All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Traceforce watches the AI assistants, agents, and MCP servers running on employee computers, a layer that endpoint and network security products were not built to see. Clumio alumna Xia Hua co-founded the San Francisco company in February 2025, it sits in Y Combinator's S26 batch, and by mid-2026 it had shipped an endpoint sensor, a browser extension, an open-source MCP scanner, a curated risk registry, and customer-owned scan storage. The July 2026 quickstart documents Windows 10 and 11 and Microsoft Edge alongside macOS and Chrome. The founders' July 2026 Launch HN post reports 1,000-plus devices across 10 organizations, none named. Its edge today is being early to a surface incumbents miss, while the same discovery is software an EDR vendor could fold into sensors already running.
| Description | Traceforce runs on company devices to secure browser AI, desktop apps, and CLI agents, giving security teams full visibility into how those AI tools get used across the fleet. | [f1] |
|---|---|---|
| Founded | 2025 | [f2] |
| HQ | San Francisco, California, US | [f3] |
| Latest funding | Y Combinator S26 batch participation, no priced round disclosed, 2026 | [f4] |
| Deployment | SaaS | [f5] |
| Compliance | ISO 27001, SOC 2 Type 1 | [f5] |
| Product | What it does |
|---|---|
| Traceforce | Traceforce: Endpoint AI security posture management that discovers the AI tools, agents, MCP servers, and skills running on devices, scores context-aware risk, and automates remediation. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
TraceForce is endpoint AI security posture management that discovers the AI tools, agents, MCP servers, and skills running on devices, scores context-aware risk, and automates remediation. It is mapped to the AI Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 3/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 2/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 1/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 2/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 1/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Traceforce: AI Security & Control Platform for Devices | official | 2026-07-09 |
| f2 | The Security Podcast of Silicon Valley episode 72 with the Traceforce founders | press | 2026-06-11 |
| f3 | Traceforce contact page | official | 2026-07-02 |
| f4 | Launch HN: Traceforce (YC S26), founder post, July 2026 | press | 2026-07-17 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-06-23 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Traceforce homepage “EDR monitors processes. CASB monitors network traffic. Neither sees AI running locally on your devices.” | official | 2026-06-12 |
| s2 | Traceforce contact page (relocated from /contact, which now returns 404) “Reach us at 166 Geary Street, San Francisco, CA 94108.” | official | 2026-07-02 |
| s3 | Traceforce legal page | official | 2026-06-12 |
| s4 | Traceforce documentation index | official | 2026-06-12 |
| s5 | Traceforce documentation on AI agents “Traceforce tracks not just agents but also the plan they run on to identify any gap in security controls.” | official | 2026-06-12 |
| s6 | Traceforce documentation on MCP servers “Traceforce Scout can discover these custom MCP servers and detect security vulnerabilities such as secrets exposure and unpinned versions.” | official | 2026-06-12 |
| s7 | MCP X-Ray repository on GitHub “Atlas has over 600 MCPs in its registry, providing a comprehensive security assessment database for the MCP ecosystem.” | official | 2026-06-12 |
| s8 | Traceforce GitHub organization | official | 2026-06-12 |
| s9 | The Security Podcast of Silicon Valley: Episode 72 with the Traceforce founders (lines verified verbatim in the served page HTML on 2026-07-02) “we sort of nailed our first customer, figured out that first product we want to build, right. After speaking with like two dozen design partners, right. ... That, that was just like last month, right. We started in February. ... much harder than getting a 4. 0 GPA at MIT” | press | 2026-07-02 |
| s10 | Podbean listing of the Traceforce podcast episode (published July 1, 2025) “TraceForce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries.” | press | 2026-06-12 |
| s11 | Ken Huang on agentic security posture management via Traceforce (Traceforce-sponsored) “Thanks you TraceForce for Sponsoring this article.” | research | 2026-06-12 |
| s12 | Ken Huang on discovering shadow AI agents (Traceforce-sponsored) “Unless a monitoring agent is also installed inside the container, which Scout Lite does automatically, the host-level EDR sees only the Docker daemon, not the Claude Code process, not the MCP servers, not the tool calls.” | research | 2026-06-12 |
| s13 | Traceforce partner listing at Cyber Security & Cloud Congress North America 2026 | press | 2026-06-12 |
| s14 | Commvault announcement of the Clumio acquisition “announced it will acquire Clumio, a technology leader in data protection for critical cloud data in AWS” | press | 2026-06-12 |
| s15 | Traceforce quickstart guide: supported OS architectures and browsers (2026-07-02 fetch) “Apple Silicon/arm64, macOS versions 15.x (Sequoia), 26.x (Tahoe) ... Windows/arm64, Windows versions 10, 11 ... Chrome Browser Stable/Extended Stable v. 138 and above ... Microsoft Edge Browser Stable v. 138 and above” | official | 2026-07-02 |
| s16 | Traceforce homepage: MDM partner network and platform counters (2026-07-02 fetch) “Preferred MDM partner network ... Integrates with Jamf, JumpCloud, NinjaOne, and Iru ... Devices ... 1K+ ... MCPs Curated ... 1K+” | official | 2026-07-02 |
| s17 | Traceforce homepage footer badges (2026-07-02 fetch, img alt and filename manifest) “img alt "ISO logo" beside img src SOC2%20Type%202.svg with alt "SOC2 logo" in the homepage badge block” | official | 2026-07-02 |
| s18 | Traceforce Scout documentation “Traceforce can discover and perform deep inspection of over 500 publicly known MCP servers.” | official | 2026-07-02 |
| s19 | Traceforce: Platform Overview (2026-07-02 fetch) “Unlike competitors that rely on enterprise APIs, gateways, or EDR/CASB extensions, we operate on-device” | official | 2026-07-02 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Traceforce homepage “EDR monitors processes. CASB monitors network traffic. Neither sees AI running locally on your devices.” | official | 2026-06-11 |
| s2 | Traceforce contact page (relocated from /contact, MSP/MSSP PORT1 route verified 2026-07-17) “Reach us at 166 Geary Street, San Francisco, CA 94108.” | official | 2026-07-02 |
| s3 | Traceforce legal page “Vulnerability Disclosure Policy ... Free Trial Data Processing Addendum ... Mutual Non-Disclosure Agreement” | official | 2026-06-15 |
| s4 | Traceforce documentation index “Release 1.0.5 ... Release 1.0.33” | official | 2026-07-17 |
| s5 | Traceforce documentation on AI agents “Traceforce tracks not just agents but also the plan they run on to identify any gap in security controls.” | official | 2026-06-11 |
| s6 | Traceforce documentation on MCP servers “Traceforce Scout can discover these custom MCP servers and detect security vulnerabilities such as secrets exposure and unpinned versions.” | official | 2026-06-11 |
| s7 | Traceforce quickstart guide: supported OS architectures and browsers, expanded from macOS and Chrome (2026-07-02 fetch) “Apple Silicon/arm64, macOS versions 15.x (Sequoia), 26.x (Tahoe) ... Windows/arm64, Windows versions 10, 11 ... Chrome Browser Stable/Extended Stable v. 138 and above ... Microsoft Edge Browser Stable v. 138 and above” | official | 2026-07-02 |
| s8 | Traceforce Scout documentation “Traceforce can discover and perform deep inspection of over 500 publicly known MCP servers.” | official | 2026-06-11 |
| s9 | Traceforce X-Ray documentation “Executes security test plans by making actual tool calls against MCP servers. Test plans are LLM-generated” | official | 2026-06-11 |
| s10 | Traceforce storage provider integration guide “Traceforce does not store scan data on its own infrastructure.” | official | 2026-06-11 |
| s11 | MCP X-Ray repository on GitHub “Atlas has over 600 MCPs in its registry, providing a comprehensive security assessment database for the MCP ecosystem.” | official | 2026-06-11 |
| s12 | Traceforce GitHub organization | official | 2026-06-11 |
| s13 | Traceforce trial signup portal “Use your company address (Google Workspace or Microsoft 365). Personal @gmail.com, @outlook.com, and similar consumer accounts are not supported.” | official | 2026-06-11 |
| s14 | The Security Podcast of Silicon Valley episode 72 with the Traceforce founders “Traceforce is actually an AI data security company that she started with her co-founder, Glenn, back in February 2025. Prior to Traceforce, Shia was the director of engineering at Clumio” | press | 2026-06-18 |
| s15 | Podbean listing of the Traceforce podcast episode (published July 1, 2025) “Traceforce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries.” | press | 2026-06-11 |
| s16 | Ken Huang on agentic security posture management via Traceforce (Traceforce-sponsored) “Thanks you Traceforce for Sponsoring this article.” | research | 2026-06-11 |
| s17 | Ken Huang on discovering shadow AI agents (Traceforce-sponsored) “Unless a monitoring agent is also installed inside the container, which Scout Lite does automatically, the host-level EDR sees only the Docker daemon, not the Claude Code process, not the MCP servers, not the tool calls.” | research | 2026-06-11 |
| s18 | Traceforce partner listing at Cyber Security & Cloud Congress North America 2026 | press | 2026-06-11 |
| s19 | Commvault announcement of the Clumio acquisition “announced it will acquire Clumio, a technology leader in data protection for critical cloud data in AWS” | press | 2026-06-11 |
| s20 | Traceforce TraceGraph Agent SDK announcement on LinkedIn “we're excited to introduce the TraceGraph Agent SDK, enabling our customers to build their own agents on top of this rich data engine” | official | 2026-06-18 |
| s21 | Traceforce quickstart guide: registration and free trial (2026-07-02 fetch) “The free trial supports up to 10 devices for 30 days and requires a Google or Microsoft Workspace email.” | official | 2026-07-02 |
| s22 | The Security Podcast of Silicon Valley episode 72: first customer, design partner, and MIT lines verified verbatim in the served page HTML (2026-07-02 fetch) “we sort of nailed our first customer, figured out that first product we want to build, right. After speaking with like two dozen design partners, right. ... That, that was just like last month, right. We started in February. ... much harder than getting a 4. 0 GPA at MIT” | press | 2026-07-02 |
| s23 | Traceforce homepage: MDM partner network and platform counters (2026-07-02 fetch) “Preferred MDM partner network ... Integrates with Jamf, JumpCloud, NinjaOne, and Iru ... Devices ... 1K+ ... MCPs Curated ... 1K+” | official | 2026-07-02 |
| s24 | Traceforce homepage footer badges (2026-07-02 fetch, img alt and filename manifest) “img alt "ISO logo" beside img src SOC2%20Type%202.svg with alt "SOC2 logo" in the homepage badge block” | official | 2026-07-02 |
| s25 | Traceforce: Pricing Plans (2026-07-17 fetch, figures in the JSON-LD offer data, visible Pro card figure-free) “$12/month billed yearly or $15/month billed monthly per device” | official | 2026-07-17 |
| s26 | Traceforce Trust Center (cyberbase-hosted, linked from the legal page, JS app, no attestation text in the raw fetch, 2026-07-17) “Traceforce Trust Center” | official | 2026-07-17 |
| s27 | Launch HN: Traceforce (YC S26), company-wide security monitoring for AI apps (founder post, July 2026) “Hey HN, we're Xia and Varun, the founders of Traceforce ... Traceforce is currently deployed across more than 1,000 devices at 10 organizations. On average, we discover over 15 AI applications per device with each application connected to 5-10 MCPs.” | official | 2026-07-17 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.