New startup ideas · B2B, security and compliance · Security and compliance
startup idea
Skirmish
The exchange where autonomous hacking agents compete to break enterprise systems.
Enterprises post scoped targets and bounties; independent builders of offensive AI agents connect their agents to compete on them inside Skirmish's isolated ranges.
- Marketplace
- Enterprise
- $10-100B market
- Platform others build on
- US first
3/5
venture judge
38
similar startups, last 2 years (100 all-time)
98%
of 4 nearest real companies still alive
yes
8 matching federal grants and programs
Direction supported by government programs and grants
Scorecard
One score that balances how trendy the idea is, the demand for it and its potential for 100x, with competition measured relative to every other idea in the catalog. Recent startup trends first, government priorities second.
58
Idea Score, 0-100 · raw 35.5 x 1.64
Crowded
competition: more crowded than 96% of ideas · headwind x0.52
+2.3
government priorities, secondary (8 matching grants)
Trend
77
Is the wave forming now? 2025-26 entrants vs 2023-24, rounds since 2025, the sector's live-batch direction, the 2026 trend analyst.
- Entrants 2025-26 vs 2023-24 (similar companies)83
- Rounds announced 2025+ in the sector25
- Rounds announced 2025+ matching the idea100
- Sector direction (live batch)100
- 2026 trend analyst75
Demand
62
Does anyone want it? YC's current RFS, companies already paid for something similar, the operator judge, founders' yes-rate in decks, readers who would run the test.
- YC asks for it (current RFS: idea / sector)60
- Someone already pays (similar companies, recent / all-time)100
- Operator judge: real pain25
100x potential
55
Can it return a fund? The venture judge (double weight), market-size and moat axes, neighbours still alive, the technologist judge.
- Venture judge50
- Market size axis67
- Moat axis20
- Neighbours still alive67
- Technologist judge75
Score = 100 x cbrt(Trend x Demand x 100x) x (1 - 0.5 x crowding) + government bonus (max 5), calibrated so the 95th-percentile idea scores 90 (order never changes). A geometric mean: a weak pillar cannot be papered over. Percentiles are among the 272 ideas in the catalog; the terms matched were exchange, autonomous, hacking, compete, break, enterprise, enterprises, post.
The idea in full
- What
- Enterprises post scoped targets and bounties; independent builders of offensive AI agents connect their agents to compete on them inside Skirmish's isolated ranges. The hard technology is the verification layer: ML-driven exploit reproduction, deduplication, and exploitability scoring that turns a flood of agent findings into a ranked, paid-per-proven-bug feed. MSSPs and cyber insurers resell access, and agent builders treat Skirmish as their distribution channel rather than building enterprise sales teams.
- Why now
- Six agentic offensive security companies appear in the last few accelerator batches alone - Trident, Parameter, Antigen, Veria Labs, Fabraix, and Lupin & Holmes - so agent supply now exists without any neutral demand-side clearinghouse, while Cytix's $7M Series A (2026-08-12) targets the cyber risk created by AI-driven software development, the exact expansion of attack surface these agents feed on.
- Wedge: first customer and entry point
- Recruit five agent-builder teams and run paid continuous-pentest programs for a handful of US mid-market SaaS companies through one MSSP partner, proving the payout-per-verified-exploit loop before opening the exchange.
- Path to 100x
- Penetration testing and offensive security services are a $10-100B market shifting from human hours to agent findings, and marketplaces in such shifts concentrate: both sides go where liquidity and trusted verification already are. The company that sets the standard for what counts as a proven exploit and pays out on it takes a rake on the whole category - liquidity is the compounding asset, though today the moat is still to be built.
- Ceiling
- If ML verification cannot cheaply separate real exploits from agent noise, Skirmish decays into a human triage shop with services margins.
- Closest real companies, as the generator saw them
- Trident, Parameter, Antigen, and Veria Labs each sell their own agent end-to-end; Skirmish is the neutral marketplace and verification layer all of them can sell through, competing on findings rather than sales teams.
- Main risk
- The best agent vendors go direct to enterprises and starve the exchange of differentiated supply.
Five judges
Each judge scores every idea in the catalog with a named rubric; the venture judge decides whether a card is shown at all (4-5 is venture-grade).
Venture investor
3/5
Neutral verification layer could take a rake on a $10-100B shift, but the best agent vendors going direct starves supply.
Bootstrapper
2/5
An exchange needing five agent builders plus enterprise targets plus ML exploit verification before liquidity is a three sided cold start in a hyped space.
Operator
2/5
Enterprises already buy pentests, but the exchange needs six agent vendors plus MSSPs to route through it before any buyer sees value.
Technologist
4/5
ML exploit reproduction, dedup and exploitability scoring is the hard part, and the verified-exploit corpus sharpens with every agent submission.
Risk
2/5
Offensive agents against live enterprise targets carry real liability, and the best agent builders going direct starves the exchange.
trends
4/5
Six offensive-agent vendors in the latest batches create supply that did not exist in 2023, and the brief's offensive security term confirms the wave.
Similar startups in the directory
Companies whose pitch matches most of the idea's terms (exchange, autonomous, hacking, compete, break, enterprise, enterprises, post): 100 all-time, 38 from the last two years. Same matching as Idea Check.
Liability insurance for AI Agents. You deploy agents, we cover you.
Autonomous security testing for web apps, APIs, cloud, and AI systems
On-device AI that knows your entire life and does your work overnight.
On-device knowledge graph engine for enterprises
An AI-Native Media Platform
Automated production-readiness platform for the AI coding era
AI B2B travel agent, capable of autonomous travel booking.
Nextdata provides an OS for managing autonomous data products for AI and analytics.
Cofactory turns websites into autonomous AI sales agents that generate personalized landing pages and ads, continuously optimizing conversions based on real-time buyer intent.
Maven AGI enhances customer support with AI-driven automation and integration.
Veris is a sandbox platform that lets enterprises train and validate autonomous agents in realistic, high-fidelity simulations before deployment.
The AI Agent Insurance Carrier
The generator's reference companies
Real companies the model named as closest when it wrote the card, with their fate. A check mark is a company the radar could verify in its directory.
Public money in this direction
US federal grants, SBIR/STTR awards and open opportunities from the radar's public-money feed, matched to the idea's terms; the sector totals give the context.
8
grants and programs matching the idea
73
startup-relevant grants in Security and compliance
$18M
awarded in the sector, tracked
23
opportunities open now in the sector
- I-Corps: Translation Potential of Cross-Platform Wearable Interface for Spatial and Ambient Computingawardhigh relevance
National Science Foundation · I-Corps · $50K · posted 2026-08-17
- I-Corps: Translation Potential of Quantum-Artificial Intelligence (AI) in Energy and Infrastructure Security and Resilienceawardhigh relevance
National Science Foundation · TIP-CHIPS KTA-3 Quantum · $50K · posted 2026-08-17
- NSF Safe-OSE: Center for Security-Assuring AI Agent Communication and Interoperability Standard and the Open-Source Ecosystemawardmedium relevance
National Science Foundation · SafeOSE · $2M · posted 2026-08-18
- Collaborative Research: SmartSOM: Self-Organizing Manufacturing with Task Constraints and Social-Organizational Learningawardmedium relevance
National Science Foundation · MSI-Manufacturing Systms Integ · $250K · posted 2026-07-29
- Collaborative Research: SmartSOM: Self-Organizing Manufacturing with Task Constraints and Social-Organizational Learningawardmedium relevance
National Science Foundation · MSI-Manufacturing Systms Integ · $248K · posted 2026-07-29
- Collaborative Research: Generative AI for Autonomous Composition of Resilient and Explainable Service-Oriented Supply Chainsawardmedium relevance
National Science Foundation · MSI-Manufacturing Systms Integ · $250K · posted 2026-07-29
- Collaborative Research: Generative AI for Autonomous Composition of Resilient and Explainable Service-Oriented Supply Chainsawardmedium relevance
National Science Foundation · MSI-Manufacturing Systms Integ · $250K · posted 2026-07-29
- NSF PCL-Test Bed: SPEED: Programmable Cloud Laboratories for Autonomous Chemistry and Materials Discoveryawardmedium relevance
National Science Foundation · PCL-Programmable Cloud Labs · $20M · posted 2026-07-21
Market signal
What the radar sees in Security and compliance: new companies by cohort year, the forming YC batch, and outcomes since the February snapshot.
Security and compliance · 42 → 45 → 83 → 75 → 32 new companies 2022 → 2026 · 94% aliveYC S26: 7 in this cluster, 3% of the batch (was 3% in X26) (F26 is still forming: 21 listed)Since February, of 171 YC companies here: 0 acquired, 2 shut down, 24 rewrote their pitch
Design attributes
The card is one cell of a designed set: every axis below was chosen before the text was written, and the text had to realize it.
- Buyer
- Enterprise
- Business model
- Marketplace
- Path to 100x
- Platform others build on
- Market size
- $10-100B market
- Capital intensity
- Capital-light (software margins)
- Speed to revenue
- Revenue in 1-3 years
- Technical depth
- Deep tech: ML, hardware, bio
- Go-to-market
- Partners and channels
- Moat
- No moat yet
- Geography
- US first
- Regulation
- Unregulated
- Vibe
- Hot space
Listed under
An idea sits in its own sector and in any sector its text clearly touches.
More ideas like this
B2B, security and compliance · Security and compliance
Claimyard
Marketplace turning scam, fraud and privacy losses into funded, aggregated consumer claims.
A consumer uploads what happened, screenshots of a romance scam, an unauthorized P2P transfer, a data misuse notice, and a no-code intake agent classifies the claim, pulls the paper trail from the bank or platform, and posts it to a marketplace of licensed attorneys, arbitration filers and litigation funders who bid to take it on contingency.
B2B, security and compliance · Security and compliance
Sentinet
Shared-defense agent for small firms: one member's confirmed fraud warns the whole network.
Sentinet connects in an afternoon to an SMB's mailbox, accounting system and bank feed, and runs an agent that screens invoices, vendor bank-detail changes and unusual logins.
B2B, security and compliance · Security and compliance
Vouchline
One AI agent answers your security questionnaires and reviews the ones you send.
Vouchline is an agent that sits on both sides of the vendor security review: for a small supplier it reads the buyer's questionnaire, pulls evidence from Drive, ticketing and cloud consoles, and returns a completed response in a day; for the buyer it reads incoming responses and flags the answers that contradict prior filings.
B2B, security and compliance · Security and compliance
Attestral
Agents that prove and verify vendor security continuously, replacing the questionnaire.
Attestral deploys agents inside an enterprise's stack that collect live control evidence and answer any customer's security review automatically; on the buying side, its agents interrogate a vendor's agents and check every claim against machine-readable evidence rather than prose.
B2B, security and compliance · Security and compliance
Codewarden
Continuous security for the AI-written software small businesses now run on.
Codewarden is a self-serve subscription platform that continuously scans, exploits and patches the AI-generated applications small businesses now build and deploy without security staff.
B2B, security and compliance · Security and compliance
Ironvane
Autonomous security operations agents that managed service providers resell and extend.
Ironvane gives managed service providers a runtime where security agents triage alerts, patch endpoints, revoke credentials and close tickets across their whole book of small business clients, with the provider approving actions rather than performing them.
Fictional company written 2026-08-26 from MarkosWeb data; the companies, grants and numbers around it are real and tracked. Treat the idea as a research prompt, not a plan.