Back to Articles
StartupsNews

HelmGuard Raises $7.3M Arguing Vanta Never Actually Solved Compliance, Just Made the Paperwork Prettier

Editorial Team

5 min read
HelmGuard founder John Daley (CEO) and Jack Miller (CTO)

HelmGuard founder John Daley (CEO) and Jack Miller (CTO)

Image credit: HelmGuard

HelmGuard, a London based governance, risk, and compliance startup, has raised 7.3 million dollars in seed funding to build AI agents that continuously assess organizational risk directly from source systems, aiming to replace the periodic questionnaires and document reviews that still underpin most corporate compliance work.

The round was co‑led by Infinity Ventures and Frontline, with additional participation from FinTech Collective, Stage 2 Capital, and Entrepreneurs First. HelmGuard was founded in 2024 by chief executive John Daley, a former Palantir executive, and chief technology officer Jack Miller. The founders met through an Entrepreneur First program organized by Matt Clifford, who later became HelmGuard's first investor.

The company's central critique targets an entire category of existing compliance software, built around annual certification cycles that Daley and Miller argue never actually solved the underlying problem. Infinity Ventures' Jay Ganatra summarized that critique directly: "Risk assurance still operates on a model that was created for a slower world in which firms certify once a year, submit the report and then hope that nothing happens. HelmGuard is one of an extremely small number of teams working on what assurance has to evolve into." In conversations with Tech Funding News, HelmGuard's founders specifically questioned whether Vanta, the widely used compliance automation company valued at 4.15 billion dollars and previously backed by Frontline, had genuinely solved compliance or simply made the existing paperwork‑driven process faster and better organized without changing its fundamentally periodic, backward‑looking nature.

HelmGuard's platform instead connects directly to live source systems, unstructured documents, and internal data, using AI agents to continuously collect and evaluate risk signals in something closer to real time rather than waiting for a scheduled audit cycle. According to the company, this approach cuts assessment cycles from what would traditionally take weeks down to hours, by unifying fragmented compliance, security, and risk data that would otherwise sit scattered across disconnected internal systems and documentation. GRCReport noted the specific problem HelmGuard is built around: an assessment can be thorough and still describe a version of an organization that no longer exists by the time it's finished, since manually compiled compliance reports are frequently outdated the moment they're completed given how quickly a large organization's actual risk exposure can shift.

Beyond assessing an organization's own compliance posture, HelmGuard is also building what it calls an agent assurance layer, aimed at a problem that sits beyond conventional third‑party risk management entirely: how organizations govern the autonomous AI agents they are increasingly deploying themselves. A written policy can establish what an AI agent is permitted to do, but HelmGuard's premise is that governing an autonomous system also requires continuously observing what it actually does in practice, since policy compliance on paper says nothing about real runtime behavior. The system is designed to let an organization define a specific claim about an agent's behavior, for instance that no production agent should simultaneously have access to sensitive data and external network exposure, and then continuously test whether the available evidence actually supports that claim holding true in practice, rather than simply trusting that the agent's original configuration guarantees it.

HelmGuard has grown quickly since its founding, expanding from three to ten employees within just the past two months, according to Tech Funding News, and the company intends to pursue a Series A round within the next 12 to 18 months. With the new seed capital, Daley said the funding will support three main priorities: expanding the company's presence in the United States, including establishing operations in New York and San Francisco, hiring across engineering and go‑to‑market roles, and continuing development of the agent assurance layer.

The market HelmGuard is targeting is substantial and growing quickly. The enterprise GRC software market was valued at 72.4 billion dollars in 2025 and is projected to reach 203.7 billion dollars by 2033, growing at a compound annual rate of roughly 13.7 percent, driven in large part by the same forces HelmGuard is betting on: regulatory complexity that continues to outpace the compliance headcount most organizations are willing or able to add, and now the entirely new governance challenge posed by autonomous AI agents operating inside enterprise environments with real, consequential access to systems and data.

HelmGuard's positioning against Vanta and similar established compliance automation vendors rests on a bet that continuous, evidence‑based assurance represents a genuinely different category from periodic certification, rather than simply a faster version of the same underlying process. Whether large, risk‑averse enterprises in finance, insurance, healthcare, and industrials are ready to trust a fundamentally different, always‑on model of compliance assurance, rather than the scheduled, human‑signed‑off audits their internal legal and risk functions have relied on for decades, will likely determine how quickly HelmGuard can convert its early team growth and fresh capital into the kind of enterprise contracts that would justify a Series A within its stated 12‑to‑18‑month timeline.

Topics

Stay informed

Startup news in your inbox

Get important funding rounds, founder stories, and startup updates.

No spam - only important startup updates.