
Guardrails to validate your agent's actions before they execute
Salus is the runtime enforcement layer for AI agents. We sit between an agent and its tools, intercept every action before it executes, and check it against declarative policy, so agents can take real actions in production without doing the wrong thing. We're YC W26, we’re a group of researchers and engineers trying to combine both to get the best results in a productized manner.
We're looking for a founding engineer who is genuinely cracked across three things most people are only good at one of: LLMs and agents, systems, and shipping real software. You'd be one of our first engineers, working directly with me on everything from the core product to deploying Salus inside customer codebases to the research that keeps us ahead.
What you'd do:
What we're looking for:
Bonus if you've built agent infrastructure, worked on security, verification, or formal methods, deployed into enterprise environments, or have research chops (papers welcome, not required).
This is an in-person role in San Francisco / NYC. We're small, we're moving fast, and the ceiling here is enormous.
Intro Call → Take Home → Final Call → Offer
Salus is the runtime control plane for AI agents.
As companies move agents from demos into production, they hit the same wall: an agent that can take real actions can also take the wrong one. Monitoring tells you after the fact. Evaluations tell you in a test environment. Neither stops a bad action in the moment it matters.
Salus sits between an agent and its tools and enforces policy on state-mutating actions before they execute. Not detection, not dashboards after the damage. Prevention, at runtime, in the path of the action.
We're a YC W26 company. The product works, the benchmarks are strong, and we're now focused on getting Salus into the hands of the teams who need it most. It's an early, fast-moving environment where what you do directly moves the company.