YC Spring 2026 (P26) company

Silmaril

Runtime security for AI that self-improves

b2bindustrial5 public signals

About Silmaril

Silmaril is the first runtime security for AI that self-improves. It understands application context to block 2x as many threats as current SOTA defenses with 10x lower latency. Customers plug us into agentic frameworks like LangGraph with 5 lines of code. Silmaril has stopped $28M of damages for customers.

Public traction evidence

Each signal links to the public source used for attribution.

  1. X

    Garry Tan post about Silmaril prompt injection defense

    Simaril (YC Spring 2026) is SOTA prompt injection defense for LLMs. This is the missing link for OpenClaw for Enterprise and all agents working on mission-critical data and workflows. The cofounders were the team that stopped billions of dollars worth of damages at...

  2. X

    Garry Tan reply about using Silmaril

    @ben_mathes Defense in depth: I use Silmaril for shell-level prompt injection and infiltration blocking. I use Clawvisor for credential-level and network-level blocking and detection. I use prompt injection detection inside my app layer and skills and code inside...

  3. LinkedIn

    Grey Baker post about Silmaril

    Silmaril are working on prompt injection defence the right way - with an adversarial network specialised to your agent. They're already working with some big names. Security friends - if you have customer facing agents you should talk to them

  4. LinkedIn

    Prompt injection is now Promptware.

    Prompt injection is now Promptware. Self-replicating, agent-chaining, and undetected by the guardrails you're running today. The AI security arms race is here, and Silmaril is here to give defenders a permanent edge. In 2 months, we stopped $28M in damages for our customers....

  5. X

    @bcherny, I guess you didn’t look hard enough.

    @bcherny, I guess you didn’t look hard enough. In 11 minutes, Codex with Silmaril Ruby found an indirect prompt injection that bypassed Fable and installed an untrusted package on the host. The race is never over. Full trace: https://t.co/GA116tnzVq