Nik King Fredel (SPS '26) is the co-founder and COO of Cortile, formerly Complama, an AI intelligence layer that helps security teams get through vendor security reviews faster by reading documentation and running tests to verify the evidence behind the controls they're checking for. Nik co-founded the company with Owen Rice, who spent his early career at Rocket evaluating the security programs of startups and enterprise vendors selling into the enterprise, watching good companies struggle to prove they were actually secure without a dedicated team or a big budget behind them. Cortile closes that gap. This summer, the two are part of the 2026 NYU Summer Launchpad cohort. Learn about the founders and Cortile— no two-factor authentication required to keep reading.
Tell us about yourself, apart from Cortile.
I'm from San Francisco. I came to New York for undergrad and went to Gallatin, where I built my own concentration in art history and culture. I loved it, and for a while I thought I might end up in academia. But I'd been around a lot of people building startups, including my parents, and I think that pulled me in a different direction. After undergrad, I co-founded and was COO of a managed security service provider, helping startups and small businesses build security programs. I loved that space so much that I came back for a master's in Management & Systems, which I just finished. Outside of work, I'm married, I have a cat, and I love to read about history — shipwrecks specifically.
Have you always been the type to build things?
I think so. My parents are entrepreneurs and I grew up around that world, so if anything I went through a phase of wanting to rebel against it. But, I had the classic lemonade-stand thing as a kid, and when I actually took the jump into my first company, it clicked — I really do like this.
How did you and Owen end up building Cortile together?
I met Owen on LinkedIn. He was posting about what he was starting to build and looking for a co-founder. We started talking about what we each wanted to build and found a lot of overlap. It's a strange thing to essentially date a stranger to figure out if you're a match, but knowing his background. He'd worked at Rocket evaluating security programs for startups and enterprise vendors. Hearing how he thought about the problem gave me enough confidence to spend real time talking before we made it official.
Give us the one-liner on Cortile.
Cortile is an AI intelligence layer for vendor security reviews — it reads documentation and runs tests to help security reviewers identify the evidence behind the controls they're supposed to have in place.
Where does the name come from?
We originally called it Complama, which is a play on "compliance," but I could never quite wrap my head around saying it out loud. Cortile is an Italian word for a courtyard — the open space in the middle of a group of buildings. A lot of security companies lean into names that sound intense or a little scary. We wanted something that felt more approachable. There's real value here and also a sense of a protected, almost beautiful space. It doesn't have to be scary.

What does it actually look like when a company gets stuck on security reviews?
A lot of the security teams we talk to are small — maybe four people who are responsible for the entire security program, not just vendor reviews. When a new vendor comes in, they have to screen it, but the process is manual: back-and-forth for documentation, then combing through it for specific passages or running tests by hand. We've talked to teams managing this on a 93-tab spreadsheet. This is an error-prone process for a company's most sensitive risk decisions, and it's happening while the rest of the business is pushing to get a new tool live.
Verizon's 2025 Data Breach Investigations Report found 30% of breaches involved a third party — up from roughly 15% the year before, a sharp jump.
What's the biggest thing that's changed about the product since Sprint and through Launchpad?
Going into Sprint, we'd already launched a vendor-side product — a tool to help startups build their own security programs. We were gaining some traction, but we hadn't done enough discovery. Once we were pushed to really dig in during Sprint, we found that the sharper pain wasn't with the startups selling into regulated industries like healthcare; it was with the buyers at those institutions who were the ones actually stuck sorting through paperwork and documentation. That's an ICP shift, and it's changed the focus of what we're building.
What's the most interesting part of the problem to you?
I'm consistently amazed by what AI can do here, taking a pile of documentation or different control libraries and quickly finding the commonalities in them. Nobody gets into a security or GRC role because they want to spend their day reading hundreds of pages of documentation. They want to do the analysis: what's the actual risk with this vendor, and how do we fix it. If we can hand them that answer instead of the paperwork, they can make better decisions faster.
The average cost of a data breach hit $4.44 million globally in 2025 (IBM); healthcare breaches, the sector Nik's examples focus on, averaged $7.42 million
What's one piece of advice from the program you'll keep with you?
Customer discovery. I think a lot of people go into a startup with this idea that being your own boss is just freedom; it is, but you also have to be genuinely willing to listen. This program pushed us to actually go do customer discovery and hear the problem in our customers' own words, instead of assuming our own experience told us what was useful. Making that a constant, iterative process alongside our customers has been the most valuable part.
Quick hits, now that you're neck-deep in cybersecurity — what can you not unsee?
Multi-factor authentication used to drive me crazy. Now every time I have to grab my phone to log in, I actually feel relieved that it exists. And I can never unsee a bad spreadsheet — once you've seen what a 93-tab security review spreadsheet looks like, it's hard to un-know that this is how some companies handle their most sensitive risk decisions.
Any password habits, hypothetically?
I use passphrases. Sometimes from a generator, sometimes ones I make up myself, often pulled from a movie quote with a few numbers worked in. It means something to me, so it's memorable, and it doubles as a way to remember trivia — like working the release date of a movie into the password so I never forget it.
What's next for Cortile?
Right now we're focused on our design partners, going deep on their feedback as we build. Once that sprint wraps, the goal is landing pilots with our ICP.