9 Sept 2026

HelmGuard lands a £5.4m seed round led by Infinity Ventures and Frontline for agents that collect risk signals directly from source systems

HelmGuard is an agentic GRC and security platform whose AI agents collect and assess risk signals directly from source systems rather than from questionnaires and static documents. Security and compliance teams in regulated industries use the platform for third-party risk management, control gap assessments and agent assurance, with citations and reasoning traces behind each conclusion.

HelmGuard, an agentic governance, risk and compliance (GRC) and security startup, has raised £5.4 million in a seed round co-led by Infinity Ventures and Frontline, with participation from FinTech Collective, Stage 2 Capital, and Entrepreneurs First.

Firms in regulated sectors such as financial services, insurance, healthcare and industrials spend billions of dollars annually compiling and reviewing documentation to assess and manage security and compliance. Legacy platforms are document- and process-oriented, focused on questionnaires, templated reports and checklist completion rather than operational decision-making, and even those now using AI cannot explain the relationship between a risk and a mitigating control, whether a vendor is safe to rely upon, or if an agent is behaving as it should. HelmGuard unifies fragmented risk, security and compliance data into a single interconnected network, drawing on unstructured data and documentation as well as direct integration with source systems. Specialised AI agents then automate workflows such as third-party risk management, agent assurance and control gap assessments, synthesising the results into a firm-wide view, with transparent citations, reasoning traces and human-in-the-loop mechanisms giving teams a defensible basis on which to report to auditors and regulators.

A Verified Risk Network extends the approach between organisations, so that instead of exchanging static documents, one company's agents answer another's assurance questions with verified, current claims. The timing reflects a market where vendors are embedding agentic capabilities into products diligenced long before AI was part of the offering, meaning vendor risk underwritten at purchase no longer describes what is actually running today. EY research found that a third of businesses rank third-party and supply chain risk as a major threat, while 41 percent of those have limited or no confidence in their compliance team's ability to manage it.

Co-founder and CEO John Daley spent eight years as an executive at Palantir. Customers span the US, Canada, United Kingdom, Hong Kong and South Africa. For one US-based insurance customer, HelmGuard assessed 1,250 counterparties in less than a week, prompting a full migration from a legacy platform that forward-deployed engineers completed in under 10 days. A global telehealth and telecommunications client has brought customer assurance first response time down from days to minutes.

The funding will support expansion in the US market, including a New York and San Francisco presence alongside the London headquarters, hiring across engineering and go-to-market, and accelerated development of an agent assurance layer that evaluates AI agent behaviour at runtime.

Most compliance platforms were built to document a process, not to reach a conclusion. Now they're using AI to produce those documents faster, which doesn't help anyone decide anything. Our agents go to the source to collect and assess risk signals directly, abstracting away the manual data collection and assessment work that burns thousands of hours annually. This funding lets us bring that capability to far more teams and extend it to governing the AI agents being deployed on other workflows.

John Daley, Co-founder & CEO

We're selling into security-aware buyers whose diligence requires a comprehensive program. While we had experience with certification-oriented tools, designing and operationalising a program that made sense for our business would have meant months of hiring and work, slowing our growth. Instead HelmGuard's platform accelerated the program build and implementation. We now have the capability of a mature security organisation and can compete at massive scale.

Danyal Akarca, Co-founder & CEO at Callosum

An AI vendor's risk profile changes with every model update and every new tool its agents can call. As a result, a certification issued months ago describes a reality that our customers cannot rely upon. Regulated buyers need to ask a current question and get a verified current answer, while vendors don't want to be bogged down re-answering stale questionnaires. The Verified Risk Network makes the unit of assurance a claim assessed directly by an agent, rather than a document, and enables agent-to-agent exchange on a continuous basis.

Jack Miller, Co-founder & CTO

Risk assurance still runs on a model built for a slower world where firms certify once a year, file the report and hope nothing changes. That model was already straining under growing regulatory complexity but it fails entirely in a world with software that reasons, plans and acts on its own. HelmGuard is one of very few teams building for what assurance has to become, rather than making the old process run faster, across well-known use cases like third-party risk management and emerging use cases such as agent assurance.

Jay Ganatra, Co-founder & Managing Partner at Infinity Ventures

Powered by
NatWestSageHarmonicNovus

Similar articles