Y Combinator Startup Podcast - This Startup Secretly Detects Fraud For Fortune 500s
Episode Date: March 31, 2026In this episode of Founder Firesides, YC Managing Partner Jared Friedman talks to Karine Mellata, co-founder of Variance (W23), who is coming out of stealth and announcing their $21 million Series A. ...Variance builds purpose-built AI agents for risk and compliance — automating fraud detection, content review, and identity verification for Fortune 500 companies and platforms like GoFundMe. They discuss why Variance built in the shadows for three years, detecting state-sponsored fraud rings, and the accident that nearly ended the company.
Transcript
Discussion (0)
So I'm particularly excited to do this founder fireside because we have a first for the founder
fireside series. We are doing a big announcement on this podcast. We are announcing that
Varianzance is coming out of stealth and announcing their $21 million series A. And I am really
excited to be here with Kareen, the co-founder of Varians. Thank you so much for joining us,
Kareen. Thank you. So this is a big day. You're coming out of stealth after building
basically in stealth for the past three years, and you built variance quietly into this big company
that powers a lot of the products that everybody knows and uses in their regular life.
Can you tell us about what variance is and about the $21 million series A you're announcing?
So variance is building purpose-built AI agents for risk and compliance.
We automate content review, fraud reviews, identity reviews at scale.
We're powering some of the largest companies in the world's Fortune 500s,
marketplaces. We've been working with GoFundMe, for instance, to review all of their
fundraisers at scale, some Fortune 50 for verifying all of their sellers and complex UBO
verifications and today coming out of stealth. And you guys built in stealth for a long time,
like three years, and you have a lot of customers that you can't even name on this podcast.
Why all the secrecy around this? Varian's usually deals with really sensitive data and
sensitive issues. And the phrase I like to use is that we're building the systems that are often
used by the bad guys, but we're building them for the good guys. So oftentimes it's really hard
to market the use cases that customers are using variance for because those issues are so sensitive.
And if we were to market those, then it may create more fraud. It may create more abuse. It may create
more bad. Like your customers are stuck in this constant cat and mouse game with the bad guys.
And you're their secret weapon.
They don't want anyone to know what their secret weapon is.
Exactly.
We're in the shadows.
I think it's good.
It's really impactful for our employees working at the company, really impactful.
You get to see that when you work at VARiance.
But I think even far beyond the Series A will always be a company that's a little bit more in the shadows.
And I think that's okay for us.
What's cool about VARiance is that even though probably no one who's watching this
video has ever actually used the product themselves, they have used many products that under
the hood are actually powered by what you've built.
And so indirectly, they're actually like using stuff built on top of variants, like a lot
of like software infrastructure kind of products.
Can you maybe tell people about a, like a specific product that they've used that's, or
have probably used that's powered by variants and how it works?
One of the customers GoFundMe is a platform that you can use.
in order to build your own fundraisers.
And GoFundMe is effectively a payments platform.
And GoFundMe actually has some very strict compliance requirements
because they are liable for facilitating payments
to, let's say, an organization that they shouldn't have done so.
So variance is used to verify, for instance,
if a fundraiser is going to be built for a military operation, for instance.
Or if you're building a fundraiser for a crisis
that you were not part of, which would be fraudulent,
well, GoFundMe sort of has a business.
responsibility to be able to detect this. They're using AI agents, so variance AI agents,
to conduct those investigations. So make sure that the money is going to the person that they say
they are. And also make sure that the money is not going to be funneled to sanctioned countries,
for instance, or be going to anything that could be a compliance risk for them.
You were telling me earlier about like one specific, very concrete form of fraud.
What does like typical fraud on GoFundMe look like?
Yeah, so GoFundMe is actually very crisis driven.
So if there is any sort of large event or any sort of natural disaster, there's usually going to be a spike in fundraisers that occur on GoFundMe.
It's really hard for the team to keep up with how many of these fundraisers are actually going to be real fundraisers for that event or possibly fraudulent.
One of the example that we saw was, I think, recently there was, for instance, the murder of Charlie Kirk.
There was a spike of fundraisers for the family of Charlie Kirk.
How do you know who's actually related to Charlie Kirk and who's just trying to raise money for their own?
Okay. So like Charlie Kirk dies.
Yes.
And then what happens is like a hundred people host a fundraiser on GoFundi, like claiming to be a family member of Charlie Kirk.
Exactly.
And it's mostly just like total fraudsters who are just hoping that some people like donate to their Charlie Kirk fundraiser instead of the real Charlie Kirk family fundraiser.
Exactly. And you're in charge of figuring out which one is the real Charlie Kirk family and who are the like hundred fraudsters.
Exactly. And there's a lot of behavioral signals you can use to do so. You have information on the identity. You have information on what that account has done in the past.
You also have information at the fundraiser level. So the image, the bio and such. So the variance AI agents are going to be using all of that context and use the GoFundMe terms of services to basically decide whether or not.
that should be allowed on the platform. That work used to be done by human analysts and now
can be fully automated in a much more consistent manner. Every person who signs up to do a
GoFundMe fundraiser, they don't realize it, but actually their request is being validated
by variants of software before it's allowed to go live. Yes, exactly. What are other like
products that people use that also are powered by variants and they don't even realize it?
So the scale has been impressive, the number of use cases that our agents can be used for.
So we have been running complex identity reviews for marketplaces, gig economy platforms,
so when you sign up to actually be, for instance, a delivery driver,
your identity needs to be verified based on selfies, based on your driver's license.
All of that data is then going to be reasoned on by our AI agents.
and then it's also going to be validated based on the company's standard operating procedures.
That's a good example of how variants is used.
We're also used for complex what we call KYB verifications.
So if you sign up to do any sort of business online, whether it's for a marketplace
or also with a financial institution, they have the compliance requirement to verify
that you are actually linked to the business you say you own.
So a good example is, for example, I sign up to say I'm going to be doing business with variants.
Well, the legal name of my company is Decoy Technologies and it is tied to Korean Malata.
That's a simple example, but building that graphet skill is really hard.
And oftentimes you're going to see company have multiple shell companies be tied to multiple different agents and different other identities.
And within that really large graph, you expend the area of risk for the company.
where one of these nodes could be in a sanctioned country.
One of these nodes could have adverse media on them
and possibly have been to court for money laundering.
And companies are required to conduct these investigations at scale.
And at the moment, it's entirely manual.
Do you license data from a bunch of different sources?
Do you like scrape all these government websites?
Yes.
But to take a step back, I think it's really elegant
how AI agents are built at the moment.
There's really only three building blocks
that you need.
So you have the compliance documents, the standard operating procedure.
So what the company deems is necessary to verify at the onboarding level or at any other
parts of the lifecycle of that entity.
Once we have those compliance documents, then the AI agent can do its work using tools
that we built and data, internal or external.
Those are the only building blocks you need to automate complex KYC, complex KYB, complex
content review. The question you're asking about data is interesting. Usually it's going to be a
split between internal customer data. So variance is really good at connecting to all data sources,
pooling unstructured data into our own data stores. And the second one is external data. So we do
have access to over hundreds business registries across the world, which makes us international.
And then our AI agents also have access to the open web. So a lot of unstructured data is found
directly on the web. I actually think, interestingly enough, that access to the web was one of
the final nodes that made this whole problem really hard to automate. Yes, because like the human
analyst, a big part of what they would do is they would go and they would like Google for names,
and then they would like look at what comes up and apply some judgment like, oh, does this seem fishy
or not? Exactly. Yeah. When you think of a large graph of abuse, if one of these nodes,
one of these intelligence signal is found on the unstructured or the open web,
then without having a human agent, Google on the web, you can't even trace back the whole graph of abuse.
What are some other interesting technical challenges that you guys have encountered and have to solve in the course of making this work?
At scale, the data problem was really the core hardest technical challenge.
Usually with customers, what we will do is that we'll pull in petabytes of data that are coming from vastly different sources.
And all of that data is unstructured, doesn't have a schema.
Unstructured.
Isn't it?
Don't you just like pull it like, right, right?
Do you pull like out of their like relational database?
I wish it was this simple.
But usually, I mean, I'll give you a very concrete example.
So for instance, if you need to verify a fundraiser, I'll pick the fundraiser.
I'll pick the fundraiser example.
Okay.
Usually the data is going to be scattered around the user identity data, so you need to have
information on the user, you need to have information on all of their login behaviors, the devices
that they've had, the PII that they've onboarded at the beginning.
You need to also be able to pull in information about the business, and then you need to have
also all of the information on the fundraiser itself and all the history of that fundraiser.
What has been hard is that oftentimes, whether your financial institution or your marketplace,
that data is going to be scattered across five to ten different systems.
It's going to be into different data stores.
And one thing that's been really interesting is that sometimes that data is going to be hidden behind a UI.
So the only way that the variance AI agents are able to sort of scoop up that data and reason over it
is to be able to directly scrape from a UI that was built for a human.
So the data piece and being able to scoop up all that data and bringing it to variance was one of the hardest technical challenge.
And it's really an onboarding one.
And so do you do that?
Do you have agents that interact with like the customers, like internal dashboards and like pull data out of them?
Yes.
So at the moment, the way to integrate with variance can be reverse ETL API.
But very recently we've been onboarded this third way, which is spinning up a browser, opening up a really old
review tool that was built for a human, pulling that data and then reasoning over it.
I guess it makes sense because the work was being done by a human before. And so like if the
human can use the dashboard, well, the agent can use the same dashboard.
Yes, exactly. You worked on related systems at Apple, like three LLMs, and now you're building
this like deeply agentic system. Can you talk about how the technology has evolved and like
why it's possible to solve this problem now? Yeah, definitely. So I think it's important to sort of
of understand how these problems were solved at scale before.
So usually companies are going to have a patchwork of different, what I call deterministic systems.
So they're going to have rules that say, well, if this transaction is over $1,000, then do this.
They're going to have classifiers that are really good at detecting one specific flavor of abuse.
Then they're going to have humans.
And humans are really good at understanding and context all of these different nodes and signals,
and then making a final decision.
And I think when you think of a fraud system,
the most important feature of a fraud system
is that it needs to evolve really rapidly
and you need to have a really tight feedback loop.
But when you think of the three nodes I've mentioned,
a rules engine, classifiers in humans,
humans being really slow oftentimes and a little bit inconsistent,
that feedback loop can only be so fast.
And we never really felt like you could achieve
a self-healing system that could be,
thrive in a dynamic environment and I think fraud is the most dynamic environment because you always
have adversaries. So Michael and I were always really, really, really stubborn about making the
system have no nodes that were inefficient, if that makes sense. And now you have AI agents that are
able to sort of close the loop from a reliance and self-healing standpoint. They're able to materialize
any features that a rules engine would be able to materialize.
You don't need a classifier anymore because AI agents are able to read a set of standard operating
procedure and reason over an image or reason over sort of unstructured data and know that
this is possibly chargeback fraud.
You don't need a specialized classifier for it, and you don't need human reasoning anymore.
So you have this fully self-healing system, which at scale is really transformative and
allows companies to be able to ship faster, open new product lines because they don't have
this sort of bottleneck.
Do you have an example of something like that with one of your customers where the
system was able to do something that just like no human team of fraud analysts could ever
have been able to do?
Yeah.
One customer specifically, and I think that fraud pattern came to be during the elections,
we had one customer that is processing a lot of content and they're also, there are Fortune
500.
opposing large communities, and they're also fairly politically exposed.
And throughout the elections, because our AI agents had access to the context of entities in relation
to other entities. So how does this user fit into all of the other users that we're looking
at? We were able to detect really complex fraud rings of especially state-sponsored actors
that were pushing one narrative over. And I don't think this would have been possible if you had
one classifier in isolation that was looking at one piece of content after the other. But because
AI agents are able to directly query our data stores, they're able to materialize features on the fly,
and they're also able to use one step to reason over what should be the next step and the
next tool call that they make, we were able to detect much more sophisticated fraud rings than
you would have been able to do before. There's also like a pretty interesting implication of
variance. Like you're actually able to like,
detect misinformation online and, like, improve the political discourse. What a, what a, like, cool
impact to have on the world? Yeah, it's been a, it's been high responsibility. But no,
it's been really interesting. I think some of the abuse vectors we've been able to detect have
had really serious physical implications. So people that are making threats online of physical
harm have a plan to do these things at scale.
Wow, so you might have actually prevented physical violence from happening in the world by detecting it early.
Yes, exactly. Yes. So at scale, some of these investigations can lead to finding things that are really scary.
And at the end of the day, once it's detected and investigated by variance, it's usually going to be in the hands of law enforcement.
But seeing that impact at scale is really interesting.
This sounds like a lot of software to build. How big is the team now?
So we're 12. We have five software engineers.
So we've been, we've remained very, very lean.
Only five software engineers building all of this.
Yes.
Are you hiring more?
We're hiring more.
So we're hiring across the board.
We're hiring for back end.
We're hiring as well for front end, which I think Michael and I hadn't realized was such
an important part of the product.
If I can give you a little bit more context, I think when Michael and I first started the
company, we were really stubborn about building a full end-to-end decisioning layer.
So we thought we needed to get really good at making really precise decisions,
but at the end of the day we could be treated like an API call.
We were not right about that.
What we found out is that because AI agents are able to take on the simplest part of the workflow,
so they're able to triage 99% of cases,
that 1% is usually going to be the most complex cases that need to be reviewed by a human.
And you need a really good dashboard, you need a really good investigative visual tool.
to be able to make sense of those super complex use cases.
What's it like working at variance?
What's cool about working there?
It's a very strong ownership culture.
Five engineers and we're processing petabytes of data.
We're making decisions in a fully automated manner
for some of the largest companies in the world.
So I think just for context, we have two ex-founders on the team.
Everyone has a really strong ownership culture
and really feels like they have agency
over every single part of the company.
So on a day-to-day basis, we're in person in San Francisco every day.
We're very, very product-focused.
Both Michael and I are engineers, of course.
So it's a very, very high ownership, but also high collaboration workplace.
And there's never really a time where Michael and I sort of dictate to the team what there is to build.
It's really more going to be we give a problem to an engineer and then they just take it and run with it.
And at the end of the day, it's been really fascinating because I can sort of proudly say that there's people on the team.
that understand certain areas of the business better than I do.
For instance, Luke on the team was one of the first engineers at Meeter,
and he understands e-vals for large language models better than anyone else on the team,
and even, I think, better than a lot of people in the industry.
So we sort of have this culture where we get to learn a lot from our engineers,
and because the team is so small, they get to be a really large part of the success of variants.
And I think that's something that's been possible now that we have coding agents.
Yeah, are you guys AI coding maximalists?
I would say we pretty much are at this point.
Everyone on the team is usually going to be almost like a manager of their own small team,
which is really interesting.
I would say we're five, but I think in terms of software output, we're probably closer to a 25 people team.
So every engineer is going to have three monitors with their coding agents running.
Okay.
We still have, you know, good oversight.
We still review all of the PRs.
But I think in terms of output, everyone is a manager of a small team of AI agents, which is really interesting.
And I think one other really interesting anecdote is that our customer success manager who's entirely non-technical, but interfaces with enterprise customers on a day-to-day basis, now gets to take on feature requests, especially the simple ones, directly give them to cursor, a cursor agent.
and then directly be able to ship features in a fully autonomous manner,
and get back to the customer a few hours later and say,
oh, it's shipped.
And she didn't even need to speak to the engineering team.
Whoa, that's awesome.
Maybe let's change gears here and talk a bit about the origin story.
How did you and Michael end up starting this company?
How did you end up working on this problem?
So Michael and I both met.
We were co-workers at Apple.
We were both engineers on the fraud engineering team.
And I was a data engineer.
Michael was a machine learning engineer.
And it was really interesting because the team in and of itself was sort of the fraud engineering as a service team of Apple.
We were providing our services to the iMessage team, the iCloud team, and we were the centralized fraud team.
And Michael's machine learning decisions were then dispatched to the rest of the organization through my own streaming jobs.
So we had a very sort of symbiotic relationship from the get-go.
We knew that we worked really well together.
I remember telling Michael, oh, well, what if the right vehicle for this product was a company?
And I told Michael, oh, we should apply to my combinator.
That was sort of the origin story.
I think it really started from the product.
We really, really wanted to just see this product exist.
And we wanted to see that problem that we were solving at Apple be solved in a much more efficient way, in a much more self-healing and resilient way.
How did you crack it? How did you convince the first customer to take a big bet on you?
I think your first customer really believes in the founders first. They believe in the founder's ability to be able to solve their problem.
Because at the end of the day, when you start enterprise, you do have a version of your product, but it's going to evolve so much based on your first customer's requirements.
So there was a belief in a trust in Michael and I that we understood their problem well enough to then translate that into a software platform.
It really started with that.
And then I think the second thing that was really important is that we needed to land on a problem space, which has evolved a lot, which was on fire.
It needed to be on fire because what we found is that if it wasn't on fire, then there was no reason to go and trust this really small startup that had no real proof points behind them.
Who was the first customer?
And what was the burning pain point that got them to be willing to do this?
this. Yes, so our first customer was a company called IAC. They're a publicly traded company.
IAC. Folks might not know of IAC because they're like a parent holding company, but I'll bet they
know a bunch of the IAC brands. Yes. I understand the IAC brands that everybody knows.
Yes. So IAC brands. I mean, IAC has care.com, Angie, we were working with Ask Media Group,
which had a very large amount of marketing content. And because IAC is a large publicly traded
company, there was a lot of compliance requirements around what could go into their marketing content.
So we basically used the platform that we had built to review content at scale to then review
their own marketing content. And I think what was really interesting is that, one, that
problem was entirely solved using human agents because those compliance guidelines are really
hard to map to a traditional classifier. You can't give advice for legal defense, for instance.
It's really hard to map to.
Right, writing a regular expression for that.
Exactly.
So it was semi-impossible.
So it was a very large team of human agents, part of a BPO outsource that was doing this work.
And that was basically hurting their growth.
There was less marketing content that they could put out in the world because they were not,
it's really hard to scale a team of human agents and human moderators.
So they knew sort of had an intuition that that could be done.
with large language models, but we were the first company to say,
hey, we can actually do that with large language models.
We were a small startup, I think that happened.
This was at the very beginning,
because you guys actually started variants re-chat GPT,
like just a little bit before chat GPT, right?
Yeah.
And so you were right at the very earliest waves of companies
that were figuring out how to use LLMs
to automate these previously unautomatable tasks.
Yes, exactly.
I think GPT4,
came out during the batch, which was really interesting. And as we were running this pilot for
this first customer, sort of opening I was coming out with new models in the middle of the pilot,
which was changing one, our cost structure by a 10x factor, but also was changing our performance
quite a lot. So it was really interesting to build in this world that was super dynamic.
Okay, so the first big battle was like getting the first customer, took eight months to land
IAC. You really did it the hard way because you went enterprise from the very beginning.
Have there been any other hard, like, challenges of building this company?
I think starting a company tests you in a lot of different ways. And we have a really
interesting story. You know, after IAC, we got to onboard a lot of great customers in the
trust and safety space, medium, of course, GoFundMe, Red Bubble. And around July 24 was
one of the times where the company was growing rapidly. We were onboarding more and more enterprise
use cases. I think during that month, our revenue was doubling within the month and then doubling
the month after. It was really exciting, very step function because it's enterprises. And we had just
wrapped up one of the largest trust and safety conferences called TrustCon in San Francisco.
And I think a couple, I want to say the day after we had worked so hard for this conference,
12 hours a day, we were super tired. I was going back to the office on a Sunday afternoon,
and I was on the bike lane, and a truck hit me. That was a really, really crazy experience to go through as a founder.
I mean, the company was doing well, but at the end of the day, we were a 10 people team,
and the CEO just gets hit by a truck. How badly were you injured?
So I broke my spine, broke my leg, and I was hospitalized for about 10 days.
I couldn't walk for about 10 days.
Whoa.
For a year and a half, as a founder, you're moving so fast.
You're working every day.
I had never, I don't think we ever took days off.
Even if you do, you're still pretty much on.
So for a year and a half, you're working super hard, and then all of a sudden, as a founder,
you're in a bed and you can't move.
Three or four days after all of that happened, Michael came to visit me in the hospital.
And of course, Michael was super anxious, one for my health, but also trying to understand what that even meant, right?
Like the CEO has a bus factor of one.
We only have engineers and we have me that's running all the sales and the customer relationships.
Yeah, because you were the, it was all founder-led sales.
You were the only person doing sales.
Yes.
And fully, the rest of the team was only engineers.
And Michael came to visit me and he brought, I don't know, I vividly remember, he brought this Norman Foster book, which was the architect of,
Apple Park as a gift to me and he was sort of sitting next to my hospital bed holding the book.
And we were both in silence because we didn't even know what to say, right?
It was silence for a couple of minutes.
And he laughed and said, well, this is going to make a really good scene in our IPO movie.
I was like, yeah, it's a good way to view it.
We laughed about it, but I think I was probably out of commission for,
about a week and then two or three weeks after that. And I think it put a lot of stress on the
company. There were a few moments where Michael was wondering if this was the end, he would tell me
and repeat to me the story of Steve Wozniak, who went through the plane crash and then left Apple
and then went to go work or went back to Berkeley. So I think there was sort of a feeling
that maybe this was going to be the end of the company and maybe we just needed to sort of
part ways, there was a really deep feeling that it was not the end. It's an interesting
challenge, so sort of like a hurdle you need to go over, but it just doesn't feel like the
end at all. It feels like there's so much more to come and I definitely felt that. I
know Michael felt that and we got to walk again, now I can walk again and we got to learn
that we definitely need to scale me so that hopefully this doesn't happen again, but we definitely,
yeah, need to scale me.
One thing that strikes me about your story is the extent to which you guys have had a very
strong opinion from the very beginning about what to build and who to build it for.
Like a lot of founders come into YC, they have some initial idea, but like it's just a hypothesis,
and then they'd like pivot through like many different ideas and like new models drop and AI changes.
is and they like might change the thing that they're working on like several times to fit with
whatever the like cool thing is. And you guys are kind of in the opposite of that you came in like
day zero with a very strong opinion of what to build. You'd seen the problem firsthand. And then
the whole company has just been like that initial hypothesis playing out. I guess, I don't know,
is that perhaps part of why it didn't seem like it could be over yet? Because you like really had to
see it through. Yes. And if we go back to work,
why Michael and I started the company. Michael and I had a very specific pair of skill sets in fraud,
and we understood what the industry looked like. We had a lot of issues with what the industry
looked like and how these problems were solved at scale. But I think from the beginning,
we always felt a really strong sense of duty to put our very specific and quite rare
pair of skill sets to the good of the industry. It was almost like,
a sense of duty. And to us, it was never really about starting a company for any problem sets,
which I think some founders are really great at doing that. Don't get me wrong. But we didn't want
to just start a company for any problems. We wanted to solve that problem. And we knew the
technology was going to evolve and we were so lucky, right? LMs got so good. Now we have
agentic systems. We have agent harnesses that are able to fully solve this problem and to end. But we
really wanted to solve this problem and this strong sense of duty, I think, is what kept
Michael and I going throughout the years. And I also think that's something that resonates deeply
with customers. So when they meet us, they sort of see these founders that are really deeply
trying to solve the problem that they're seeing on a day-to-day basis once because they've seen it
before, but also, too, because it's something that is doable if you put enough care into building
the right engineering system in the right ways.
All right. I feel like that might be a great note to end on.
Thank you so much, Karin.
Thank you.
