New startup ideas · B2B, security and compliance · Security and compliance

startup idea

Vendorproof

An exchange where small vendors sell machine-verifiable proof that their security controls held.

Small software and services vendors connect their cloud, identity and endpoint tools once; Vendorproof produces cryptographic proofs that a named control held over a named time window, without exposing raw logs.

3/5

venture judge

0

similar startups, last 2 years (22 all-time)

98%

of 4 nearest real companies still alive

yes

5 matching federal grants and programs

Direction supported by government programs and grants

Test it before you build it

$800 · 5 weeks · 20 prospects

For $800 and 5 weeks, this proves a mid-market vendor-risk buyer will pay $2,000, half up front, for verified control evidence on 20 small vendors instead of accepting free PDFs.

Riskiest assumption · A mid-market vendor-risk buyer who accepts free PDF questionnaires today, and faces no penalty for doing so, will pay $100 per vendor for independently verified control evidence

1Focus group: who and where

Head of third-party risk or security GRC manager at a 500-5,000 employee US company (regional bank, hospital system, mid-market SaaS) facing a queue of 50-300 vendor reviews a year, who already pays for an external signal like SecurityScorecard or BitSight

where to find 20 · The Third Party Risk Association's member working groups (a community); the published member and Summit sponsor roster of Shared Assessments (a list); and local ISACA chapter meetings in the two nearest metros, plus the OneTrust and ServiceNow GRC user communities where these reviewers already post (events and channels)

2Sell first, build later

A 30-day verification pilot: for 20 of the buyer's smallest vendors, evidence pulled from the vendors' own tooling that MFA is enforced, a backup restore was tested and endpoints are encrypted, delivered as a per-vendor evidence pack the buyer can file against its review checklist

the ask · $2,000 per pilot ($100 per vendor), $1,000 due at SOW signing and $1,000 on delivery

a real yes · A real yes is a signed one-page SOW with the $1,000 half paid by ACH; 'this would save us so much time', a request to run it free on two vendors, or an intro to procurement is not a yes

3Small experiments

The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.

  1. 1. Buyer payment interviews

    $200 · 10 days

    Book 15 calls with TPRM leads sourced from TPRA working groups and ISACA chapter meetings. Ask hours spent per vendor review, what they already pay per vendor for ratings, and close every call by showing the priced pilot one-pager: three controls verified across their 20 smallest vendors for $2,000.

    keep going if · 9 of 15 spend 4 or more hours per vendor review, and 6 of 15 ask to take the priced pilot to their boss or budget

  2. 2. Vendor supply test

    $150 · 10 days

    Post in r/msp and message members of The ASCII Group: when a named buyer of yours requests it, will you connect read-only evidence of MFA enforcement, a tested backup restore and endpoint encryption within 7 days, free, in exchange for a proof you can reuse with your next buyer? Collect written yeses.

    keep going if · 12 of 25 MSPs and dev shops agree in writing to connect within 7 days of a buyer request

  3. 3. Paid pilot SOW signings

    $450 · 21 days

    Send the 10 warmest buyers a one-page SOW: MFA, tested backup restore and endpoint encryption verified across 20 of their smallest vendors in 30 days for $2,000, half due at signing. Delivery is assembled by hand for the pilot, read-only API pulls and screenshots reviewed by a founder, because the thing under test is payment, not cryptography.

    keep going if · 2 of 10 buyers shown the SOW sign and pay the $1,000 up-front half

4Collect a deposit up front

Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.

$1,000

per prospect, refundable

how · A paid design-partner pilot invoiced up front: the buyer's TPRM or security lead signs the one-page SOW and pays 50% of the $2,000 fee by ACH invoice before work starts, chosen because a mid-market security manager can approve a services invoice under $2,500 without a procurement cycle set up: Stripe Invoicing ↗

what it reserves · One of five slots in the first pilot cohort, verification of 20 named vendors within 30 days, and the $100 per vendor price locked for a following batch of up to 100 vendors

refund · The $1,000 is refunded in full if fewer than 15 of the 20 vendors produce verifiable evidence within 30 days

target · 2 paid pilots with the $1,000 half collected, from 20 buyer conversations, within 35 days

Go: build it if

2 buyers pay $1,000 up front within 35 days and 12 of 25 vendors agree in writing to connect evidence on request

Kill: stop if

0 paid pilots from 20 buyer conversations, or fewer than 5 of 25 vendors will connect; buyers are staying with free PDFs and the demand side never pays, stop

5 Scripts to run itoutreach message, landing copy, deposit terms · click to open

outreach message

Your vendor review queue is full of PDFs someone typed, and you spend half a day per vendor chasing them. I verify three controls, MFA enforced, backups restore-tested, endpoints encrypted, straight from your 20 smallest vendors' own tooling and hand you evidence instead of attestations, in 30 days for $2,000. Worth 20 minutes this week to see a sample evidence pack from a real MSP?

landing page

Vendor security answers you can verify, not just file $2,000 verifies three controls across 20 vendors in 30 days Sign the pilot: $1,000 at signing, balance on delivery

deposit terms

$1,000 is due when you sign the one-page pilot SOW; it reserves one of five slots in the first cohort and locks $100 per vendor for your next batch of up to 100. If fewer than 15 of your 20 vendors produce verifiable evidence within 30 days, the $1,000 is refunded in full. The balance is invoiced only on delivery.

Would you run this test?

One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.

Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.

Scorecard

One score that balances how trendy the idea is, the demand for it and its potential for 100x, with competition measured relative to every other idea in the catalog. Recent startup trends first, government priorities second.

92

Idea Score, 0-100 · raw 57.0 x 1.61

Open

competition: more crowded than 6% of ideas · headwind x0.97

+1.5

government priorities, secondary (3 matching grants)

Trend

49

Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.

  • Entrants 2025-26 vs 2023-24 (similar companies)23
  • Rounds announced 2025+ in the sector47
  • Sector direction (live batch)100
  • 2026 trend analyst25

Demand

62

Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.

  • YC asks for it (current RFS: idea / sector)60
  • Someone already pays (similar companies, recent / all-time)100
  • Operator judge: real pain25

100x potential

62

Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.

  • Venture judge50
  • Market size axis67
  • Moat axis100
  • Neighbours still alive32
  • Technologist judge75

Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 272 ideas in the catalog; the terms matched were exchange, vendors, sell, machine-verifiable, proof, connect, cloud, identity.

The idea in full

What
Small software and services vendors connect their cloud, identity and endpoint tools once; Vendorproof produces cryptographic proofs that a named control held over a named time window, without exposing raw logs. Buyers running vendor reviews query the exchange and pay per verified proof pack instead of mailing spreadsheets. Vendors list for free and pay a take rate on each proof delivered, so a proof produced for one buyer is resold to the next twenty.
Why now
The compliance side of this cluster is filling up with document generators (Probo, ComplyDo, Regbase, Sparkle AI, ComplyBridge, Inc.), and YC's Fall 2026 RFS asks for AI-Native Compliance Infrastructure rather than more questionnaire software. JumpWire (2022), which tried dynamic access controls across all data stores, is in the graveyard because it needed to sit inline; proofs over telemetry commitments do not.
Wedge: first customer and entry point
US managed IT and dev shops selling into mid-market buyers: cover exactly three controls (MFA enforcement, backup restore tested, endpoint encryption) and let one buyer verify a hundred of its small vendors.
Path to 100x
Vendor risk and security assurance sit inside a $10-100B GRC and third-party risk spend, and this is a classic exchange: every buyer that demands Vendorproof drags in its vendor tail, and every listed vendor pulls in its other buyers. Once a proof format is what buyers ask for by name, it is winner-takes-most because a second exchange means re-proving everything.
Ceiling
The proof system takes three years to earn trust while a large incumbent GRC vendor simply declares its own attestation format and ships it to an installed base.
Closest real companies, as the generator saw them
Probo, ComplyDo and Sparkle AI make one company look compliant on paper for an auditor. Vendorproof makes a claim independently checkable by a counterparty and reusable, so its unit is a transaction between two firms, not a subscription to a document.
Main risk
Buyers keep accepting PDFs because nobody is punished for accepting a weak one, so the demand side never pays for verified proof.

Five judges

Each judge scores every idea in the catalog with a named rubric; the venture judge decides whether a card is shown at all (4-5 is venture-grade).

  • Venture investor

    3/5

    Genuine two-sided exchange in $10-100B GRC spend, but three years of R&D against buyers who face no penalty for accepting PDFs.

  • Bootstrapper

    1/5

    R&D first with revenue after three years, and buyers still accept PDFs, so nobody is paying while the proof system earns trust.

  • Operator

    2/5

    The card admits buyers keep accepting PDFs because nobody is punished, so the side that must pay feels no pain.

  • Technologist

    4/5

    Proofs that a control held over a time window without exposing raw logs is genuine crypto engineering, and each proof pack resold to twenty buyers compounds.

  • Risk

    4/5

    Unregulated, self-serve, and reads telemetry from many tools rather than sitting inline, so no one vendor's terms change can switch off the exchange.

  • trends

    2/5

    The AI-Native Compliance Infrastructure RFS fits, but cryptographic control proofs were possible years ago and no dated 2025-2026 shift forces buyers off PDFs now.

Similar startups in the directory

Companies whose pitch matches most of the idea's terms (exchange, vendors, sell, machine-verifiable, proof, connect, cloud, identity): 22 all-time, 0 from the last two years. Same matching as Idea Check.

  • Vantayc W18 · 2018 · Security and compliancealive

    Vanta—the proven leader in automated compliance helping startups…

  • Quantized Technologiesplugandplay · Security and compliancealive

    A quantum communications startup using quantum tech to solve communication, information, and security challenges.

  • Flexpa500global · 2022 · Healthcare and bioalive

    Developer of a healthcare platform designed to ensure better outcomes through the use of diagnostic tests and lab reports. The company's product digitizes collected data from disparate hardware providers, interprets it, and then creates analytics dashboards to see how both individual patients and groups of patients are doing, enabling healthcare providers to determine treatment plans and pharmaceutical options for patients.

  • Dabchy500global · 2018 · Consumeralive

    Operator of a peer-to-peer fashion marketplace intended to connect buyers and sellers for online shopping. The company offers a marketplace that is a mix of a social network and a forum where people like and comment on the articles posted and give each other fashion tips, enabling customers to buy, sell, exchange, and review new and used fashion items with ease.

  • Freshket500global · 2017 · Commerce and marketplacesalive

    Operator of a web-based platform intended for restaurant supply management. The company's marketplace offers tools to find vendors and buy or sell fresh ingredients effortlessly through its connective marketplace and order management system, enabling clients to increase their business transaction efficiency, and information transparency and improve profitability.

  • Genomelink500global · 2017 · Consumeralive

    Developer of a personal DNA cloud data upload application designed to make people connect DNA data with insights, products, and research. The company's platform allows members to upload their raw DNA data files and discover their DNA identities and traits through intuitive visualization and scientific-educational content, enabling members to learn about their DNA data while ensuring ultimate transparency.

  • Storehub500global · 2016 · B2B SaaSalive

    Developer of cloud-based point-of-sale software designed to help retailers to digitize their business. The company's software develops a cloud-based point-of-sale system that offers real-time reports, inventory management, and customer data collection that help to connect the long line of less sophisticated physical traders online, enabling users to digitize their finances and inventory management.

  • HistoWizyc W16 · 2016 · Healthcare and bioalive

    Accelerating Histopathology for Cancer Research

  • Crypto Quantiqueef EF London 2016 · 2016 · Security and compliancealive

    Quantum-secure root of trust for IoT.

  • Cirrus Identity500global 500G GA 15 · 2015 · Security and compliancealive

    Developer of a cloud-hosted identity and access management software designed to focus on higher education. The company uses managed solutions to support multilateral federations to enable participation in InCommon and eduGAIN for identity and service providers, enabling affiliated users like applicants, parents, alumni, and continuing education students to get support for onboarding and authentication.

  • 3DPrinterOSalchemist Alchemist Class 7 · 2014 · Robotics and physical worldunchecked
  • DropShip Commerce500global · 2013 · Commerce and marketplacesacquired

    Provider of a cloud-based drop-shipping platform designed to provide product push and predictive supply chain, models. The company's online platform integrates and manages drop ship partners, inventory, data, and orders by handling the exchange of data through a single connection and integration point, helping trading partners streamline operations, generate more sales, and fulfill more orders using the virtual supply chain.

Run this as an Idea Check →

The generator's reference companies

Real companies the model named as closest when it wrote the card, with their fate. A check mark is a company the radar could verify in its directory.

Public money in this direction

US federal grants, SBIR/STTR awards and open opportunities from the radar's public-money feed, matched to the idea's terms; the sector totals give the context.

5

grants and programs matching the idea

88

startup-relevant grants in Security and compliance

$41M

awarded in the sector, tracked

13

opportunities open now in the sector

All public money by sector →

Market signal

What the radar sees in Security and compliance: new companies by cohort year, the forming YC batch, and outcomes since the February snapshot.

Security and compliance · 43 → 45 → 83 → 74 → 47 new companies 2022 → 2026 · 94% aliveYC F26 live: 5 in this cluster, 4% of the batch (was 3% in S26)Since February, of 171 YC companies here: 2 acquired, 2 shut down, 27 rewrote their pitch

Security and compliance: companies, trend and grants →

Design attributes

The card is one cell of a designed set: every axis below was chosen before the text was written, and the text had to realize it.

Buyer
Small business
Business model
Marketplace
Path to 100x
Network effects, winner takes most
Market size
$10-100B market
Capital intensity
Capital-medium (ops, field teams)
Speed to revenue
R&D first, revenue after 3 years
Technical depth
Deep tech: ML, hardware, bio
Go-to-market
Self-serve
Moat
Network effects
Geography
US first
Regulation
Unregulated
Vibe
Boring business

Listed under

An idea sits in its own sector and in any sector its text clearly touches.

More ideas like this

B2B, security and compliance · Security and compliance

Claimyard

Marketplace turning scam, fraud and privacy losses into funded, aggregated consumer claims.

A consumer uploads what happened, screenshots of a romance scam, an unauthorized P2P transfer, a data misuse notice, and a no-code intake agent classifies the claim, pulls the paper trail from the bank or platform, and posts it to a marketplace of licensed attorneys, arbitration filers and litigation funders who bid to take it on contingency.

Score 94Open competitionVC 5/5MarketplaceConsumertest: $1k · 5w83% of 4 neighbours alive

B2B, security and compliance · Security and compliance

Sentinet

Shared-defense agent for small firms: one member's confirmed fraud warns the whole network.

Sentinet connects in an afternoon to an SMB's mailbox, accounting system and bank feed, and runs an agent that screens invoices, vendor bank-detail changes and unusual logins.

Score 90Warm competitionVC 4/5AI agent as a serviceSmall businesstest: $700 · 4w97% of 3 neighbours alive

B2B, security and compliance · Security and compliance

Vouchline

One AI agent answers your security questionnaires and reviews the ones you send.

Vouchline is an agent that sits on both sides of the vendor security review: for a small supplier it reads the buyer's questionnaire, pulls evidence from Drive, ticketing and cloud consoles, and returns a completed response in a day; for the buyer it reads incoming responses and flags the answers that contradict prior filings.

Score 80Active competitionVC 4/5AI agent as a serviceSmall businesstest: $600 · 3w98% of 4 neighbours alive

B2B, security and compliance · Security and compliance

Attestral

Agents that prove and verify vendor security continuously, replacing the questionnaire.

Attestral deploys agents inside an enterprise's stack that collect live control evidence and answer any customer's security review automatically; on the buying side, its agents interrogate a vendor's agents and check every claim against machine-readable evidence rather than prose.

Score 75Crowded competitionVC 5/5AI agent as a serviceEnterprisetest: $800 · 3w97% of 3 neighbours alive

B2B, security and compliance · Security and compliance

Codewarden

Continuous security for the AI-written software small businesses now run on.

Codewarden is a self-serve subscription platform that continuously scans, exploits and patches the AI-generated applications small businesses now build and deploy without security staff.

Score 71Crowded competitionVC 5/5Software subscriptionSmall businesstest: $500 · 3w96% of 2 neighbours alive

B2B, security and compliance · Security and compliance

Ironvane

Autonomous security operations agents that managed service providers resell and extend.

Ironvane gives managed service providers a runtime where security agents triage alerts, patch endpoints, revoke credentials and close tickets across their whole book of small business clients, with the provider approving actions rather than performing them.

Score 60Crowded competitionVC 4/5AI agent as a serviceSmall businesstest: $1.3k · 4w97% of 3 neighbours alive
Swipe ideas like this in the deckTalk to the radar about it

Fictional company written 2026-08-23 from MarkosWeb data; the companies, grants and numbers around it are real and tracked. Treat the idea as a research prompt, not a plan.