EN
Back to the archive

The archive · Developer & Business Tools · Product decision · 2025–2026

Multifactor bets agents get scoped access, not passwords — $15M seed, YC F25

Ex-CIA and ex-NASA founders turn any online account into a revocable read-only link for humans and AI agents; $15M seed led by Nexus, YC F25.

Multifactor

The betThat handing passwords to AI agents is broken: Multifactor turns every account into a scoped, revocable permission link — access without shared secrets.Live

What the business is

Multifactor is an account manager that turns any online account into a shareable 'Checkpoint' link with granular permissions — read-only, feature-scoped or dollar-capped — for humans and AI agents, with one-click revocation and a cryptographically signed event history.

Starting capital$15M seed led by Nexus Venture Partners (December 2025)

How it started

Vivek Nair and Colin Roberts had spent over a decade in national-security cryptography. They watched AI agents begin booking travel, moving money and reading inboxes, and concluded the password model — share the secret, and the recipient can do anything forever — could not survive agents that act in parallel at machine speed and can be hijacked by prompt injection. They founded Multifactor in 2025 in San Francisco and joined Y Combinator's Fall 2025 batch.

What happened

The product, Checkpoint, launched 2025-11-12: any online account becomes a shareable link with read-only, feature or dollar limits, one-click revocation and signed audit logs. The launch stunt put the company's own corporate bank account — about $1M in operating funds — behind a public read-only link advertised on a Times Square billboard. In December 2025 Multifactor announced a $15M seed led by Nexus Venture Partners, with Y Combinator, Taurus Ventures, Pioneer Fund, Flex Capital and Liquid2 Ventures among the participants, plus angels including Gokul Rajaram and Mathilde Collin. The company holds 8 patents and pitches post-quantum, provably safe execution for agents, with early enterprise partners evaluating it in supply chains exceeding $7.5B in throughput.

How it ended up

Still live and scaling: the free consumer product is out, an enterprise tier adds compliance auditing and SSO, developer API access is planned, and the team is pitching 'Multi', an AI assistant that acts inside accounts through the same permissioned, audited channel.

Background

Multifactor is a San Francisco security startup founded in 2025 by Vivek Nair, an ex-CIA cyber officer and PhD computer scientist, and Colin Roberts, an ex-NASA applied cryptographer. Its bet: the password model breaks the moment AI agents start acting on accounts. Giving an agent a password hands over everything the account allows, forever, with no audit trail and no way to take it back; Multifactor instead turns any online account into a shareable link with scoped, revocable permissions.

The product, Checkpoint, launched on 2025-11-12 with a stunt designed to prove the claim: the company put its own corporate bank account — about $1M in operating funds — behind a public read-only link and advertised it on a Times Square billboard. Anyone could log in and view the balance and transactions; nobody could touch them. The launch was backed by 8 patents and a 'zero-trust' pitch for agents: authentication, authorization and auditing with signed event history, aimed at prompt injection, cross-agent hijacking and confused-deputy attacks.

Multifactor completed YC's Fall 2025 batch (demo day December 2025), where UIUC's engineering college called it an early success story and reported a Forbes feature on the batch. In December 2025 the company raised a $15M seed led by Nexus Venture Partners, with Y Combinator and others participating, plus angels including Gokul Rajaram and Mathilde Collin. As of July 2026 the free consumer product is live, an enterprise tier and developer API are planned, and the team is building 'Multi', an AI assistant that works inside accounts without ever holding the credentials.

What has to be true

  • Agents change the threat model: a human hesitates, an agent acts in parallel at machine speed, and a password grants it standing permission with no scope and no log.
  • The reframe — share permission, not the secret — positions Multifactor against password managers and identity tools that only store the secret more carefully.
  • The Times Square bank-account demo turned an abstract security claim into a concrete, checkable proof, which is why the launch and the company got covered.
  • A $15M seed for a roughly five-person team priced a market that barely exists yet: delegated access for agents, which investors bet will arrive as agents become routine.

What can be applied

Sell the reframe: 'share permission, not the secret' became a demo anyone understood when Multifactor put its own bank account behind a public read-only link — proof is the pitch.

Aftermath

As of 2026-07-29, Multifactor is live: Checkpoint is free for individuals, an enterprise tier adds compliance auditing and SSO, and developer API access is planned. The roughly five-person team is backed by a $15M seed led by Nexus Venture Partners with Y Combinator and other investors, and is building 'Multi', an AI assistant that acts inside accounts through the same permissioned, audited channel, plus post-quantum protection against prompt injection and agent hijacking. The bet remains unproven: it depends on agents becoming routine enough that all-or-nothing passwords look broken.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases