New startup ideas · AI for people who run the AI themselves · Shadow AI made sanctioned
startup concept
Tollgate
A policy gateway between your assistant and every MCP server it touches
A lightweight gateway a power user runs on their own machine that sits between their assistant and its MCP servers, enforcing an allowlist, blocking defined data categories from egress, and writing a signed local audit log.
- Infrastructure and APIs
- Enterprise
- 'MCP donated to the Agentic AI Foundation' (December 9
6
similar startups, last 2 years (10 all-time)
yes
8 matching federal grants and programs
Direction supported by government programs and grants
Test it before you build it
$600 · 5 weeks · 20 prospects
Prove that IT leads will pay $3,000 up front to sanction shadow MCP setups instead of banning them, in 5 weeks for $600.
Riskiest assumption · An IT lead who discovers unsanctioned MCP usage will pay now to govern and sanction it, rather than ban it or wait for the MCP specification and the assistant vendors to ship policy controls natively.
1Focus group: who and where
The director of IT, CISO or lone security engineer at a 200-2,000 person US company in finance, healthcare or SaaS who has just discovered developers pointing Claude, Cursor or ChatGPT at internal systems through MCP servers and must choose this quarter between a ban nobody will follow and an exception nobody can monitor.
where to find 20 · The MacAdmins Slack security channels, where IT admins already trade shadow-AI war stories; local ISSA and ISACA chapter meetings plus the nearest BSides conference (they run year-round across US cities); Hacker News and r/cybersecurity threads on MCP security, where these exact people comment under their real concerns; plus warm introductions through former colleagues and any angel contacts.
2Sell first, build later
A four-week design-partner pilot: a local gateway installed for up to 10 of their power users, enforcing a server allowlist and blocking defined data categories from egress, ending with a signed audit report to IT proving the personal setups obey company policy; first pilots start October 2026.
the ask · $3,000 per pilot, $1,500 invoiced at signature and $1,500 at completion
a real yes · A real yes is a paid $1,500 signature invoice, or a signed LOI with a named start date and named pilot users when procurement genuinely blocks prepayment. Enthusiastic calls, security-team intros, and unpaid proof-of-concept requests are not yeses.
3Small experiments
The first one attacks the riskiest assumption; each ends with a number that says whether to run the next.
1. Ban-or-sanction discovery calls
$250 · 14 days
Book 15 twenty-minute calls with IT and security leads sourced from MacAdmins Slack, one local ISSA or BSides event attended in person, and warm intros. Ask what they did when they found unsanctioned MCP or AI tool usage, what a sanctioned path would need to prove, and close by proposing a paid four-week design-partner pilot. The founder runs every call and logs ban-vs-sanction stance verbatim.
keep going if · 5 of 15 leads prefer sanction-with-controls over a ban and book a pilot scoping session
2. Power-user pull test
$150 · 10 days
Publish a one-page site describing the local gateway (allowlist, egress blocking, signed audit log) with a waitlist form that requires naming the policy problem at work, and post it to Hacker News and r/ClaudeAI. This measures the bottom-up wedge: whether individual power users want their setup sanctioned badly enough to raise their hand.
keep going if · 100 waitlist signups with 25 naming a regulated or mid-size employer
3. Paid pilot close
$200 · 21 days
Send each scoping session a one-page pilot spec: four weeks, up to 10 power users, per-server allowlist and egress rules, ending with a signed audit report addressed to IT, for $3,000 with half invoiced at signature. Use an e-sign template; nothing is built until money or a dated LOI lands. Track every stall reason (budget, vendor review, waiting on the MCP spec).
keep going if · 2 of 5 scoping sessions convert to a half-paid pilot or a signed LOI with a start date
4Collect a deposit up front
Tesla took $1,000 refundable reservations for the Model 3 and $100 for the Cybertruck before building either: the deposit is the measurement, not the revenue.
$1,500
per prospect, refundable
how · A paid design-partner pilot with 50% invoiced up front, signed by the IT director or CISO; chosen because a mid-size security lead can approve a $3,000 pilot from a discretionary budget without a full procurement cycle. Where even that stalls in vendor review, fall back to a signed LOI with a dated start and named users, and count it as half a yes. set up: Stripe Invoicing ↗
what it reserves · One of 5 design-partner slots, a policy pack built for their specific data categories, a start date within 30 days, and weekly direct access to the founders during the pilot.
refund · Refunded in full if the pilot has not started within 30 days of signature or if they cancel before day one.
target · 2 half-paid pilots, or 1 paid pilot plus 2 dated LOIs, from 20 conversations within 35 days
before taking money · Expect vendor security questionnaires: the pilot scope must state in writing that no customer data leaves the user's machine and the team processes none of it, or the deal will stall in review before any money moves.
Go: build it if
2 or more pilots with $1,500 paid up front, plus 100 or more individual waitlist signups validating the bottom-up wedge
Kill: stop if
Zero paid pilots and zero dated LOIs after 15 calls and 5 scoping sessions, with most leads saying they will ban MCP outright or wait for native policy controls in the protocol
5 Scripts to run itoutreach message, landing copy, deposit terms · click to open
outreach message
If your last review turned up developers pointing Claude or Cursor at internal systems through MCP servers, you're stuck choosing between a ban nobody will follow and an exception you can't monitor. I'm building Tollgate, a gateway that runs on the user's own machine, enforces an allowlist and egress rules per MCP server, and hands you a signed audit log. I'm scoping 5 paid design-partner pilots this month. Can I get 20 minutes this week to compare notes on what your policy would need it to prove?
landing page
Sanction the AI setups your power users already run. $3,000 four-week pilot: per-server allowlist, egress blocking, and a signed audit report for up to 10 users. Book a scoping call - 5 design-partner slots, first pilots start October 2026.
deposit terms
You are invoiced $1,500, half the $3,000 pilot fee, at signature; it reserves one of 5 design-partner slots and a start date within 30 days, with the balance due at completion. Full refund if we miss your start date or you cancel before day one.
Would you run this test?
One tap. The yes-share feeds the Demand pillar of this idea's score; nobody sees who answered.
Budgets are out-of-pocket estimates for a team of one to three, US market. Size the deposit to the deal, and check the terms before taking money in a regulated line.
Scorecard
Ranked against every idea in the catalog: trend, demand and 100x potential from the corpus, competition relative to the other ideas. A generated concept has no judges or swipes yet, so its pillars use the data signals only.
69
Idea Score, 0-100 · raw 43.0 x 1.61
Active
competition: more crowded than 65% of ideas · headwind x0.67
+3.0
government priorities, secondary (11 matching grants)
Trend
41
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)74
- Rounds announced 2025+ in the sector0
- Sector direction (live batch)50
Demand
65
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)30
- Someone already pays (similar companies, recent / all-time)100
100x potential
78
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- Neighbours still alive78
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 382 ideas in the catalog; the terms matched were policy, gateway, assistant, mcp, server, touches, lightweight, power.
The concept in full
- What
- A lightweight gateway a power user runs on their own machine that sits between their assistant and its MCP servers, enforcing an allowlist, blocking defined data categories from egress, and writing a signed local audit log. The user hands IT a standing report proving their personal setup obeys company rules, instead of hiding it. In the first hour a user points Claude, Cursor or ChatGPT at the gateway endpoint, imports their existing MCP servers and toggles policies per server.
- Grounded in (2025-2026 signals)
- MCP donation to the Agentic AI Foundation under the Linux Foundation on December 9, 2025, with 97 million monthly SDK downloads, 10,000 active servers and first-class support in ChatGPT, Claude, Cursor, Gemini, Copilot and VS Code; MIT NANDA (August 2025) on the 40%-plus shadow AI economy inside companies.
- What it rides
- 'MCP donated to the Agentic AI Foundation' (December 9, 2025): one protocol with 97 million monthly SDK downloads and 10,000 active servers means a single choke point can govern everything a personal assistant connects to.
- Why now
- After the December 9, 2025 donation, MCP is a neutral standard every major assistant speaks, so one gateway now covers the whole personal stack; a year ago each tool had its own connector surface and no single enforcement point existed.
- Wedge: first customer and entry point
- IT leads at mid-size companies who discover employees already running MCP servers; bottom-up adoption by individual power users who want their setup sanctioned, then a paid team tier for the audit trail.
- Closest real companies, as the generator saw them
- Corsair (yc W25) connects a product's end users to their apps, serving developers who ship software; Prism (yc X25) deploys agents via API; Tollgate instead governs the tools a person's own assistant already uses.
- Main risk
- The MCP specification absorbs a native permissions and policy layer, making an external gateway redundant.
Similar startups in the directory
Companies whose pitch matches most of the concept's terms (policy, gateway, assistant, mcp, server, touches, lightweight, power).
Search Engine for the Physical World
MCP security gateway that secures autonomous AI by replacing broad human access grants with strictly scoped, fully auditable agent identities.
One connector per employee. Every AI tool and skill your company allows, and nothing else.
BizTrip AI leverages machine learning to transform corporate travel by streamlining planning and booking for travelers and corporations.
The AI copilot for in-person conversations.
Qumis is an AI-powered platform for insurance knowledge workflows.
The Control Plane for Enterprise Agents
Easiest way to set up Zero Trust Access for your team
Building the human layer of AI
Cosmic is an AI-powered headless CMS
Public money in this direction
US federal grants and open opportunities matched to the concept's terms.
National Science Foundation · Use-Inspired NextG, GVF - Global Venture Fund · $675K
National Science Foundation · TIP-CHIPS KTA-6 Communications · $5M
National Science Foundation · I-Corps · $50K
National Science Foundation · I-Corps · $50K
National Science Foundation · Use-Inspired NextG · $1M
National Science Foundation · I-Corps · $50K
National Science Foundation · TIP-CHIPS KTA-6 Communications · $425K
National Science Foundation · FRR-Foundationl Rsrch Robotics · $200K
Other concepts in this collection
- SkillproofRegression testing for the Agent Skills you actually depend on
- ProvenaryScan third-party skills and MCP servers before you let them touch your data
- LedgerkitVersioned skill packs that make a solo CPA's assistant work like a tax practice
- VendfoldLicensing, signing and auto-update infrastructure for people who sell Agent Skills
- PackroomOne shared skill library for a team where everyone runs their own agent
- TokentabPer-skill cost, routing and drift telemetry for the person who runs AI all day
- ThreadkeepA memory vault you own that every assistant you run can read
- RelayfileHand a running task from Claude Code to Codex without losing state
- MeterhouseOne budget, meter and kill switch for every agent you run
- AttestlyAudit trail and approval inbox for the agents you run at work
- SkillvaneVersion control and regression tests for the skills your agents load
- CrewlineA shared board where each teammate's agents pick up each other's work
- WardkeySecurity scanner that finds and fixes exposed keys in vibe-coded apps
- StillupUptime and error monitoring that answers in fix prompts, not stack traces
- CopystoneAutomatic backups and one-click restore for apps built without engineers
- GroundskeepMonthly maintenance for shipped vibe-coded apps, applied as reviewable patches
- TillhousePayments, sales tax and refunds as one drop-in for non-developer founders
- SpendgateMeter, cap and route the AI spend inside apps vibe coders shipped
- DryloopRehearsal mode for the automations a small business owner builds alone
- MeterlyOne metered key with spend caps for every AI step you run
- FlowmedicWatches your automations, explains failures in plain English, proposes the fix
- ScrubdeckA data-cleaning step any workflow can call, with rules the owner keeps
- OpshandTurns your written SOPs into versioned Agent Skills with tests included
- CrewtraceShared visibility when five people at one business each run their own automations
- VeraciteCitation verification and AI work records for solo attorneys who draft with Claude
- TickstoneTurns a solo CPA's AI sessions into reviewable workpapers with tickmarks and source trails
- ChartproofA verification layer for physicians who use AI on clinical notes under their own license
- CoverlensPolicy-form verification for independent insurance agents who quote with AI
- MethodkitSolo consultants package their methodology as versioned Agent Skills they own and resell
- AttestrailTamper-evident logs of every AI action, built for licensed professionals' liability files
- ScrublineLocal redaction proxy that makes your personal AI accounts safe for work data
- StipendlyTurn personal Claude Max and ChatGPT Pro seats into managed employer stipends
- SkillvetScan, pin and approve Agent Skills before they touch company data
- DaylightSelf-serve shadow AI registry and policy for companies with no security team
- LedgerlineRightsizing dashboard for everyone paying for AI out of their own pocket
- SwitchyardOne metered endpoint with routing, fallback and per-person caps for tiny teams
- HearthmeterUsage budgets and one bill for the household that shares AI plans
- SeatcaseMeasures who on your team earns a Max seat and who wastes one
- TokencairnProfiler that shows what each installed skill and MCP server really costs
- FusegateBudget caps, fallback and kill switches for automations you run yourself
- SkillbenchRegression testing for Agent Skills before every model and skill update
- CitelockVerifies every citation in AI-drafted work before a licensed professional signs it
- MiddlegateA local gateway where you set the rules for what your MCP servers can do
- DriftwatchCatches output drift in the automations small operators wired themselves
- ShipcheckPre-launch review gates non-technical builders run on their own vibe-coded apps
- TracelineA claim-level provenance trail for every number in an AI-assisted report
- DrillyardScored practice repos where you learn to drive coding agents well
- PassrateA proctored AI operation exam scored from your real agent transcripts
- PatchcraftDebugging drills that teach non-technical builders to maintain what they vibe coded
- SkillsmithA workshop for writing, testing and versioning Agent Skills that actually hold up
- TickmarkSynthetic client caseloads where CPAs drill AI-assisted work before trying it on real clients
- PostgameAn MCP server that scores your own agent sessions and drills your weakest habits
- CitegridEvery number in your published research links to a source snapshot you verified
- MnemosYour research corpus as a private MCP server every assistant can query
- MeterlineModel routing and cost accounting for one person's AI research pipeline
- SkillcaskVersion, test, and sell your expertise as licensed Agent Skills
- StackfeedA personal data pipeline that repairs itself when sources change
- ClaimboardA shared evidence ledger for small teams where everyone runs their own agent
Fictional concept generated 2026-08-26 by claude-fable-5 from the collection's brief and MarkosWeb data. Treat it as a research prompt, not a plan.