SolidCore.ai Raises $4M to Close the Enterprise GenAI Trust Gap
SolidCore.ai closed a $4M seed round led by Runtime Ventures and Epic Ventures to help enterprises monitor GenAI risk. With 70% of legal teams citing compliance concerns, founders Eric Chiu and Hemma Prafullchandra are betting on trust infrastructure.
9 min read
On October 6, 2025, SolidCore.ai announced a $4 million seed round led by Runtime Ventures and Epic Ventures, positioning itself at the intersection of two enterprise realities that rarely share a headline: generative AI adoption is accelerating, and legal and compliance teams are not ready to trust it. The San Francisco–based startup, founded by Eric Chiu and Hemma Prafullchandra, builds risk monitoring and governance infrastructure for GenAI deployments — the unglamorous layer that determines whether a copilot pilot becomes production software or a board-level incident. In a market saturated with model vendors and agent frameworks, SolidCore is betting that the next enterprise budget line item is not another chatbot but continuous assurance that AI systems behave within policy, regulation, and brand guardrails.
The Seed Round and the Investors' Thesis
Runtime Ventures and Epic Ventures co-led the round with participation from strategic angels tied to cloud and security ecosystems. Four million dollars is modest compared with frontier model fundraises, but that is precisely the point. SolidCore is not training foundation models; it is building observability, policy enforcement, and audit trails for models others deploy. Investors described the opportunity as "trust infrastructure" — software that sits between LLM applications and enterprise risk functions the way payment fraud monitoring sits between checkout flows and finance teams.
Runtime's thesis, as articulated in the announcement, emphasizes that enterprise GenAI spending has outpaced governance tooling by a wide margin. CIOs approve pilots; CISOs and general counsel discover them afterward. SolidCore aims to shorten that discovery cycle from reactive audit to proactive monitoring. Epic Ventures highlighted founder-market fit: Chiu's background spanning enterprise security and AI productization, combined with Prafullchandra's experience in compliance-heavy cloud environments, maps cleanly onto buyer personas who control production rollouts — not just innovation labs.
For the venture audience, the round is a data point in a broader pattern. After eighteen months of "every company is an AI company" messaging, 2025 capital is flowing toward picks-and-shovels plays with identifiable buyers and renewal logic. Governance, evals, red-teaming, and runtime policy engines are crowded categories, but rounds still close when teams demonstrate integrations with the stacks enterprises already run — NVIDIA GPUs in training clusters, Google Cloud and Vertex pipelines, Microsoft Azure OpenAI deployments, and AWS Bedrock endpoints.
Founders Eric Chiu and Hemma Prafullchandra
Eric Chiu comes from the enterprise security world, where the default question is not "Can we build it?" but "What happens when it fails at 2 a.m. on a regulated workload?" That orientation shapes SolidCore's product philosophy. Rather than marketing abstract "responsible AI," the company focuses on detectable events: prompt injections that exfiltrate data, model outputs that violate retention rules, agents that call unauthorized tools, and drift in model behavior after silent vendor updates.
Hemma Prafullchandra brings deep experience in cloud compliance and cryptographic assurance — credentials that matter when customers ask whether monitoring itself meets SOC 2, HIPAA, or EU AI Act expectations. Together, the founders articulate a split mandate: engineering teams need velocity; risk teams need evidence. SolidCore's pitch is that both can be served if monitoring is embedded in CI/CD and runtime paths instead of bolted on after a quarterly review.
In interviews surrounding the raise, Chiu emphasized that most enterprises do not lack AI ambition; they lack a shared vocabulary between builders and lawyers. Prafullchandra added that compliance concerns are not irrational conservatism — they reflect real liabilities when models summarize client data incorrectly or agents execute irreversible actions. The startup's name signals intent: a solid core of policy and telemetry beneath fluid application layers.
The 70% Compliance Concern — and What It Actually Means
SolidCore cited internal and third-party survey data indicating that roughly 70 percent of legal and compliance stakeholders express material concern about GenAI deployments in their organizations. The figure aligns with parallel industry surveys from 2024 and 2025 showing general counsel ranking hallucination risk, data leakage, and unclear accountability among top blockers to enterprise AI scale.
It is important to parse what "concern" means operationally. It does not always mean "no AI allowed." Often it means AI is allowed in sandboxes while production systems remain off limits. That gray zone is expensive. Companies duplicate work — innovation teams ship demos legal teams cannot approve, while approved use cases stagnate for lack of monitoring tooling. SolidCore targets that gap with dashboards and alerts legal stakeholders can interpret without reading Python stack traces, alongside technical hooks engineers need in Kubernetes, API gateways, and agent orchestrators.
The compliance narrative also intersects with emerging regulation. The EU AI Act's staged obligations, U.S. state-level privacy laws, and sector-specific guidance in financial services and healthcare create a patchwork SolidCore customers must map to model behavior. Risk monitoring products that encode policy templates — export controls on certain prompts, PII redaction thresholds, retention limits on conversation logs — reduce the bespoke consulting burden that slows deals.
Seventy percent concern is therefore not a headline statistic alone; it is a budget justification. When seven in ten legal leaders worry, CIOs have cover to fund governance alongside inference costs.
Product: GenAI Risk Monitoring in Practice
SolidCore.ai's platform, as described in the October 6 announcement, spans three layers: discovery, runtime monitoring, and post-incident forensics.
Discovery inventories GenAI endpoints across an organization — sanctioned Azure OpenAI instances, shadow Slack bots using personal API keys, embedded copilots in SaaS tools, and internal agents calling MCP servers. You cannot govern what you cannot see; discovery is the unsexy prerequisite every CISO asks for first.
Runtime monitoring evaluates prompts, retrievals, tool calls, and outputs against customer-defined policies. Examples include blocking requests that attempt to override system instructions, flagging answers that cite outdated regulated disclosures, and detecting anomalous token volumes that suggest scraping or data exfiltration. SolidCore integrates with existing SIEM and SOAR workflows so alerts land where security operations already work.
Forensics preserves tamper-evident logs suitable for legal hold and regulatory inquiry. When a model gives harmful advice or leaks training-adjacent data, enterprises need replayable context: model version, retrieval corpus snapshot, agent graph state, and user approvals. SolidCore emphasizes export formats counsel recognizes, not only ML experiment trackers engineers prefer.
The product is partner-aware. SolidCore does not ask customers to rip out NVIDIA, Google, Microsoft, or AWS investments; it attaches to them.
Cloud and Hardware Partnerships: NVIDIA, Google, Microsoft, AWS
SolidCore's go-to-market leans heavily on ecosystem credibility. The company highlighted working relationships and technical integrations across the dominant enterprise AI stack:
NVIDIA — Enterprises training and serving models on NVIDIA infrastructure need visibility into GPU-bound inference paths and NIM microservices. SolidCore positions itself as a policy and telemetry layer compatible with NVIDIA's enterprise AI suite, helping customers who deploy open models on-premises satisfy internal risk reviews.
Google Cloud and Vertex AI — Google customers using Gemini and Vertex model garden gain monitoring for grounding sources, safety filters, and agent builder flows. SolidCore's integration story aligns with Google's emphasis on DLP and VPC service controls, extending those concepts into generative outputs rather than only inputs.
Microsoft Azure OpenAI Service and Copilot extensibility — Microsoft's enterprise footprint makes Azure the default GenAI host for many regulated buyers. SolidCore monitors API traffic and Copilot Studio agents, addressing a pain point Microsoft partners frequently cite: customers want Copilot but need auditable guardrails before enabling write actions.
AWS Bedrock and SageMaker — AWS's multi-model Bedrock strategy increases choice — and complexity. SolidCore provides unified policy across models from Anthropic, Meta, and Amazon, reducing the risk that teams adopt inconsistent safeguards per vendor.
Partnerships here are not mere logo slides. They reduce implementation friction — a decisive factor when governance vendors compete with homegrown scripts that cost nothing upfront and everything after an incident.
Market Context: Why Now, Why SolidCore
The GenAI trust gap opened in 2023 with chatbot pilots and widened in 2024–2025 as agents gained tool use. Tool-using agents can send email, modify tickets, and execute SQL — capabilities that transform hallucinations from embarrassing text into operational damage. Venture investors are funding companies like SolidCore because the agent era raises the stakes of monitoring by orders of magnitude.
Competition includes established GRC platforms adding AI modules, observability vendors extending APM to LLM traces, and startups focused narrowly on red-teaming or evals. SolidCore's differentiation claim is end-to-end coverage tuned for legal/compliance buyers, not only ML engineers. That buyer alignment matters for seed-stage ACV and expansion paths into financial services and healthcare.
The $4 million seed provides roughly eighteen to twenty-four months of runway to deepen integrations, publish reference architectures with cloud partners, and land design partners who convert to paid logos. Follow-on investors will look for evidence that SolidCore compresses sales cycles for Azure and Bedrock customers who otherwise stall in legal review.
Implications for Enterprise Buyers and the Venture Ecosystem
For enterprises, SolidCore's raise validates a procurement pattern: budget for governance concurrently with inference, not sequentially after a scare. Teams should ask vendors for runtime policy hooks, not only static eval reports. Legal stakeholders should participate in pilot definitions when monitoring dashboards exist, not after user adoption makes shutdown politically costly.
For founders in adjacent spaces, SolidCore illustrates a repeatable playbook — identify a fear tax (compliance delay), build infrastructure incumbents lack, integrate with platforms customers already approved, and sell evidence risk teams can defend to boards. For LPs and seed investors, the round is a reminder that not every AI exit requires training a trillion-parameter model. Trust, logging, and policy enforcement may produce slower headlines but durable revenue in regulated segments.
SolidCore.ai's October 6 announcement will not trend on consumer tech Twitter. It should still register with CIOs, CISOs, and general counsel because it names the bottleneck honestly: enterprises want GenAI productivity without betting their license to operate. Closing that gap is a business — and $4 million is the opening check on a market where seventy percent of legal leaders already said they need help saying yes.
More in business
Venture
Write for entrepreneurs, founders, and builders.
Share startup lessons, growth tactics, and founder stories with readers on the same journey.
One free account across In Plain English, Stackademic, Venture, and Cubed.
How it works- Startups & entrepreneurship
- Marketing & growth
- Productivity & leadership
- Founder stories & lessons learned
Sign in
Google or GitHub
Complete profile
Takes a few minutes
Get approved & publish
Start sharing
Why write for Venture?
Entrepreneurship is rarely a straight path. The lessons worth sharing are learned while building.
Comments
Loading comments…