawardhigh relevance
National Science Foundation · TIP-CHIPS KTA-6 Communications · $5M · posted 2026-09-18
- In vivo CAR therapies for lupus treatment using selectively expressed genetic payloads in immune-cell-biased lipid nanoparticlesawardhigh relevance
NIH / NIAID · SBIR phase I · $307K · posted 2026-08-14
- SBIR Phase I: AI-Driven Cloud Application Programming Interface for Quantum-Accurate Materials Simulationawardhigh relevance
National Science Foundation · SBIR Phase I · $305K · posted 2026-08-11
- Collaborative Research: SaTC 2.0: RES: AIGIS: Securing the Deep Learning Model Supply Chainawardmedium relevance
National Science Foundation · Secure &Trustworthy Cyberspace · $410K · posted 2026-05-19
- Collaborative Research: SaTC 2.0: RES: AIGIS: Securing the Deep Learning Model Supply Chainawardmedium relevance
National Science Foundation · Secure &Trustworthy Cyberspace · $410K · posted 2026-05-19
- Collaborative Research: SaTC 2.0: RES: AIGIS: Securing the Deep Learning Model Supply Chainawardmedium relevance
National Science Foundation · Secure &Trustworthy Cyberspace · $400K · posted 2026-05-19
- Research Infrastructure: Mid-scale RI-1 (M1:DA): A Generative AI Learning Agent Infrastructure for STEM Education Researchawardmedium relevance
National Science Foundation · Mid-scale RI - Track 1 · $855K · posted 2026-09-11
Market signal
What the radar sees in Developer tools: new companies by cohort year, the forming YC batch, and outcomes since the February snapshot.
Developer tools · 64 → 105 → 121 → 90 → 57 new companies 2022 → 2026 · 87% aliveYC F26 live: 8 in this cluster, 6% of the batch (was 3% in S26)Since February, of 474 YC companies here: 6 acquired, 8 shut down, 59 rewrote their pitch
Design attributes
The card is one cell of a designed set: every axis below was chosen before the text was written, and the text had to realize it.
- Buyer
- Enterprise
- Business model
- Infrastructure and APIs
- Path to 100x
- Creates a new category
- Market size
- $10-100B market
- Capital intensity
- Capital-medium (ops, field teams)
- Speed to revenue
- Revenue in 1-3 years
- Technical depth
- Deep tech: ML, hardware, bio
- Go-to-market
- Founder-led sales
- Moat
- Data moat
- Geography
- Global from day one
- Regulation
- Heavily regulated
- Vibe
- Boring business
Listed under
An idea sits in its own sector and in any sector its text clearly touches.
More ideas like this
AI and software · Developer tools
Faultline
An incident agent that learns every production failure across its customers, then fixes yours.
Faultline runs as an on-call agent inside a large company's production environment: it reads traces, logs and deploys, reproduces the failure in a sandbox, and proposes or applies the fix.
AI and software · Developer tools
Reglet
Regulatory intelligence APIs that tell coding agents what the law requires.
Reglet is an API layer that maps code changes to regulatory obligations - HIPAA, PCI-DSS, GDPR, banking rules - in real time, so a bank's or hospital's coding agents and CI pipelines know when a diff touches regulated data flows and exactly what evidence to attach.
AI and software · Developer tools
Patchwright
An upgrade agent that keeps small software companies current, with a recipe store others fill.
Patchwright is a hosted agent that watches a small software vendor's repositories and does the maintenance work nobody staffs: dependency and framework upgrades, breaking API migrations, deprecation fixes, and the evidence trail for SOC 2, GDPR and accessibility questionnaires that their own customers demand.
AI and software · Developer tools
Appcroft
The operating layer that keeps small businesses' AI-built apps running.
Appcroft hosts, patches, monitors and integrates the AI-generated apps that small businesses now get built by freelancers and dev shops using tools like Lovable.
AI and software · Developer tools
Miniplex
The cloud built for a billion small apps.
Miniplex is purpose-built cloud infrastructure for agent-generated software: sub-second cold-start microVMs, per-app metering in fractions of a cent, and a deploy API that coding agents and app builders call directly.
AI and software · Developer tools
Portway
A machine-readable catalogue of every internal enterprise app, so agents can use them.
Portway is a subscription platform where a large company describes its internal applications once, in a no-code editor, as capability manifests: what each app does, which actions it exposes, who may call them, and what the fields mean.
Fictional company written 2026-08-22 from MarkosWeb data; the companies, grants and numbers around it are real and tracked. Treat the idea as a research prompt, not a plan.