Table of Contents
OneCLI Investment Report
Category: B2B AI Agent Security / Infrastructure
Company Stage: Seed-stage / Y Combinator Summer 2026
Founder or Founders: Jonathan Fishner and Guy Ben-Aharon
Headquarters: San Francisco, California, United States
Funding: Y Combinator-backed; total funding and round terms are not publicly disclosed
Business Model: Open-core SaaS with paid team, scale, and enterprise plans
Product Hunt Launch Date: August 21, 2026
Report Date: August 26, 2026
| Investment Metric | Assessment |
|---|---|
| Venture Potential | 75/100 |
| Unicorn Path | Plausible |
| Valuation Attractiveness | Not Assessable |
| Evidence Confidence | 68/100 |
| Final Decision | DD |
Executive Summary
OneCLI is an open-source agent harness and security control plane for companies deploying autonomous AI agents. Each employee receives an isolated agent connected to business systems, while credentials, network access, policy, approvals, and audit trails are enforced outside the model. The architecture aims to keep raw secrets outside agents.
Enterprises want agents to act across business systems, but ordinary frameworks lack centralized identity, least privilege, deterministic approvals, and governance. OneCLI integrates the runtime and security layer.
The strongest evidence is founder fit plus open-source adoption. Y Combinator verifies the S26 company and founders. The repository shows about 3,400 stars, 204 forks, and hundreds of commits. The reported 350,000 downloads require definition and deduplication.
The main concern is commercial evidence. Pricing and recognizable logos are public, but ARR, paid customers, retention, margins, and case studies are not verified. The HTTPS-intercepting gateway and secret vault require rigorous testing; SOC 2 Type II remains in progress.
Final decision: DD. OneCLI has a credible venture market, differentiated architecture, strong technical founders, open-source pull, and a monetization path. Formal diligence should test revenue quality, customer use, security controls, and financing terms before investment.
Product Overview
The beachhead is security-conscious technology companies deploying internal agents. Alternatives are broad API keys, custom vault and policy infrastructure, low-value agents, or pervasive manual approval.
OneCLI’s site describes a sandboxed agent per employee, accessible through the web or Slack. A gateway injects credentials after authorizing each outbound request; the model sees a placeholder rather than the raw secret. Admins can block endpoints, scope resources, rate-limit activity, and require deterministic human approval. The system records the employee identity and policy behind each call.
GitHub documents an outbound-only runner, sandbox supervisor, control plane, Slack adapter, and Rust gateway that intercepts HTTPS and encrypts stored secrets with AES-256-GCM. Most code is Apache 2.0; enterprise directories require a production subscription.
Pricing includes Free with three users, three agents, $5 model credit, and 500 monthly calls; Team at $149/month for five users and ten agents using customer model keys; Scale at $499/month for ten users and twenty agents; and custom Enterprise. Hosted-model versions cost more. This is a clear land-and-expand structure.
Founder and Team Assessment
YC identifies Jonathan Fishner as CEO and Guy Ben-Aharon as CTO. Fishner says he built zero-trust network access at Axis Security, acquired by HPE. Ben-Aharon was reportedly Argon Security’s first engineer before its acquisition by Aqua Security and later worked at Aqua, Wix, and Israel’s Unit 8200. These histories match the product’s security problem.
LinkedIn shows two employees, consistent with a founder-only team. The two-person team creates capacity and key-person risk across uptime, security, sales, and support.
The terms identify ChartDB, Inc. as the legal operator. Founder equity, IP assignments, prior ChartDB obligations, full cap table, and current financing structure require diligence.
Founder Assessment: Excellent technical founder-market fit, with commercial execution and organizational capacity still to be proven.
Market Opportunity
The beachhead is venture-backed and mid-market software companies deploying internal agents that need authenticated access to multiple systems. Buyers already spend on identity, secrets management, endpoint security, and workflow automation; agent identity and authorization could become a distinct budget.
A conservative illustrative market of 25,000 organizations at $10,000 average annual revenue equals $250 million ARR. Expansion into regulated enterprises, machine identities, policy analytics, and third-party agent ecosystems can increase ACV. Timing is strong, but identity, secrets, and cloud vendors can enter. OneCLI must become part of the enterprise control plane.
Traction and Growth Signals
The repository’s approximately 3,400 GitHub stars, 204 forks, and visible commit history are meaningful developer-interest signals. The founders report more than 350,000 downloads and Product Hunt shows 154 followers, 143 points, and a #7 daily rank. They establish reach, not paid adoption.
The site lists major organizations as “trusted by.” No case studies verify deployment depth, contract value, production status, or outcomes.
Unknowns include ARR, revenue growth, paying accounts, active agents, requests per customer, conversion, logo retention, net revenue retention, sales cycle, concentration, and security incidents.
Traction Assessment: Strong open-source awareness and potentially credible customer interest, but commercial traction requires verification.
Competitive Position
Direct competitors include agent-security gateways, secure MCP platforms, agent identity products, and managed internal-agent systems. Adjacent incumbents include HashiCorp Vault, CyberArk, Akeyless, Okta, Microsoft Entra, cloud IAM, and API gateways. Open-source agents plus ordinary vaults and custom proxies are free or lower-cost alternatives.
OneCLI’s differentiation is an integrated employee-agent harness with network-layer secret injection, sandboxing, centralized policy, deterministic approvals, and an identity trail. Open source creates trust and distribution; enterprise-licensed modules provide monetization. Switching costs can grow with policies, integrations, audit history, and deployed agent identities.
If a major identity or cloud platform launched the same feature within six months, customers might stay for vendor-neutral agent support, faster connectors, self-hosting, and a developer-friendly open-source ecosystem. That answer is credible but not yet proven in competitive wins.
Defensibility Assessment: Medium.
Business Model and Economics
OneCLI uses open-core SaaS. Published BYOC plans yield $1,788 annual revenue for Team and $5,988 for Scale before discounts; enterprise is custom. Hosted-model plans increase revenue but also inference cost. Enterprise licensing, self-hosting, SSO/SAML, longer audit retention, SLAs, and support can lift ACV.
BYOC can support strong margin, but VMs, vaults, storage, logs, support, and security add cost. Hosted models create inference risk; self-hosting may limit conversion.
Diligence should measure contribution margin by plan, infrastructure per active agent, support load, model-credit usage, conversion from OSS and Free, expansion, and sales efficiency.
Unicorn Path
Assume an 8x ARR multiple for a high-growth security SaaS business with durable retention and software-like margins. A $1 billion valuation requires approximately $125 million ARR.
At Scale’s $5,988 annual price, OneCLI would need about 20,900 customers. At a hypothetical $50,000 enterprise ACV, it would need 2,500 customers. A plausible blend requires thousands of mid-market customers plus hundreds of larger enterprises and expansion revenue from agents, seats, policy, and usage.
The path depends on agent governance becoming a durable category, SOC 2 and stronger enterprise assurances, repeatable sales, high retention, and differentiation from IAM incumbents. It is ambitious but consistent with security-platform economics.
Unicorn Path: Plausible.
Valuation Assessment
YC backing is verified, but no total funding, current round size, SAFE cap, post-money valuation, or investor ownership was found. Secondary databases conflict on the YC amount and should not replace company documents. No revenue or growth data supports a comparable-multiple valuation.
Valuation Attractiveness: Not Assessable.
Required information includes ARR, growth, gross and contribution margin, cohort retention, NRR, burn, runway, cap table, prior ChartDB securities, option pool, round size, SAFE cap or price, valuation, and preferences.
Key Risks
- Commercial proof: downloads and logos may not translate into meaningful paid deployments.
- Security architecture: HTTPS interception, vaulting, and policy enforcement create a critical attack surface.
- Incumbent bundling: IAM, secrets, cloud, and model platforms can converge on agent identity.
- Two-person capacity: uptime, enterprise sales, compliance, and incident response may outstrip the team.
- Open-core conversion: customers may self-host free components without buying enterprise features.
- Hosted-model economics: heavy usage may compress margin under fair-use plans.
- Agent-market volatility: frameworks and platform policies change rapidly.
- Customer liability: agents can still cause damage within authorized policies.
Final Assessment
Venture Potential: 75/100
| Category | Score |
|---|---|
| Market Size and Expansion Potential | 17/20 |
| Traction and Growth Evidence | 12/20 |
| Founder and Team | 14/15 |
| Product Strength | 9/10 |
| Distribution Potential | 11/15 |
| Business Model and Economics | 7/10 |
| Defensibility | 5/10 |
| Total | 75/100 |
The venture case is strongest in founder fit, product architecture, market timing, and open-source reach. It is weakest in verified revenue, team depth, and moat against platforms.
Evidence Confidence: 68/100
YC status, founders, legal operator, code, repository activity, architecture, and pricing are verified. Downloads, customer logos, and founder biographies are partly company-reported. Revenue, retention, margins, funding terms, customer depth, burn, and valuation remain unavailable.
Final Decision: DD
OneCLI merits a founder meeting and data-room review. It meets the threshold for a potentially venture-backable security company, but an investment decision is premature without commercial, security, and financing evidence.
Upgrade Conditions
- Verify material ARR, sustained growth, and strong 90-day and annual logo retention.
- Provide customer references confirming production use and measurable risk reduction.
- Demonstrate strong OSS-to-paid conversion and repeatable acquisition.
- Complete SOC 2 Type II and independent penetration testing.
- Show BYOC gross margin above 75% and credible hosted-model unit economics.
- Present reasonable financing terms and clean ChartDB/OneCLI IP ownership.
Downgrade Conditions
- Download claims prove inflated or dominated by automated/repeat events.
- Named logos are only experiments with no paid or production use.
- Material vulnerabilities undermine network-layer enforcement.
- Low open-source conversion or weak retention persists.
- Incumbents win the same use cases through bundled offerings.
Questions for Further Diligence
- What are ARR, MRR growth, paying organizations, and revenue concentration today?
- How are the 350,000 downloads counted, deduplicated, and converted into active or paying deployments?
- What are 30-, 90-, and 180-day retention, logo retention, and NRR by cohort?
- Which listed customers pay and run production agents, and can three provide references?
- What are gross margin and infrastructure cost per active agent for BYOC and hosted-model plans?
- What independent penetration tests cover the local CA, HTTPS interception, vault, runner, and control plane?
- Which controls are deterministic, and where can prompts or model judgment influence authorization?
- What is the SOC 2 Type II timeline, incident history, and cyber-insurance coverage?
- Which open-source features drive paid conversion, and what prevents enterprise-license circumvention?
- What are CAC, sales cycle, pipeline, and the primary acquisition channel beyond GitHub?
- What are founder roles, hiring plans, burn, runway, cap table, and current round terms?
- How are ChartDB’s prior IP and securities separated or assigned to OneCLI?

