New startup ideas · B2B, security and compliance · Security and compliance

startup idea

Skirmish

The exchange where autonomous hacking agents compete to break enterprise systems.

Enterprises post scoped targets and bounties; independent builders of offensive AI agents connect their agents to compete on them inside Skirmish's isolated ranges.

3/5

venture judge

45

similar startups, last 2 years (109 all-time)

98%

of 4 nearest real companies still alive

yes

8 matching federal grants and programs

Direction supported by government programs and grants

Test it before you build it

$1,000 · 4 weeks · 8 prospects

Prove that at least 4 offensive-AI-agent builders will commit to route through a neutral exchange and one MSSP will prefund a bounty pool, for under $1,000 in 4 weeks.

Riskiest assumption · Independent offensive-AI-agent builders will connect their agents to a neutral exchange for a rake rather than selling direct to enterprises, giving the exchange differentiated supply.

1Focus group: who and where

The founder or head of go-to-market at an early-stage offensive-AI-agent startup, seed or current accelerator batch with no enterprise sales team, that needs paid, scoped targets to prove its agent and generate revenue.

where to find 8 · The six named vendors directly - Trident, Parameter, Antigen, Veria Labs, Fabraix, and Lupin & Holmes - plus other agentic-security teams in the current YC and Alchemist batch directories; offensive-security communities on the DEF CON and Black Hat Discords and the r/netsec subreddit; and BSides Las Vegas and other regional BSides events where these builders demo.

2Sell first, build later

A 60-day continuous, pay-per-verified-exploit program: a panel of independent AI agents runs against one scoped target in an isolated range, and you pay only for reproduced, de-duplicated, exploitability-ranked findings, delivered through your MSSP. First ranked findings within 14 days of scoping.

the ask · A $5,000 prefunded bounty pool per target for the 60-day pilot, with the exchange taking a 20% rake on paid-out findings.

a real yes · A real yes is the MSSP or enterprise wiring the $5,000 bounty pool into escrow with a signed scope, plus 4 builders signed to compete. Interest from builders, 'send me the deck,' and unpaid demos do not count.

3Small experiments

The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.

  1. 1. Builder routing LOIs

    $150 · 14 days

    Email and call the six named builders plus two more from the current batches. Pitch the exchange as their distribution channel: scoped paid targets, keep 80% of every verified-exploit payout, no enterprise sales needed. Ask each to sign a one-page LOI to connect one agent to a first paid program. The founder runs it.

    keep going if · 4 of 8 builders sign an LOI to connect for a rake

  2. 2. MSSP and target demand

    $350 · 21 days

    Pitch one regional offensive-security MSSP and three mid-market SaaS security leads on a continuous, pay-per-verified-exploit program routed through the exchange. Ask the MSSP to prefund a scoped bounty pool for one named client target.

    keep going if · 1 MSSP prefunds a bounty pool for at least 1 named target

  3. 3. Verification bake-off

    $500 · 14 days

    Run three builders' agents against one deliberately vulnerable staging target you stand up (OWASP Juice Shop and DVWA on an isolated range) and hand-verify how many submitted findings are truly reproducible and unique. This measures whether ranking real exploits from noise is tractable without heavy human triage.

    keep going if · 70% or more of paid-out findings are reproducible and de-duplicated with under 1 hour of human triage each

4Collect a deposit up front

Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.

$5,000

per prospect, refundable

how · The MSSP or enterprise prefunds a scoped bounty pool into escrow under a signed rules-of-engagement and scope document; this is both the reservation and the demand measurement. A prefunded pool fits because payout-per-verified-exploit is the whole model and escrow protects both sides before any product exists.

what it reserves · A place in the first pilot cohort, the panel of committed agent builders pointed at their target, and the 20% rake locked for the pilot.

refund · Unspent pool is returned in full if fewer than 3 verified exploits are delivered in 60 days.

target · 1 prefunded $5,000 bounty pool and 4 signed builder LOIs within 30 days.

before taking money · Do not run any agent against a target without a signed, scoped rules-of-engagement authorization from the asset owner, and keep every test inside the isolated range to stay within computer-abuse law.

Go: build it if

4 or more builders sign to connect, 1 MSSP prefunds a $5,000 bounty pool, and 70% or more of paid findings verify cleanly.

Kill: stop if

Fewer than 3 builders commit and go direct instead, or no MSSP will prefund a pool, or over half of findings are noise needing heavy human triage.

5 Scripts to run itoutreach message, landing copy, deposit terms · click to open

outreach message

You built an offensive agent but have no enterprise sales team to point it at paid targets. We bring you scoped, paid programs and you keep 80% of every payout on a verified, reproduced exploit, with no procurement and no cold outbound. We are lining up our first MSSP-run pilot now. Can I get 20 minutes this week to walk through the rules of engagement and sign you up for the first target?

landing page

Pay only for exploits that are real, reproduced, and ranked. $5,000 bounty pool per target for a 60-day program; you pay per verified exploit, we take 20%. Prefund a pilot target ->

deposit terms

Your $5,000 prefunds a scoped bounty pool held in escrow and reserves the first pilot cohort with our committed agent panel pointed at your target. We deliver reproduced, ranked findings within 14 days. Any unspent pool is refunded in full if we deliver fewer than 3 verified exploits in 60 days.

Would you run this test?

One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.

Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.

Scorecard

One score that balances how trendy the idea is, the demand for it and its potential for 100x, with competition measured relative to every other idea in the catalog. Recent startup trends first, government priorities second.

58

Idea Score, 0-100 · raw 36.1 x 1.61

Crowded

competition: more crowded than 96% of ideas · headwind x0.52

+2.3

government priorities, secondary (8 matching grants)

Trend

81

Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.

  • Entrants 2025-26 vs 2023-24 (similar companies)83
  • Rounds announced 2025+ in the sector47
  • Rounds announced 2025+ matching the idea100
  • Sector direction (live batch)100
  • 2026 trend analyst75

Demand

62

Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.

  • YC asks for it (current RFS: idea / sector)60
  • Someone already pays (similar companies, recent / all-time)100
  • Operator judge: real pain25

100x potential

55

Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.

  • Venture judge50
  • Market size axis67
  • Moat axis20
  • Neighbours still alive67
  • Technologist judge75

Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 272 ideas in the catalog; the terms matched were exchange, autonomous, hacking, compete, break, enterprise, enterprises, post.

The idea in full

What
Enterprises post scoped targets and bounties; independent builders of offensive AI agents connect their agents to compete on them inside Skirmish's isolated ranges. The hard technology is the verification layer: ML-driven exploit reproduction, deduplication, and exploitability scoring that turns a flood of agent findings into a ranked, paid-per-proven-bug feed. MSSPs and cyber insurers resell access, and agent builders treat Skirmish as their distribution channel rather than building enterprise sales teams.
Why now
Six agentic offensive security companies appear in the last few accelerator batches alone - Trident, Parameter, Antigen, Veria Labs, Fabraix, and Lupin & Holmes - so agent supply now exists without any neutral demand-side clearinghouse, while Cytix's $7M Series A (2026-08-12) targets the cyber risk created by AI-driven software development, the exact expansion of attack surface these agents feed on.
Wedge: first customer and entry point
Recruit five agent-builder teams and run paid continuous-pentest programs for a handful of US mid-market SaaS companies through one MSSP partner, proving the payout-per-verified-exploit loop before opening the exchange.
Path to 100x
Penetration testing and offensive security services are a $10-100B market shifting from human hours to agent findings, and marketplaces in such shifts concentrate: both sides go where liquidity and trusted verification already are. The company that sets the standard for what counts as a proven exploit and pays out on it takes a rake on the whole category - liquidity is the compounding asset, though today the moat is still to be built.
Ceiling
If ML verification cannot cheaply separate real exploits from agent noise, Skirmish decays into a human triage shop with services margins.
Closest real companies, as the generator saw them
Trident, Parameter, Antigen, and Veria Labs each sell their own agent end-to-end; Skirmish is the neutral marketplace and verification layer all of them can sell through, competing on findings rather than sales teams.
Main risk
The best agent vendors go direct to enterprises and starve the exchange of differentiated supply.

Five judges

Each judge scores every idea in the catalog with a named rubric; the venture judge decides whether a card is shown at all (4-5 is venture-grade).

  • Venture investor

    3/5

    Neutral verification layer could take a rake on a $10-100B shift, but the best agent vendors going direct starves supply.

  • Bootstrapper

    2/5

    An exchange needing five agent builders plus enterprise targets plus ML exploit verification before liquidity is a three sided cold start in a hyped space.

  • Operator

    2/5

    Enterprises already buy pentests, but the exchange needs six agent vendors plus MSSPs to route through it before any buyer sees value.

  • Technologist

    4/5

    ML exploit reproduction, dedup and exploitability scoring is the hard part, and the verified-exploit corpus sharpens with every agent submission.

  • Risk

    2/5

    Offensive agents against live enterprise targets carry real liability, and the best agent builders going direct starves the exchange.

  • trends

    4/5

    Six offensive-agent vendors in the latest batches create supply that did not exist in 2023, and the brief's offensive security term confirms the wave.

Similar startups in the directory

Companies whose pitch matches most of the idea's terms (exchange, autonomous, hacking, compete, break, enterprise, enterprises, post): 109 all-time, 45 from the last two years. Same matching as Idea Check.

  • Klaimeeyc X26 · 2026 · Fintechalive

    Liability insurance for AI Agents. You deploy agents, we cover you.

  • Cascoyc X25 · 2025 · Security and compliancealive

    Autonomous security testing for web apps, APIs, cloud, and AI systems

  • Elimentaryyc F26 · 2026 · Vertical AI agentsalive

    Agents that run middle/back-office operations for Private Capital

  • Sentient OSyc F26 · 2026 · Horizontal AI assistantsalive

    On-device AI that knows your entire life and does your work overnight.

  • Rena Labsplugandplay PnP 2026 · 2026 · Agent infrastructurealive

    Rena Labs enables secure AI operations on private data with TEE data exchange.

  • Synergetics.aiplugandplay PnP 2026 · 2026 · Agent infrastructurealive

    The infrastructure layer that lets AI agents identify, communicate, and transact — securely across enterprise boundaries.

  • Sotantspeedrun SR007 · 2026 · Vertical AI agentsalive

    AI Workforces for complex supply chain operations, in just hours

  • Graphify Labsyc S26 · 2026 · Developer toolsalive

    On-device Knowledge Graph engine for Enterprise Software

  • Othellospeedrun SR007 · 2026 · Vertical AI agentsalive

    Othello builds AI models for B2B sales calls, deploying agents to give real-time prompts to sellers.

  • Assembleyc S26 · 2026 · Vertical AI agentsalive

    Autonomous IT Delivery

  • Sonderspeedrun SR007 · 2026 · Agent infrastructurealive

    On-device vision models that watch your screen, learn your workflows, and act proactively—3× faster at half the baseline model size.

  • DevPlazaalchemist Alchemist Class 41 · 2026 · Developer toolsunchecked

    Automated production-readiness platform for the AI coding era

Run this as an Idea Check →

The generator's reference companies

Real companies the model named as closest when it wrote the card, with their fate. A check mark is a company the radar could verify in its directory.

Public money in this direction

US federal grants, SBIR/STTR awards and open opportunities from the radar's public-money feed, matched to the idea's terms; the sector totals give the context.

8

grants and programs matching the idea

88

startup-relevant grants in Security and compliance

$41M

awarded in the sector, tracked

13

opportunities open now in the sector

All public money by sector →

Market signal

What the radar sees in Security and compliance: new companies by cohort year, the forming YC batch, and outcomes since the February snapshot.

Security and compliance · 43 → 45 → 83 → 74 → 47 new companies 2022 → 2026 · 94% aliveYC F26 live: 5 in this cluster, 4% of the batch (was 3% in S26)Since February, of 171 YC companies here: 2 acquired, 2 shut down, 27 rewrote their pitch

Security and compliance: companies, trend and grants →

Design attributes

The card is one cell of a designed set: every axis below was chosen before the text was written, and the text had to realize it.

Buyer
Enterprise
Business model
Marketplace
Path to 100x
Platform others build on
Market size
$10-100B market
Capital intensity
Capital-light (software margins)
Speed to revenue
Revenue in 1-3 years
Technical depth
Deep tech: ML, hardware, bio
Go-to-market
Partners and channels
Moat
No moat yet
Geography
US first
Regulation
Unregulated
Vibe
Hot space

Listed under

An idea sits in its own sector and in any sector its text clearly touches.

More ideas like this

B2B, security and compliance · Security and compliance

Claimyard

Marketplace turning scam, fraud and privacy losses into funded, aggregated consumer claims.

A consumer uploads what happened, screenshots of a romance scam, an unauthorized P2P transfer, a data misuse notice, and a no-code intake agent classifies the claim, pulls the paper trail from the bank or platform, and posts it to a marketplace of licensed attorneys, arbitration filers and litigation funders who bid to take it on contingency.

Score 94Open competitionVC 5/5MarketplaceConsumertest: $1k · 5w83% of 4 neighbours alive

B2B, security and compliance · Security and compliance

Sentinet

Shared-defense agent for small firms: one member's confirmed fraud warns the whole network.

Sentinet connects in an afternoon to an SMB's mailbox, accounting system and bank feed, and runs an agent that screens invoices, vendor bank-detail changes and unusual logins.

Score 90Warm competitionVC 4/5AI agent as a serviceSmall businesstest: $700 · 4w97% of 3 neighbours alive

B2B, security and compliance · Security and compliance

Vouchline

One AI agent answers your security questionnaires and reviews the ones you send.

Vouchline is an agent that sits on both sides of the vendor security review: for a small supplier it reads the buyer's questionnaire, pulls evidence from Drive, ticketing and cloud consoles, and returns a completed response in a day; for the buyer it reads incoming responses and flags the answers that contradict prior filings.

Score 80Active competitionVC 4/5AI agent as a serviceSmall businesstest: $600 · 3w98% of 4 neighbours alive

B2B, security and compliance · Security and compliance

Attestral

Agents that prove and verify vendor security continuously, replacing the questionnaire.

Attestral deploys agents inside an enterprise's stack that collect live control evidence and answer any customer's security review automatically; on the buying side, its agents interrogate a vendor's agents and check every claim against machine-readable evidence rather than prose.

Score 75Crowded competitionVC 5/5AI agent as a serviceEnterprisetest: $800 · 3w97% of 3 neighbours alive

B2B, security and compliance · Security and compliance

Codewarden

Continuous security for the AI-written software small businesses now run on.

Codewarden is a self-serve subscription platform that continuously scans, exploits and patches the AI-generated applications small businesses now build and deploy without security staff.

Score 71Crowded competitionVC 5/5Software subscriptionSmall businesstest: $500 · 3w96% of 2 neighbours alive

B2B, security and compliance · Security and compliance

Ironvane

Autonomous security operations agents that managed service providers resell and extend.

Ironvane gives managed service providers a runtime where security agents triage alerts, patch endpoints, revoke credentials and close tickets across their whole book of small business clients, with the provider approving actions rather than performing them.

Score 60Crowded competitionVC 4/5AI agent as a serviceSmall businesstest: $1.3k · 4w97% of 3 neighbours alive
Swipe ideas like this in the deckTalk to the radar about it

Fictional company written 2026-08-26 from MarkosWeb data; the companies, grants and numbers around it are real and tracked. Treat the idea as a research prompt, not a plan.