The breaches that hurt now rarely look like attacks. They look like a valid login, a connected vendor or an AI agent doing exactly what its token allows. Hilt is a seed-stage bet on that problem.
The round. Hilt came out of stealth with a $4.2M seed led by Array Ventures, with Verdict Capital, Base10 Partners, Brickyard, Liquid 2 Ventures, Sequel, the Sarah Smith Fund and Alumni Ventures (per Crunchbase News). Total funding is $4.7M, including a $500,000 pre-seed led by Pear VC in October 2025. The company has 11 employees and moved from San Francisco to Chattanooga with Brickyard. Valuation: Undisclosed.
What it does. Hilt sits at the kernel and streams activity data to graph neural networks that baseline how users and resources move data across cloud, endpoints and networks. It flags unusual activity even when the user has permission, and in some cases quarantines it as it happens. Customers run it inside their own infrastructure and pay an annual fee per data collector (per Crunchbase News).
Our POV. This is the right axis. Classic DLP starts with content: classify the file, tag it, write a pattern, hope the label survives the copy. Array’s Shruti Gandhi put the failure bluntly. Most tools either “predict what’s sensitive upfront and get it wrong a lot,” or tell you what happened after the data is gone. Content-first controls break hardest when the actor is legitimate. An agent with a valid OAuth grant doesn’t trip a policy built around who may open a file. It trips one built around how data normally moves.
Behavior below the app layer also ages better. Apps change every quarter. Syscalls don’t.
The wedge is smart. Hilt’s first customer was a large hedge fund running high-frequency trading, where systems trade in microseconds and security that adds latency gets ripped out. CEO Will Cielen says the fund offered a potential $1M to $2M contract and paid a six-figure sum upfront before the product existed. A second HFT firm followed. That’s the founder’s account, not a disclosed contract. But if you can sit in the kernel of a trading stack without slowing it down, neobanks and healthcare look easier.
Where we’re skeptical. Kernel access is the most dangerous place in your fleet to put new code. In July 2024, a faulty CrowdStrike content update crashed Windows hosts worldwide, and Microsoft estimated 8.5 million devices were affected. Every CISO who lived through that will ask the same questions before a seed-stage kernel sensor touches production. Hilt hasn’t published which kernels it supports, whether it uses eBPF or a driver, or how it fails. Cielen says one customer measured faster cloud systems after deployment. Treat that as an anecdote until there’s a benchmark.
Then there’s the quarantine. Auto-blocking “unusual” data movement in a trading firm is a business decision, not a detection setting. A false positive that freezes a legitimate batch job costs real money.
What we’d ask in the pilot. Which operating systems and kernel versions, and is it eBPF or a kernel module? Fail-open or fail-closed when the sensor crashes? What’s the false-positive rate on our estate after 30 days, not in the demo? How does it tell a human from an agent running under the same account? Who approves a quarantine, and how fast can we release one?
For investors. $4.2M buys a design-partner phase, not a category. Customer count is Undisclosed, though Cielen says it doubled in the month after a bigger go-to-market push. The tell will be whether that hedge fund contract converts at the size he described, and whether a second sector signs. If it does, Hilt stops being a DLP startup and starts competing for insider-risk and agent-monitoring budget at the same time. That’s a bigger market, and a crowded one.
