Idea Lab
Pick a vertical. The radar reads everything it tracks there - momentum by year, crowded subniches, dead companies, fresh rounds, grant money, open YC RFS themes - and proposes concrete startups someone should build. The companies below are fictional; the data behind them is not.
Security and compliance
64
companies, last 2 years
490
tracked all-time
91%
of checked sites alive
$127M
across 3 recent rounds
concept 1
Latheguard
Cyber certification and evidence packets for small manufacturers, delivered through SBA-funded programs.
Latheguard is an assessment and remediation agent for machine shops and small manufacturers that maps their IT and shop-floor OT assets, scores them against a named cyber certification baseline, and generates the auditor-ready evidence packet plus a fixed-price remediation plan. It ships as a co-branded tool for the SBDCs, MEP centers and MSPs that actually reach these firms, not as a self-serve SaaS the owner has to configure.
- why now
- Two SBA grant streams are open at once — the MANUFACTURING AND SMALL BUSINESS CYBERSECURITY RESILIENCE PROGRAM 2026 (closes 2026-09-04) and CYBER CERTIFICATION PROGRAM 2026-01 (closes 2026-09-01) — which funds intermediaries to push certification onto SMBs; Inforcer's $50M round in July 2026 was raised explicitly to help smaller businesses prepare for AI and security risks, confirming the buyer exists but is reached indirectly.
- wedge
- One regional MEP center or manufacturing-focused MSP with 30-80 machine shop clients: run the assessment for their first cohort under grant funding, get paid per completed certification packet.
- closest real companies
- Strongkeep (SMB cybersecurity, sold direct and generic), Probo and ComplyBridge (compliance workflows for regulated/tech firms, not OT-heavy manufacturers), Inforcer (MSP tooling, not certification evidence). Latheguard differs by being grant-channel-native and scoped to one certification outcome rather than continuous posture management.
- main risk
- Grant-funded channels move on federal timelines, so a slipped award cycle can stall revenue for a year with no direct-sales fallback.
concept 2
Provewire
Verified-human sessions for wire instructions and closing calls at title and escrow agencies.
Provewire issues a device-bound, notary-grade human credential to each party in a real estate closing, then binds it to the live video or phone session where wire instructions are confirmed, producing a signed transcript that a lender or title agent can verify later. Buyers are small title agencies, escrow firms and closing attorneys who eat the loss on wire fraud.
- why now
- YC's Fall 2026 RFS names 'Proving You're Human' as a theme, while pure detection approaches have already failed once — Aedilic (open-source deepfake detection) died in 2024 and Alterya (protecting humans from scams) in 2022; the surviving 2026 cohort (Raid AI, BeeSafe AI) is still on the detection side of the problem rather than issuing verifiable attestations.
- wedge
- Ten independent title agencies in one state: replace their emailed 'call us to confirm wire instructions' step with a Provewire session, priced per closing.
- closest real companies
- Didit (identity and fraud infrastructure, developer-generic), Raid AI (real-time deepfake detection), BeeSafe AI (social engineering defense), Keyri (dead 2021, developer authentication). Provewire sells a per-transaction liability artifact to a specific escrow workflow instead of a detection API.
- main risk
- Title agents may treat wire fraud as an insurable cost and refuse to add friction to a closing they are already fighting to schedule.
concept 3
Beatline
Body-worn camera policy auditing and public-records redaction for small police departments.
Beatline ingests body-worn camera footage and CAD records for departments under 200 officers, flags policy violations (late activation, early termination, missing metadata), and auto-redacts faces, minors and PII for public-records releases with a chain-of-custody log a prosecutor can defend. It is sold to city and county agencies as the compliance half of a BWC deployment, which grant-funded departments are required to document but rarely staff.
- why now
- BJA FY26 Body-Worn Camera Policy and Implementation Program closes 2026-09-25 and funds exactly the policy-and-implementation side of BWC programs; in the same cluster the 2026 cohorts fund camera and law-enforcement AI (Lexius, Protent) but nothing pointed at records-release redaction, and LogosGuard's redaction work is aimed at AI data pipelines, not evidence.
- wedge
- One mid-size sheriff's office with a public-records backlog: charge per redacted release hour, then attach to their next BJA application as the named compliance vendor.
- closest real companies
- Lexius (AI for corporate security cameras, private-sector buyer), Protent (real-time intelligence for law enforcement, live operations rather than after-action audit), LogosGuard (redaction layer for AI). Beatline's differentiator is defensible chain-of-custody output for records law, not analytics.
- main risk
- Municipal procurement cycles plus incumbent camera vendors bundling redaction for free can push the deal price to zero.
concept 4
Tickmark
Audit tooling for CPA firms whose sampling breaks when the controls are run by agents.
Tickmark is a workpaper platform for mid-size assurance firms performing SOC 2, ISO and financial IT audits at companies where approvals, provisioning and reconciliations are executed by AI agents. It ingests agent action logs, reconstructs a population that can actually be sampled, and produces testing evidence plus exception narratives in the firm's existing workpaper format.
- why now
- YC's Fall 2026 RFS lists 'AI-Native Compliance Infrastructure', and the last four cohorts funded five sell-to-the-audited-company plays (Probo, ComplyDo, Regbase, ComplyBridge, Sparkle AI) while nobody in 490 tracked companies is selling to the assessor side that has to accept the evidence.
- wedge
- Two 40-person assurance firms that audit AI-heavy SaaS clients: start with one control family (access provisioning) where agent-executed approvals already fail traditional sampling.
- closest real companies
- Probo, ComplyDo, Regbase, ComplyBridge and Sparkle AI all sell compliance workflow to the company being audited; Inth sells privacy governance to fast-shipping teams. Tickmark's buyer is the auditor, which makes it a distribution channel into every client rather than a per-company sale.
- main risk
- Audit firms are slow, partner-consensus buyers and may keep doing this in Excel until a standards body forces a change.
concept 5
Counterline
Prosecution-grade evidence packages for counterfeit goods cases, built from marketplace listings.
Counterline monitors marketplace and social listings for a brand's products, captures listings with hashed, timestamped chain-of-custody, links sellers into networks via payment handles, warehouse addresses and image reuse, and exports a filing-ready package for state prosecutors and IP task forces. Brands pay for monitoring; task forces get the case package free so brands' complaints actually get charged.
- why now
- BJA FY 2026 Intellectual Property Enforcement Program (closes 2026-09-23) funds state and local prosecution of counterfeit goods, and the only IP-adjacent company in the recent cohorts is Patent Watch (yc F25) working on patent infringement detection — trademark and counterfeit enforcement evidence is untracked in this cluster.
- wedge
- One consumer-brand anti-counterfeiting manager plus the single state IP task force that already receives their referrals; get one case charged and use it as the reference for both sides.
- closest real companies
- Patent Watch (patent infringement detection, not trademark/counterfeit chain of custody), Protent (law enforcement real-time intelligence, not case-file construction). Counterline differs by producing admissible evidence artifacts rather than takedown notices.
- main risk
- Brands may keep buying takedown volume rather than prosecutions, leaving the government side with enthusiasm and no budget.
concept 6
Sluice
A recorded egress broker that answers what your coding agents touched during an incident.
Sluice is a proxy and credential broker that every AI coding or ops agent must route through: it mints short-lived scoped credentials per task, records each outbound call, package fetch and repo write, and lets responders replay a full agent session against the change it produced. Buyers are platform and security engineering teams at companies where agents already open a meaningful share of pull requests.
- why now
- Cytix raised a $7M Series A on 2026-08-12 specifically for cyber risk from AI-driven software development, and Censys raised $70M in March 2026 to expand asset intelligence — both point at exposure, not attribution; JumpWire's dynamic data access controls died in 2022 because human developers routed around them, whereas agents run through a fixed runtime that can be forced through a broker.
- wedge
- One platform team with 50+ engineers running Claude/Codex-style agents in CI: install as the required proxy for agent service accounts only, priced per agent seat.
- closest real companies
- Cytix (risk assessment for AI-driven development), BitPatrol (AI-powered code security), Golf (agentic AI security and governance, policy layer), Traceforce (securing AI-native apps on devices), JumpWire (dead 2022). Sluice is forensic and credential-scoped rather than a scanner or policy dashboard.
- main risk
- Cloud and model vendors are likely to ship agent audit logs natively, turning a recorded egress broker into a feature of someone else's platform.
Fictional concepts generated 2026-08-17 by claude-opus-5 from MarkosWeb data (accelerator portfolios, funding news, US federal grants, YC RFS). Numbers reflect tracked sources only; treat every concept as a research prompt, not a plan.