New startup ideas · AI for people who run the AI themselves · Evaluation and trust the user controls
startup concept
Middlegate
A local gateway where you set the rules for what your MCP servers can do
An MCP proxy an individual installs between their assistant and their servers.
- Infrastructure and APIs
- Consumer
- MCP donated to the Agentic AI Foundation
4
similar startups, last 2 years (11 all-time)
yes
8 matching federal grants and programs
Direction supported by government programs and grants
Test it before you build it
$400 · 3 weeks · 30 prospects
Prove for $400 in 3 weeks that MCP power users will put $25 on a card for a $20-a-month local policy proxy before any client ships native gates.
Riskiest assumption · Power users running three or more MCP servers will personally pay $20 a month for approval gates and a signed audit log now, rather than wait for Claude Desktop, Cursor and the other first-class clients to ship native per-server permissions for free
1Focus group: who and where
A senior engineer, staff engineer or technical PM at a mid-size or large company who runs three or more personal MCP servers (email, files, GitHub, Slack) through Claude Desktop or Cursor, inside or around company policy, and knows one unattended write or send could become a security incident with their name on it
where to find 30 · r/mcp and r/ClaudeAI on Reddit, where users post server setups and near-miss stories; GitHub Discussions and issues on the modelcontextprotocol org, plus contributors to the awesome-mcp-servers list as a directory of exactly these users; local AI Tinkerers meetups, which run monthly in most major US cities
2Sell first, build later
A reserved first-cohort license for a single-binary local MCP proxy with three template policies (read-only default, approval on writes and sends, per-server blocklists) and a signed audit log, shipping to the first 50 reservers on November 2, 2026
the ask · $20 per month, personal card, founding rate locked through 2027; $25 refundable reservation up front
a real yes · A real yes is a completed $25 card reservation; upvotes, GitHub stars, 'ship it and I'll subscribe' comments and free waitlist emails do not count
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Spec post with paid reservation
$200 · 10 days
Write the full README for Middlegate before any code exists: the policy file format, the three template policies, the signed log, the single-binary install. Post it to r/mcp and as a Show HN, linking a landing page that shows $20 a month and takes a $25 refundable card reservation for the first 50 binaries. The reservation count is the direct test of the riskiest assumption.
keep going if · 15 card-backed $25 reservations within 10 days of the two posts
2. Fifteen incident interviews
$50 · 7 days
Book 20-minute calls with reservers and with r/mcp posters who described unwanted tool calls, recruited by DM. Ask each for the specific incident: what the server did, what it touched, and what hand-rolled mitigation they run today, if any. The founder runs all calls in one week.
keep going if · 9 of 15 describe a specific unwanted write, send or data pull, and at least 6 currently mitigate by hand (disabling servers, reading every diff)
3. AI Tinkerers live demo
$150 · 14 days
Present the policy file format and a mocked approval-gate flow at one local AI Tinkerers meetup, then take reservations in person on a tablet at the same $25. This tests whether the pitch converts strangers outside the Reddit echo chamber.
keep going if · 5 reservations from one event of 30-60 attendees
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$25
per prospect, refundable
how · A $25 refundable pre-order reservation taken by card on the landing page checkout, the right instrument for a consumer-priced tool bought on a personal card with no procurement in the way; the buyer checks a one-line terms box, nothing is signed set up: Stripe Checkout ↗
what it reserves · One of 50 first-cohort licenses, the $20 a month rate locked through 2027, and the November 2, 2026 ship date
refund · Refunded in full with one click any time before ship day or within 14 days after; otherwise it credits the first month with $5 rolling to the second
target · 20 paid reservations within 21 days across the two posts and one meetup
Go: build it if
20 or more $25 reservations and 9 of 15 interviews naming a real incident: build the binary and ship to the cohort on the promised date
Kill: stop if
Fewer than 8 reservations from 500 or more landing visits, or interviews showing users expect their client to ship native gates and will simply wait: the stated risk is real and the wedge is too thin
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
You're running MCP servers against your real email, files and repos, and you're one unattended tool call away from writing an incident report about yourself. I'm building Middlegate: a single-binary local proxy where you set the rules - read-only by default, human approval on writes and sends, a signed log of every call. $20 a month, first binaries ship November 2. Do you have 20 minutes this week to show me your server setup and where you'd put the gates?
landing page
Your MCP servers, on your rules $25 refundable reservation holds a first-cohort license at $20 a month, locked through 2027 Reserve your binary - first 50 ship November 2, 2026
deposit terms
$25 reserves one of 50 first-cohort licenses at $20 a month, locked through 2027. Fully refundable with one click any time before ship day or within 14 days after; otherwise it credits your first month, with $5 rolling to your second. Binaries ship November 2, 2026.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.
70
Idea Score, 0-100 · raw 43.3 x 1.61
Active
competition: more crowded than 57% of ideas · headwind x0.71
+3.7
government priorities, secondary (26 matching grants)
Trend
49
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)98
- Rounds announced 2025+ in the sector0
- Sector direction (live batch)50
Demand
61
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)92
100x potential
57
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- Neighbours still alive57
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were local, gateway, set, rules, mcp, servers, proxy, individual.
The concept in full
- What
- An MCP proxy an individual installs between their assistant and their servers. The user writes their own gate rules: read-only by default, human approval on writes and sends, blocklists for specific data leaving specific servers, and a signed log of every tool call for their own audit trail. In the first hour a user routes two MCP servers through it, sets an approval gate on outbound email, and watches the first blocked call appear in the log.
- Grounded in (2025-2026 signals)
- 'On December 9, 2025 Anthropic donated the Model Context Protocol to the new Agentic AI Foundation', with 'MCP had 97 million monthly SDK downloads and 10,000 active servers, with first-class support in ChatGPT, Claude, Cursor, Gemini, Copilot and VS Code'. Gartner (June 25, 2025) predicted over 40% of agentic AI projects cancelled by end of 2027, citing weak risk controls.
- What it rides
- MCP donated to the Agentic AI Foundation. With MCP as neutral infrastructure under the Linux Foundation and 10,000 active servers, the trust question moved from the protocol to the person plugging servers in, and no vendor sets those gates for the individual user.
- Why now
- MCP hit 97 million monthly SDK downloads and 10,000 active servers as of the December 9, 2025 foundation announcement, while Gartner's June 25, 2025 prediction names weak risk controls as a top reason 40% of agentic projects will die; the individual running personal tools inside company policy needs controls they own, today, at any of the six first-class MCP clients.
- Wedge: first customer and entry point
- The enterprise power users in MIT NANDA's 40%-plus shadow AI population who want to keep using personal tools without triggering a security incident; entry point is a single-binary proxy with three template policies, paid personally at $20 a month.
- Closest real companies, as the generator saw them
- Tinfoil (yc X25) offers encrypted AI with verifiable privacy at the infrastructure layer, not user-authored action gates on tool calls. Corsair (yc W25) connects users to their apps; it does not let the user gate what the connection may do.
- Main risk
- MCP clients add native per-server permission prompts rich enough that a separate policy layer feels redundant.
Similar startups in the directory
Companies whose pitch matches most of the concept's terms (local, gateway, set, rules, mcp, servers, proxy, individual).
Hedro Sistemas Inteligentes is an it consulting firm that sensors enable efficient and personalized data collection.
Your personal context, securely portable across every AI app.
Agents that own the work
We help software companies get discovered and used by AI agents
Atmosfy is a short-form video platform enabling hyper-local discovery of dining, nightlife, and travel experiences through real-time user-generated content.
We help US tech companies hire and manage software engineers in LATAM
Palantir for sales people
Apollo helps engineering teams accelerate delivery
ATOMica is a co-working space and business management company for conference rooms, event venues, circles, and schools.
Menew is an online platform that enables users to organize and set menus for family meals.
PortRay is a training platform that helps users prepare for interviews by conducting mock interviews and providing feedback.
Public money in this direction
US federal grants and open opportunities matched to the concept's terms.
NIH / NIMHD · SBIR phase I · $307K
National Science Foundation · SBIR Phase I · $303K
National Science Foundation · Use-Inspired NextG · $1M
National Science Foundation · Use-Inspired NextG, GVF - Global Venture Fund · $675K
NIH / NEI · SBIR phase I · $349K
NIH / NIA · SBIR phase II · $499K
NIH / NICHD · SBIR phase I · $270K
NIH / NCI · SBIR phase II · $1M
Other concepts in this collection
- SkillproofRegression testing for the Agent Skills you actually depend on
- ProvenaryScan third-party skills and MCP servers before you let them touch your data
- LedgerkitVersioned skill packs that make a solo CPA's assistant work like a tax practice
- VendfoldLicensing, signing and auto-update infrastructure for people who sell Agent Skills
- PackroomOne shared skill library for a team where everyone runs their own agent
- TokentabPer-skill cost, routing and drift telemetry for the person who runs AI all day
- ThreadkeepA memory vault you own that every assistant you run can read
- RelayfileHand a running task from Claude Code to Codex without losing state
- MeterhouseOne budget, meter and kill switch for every agent you run
- AttestlyAudit trail and approval inbox for the agents you run at work
- SkillvaneVersion control and regression tests for the skills your agents load
- CrewlineA shared board where each teammate's agents pick up each other's work
- WardkeySecurity scanner that finds and fixes exposed keys in vibe-coded apps
- StillupUptime and error monitoring that answers in fix prompts, not stack traces
- CopystoneAutomatic backups and one-click restore for apps built without engineers
- GroundskeepMonthly maintenance for shipped vibe-coded apps, applied as reviewable patches
- TillhousePayments, sales tax and refunds as one drop-in for non-developer founders
- SpendgateMeter, cap and route the AI spend inside apps vibe coders shipped
- DryloopRehearsal mode for the automations a small business owner builds alone
- MeterlyOne metered key with spend caps for every AI step you run
- FlowmedicWatches your automations, explains failures in plain English, proposes the fix
- ScrubdeckA data-cleaning step any workflow can call, with rules the owner keeps
- OpshandTurns your written SOPs into versioned Agent Skills with tests included
- CrewtraceShared visibility when five people at one business each run their own automations
- VeraciteCitation verification and AI work records for solo attorneys who draft with Claude
- TickstoneTurns a solo CPA's AI sessions into reviewable workpapers with tickmarks and source trails
- ChartproofA verification layer for physicians who use AI on clinical notes under their own license
- CoverlensPolicy-form verification for independent insurance agents who quote with AI
- MethodkitSolo consultants package their methodology as versioned Agent Skills they own and resell
- AttestrailTamper-evident logs of every AI action, built for licensed professionals' liability files
- ScrublineLocal redaction proxy that makes your personal AI accounts safe for work data
- StipendlyTurn personal Claude Max and ChatGPT Pro seats into managed employer stipends
- TollgateA policy gateway between your assistant and every MCP server it touches
- SkillvetScan, pin and approve Agent Skills before they touch company data
- DaylightSelf-serve shadow AI registry and policy for companies with no security team
- LedgerlineRightsizing dashboard for everyone paying for AI out of their own pocket
- SwitchyardOne metered endpoint with routing, fallback and per-person caps for tiny teams
- HearthmeterUsage budgets and one bill for the household that shares AI plans
- SeatcaseMeasures who on your team earns a Max seat and who wastes one
- TokencairnProfiler that shows what each installed skill and MCP server really costs
- FusegateBudget caps, fallback and kill switches for automations you run yourself
- SkillbenchRegression testing for Agent Skills before every model and skill update
- CitelockVerifies every citation in AI-drafted work before a licensed professional signs it
- DriftwatchCatches output drift in the automations small operators wired themselves
- ShipcheckPre-launch review gates non-technical builders run on their own vibe-coded apps
- TracelineA claim-level provenance trail for every number in an AI-assisted report
- DrillyardScored practice repos where you learn to drive coding agents well
- PassrateA proctored AI operation exam scored from your real agent transcripts
- PatchcraftDebugging drills that teach non-technical builders to maintain what they vibe coded
- SkillsmithA workshop for writing, testing and versioning Agent Skills that actually hold up
- TickmarkSynthetic client caseloads where CPAs drill AI-assisted work before trying it on real clients
- PostgameAn MCP server that scores your own agent sessions and drills your weakest habits
- CitegridEvery number in your published research links to a source snapshot you verified
- MnemosYour research corpus as a private MCP server every assistant can query
- MeterlineModel routing and cost accounting for one person's AI research pipeline
- SkillcaskVersion, test, and sell your expertise as licensed Agent Skills
- StackfeedA personal data pipeline that repairs itself when sources change
- ClaimboardA shared evidence ledger for small teams where everyone runs their own agent
Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.