Tracebit

DeceptionDetection ResponseCloud Security

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2023
Funding $25M
Last updated 2026-07-05

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Tracebit deploys decoy cloud resources, credentials, and identity applications across AWS, Azure, Google Cloud, Kubernetes, CI/CD pipelines, and workstations, and alerts the moment an attacker touches one. Former Tessian employees Andy Smith and Sam Cox founded the company in London in 2023 and have raised $25 million, with named customers including Riot Games, Snyk, Docker, and Synthesia. The company reports that in its own benchmark the decoys warned defenders roughly eight minutes before an AI attacker's first damaging action. Every number behind that argument is vendor-published, with no independent replication. It is most defensible for cloud-heavy teams that build alert handling around the canaries, weakest where a rival adds the same decoy to a tool the buyer already runs.

Sourced Details

Description Cloud-native deception company whose platform deploys and maintains canary resources, credentials, and decoy applications across cloud, Kubernetes, CI/CD, identity providers, and workstations, alerting when an attacker touches one. [f1]
Founded 2023 [f2]
HQ London, UK [f3]
Funding $25M total [f4]
Latest funding Series A, $20M (March 2026) [f2]

Products

Product What it does
Tracebit Canary deception platform that deploys decoy cloud resources, credentials, and identity applications and produces an alert the moment an attacker interacts with one.

Matrix Coverage

Cyber Defense Matrix

IdentifyProtectDetectRespondRecover
Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware.
Applications Software, interactions, and application flows on the devices.
Networks Connections and traffic flowing among devices and apps, plus communication paths.
Data Content at rest, in transit, or in use across devices, apps, and networks.
Users The people using the devices, apps, networks, and data.

Canary decoys across cloud resources, CI/CD, identities, and workstations produce detection signal. Tracebit defends general infrastructure and is mapped to the Cyber Defense Matrix.

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 26 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. 3/5
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 3/5
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 4/5
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 3/5

Unlock the Full Analysis

The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.

One-time purchase: $20 per profile.

Unlock

Reading several? Unlock the entire catalog.

Business Risks
Problem & Market
Product Capabilities
Competitive Positioning
Go-to-Market & Traction
Team & Credibility
Trust Readiness
Competitors

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 10 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Dimension Score
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 1/3
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3

Unlock the Full Analysis

The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.

One-time purchase: $20 per profile.

Unlock

Reading several? Unlock the entire catalog.

Strategic Market Segmentation
Product Capabilities & AI Advantages
Sales Engagement & Go-to-Market
Pricing Model
Product Delivery & Operations
Earning Customers' Trust
Platform Strategy & Ecosystem Positioning
Team & Execution Capability

Sources

Company Detail Sources (4)
Id Source Tier Accessed
f1 Tracebit homepage official 2026-06-10
f2 Tracebit raises $20M Series A to expand cloud-native deception tech press 2026-06-10
f3 Tracebit Raises $5 Million for Threat Deception Solution press 2026-06-10
f4 Tracebit raises $20M Series A to expand cloud-native deception tech press 2026-06-12
Profile Analysis Sources (29)
Id Source Tier Accessed
s1 Tracebit homepage
“The average attacker spends 11 days inside an environment before anyone notices.”
official 2026-06-12
s2 Tracebit about page official 2026-06-12
s3 Tracebit pricing page
“Community Edition provides a limited number of Canary Credentials free forever.”
official 2026-06-12
s4 Tracebit AWS platform page
“S3 Buckets · DynamoDB Tables · Secrets Manager Secrets · SSM Parameters · IAM Roles”
official 2026-06-18
s5 Tracebit identity platform page official 2026-06-12
s6 Tracebit CI/CD platform page official 2026-06-12
s7 Tracebit workstations platform page official 2026-06-12
s8 Tracebit credentials and artifacts page official 2026-06-12
s9 Tracebit Kubernetes platform page official 2026-06-12
s10 Tracebit AI agent detection use case official 2026-06-12
s11 Tracebit customers page
“Invoking their Terraform module is incredibly elegant, just 7 lines of HCL, and you suddenly have dozens of decoys spun up, all tailored to your environment”
official 2026-06-18
s12 Riot Games case study
“2/2 separate 3rd Party Red Team exercises detected by Tracebit Canaries”
official 2026-06-12
s13 Synthesia case study
“One week deployment time for broad coverage”
official 2026-06-12
s14 SecurityWeek on the Tracebit seed round
“Tracebit, a new British startup working on technology in the cloud-based threat detection and deception space, has attracted $5 million in seed-stage financing.”
press 2026-06-12
s15 Tech.eu on the Tracebit Series A
“Tracebit, a cloud-native cybersecurity company focused on threat detection, has raised a $20 million Series A round led by FirstMark, with participation from Accel.”
press 2026-06-12
s16 TNW on the Tracebit Series A
“closed its Series A led by FirstMark as enterprise security teams warm to deception as a primary detection strategy”
press 2026-06-12
s17 Tracebit Series A announcement
“led by FirstMark and joined by Accel, MMC Ventures, Tapestry VC and CCL; with continued support from our fantastic angel investors. This brings the total investment in Tracebit to $25M.”
official 2026-06-12
s18 Tracebit Gemini CLI research post official 2026-06-12
s19 BleepingComputer on the Tracebit Gemini CLI research
“The flaw was discovered and reported to Google by the security firm Tracebit on June 27, with the tech giant releasing a fix in version 0.1.14, which became available on July 25.”
press 2026-06-12
s20 SC Media on the Gemini CLI fix
“An exploit discovered by Tracebit combined two main flaws in the tool to execute shell commands without a user's permission or knowledge”
press 2026-06-12
s21 Tracebit trust center
“Compliance: SOC 2, UK Cyber Essentials. Resources: CAIQ 4.0.2., Penetration test, Tracebit SOC 2 Type 2 Report.pdf”
official 2026-06-10
s22 Tracebit AWS Marketplace listing
“Tracebit generates and maintains tailored canary resources in your cloud environments, closing gaps in stock intrusion detection without time and cost intensive detection engineering.”
official 2026-06-12
s23 Tracebit and Panther partnership announcement official 2026-06-12
s24 AIMultiple deception technology vendor roundup
“List of deception technology vendors”
research 2026-06-12
s25 SecurityBrief UK on the Tracebit Community Edition launch
“These include AWS session tokens, SSH keys, browser session cookies, password manager credentials, email trackers and so-called LLM canaries planted in AI-related workflows.”
press 2026-06-12
s26 Tech.eu on the Tracebit founders
“Founded in 2023 by former Tessian employees Andy Smith (CEO) and Sam Cox (CTO), Tracebit develops cloud-native deception technology designed for modern infrastructure.”
press 2026-06-13
s27 Tech.eu on Tracebit named customers
“generates millions of canaries daily for customers, including Riot Games, Snyk, Synthesia, Docker, and Admiral Insurance.”
press 2026-06-13
s28 Tracebit Azure platform page
“Storage Accounts · Key Vault Secrets · Managed Identities”
official 2026-06-18
s29 Tracebit Google Cloud platform page
“Cloud Storage Buckets · Secret Manager Secrets · Service Accounts”
official 2026-06-18
Deep-Dive Sources (30)
Id Source Tier Accessed
s1 Tracebit homepage
“The average attacker spends 11 days inside an environment before anyone notices.”
official 2026-06-18
s2 Tracebit about page official 2026-06-12
s3 Tracebit pricing page
“Community Edition provides a limited number of Canary Credentials free forever.”
official 2026-06-12
s4 Tracebit AWS platform page
“S3 Buckets · DynamoDB Tables · Secrets Manager Secrets · SSM Parameters · IAM Roles”
official 2026-06-12
s5 Tracebit identity platform page official 2026-06-12
s6 Tracebit CI/CD platform page official 2026-06-12
s7 Tracebit workstations platform page official 2026-06-12
s8 Tracebit credentials and artifacts page
“Terraform State Files Infrastructure state with embedded secrets”
official 2026-06-12
s9 Tracebit Kubernetes platform page official 2026-06-12
s10 Tracebit AI agent detection use case
“AI agents are still early, but Tracebit is already detecting rogue agents in production environments.”
official 2026-06-12
s11 Tracebit customers page
“Invoking their Terraform module is incredibly elegant, just 7 lines of HCL, and you suddenly have dozens of decoys spun up, all tailored to your environment”
official 2026-06-12
s12 Riot Games case study
“2/2 separate 3rd Party Red Team exercises detected by Tracebit Canaries”
official 2026-06-12
s13 Synthesia case study
“One week deployment time for broad coverage”
official 2026-06-12
s14 SecurityWeek on the Tracebit seed round
“Courtesy of its infrastructure-as-code deployments, Tracebit said it will allow enterprises to switch threat deception on within minutes, without having to deploy additional hardware.”
press 2026-06-12
s15 Tech.eu on the Tracebit Series A
“The platform currently supports thousands of accounts, monitors around five billion events each week, and generates millions of canaries daily for customers, including Riot Games, Snyk, Synthesia, Docker, and Admiral Insurance.”
press 2026-06-12
s16 TNW on the Tracebit Series A
“The round comes roughly 18 months after the company raised a $5M seed to build out its cloud-native deception platform”
press 2026-06-12
s17 Tracebit Series A announcement
“led by FirstMark and joined by Accel, MMC Ventures, Tapestry VC and CCL; with continued support from our fantastic angel investors. This brings the total investment in Tracebit to $25M.”
official 2026-06-12
s18 Tracebit Gemini CLI research post
“On June 27, Tracebit reported a vulnerability to Google VDP which meant Gemini CLI in its default configuration could silently execute arbitrary malicious code on a user's machine when run in the context of untrusted code.”
official 2026-06-12
s19 BleepingComputer on the Tracebit Gemini CLI research
“The flaw was discovered and reported to Google by the security firm Tracebit on June 27, with the tech giant releasing a fix in version 0.1.14, which became available on July 25.”
press 2026-06-12
s20 SC Media on the Gemini CLI fix
“An exploit discovered by Tracebit combined two main flaws in the tool to execute shell commands without a user’s permission or knowledge”
press 2026-06-12
s21 Tracebit AWS Marketplace listing
“Tracebit generates and maintains tailored canary resources in your cloud environments, closing gaps in stock intrusion detection without time and cost intensive detection engineering.”
official 2026-06-12
s22 Tracebit and Panther partnership announcement
“Ingestion of Tracebit logs into Panther’s SIEM platform.”
official 2026-06-12
s23 Tracebit blog index
“We pointed ten frontier models at a live AWS environment to see what canaries do against an autonomous attacker”
official 2026-06-12
s24 Tracebit AI agents vs canaries webinar page
“Across 951 attack runs, AI reached admin privilege escalation in an average of 14 minutes - but canaries warned the defender before the attack landed in 95.9% of those runs, a median 8 minutes ahead of the attacker's first critical action.”
official 2026-06-12
s25 Tracebit agentic attacks working paper
“simply telling models to expect deception reduced the number of accounts fully compromised (admin + persistence) from 20% to 3%”
official 2026-06-12
s26 SecurityBrief UK on the Tracebit Community Edition launch
“These include AWS session tokens, SSH keys, browser session cookies, password manager credentials, email trackers and so-called LLM canaries planted in AI-related workflows.”
press 2026-06-12
s27 AIMultiple deception technology vendor roundup
“FortiNet FortiDeceptor, Broadcom Symantec Endpoint Protection, Akamai GuardiCore, Commvault Metallic ThreatWise, Rapid7, ForeScout Continuum Platform, LogRhythm”
research 2026-06-18
s28 Tech.eu on the Tracebit founders
“Founded in 2023 by former Tessian employees Andy Smith (CEO) and Sam Cox (CTO), Tracebit develops cloud-native deception technology designed for modern infrastructure.”
press 2026-06-13
s29 Tracebit platform navigation
“AWS Azure CI/CD Google Cloud Identity Kubernetes Workstations Credentials & artifacts”
official 2026-06-13
s30 Tracebit Trust Center (SOC 2 Type 2, UK Cyber Essentials)
“Tracebit has attained our SOC 2 Type 2 Attestation. Published November 12, 2024. Tracebit SOC 2 Type 2 Report.pdf”
official 2026-06-18

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Do not republish its content or share access without the operator's permission.