All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Traceforce sells an agent that runs on employee laptops, finds the AI assistants and coding tools installed there, and can block an action a security team has ruled out. It installs inside containers too, where a host-level security tool sees the container service rather than the AI processes and tool calls running within it. Scan data stays in the customer's own cloud storage rather than on Traceforce infrastructure. Xia Hua founded the company in February 2025 after running engineering at Clumio, and Traceforce joined the Summer 2026 batch at Y Combinator. A buyer cannot size the deployed base outside the company: the founders' two July 2026 posts count differently, 1,000-plus devices at 10 organizations and 1,500-plus devices across five midsize enterprises.
| Description | Traceforce runs on company devices to secure browser AI, desktop apps, and CLI agents, giving security teams full visibility into how those AI tools get used across the fleet. | [f1] |
|---|---|---|
| Founded | 2025 | [f2] |
| HQ | San Francisco, California, US | [f3] |
| Latest funding | Y Combinator S26 batch participation, no priced round disclosed, 2026 | [f4] |
| Deployment | SaaS | [f5] |
| Compliance | ISO 27001, SOC 2 Type 1 | [f5] |
| Product | What it does |
|---|---|
| Traceforce | Endpoint agent that inventories the AI apps, agents, MCP servers, and skills on employee devices, warns on or blocks dangerous tool calls, and patches AI packages on the device. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Traceforce endpoint agents discover the AI tools, MCP servers, and skills on each device, block or warn on dangerous tool calls and on unsafe transfers to AI apps, and remediate by auto-patching AI packages and quarantining malicious MCPs. These capabilities are mapped to the AI Defense Matrix. [f6]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | The vendor states the gap precisely, contrasting tools that work through enterprise APIs, gateways, or EDR and CASB extensions with an agent that runs on the device itself, and it names the security team facing employee-installed AI as the buyer. The accounts of the problem beyond the vendor are sponsored or founder-authored and none puts the pain in dollars or incident counts, so only Traceforce has described how widespread the problem is. [s19, s1, s11, s12, s9] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 4/5 | The documentation portal covers the Scout sensor, the browser extension, policies, MCP inspection, and MDM deployment, with release notes running from 1.0.5 through 1.0.33 and a published API reference. MCP X-Ray is Apache-licensed Go code still taking commits, so the capability claims can be read in working code rather than only on marketing pages, while the third-party accounts of the product itself remain sponsored, which leaves the depth a buyer can check independently confined to the code and the docs. [s4, s5, s6, s7, s18, s25, s12] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | The enabling shift is employees running autonomous agents and MCP servers on their own devices, which the founders presented as the coming security risk on a July 2025 podcast and which sponsored practitioner coverage treated as a live enterprise problem through spring 2026. Buyer-side evidence stays indirect, since the July 2026 launch posts are founder-authored and no analyst note, RFP language, or budget-line signal appears in fetched sources. [s12, s9, s10, s20, s22] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 3/5 | The cited record documents Xia Hua's Clumio and Oracle background, the founder-authored launch page describes her co-founder as Clumio's tech lead, and Commvault's September 2024 announcement of its agreement to acquire Clumio corroborates the company they came from. The fetched record shows neither identified founder previously leading an endpoint security product, and the co-founder named beside Xia Hua differs across the podcast, the launch post, and the About page. [s9, s10, s14, s21, s23] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 2/5 | Traceforce's traction record is still the founders' own telling, from two dozen design partners and an unnamed first customer in 2025 to 1,500-plus devices across five enterprises in July 2026, with a reference quoted only as a database provider of more than 500 employees. No fetched source names a customer, the site's own customer-stories page returns a 404, and the MDM partner network of Jamf, JumpCloud, NinjaOne, and Iru is a deployment path rather than buyer proof. [s9, s20, s22, s26, s16] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 2/5 | The fetched record identifies the Summer 2026 Y Combinator batch and no priced round, amount, or investor, so the match between capital and ambition cannot be checked. Traceforce shipped a sensor, a documented platform, and an open-source scanner, but the spend behind that output is not public. [s21, s22, s7, s4] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 | Traceforce's own site sells an AI security and control platform for devices, while the sponsored coverage coins agentic security posture management for the same slice. Buyers still must decide whether this is a new budget line or a feature of endpoint tooling they already own. [s1, s11] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 | Endpoint platform vendors already deploy sensors to the devices this product instruments, so they could attempt the same discovery, blocking, and on-device remediation through agents already in place, though the fetched record establishes no parity. Container-level discovery and the curated Atlas registry are early differentiators rather than a structural moat. [s1, s7, s12] |
Traceforce aims at AI activity that network-layer controls can miss, because the consequential action starts on the device. The company states the gap on its platform overview page, saying that rivals work through enterprise APIs, gateways, or EDR and CASB extensions while Traceforce operates on the device, and the founders make the same argument in their July 2026 launch post, that the risky action happens on the laptop before anything crosses the wire. The assets in question are the AI assistants, coding agents, connectors, and skills that employees install themselves, often without review.
The buyer is the enterprise security team facing employee-installed AI. In a Traceforce-sponsored writeup, Ken Huang describes approved AI tools coexisting with unapproved local setups and experimental scripts, and he argues that standard software inventory misses agents that make decisions and call tools at runtime. A local assistant may hold connections to the filesystem, a shell helper, code repositories, and internal documents, so one unsanctioned assistant can reach files, shells, and repositories at once.
Corroboration beyond the vendor's orbit is the weak spot. Both practitioner writeups that discuss Traceforce are vendor-sponsored, the podcast appearance and the two July 2026 launch posts are the founders' own, and no fetched source puts the pain in dollars or incident counts. The problem statement is specific and current, and the reviewed record carries no public test of it by a buyer the vendor did not bring. [s19, s1, s20, s11, s12, s9]
The product's first job is discovery. The Scout sensor inventories the AI agents, MCP servers, and skills present on each device, and the documentation describes tracking down to the agent's plan tier and underlying model, since personal and enterprise plans differ in the security controls they include. A browser extension extends discovery into Chrome and Edge, with a documented deployment path through Google Workspace management, and the quickstart lists the sensor on macOS Sequoia and Tahoe and on Windows 10 and 11 as of July 2026.
Traceforce now sells enforcement alongside discovery. The homepage says Traceforce tracks every tool call from connectors to command-line agents and stops dangerous actions from running, detects and quarantines a malicious connector, and patches AI packages on the device with policy and audit logs rather than remediation scripts. The fetched record carries no independent account of how those controls behave in a customer fleet, so their effect stays vendor-reported.
Traceforce also scores what it finds. The Atlas registry assigns security ratings to hundreds of known agents and to a connector catalog the vendor counts differently by page, with the GitHub README stating over 600 MCPs, the Scout docs describing deep inspection of over 500, and the homepage counter showing 1K+ MCPs curated. The docs cover default and custom policies that pair target risk scores with remediation actions, and the product surfaces policy violations as issues with automated responses.
Container visibility is the most distinctive documented capability. The docs include a sandbox setup guide for AI-assistant monitoring inside containers, and the sponsored demo writeup details the mechanism, with a Scout Lite agent auto-installed in dev containers because host-level EDR sees only the Docker daemon rather than the agent processes and MCP servers inside.
Traceforce backs the marketing site with public engineering artifacts. MCP X-Ray is an Apache-licensed open-source scanner, written in Go, that checks connector configurations for exposed secrets, unsafe connections, and risky tool descriptions, and emits SARIF reports for CI pipelines. A July 2026 tutorial on a non-vendor site documents its configuration scan, penetration test, and repository scan commands and its SARIF output format, carrying no Traceforce sponsorship disclosure, unlike the practitioner writeups the vendor paid for. The GitHub organization also hosts a Terraform provider and a Go SDK, and the docs portal publishes an API reference. [s4, s5, s6, s7, s8, s12, s1, s15, s16, s18, s19, s25]
Traceforce positions against the tools enterprises already own rather than against named rivals. The platform overview page claims that rivals working through enterprise APIs, gateways, or EDR and CASB extensions miss AI running on the device, and Ken Huang's sponsored shadow-AI writeup extends the argument to SIEM, DLP, CSPM, and network analysis, tools he says were not designed to inventory or govern agents on devices.
Absorption by an endpoint platform is the threat that matters most. Those vendors already deploy sensors to the kind of devices Traceforce instruments, so they could attempt the same discovery and blocking through an agent already on the endpoint, and no fetched source shows one doing it yet. Traceforce's visible counters are container-level discovery, which the sponsored demo writeup says host-level EDR does not perform, and the curated Atlas risk registry, and no fetched source shows either one being hard to replicate.
Category vocabulary is still settling. The site sells an AI security and control platform for devices while the sponsored coverage coins agentic security posture management for the same slice, and buyers must decide whether this capability is a new budget line or a feature of endpoint tooling they already pay for. Analysts could define the emerging category around endpoint specialists, which would favor Traceforce, or buyers could file the capability under platforms they already own, which would not. [s1, s11, s12, s19]
Traction is told almost entirely in the founders' own voice. On a podcast published in July 2025, CEO Xia Hua described speaking with about two dozen design partners and landing the company's first customer roughly a month before the recording, about four months after founding. The July 2026 launch posts carry the current figures, more than 1,000 devices at 10 organizations in the Hacker News post and 1,500-plus devices across five enterprises in the Y Combinator launch eleven days later, with the closest thing to a reference quoted as a database provider of more than 500 employees.
No fetched third-party source names a Traceforce customer. The site's navigation offers a Customer Stories page, and that page returns a 404, so the vendor's own reference collection is not published either.
Traceforce sells founder-first over a self-service entry point. The founders front the public storytelling through the podcast, the launch posts, and the company site, the site offers a free trial covering ten devices for thirty days with no credit card, and Traceforce appears on the partner listing for the Cyber Security & Cloud Congress North America event. No go-to-market hire appears in the reviewed record, so the sellers it names are the founders themselves.
Open source is the other channel bet. MCP X-Ray gives practitioners a free scanner that can upload results to the hosted Atlas service, a classic tool-to-platform funnel, and the repository was still taking commits in late July 2026. A tutorial on a non-vendor site walked through its commands in July 2026 with no sponsorship disclosure on the page, the one write-up in the reviewed record that Traceforce is not shown to have arranged. [s9, s20, s22, s26, s1, s16, s7, s13, s24, s25]
The founders come from data protection rather than endpoint security, and nothing in the reviewed record shows either of them having shipped an endpoint agent before the one they now ask enterprises to install. CEO Xia Hua was director of engineering at Clumio and built in-memory databases at Oracle before that, a career she and the hosts walk through on the July 2025 podcast, where she also references her MIT background in passing. The Y Combinator launch page describes the pair as the engineers who ran Clumio's engineering organization, with Xia as director of engineering and her co-founder as tech lead.
The Clumio chapter is the strongest verifiable credential. Commvault announced in September 2024 that it would acquire Clumio, calling it a technology leader in data protection for critical cloud data in AWS, so a public acquirer moved to buy the company the founders came from. The cited record identifies their Clumio roles as employees and documents no prior founder outcome for either name.
Who the second founder is remains unsettled in the public record. The July 2025 podcast listing names Xia Hua and Glenn Mulvaney, the July 2026 launch post introduces the founders as Xia and Varun, and the About page lists Xia Hua and Daniel Seixas, each carrying the title co-founder and CEO. The conflicting founder records leave a material diligence question open for a fleet-wide sensor deployment.
The reviewed record names no employee beyond the founders. They describe leaning on advisors who have sold companies before, and the contact page lists a San Francisco address. Public evidence of bench depth beyond the founders is thin, and the fetched GitHub pages identify no contributor roster and no named maintainer of the endpoint sensor, so the reviewed record leaves the sensor's upkeep unattributed. [s9, s10, s14, s21, s22, s23, s2, s7]
The public trust posture is more formal than the company's stage would suggest. Traceforce displays the same two badges on its homepage and under the Legal and Compliance header on its legal page, and they render as ISO 27001 and AICPA SOC 2 Type 2, the standard report type an enterprise buyer asks for. The legal page also publishes a vulnerability disclosure policy, free-trial terms of service, a data processing addendum, a privacy policy, and a mutual NDA, so the documents a procurement reviewer asks for first are present.
What the badges assert is not yet checkable. The rendered legal page carries the pair with no auditor name, no scope statement, and no reporting period, and the trust center at traceforce.trust.cyberbase.ai puts its View audit documents control behind a sign-in, so a reviewer who wants to know what the SOC 2 covers has to contact the company for it.
Deployment controls match enterprise expectations on paper. The docs cover SSO configuration, Jamf Pro and MDM integration, and a storage-provider option that keeps scan data in the customer's own cloud storage. For a product that watches employee devices, customer-controlled storage addresses part of the data-sensitivity concern.
The counterparty itself is the remaining trust question. Traceforce is a young company whose backing in the fetched record is an accelerator batch with no priced round, and it asks enterprises to install a sensor on every endpoint, a dependency security reviewers weigh heavily when they assess vendor viability. Named references or a disclosed round would shorten that conversation. [s1, s17, s28, s3, s27, s4, s21]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Zenity | competes with | Approaches AI security posture management from enterprise copilots and agent platforms, overlapping Traceforce's discovery and governance claims from the platform side. | |
| Prompt Security | competes with | Screens employee AI use, homegrown LLM apps, and agents for prompt injection and data leakage, overlapping the employee-AI coverage Traceforce sells. | |
| WitnessAI | competes with | Watches employee AI use and enforces policy primarily from the network path rather than on the device. | |
| Noma Security | adjacent | Discovers, governs, and protects AI and AI agents across an enterprise, reaching the same activity Traceforce watches from an enterprise platform rather than from the device. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
Add analyzed competitors to compare them side by side with Traceforce.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
pivot urgently
Traceforce sells an agent its customers install and run themselves, which inventories the AI tools on employee devices and can stop a tool call. Instrumenting containers and interrupting a tool call while it runs is specialized endpoint engineering. Its accumulated asset is the Atlas registry of publicly known agents and connectors, a catalog a funded rival could assemble as well. Leaving means pulling the sensor off every managed device, while the scan data stays in storage the customer owns. No cited source says whether the AI tools it watches keep working normally once the sensor comes off. No compliance regime in the cited record requires this product class, so the fit is a security team that wants AI activity on its laptops inventoried and gated.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | The customer's team deploys the agent across its own devices and operates it. What it buys is discovery, risk scoring, and blocking of a tool call, through a self-service trial or a per-device license. Delivery sits at the software-product level. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | Traceforce reaches a customer through the fleet, installed on each covered macOS and Windows device with browser components beside it, and integrated with the mobile device management tools its partner network names. Withdrawing it means a removal pass across that estate. Scan data stays portable, since it persists in storage the customer connects and keeps, so the friction is operational rather than a network effect or a data residency requirement. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 | Traceforce publishes ISO 27001 and SOC 2 Type 2 badges alongside a legal package carrying a vulnerability disclosure policy, a data processing addendum, and a mutual non-disclosure agreement. The cited record names no certification regime or insurer mandate that requires this product class, so nothing in it stands between a customer and a replacement. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | The sensor runs on the device itself, inspecting the assistants and connectors installed across macOS and Windows and the Chrome and Edge browsers, and interrupting a tool call while it runs. It also reaches inside containers, where a host-level endpoint tool sees the container service rather than the processes and tool calls within it. Enforcement in that position is specialized endpoint engineering rather than integration work. The cited sources describe the mechanism and carry no evaluation of the deployed platform. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The motion mixes. A published per-device price and a trial that opens on a work address reach a team that can start on its own, while deployment through mobile device management fits an organization with IT governance behind it. The founders describe midsize enterprises and a reference of more than five hundred employees, and the cited record names no customer, so no procurement or legal gate is shown standing between Traceforce and a replacement. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | Traceforce is a control platform with application features for the security team rather than a tool for a single use. Alongside the sensor and the browser components it publishes a documented application programming interface, a Terraform provider, a Go software development kit, and an announced agent kit that lets customers build on its activity graph. The cited record names no software that depends on Traceforce to run, which keeps it below the infrastructure rung. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 | The Atlas registry rates publicly known agents and connectors, and the cited pages give its size as over 600 while a homepage counter reads more than a thousand curated. Scout separately reports deep inspection of over 500 publicly known connector servers. The asset is scoring of public ecosystem artifacts that a funded rival could assemble. The cited record documents no pooling of customer telemetry across accounts and names no non-public corpus behind the ratings. |
Traceforce aims its messaging at enterprises while its packaging serves small deployments first. The homepage claims trust from companies that power the Fortune 500, yet the visible entry path is a free trial capped at 10 devices for 30 days that requires a Google or Microsoft Workspace email, with an unlimited enterprise version behind SSO setup. The economic buyer is the security leader accountable for AI activity on employee devices, and the deploying persona is the IT administrator pushing MDM policies.
Documented platform support covers both major desktop estates as of July 2026. The quickstart lists Apple Silicon and Intel macOS on Sequoia and Tahoe, Windows 10 and 11 on arm64 and x86, and the Chrome and Edge browsers at version 138 and above. The documentation no longer supports scoping the addressable buyer to Mac-and-Chrome technology estates. Linux endpoints stay undocumented and no fetched page describes how mature the Windows coverage is, so a buyer with a mixed estate cannot tell from the documentation which parts of its fleet Traceforce covers to the same depth.
Named-customer evidence has not appeared since the founders' July 2025 podcast, which described two dozen design-partner conversations and one unnamed first customer. The current demand signals are the two July 2026 founder posts, one reporting 1,000-plus devices at 10 organizations and the other 1,500-plus devices across five midsize enterprises (s27, s28), both vendor-reported and unnamed, with a reference quoted only as a database provider of more than 500 employees.
The reviewed record traces every account of that demand back to the company. The two launch posts are the founders' own, the earlier SDK announcement is the company's (s20), the April and May practitioner writeups are sponsored, the conference listing carries the vendor's own positioning line, and the site's own customer-stories page returns a 404 (s32). The pitch tracks the current agent and connector generation, and Traceforce has published no buyer-side evidence to match it.
The claimed pain points are specific, and the documentation shows the mechanisms Traceforce built against them. Traceforce names unseen AI tools, agents, MCP servers, and skills on devices as the problem, and the docs show the mechanism, with Scout detecting over 100 publicly known desktop and browser agents, deep inspection of ChatGPT Desktop, Claude Desktop, Cursor, Windsurf, Claude Code, and VS Code, and discovery plus deep inspection of over 500 known MCP servers. Tracking extends to the agent's plan tier and underlying model, since plan levels differ in the security controls they include.
Container discovery is the most differentiated documented capability. The docs include a sandbox guide for monitoring AI assistants inside containers, and the sponsored demo writeup explains why it matters, since host-level EDR sees the Docker daemon rather than the agent processes and MCP servers inside. It is also the claim most worth independent verification, which no fetched source provides.
Traceforce's accumulated data sits per customer in the fetched record. The Atlas registry carries curated security ratings, and the vendor's own pages count its size three ways, with the GitHub README stating over 600 MCPs, the Scout docs describing deep inspection of over 500, and the homepage counter showing 1K+ MCPs curated.
TraceGraph builds a real-time AI activity graph from the telemetry of agents on each customer's endpoints, exposed through a TraceGraph Agent SDK that lets customers build on that data engine. The fetched record describes a per-customer design, and while X-Ray results can upload to the hosted Atlas registry (s11), no fetched source documents telemetry pooled across customers into a flywheel. Where the product applies AI, such as X-Ray's LLM-generated pentest plans and its optional LLM analyzer, it consumes third-party frontier models rather than proprietary ones.
Traceforce now sells runtime control alongside discovery. The homepage states that Traceforce tracks every tool call from connectors to command-line agents and stops dangerous actions from running, detects and quarantines a malicious connector, and patches AI packages on the device with policy and audit logs instead of remediation scripts (s1). A homepage counter puts the rate at 10K dangerous actions blocked per second (s23), and no methodology, independent benchmark, or customer-fleet result in the fetched record substantiates that number or shows how the block and warn rules behave in a live estate.
External validation is the standing gap on the commercial product. The third-party capability writeups are Traceforce-sponsored, and the founders' podcast was a Traceforce-focused founder appearance rather than an independent review. One July 2026 tutorial on a non-vendor site comes closest to an exception, documenting the scanner's configuration scan, penetration test, and repository scan commands and its SARIF output format, and carrying no Traceforce sponsorship disclosure (s31). No independent evaluation, benchmark, or customer technical writeup of the paid platform appears in any fetched source.
Traceforce sells founder-first over a self-service entry point. The founders front the public storytelling through a podcast appearance, LinkedIn activity, and a partner listing on the Cyber Security & Cloud Congress North America site, and no go-to-market hire is visible in any fetched source. Their own account is sell-first, with two dozen design-partner conversations coming before any product commitment.
Self-service is real but gated. The trial provisions 10 devices for 30 days and requires a Google or Microsoft Workspace email, so Traceforce filters for organizational buyers even at the free tier, and the trial portal also routes managed service providers through PORT1 (s13). The homepage shows counters of 1K+ devices and 1K+ MCPs curated, the founders' Hacker News post reports 1,000-plus devices across 10 organizations with about 15 AI apps per device (s27), and their Y Combinator launch page reports 1,500-plus devices across five midsize enterprises plus proof-of-concept work with large enterprises (s28). No named customer corroborates any of those figures.
Distribution is the thinnest layer of the strategy. Buyers encounter Traceforce through its own site, its founders, a conference partner listing, sponsored content, and the MCP X-Ray repository, and the reviewed record shows no exclusive arrangement behind any of them. The homepage now names a preferred MDM partner network of Jamf, JumpCloud, NinjaOne, and Iru, a deployment integration rather than a resale motion, and while the contact page now routes MSPs and MSSPs to PORT1 to get started (s2), no cloud marketplace listing appears in fetched sources, so an incumbent shipping equivalent discovery would face little channel disadvantage.
Open source is the distribution experiment carrying the most upside. X-Ray scans connector configurations for free and can upload results to the hosted Atlas service, a tool-to-platform funnel that could seed the registry while creating awareness, and the repository was still taking commits in late July 2026. A July 2026 tutorial on a non-vendor site walked through its commands with no Traceforce sponsorship disclosure on the page (s31), the one write-up in the reviewed record that Traceforce is not shown to have arranged, while the fetched pages document no third-party contributions, so the funnel is a bet rather than an asset.
Public pricing spans three tiers as of July 2026. The free trial covers 10 devices for 30 days with no credit card, the Pro tier is sold per device, and the Enterprise tier, which adds SSO, multi-tenant support, and onboarding services, is custom-priced through sales contact. The rendered Pro card names no figure; the page's structured data carries the numbers, listing $12/month billed yearly or $15/month billed monthly per device (s25), so a buyer reading the page alone leaves without a price.
The published unit is the device, and it is the right unit for this buyer. Security teams count endpoints, so a per-device price makes the spend scale with the fleet a buyer already inventories. The custom Enterprise tier leaves room for site licensing above the metered plan.
Traceforce faces a unit-economics question that public materials do not answer. The monitored surface grows with agents, MCP servers, and skills per device rather than with device count, so device-based pricing absorbs that growth without new revenue, while LLM-driven features such as X-Ray's generated test plans imply model usage whose cost bearer the record does not identify. How Traceforce handles cost spikes, expansion revenue, and agent-driven consumption is not disclosed.
Deployment is MDM-first and documented per platform. The macOS installer ships as a signed and notarized Apple package with two mobileconfig profiles, one granting full disk access and one installing the Chrome and Edge extension, plus Jamf and general MDM post-install scripts. The Windows installer ships as a signed MSI, also packaged for Microsoft Intune, with credentials stored in the SYSTEM Credential Manager, and the quickstart's post-login path starts with creating an API client and downloading the installer, with MDM installation and verification documented separately. The components themselves are non-persistent binaries and a browser extension, per the prerequisites page.
The storage architecture is the most distinctive operational choice. Traceforce stores no scan data on its own infrastructure, and customers connect their own cloud storage, such as Amazon S3, to persist findings and audit logs, which leaves sensitive AI-usage data in the customer's own account rather than the vendor's. Production tenants run at traceforce.co and trial tenants at trial.traceforce.co.
Operational maturity signals are mixed. The documentation index lists versioned release-note pages running through release 1.0.33 (s4, July 2026), a documented API reference, and an llms.txt index formatted for AI assistants, and the quickstart now documents macOS Sequoia and Tahoe, Windows 10 and 11, and the Chrome and Edge browsers as of July 2026. The reviewed documentation covers no Linux endpoint, lists a macOS popup asking permission to find devices on local networks, and states no SLA, status page, or uptime commitment, so a team running Traceforce across a fleet has no published availability commitment to hold it to.
Traceforce publishes a formal trust package. It serves the same two badge assets on its homepage, under a Compliance and Certifications heading (s24), and on its legal page under a Legal and Compliance header, where they render as ISO 27001 and AICPA SOC 2 Type 2 (s34), the standard report type an enterprise buyer asks for. The legal page also publishes a vulnerability disclosure policy, free-trial terms, a data processing addendum, a privacy policy, and a mutual NDA, so the procurement starter kit is present.
What the badges assert is not yet checkable. The rendered legal page carries the pair with no auditor name, no scope statement, and no reporting period (s34), and the trust center at traceforce.trust.cyberbase.ai puts its View audit documents control behind a sign-in (s26), so the scope and period of either attestation are not readable from the public pages. The report type is legible in the badge artwork but not in the markup, since the underlying image files are named ISO 27001 and SOC2 Type 3 with empty alt text on both, so a reviewer reading markup rather than pixels gets a label that matches no report type.
Part of the trust argument is architectural. A vendor whose sensor holds full disk access asks for substantial trust, and Traceforce answers by keeping scan data in the customer's own storage and shipping signed and notarized binaries. Those two choices reduce what a customer must take on faith. The trial additionally requires a Google or Microsoft Workspace email, which qualifies signups as organizational buyers rather than individuals.
The remaining trust question is the counterparty. Traceforce asks enterprises to grant deep endpoint access while the fetched record names no customer and identifies accelerator backing but no priced round, which is exactly the profile a vendor-viability review is designed to catch.
Traceforce shows platform instincts ahead of its platform reality. Traceforce announced a TraceGraph Agent SDK for customers to build their own agents on its platform (s20), the docs expose a documented API reference, an llms.txt file makes the documentation legible to AI assistants, and a Terraform provider supports infrastructure-as-code deployment. Those are the architectural moves of a company designing early for programmatic and agent-driven consumption.
Atlas could become a two-sided dynamic. X-Ray users can upload scan results to Atlas for centralized tracking (s11) and Scout deployments consume its ratings, though no cited page says uploaded results enter the shared registry or improve its ratings. The GitHub README counts over 600 MCPs in the registry, and the fetched pages document no third-party contribution to it.
No third party appears in the reviewed record building on Traceforce. The MDM partner network and the PORT1 MSP route are deployment and onboarding channels (s23, s2), while no marketplace listing, SDK developer ecosystem, or third party building on the SDK appears in fetched sources, and the integration points Traceforce names for the platform are MDM, single sign-on, and customer-owned storage. The SARIF output of the open-source scanner is the clearest advertised path into other security tooling (s11), and no fetched page shows platform findings flowing into a SIEM or a ticketing system.
The founders come from data protection and cloud infrastructure rather than endpoint security, and nothing in the reviewed record shows either of them having shipped an endpoint agent before the one they now ask enterprises to install. CEO Xia Hua was director of engineering at Clumio and built in-memory databases at Oracle, with an MIT education she references in passing on the July 2025 podcast. The Y Combinator launch page describes the pair as the engineers who ran Clumio's engineering organization, Xia as director of engineering and her co-founder as tech lead (s29), and Commvault announced its acquisition of that company in September 2024.
Who the second founder is remains unsettled in the public record. The July 2025 podcast listing names Glenn Mulvaney, the July 2026 launch post introduces the pair as Xia and Varun (s27), and the About page lists Xia Hua and Daniel Seixas, each carrying the title co-founder and CEO (s30). Three names across three public surfaces, a founder interview, a founder-authored launch post, and the company's About page, give a diligence reviewer nothing stable to verify about who is accountable for a sensor holding full disk access.
Execution speed is the team's strongest public evidence. From a February 2025 start, Traceforce shipped a working sensor, a documentation portal with release notes running from 1.0.5 through 1.0.33, displayed ISO 27001 and SOC 2 Type 2 badges, an open-source scanner still taking commits in late July 2026, and a free trial. The fetched GitHub pages document repository activity but no contributor roster, so the engineering bench behind the founders is not measurable from the record.
The organization beyond the founders is mostly invisible. No executive hires, sales leaders, or headcount figures appear in fetched sources, and the founders describe leaning on advisors with prior exits. The reviewed record leaves the sensor's upkeep unattributed beyond the founders.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Traceforce: AI Security & Control Platform for Devices | official | 2026-07-28 |
| f2 | The Security Podcast of Silicon Valley episode 72 with the Traceforce founders | press | 2026-06-11 |
| f3 | Traceforce contact page | official | 2026-07-28 |
| f4 | Launch HN: Traceforce (YC S26), founder post, July 2026 | press | 2026-07-17 |
| f5 | AI Defense Matrix Catalog entry | other | 2026-06-09 |
| f6 | AI Defense Matrix Catalog mapping | other | 2026-07-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Traceforce homepage, AI Security & Control Platform for Devices: runtime control claims (2026-07-28 fetch) “Traceforce tracks every tool call from MCPs to CLIs and stops dangerous actions from being run.” | official | 2026-07-28 |
| s2 | Traceforce contact page “Address: 166 Geary Street, 15th Floor #97 San Francisco, CA, 94108, USA” | official | 2026-07-28 |
| s3 | Traceforce legal page “Vulnerability Disclosure Policy ... Free Trial Data Processing Addendum ... Mutual Non-Disclosure Agreement” | official | 2026-07-28 |
| s4 | Traceforce documentation index “Release 1.0.5 ... Release 1.0.33 ... API Reference” | official | 2026-07-28 |
| s5 | Traceforce documentation on AI agents “Traceforce tracks not just agents but also the plan they run on to identify any gap in security controls.” | official | 2026-07-28 |
| s6 | Traceforce documentation on MCP servers “Traceforce Scout can discover these custom MCP servers and detect security vulnerabilities such as secrets exposure and unpinned versions.” | official | 2026-07-28 |
| s7 | MCP X-Ray repository on GitHub (Apache-licensed, commits through 2026-07-28) “Atlas has over 600 MCPs in its registry, providing a comprehensive security assessment database for the MCP ecosystem. ... It generates production-ready ... SARIF reports ... for seamless integration with security tooling and CI/CD pipelines.” | official | 2026-07-28 |
| s8 | Traceforce GitHub organization “terraform-provider-traceforce ... traceforce-go-sdk ... mcp-xray” | official | 2026-07-28 |
| s9 | The Security Podcast of Silicon Valley: Episode 72 with the Traceforce founders (lines verified verbatim in the served page HTML on 2026-07-28) “we sort of nailed our first customer ... After speaking with like two dozen design partners, right. ... she started with her co-founder, Glenn, back in February 2025 ... building in-memory databases at Oracle ... 4. 0 GPA at MIT” | press | 2026-07-28 |
| s10 | Podbean listing of the Traceforce podcast episode (published July 1, 2025) “TraceForce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries.” | press | 2026-07-28 |
| s11 | Ken Huang on agentic security posture management via Traceforce (Traceforce-sponsored) “Thanks you Traceforce for Sponsoring this article.” | research | 2026-07-28 |
| s12 | Ken Huang on discovering shadow AI agents (Traceforce-sponsored) “Unless a monitoring agent is also installed inside the container, which Scout Lite does automatically, the host-level EDR sees only the Docker daemon, not the Claude Code process, not the MCP servers, not the tool calls.” | research | 2026-07-28 |
| s13 | Traceforce partner listing on the Cyber Security & Cloud Congress North America site (plain fetch returns 403, rendered in a real browser on 2026-07-28) “Traceforce secures AI native workloads running on endpoints.” | press | 2026-07-28 |
| s14 | Commvault announcement of the Clumio acquisition “Sep 24, 2024 ... announced it will acquire Clumio, a technology leader in data protection for critical cloud data in AWS” | press | 2026-07-28 |
| s15 | Traceforce quickstart guide: supported OS architectures and browsers (2026-07-28 fetch) “Apple Silicon/arm64, macOS versions 15.x (Sequoia), 26.x (Tahoe) ... Windows/arm64, Windows versions 10, 11 ... Chrome Browser Stable/Extended Stable v. 138 and above ... Microsoft Edge Browser Stable v. 138 and above” | official | 2026-07-28 |
| s16 | Traceforce homepage: MDM partner network and platform counters (2026-07-28 fetch) “Preferred MDM partner network ... Integrates with Jamf, JumpCloud, NinjaOne, and Iru ... Devices ... 1K+ ... MCPs Curated ... 1K+” | official | 2026-07-28 |
| s17 | Traceforce homepage compliance badges (2026-07-28 fetch, img filename manifest; the rendered badge lettering reads AICPA SOC 2 Type 2, see s28) “img src "ISO 27001.svg" and img src "SOC2 Type 3.svg", both with empty alt text, in the homepage Compliance and Certifications block” | official | 2026-07-28 |
| s18 | Traceforce Scout documentation “Traceforce can discover and perform deep inspection of over 500 publicly known MCP servers.” | official | 2026-07-28 |
| s19 | Traceforce: Platform Overview (2026-07-28 fetch) “Unlike competitors that rely on enterprise APIs, gateways, or EDR/CASB extensions, we operate on-device” | official | 2026-07-28 |
| s20 | Traceforce launch page on Y Combinator (founder-authored, published 2026-07-28) “Securing 1500+ employee devices across 5 medium-sized enterprises. ... Customer quote from a leading database provider with over 500 employees” | official | 2026-07-28 |
| s21 | Traceforce launch page on Y Combinator: founder backgrounds and batch (2026-07-28) “We ran engineering at Clumio, a cyber-resilience company acquired by Commvault in 2024, where Xia was Director of Engineering and Varun was tech lead. ... Summer 2026” | official | 2026-07-28 |
| s22 | Launch HN: Traceforce, company-wide security monitoring for AI apps (founder post, July 2026) “Traceforce is currently deployed across more than 1,000 devices at 10 organizations.” | official | 2026-07-28 |
| s23 | Traceforce About Us page: founder listing (2026-07-28 fetch) “Xia Hua Co-Founder & CEO ... Daniel Seixas Co-Founder & CEO” | official | 2026-07-28 |
| s24 | Traceforce pricing page: three published tiers, per-device figures carried in the page's structured data (2026-07-28 fetch) “$12/month billed yearly or $15/month billed monthly per device” | official | 2026-07-28 |
| s25 | Independent developer walkthrough of the MCP X-Ray scanner, tinyash.com, July 2026 “今天介绍 MCP X-Ray ,一款由 Traceforce(YC S26) 开源的 MCP 服务器安全扫描和渗透测试工具。” | press | 2026-07-28 |
| s26 | Probe of the Traceforce customer-stories page linked from site navigation, HTTP 404 on 2026-07-28 | official | 2026-07-28 |
| s27 | Traceforce Trust Center probe (linked from the legal page, rendered in a browser 2026-07-28, audit documents behind sign-in) “View audit documents” | official | 2026-07-28 |
| s28 | Traceforce legal page badges (agent-browser render 2026-07-28, capture at scratchpad/traceforce/legal-render-2026-07-28.png, no auditor, scope, or period shown) “badge images served as ISO 27001.svg and SOC2 Type 3.svg render as "ISO 27001" and "AICPA SOC2 TYPE 2" beneath the Legal & Compliance header” | official | 2026-07-28 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Traceforce homepage, AI Security & Control Platform for Devices: runtime control claims (2026-07-28 fetch) “Traceforce tracks every tool call from MCPs to CLIs and stops dangerous actions from being run.” | official | 2026-07-28 |
| s2 | Traceforce contact page (MSP and MSSP route through PORT1 verified 2026-07-28) “Address: 166 Geary Street, 15th Floor #97 San Francisco, CA, 94108, USA” | official | 2026-07-28 |
| s3 | Traceforce legal page “Vulnerability Disclosure Policy ... Free Trial Data Processing Addendum ... Mutual Non-Disclosure Agreement” | official | 2026-07-28 |
| s4 | Traceforce documentation index “Release 1.0.5 ... Release 1.0.33 ... API Reference” | official | 2026-07-28 |
| s5 | Traceforce documentation on AI agents “Traceforce tracks not just agents but also the plan they run on to identify any gap in security controls.” | official | 2026-07-28 |
| s6 | Traceforce documentation on MCP servers “Traceforce Scout can discover these custom MCP servers and detect security vulnerabilities such as secrets exposure and unpinned versions.” | official | 2026-07-28 |
| s7 | Traceforce quickstart guide: supported OS architectures and browsers (2026-07-28 fetch) “Apple Silicon/arm64, macOS versions 15.x (Sequoia), 26.x (Tahoe) ... Windows/arm64, Windows versions 10, 11 ... Chrome Browser Stable/Extended Stable v. 138 and above ... Microsoft Edge Browser Stable v. 138 and above” | official | 2026-07-28 |
| s8 | Traceforce Scout documentation “Traceforce can discover and perform deep inspection of over 500 publicly known MCP servers.” | official | 2026-07-28 |
| s9 | Traceforce X-Ray documentation “Executes security test plans by making actual tool calls against MCP servers. Test plans are LLM-generated” | official | 2026-07-28 |
| s10 | Traceforce storage provider integration guide “Traceforce does not store scan data on its own infrastructure. ... Amazon S3” | official | 2026-07-28 |
| s11 | MCP X-Ray repository on GitHub (Apache-licensed, commits through 2026-07-28) “Atlas has over 600 MCPs in its registry, providing a comprehensive security assessment database for the MCP ecosystem. ... It generates production-ready ... SARIF reports ... for seamless integration with security tooling and CI/CD pipelines.” | official | 2026-07-28 |
| s12 | Traceforce GitHub organization “terraform-provider-traceforce ... traceforce-go-sdk ... mcp-xray” | official | 2026-07-28 |
| s13 | Traceforce trial signup portal (JavaScript app, rendered in a browser 2026-07-28) “Work with PORT1 to set up a free trial with service provider features.” | official | 2026-07-28 |
| s14 | The Security Podcast of Silicon Valley episode 72 with the Traceforce founders “Traceforce is actually an AI data security company that she started with her co-founder, Glenn, back in February 2025. Prior to Traceforce, Shia was the director of engineering at Clumio ... building in-memory databases at Oracle” | press | 2026-07-28 |
| s15 | Podbean listing of the Traceforce podcast episode (published July 1, 2025) “Traceforce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries.” | press | 2026-07-28 |
| s16 | Ken Huang on agentic security posture management via Traceforce (Traceforce-sponsored) “Thanks you Traceforce for Sponsoring this article.” | research | 2026-07-28 |
| s17 | Ken Huang on discovering shadow AI agents (Traceforce-sponsored) “Unless a monitoring agent is also installed inside the container, which Scout Lite does automatically, the host-level EDR sees only the Docker daemon, not the Claude Code process, not the MCP servers, not the tool calls.” | research | 2026-07-28 |
| s18 | Traceforce partner listing on the Cyber Security & Cloud Congress North America site (plain fetch returns 403, rendered in a real browser on 2026-07-28) “Traceforce secures AI native workloads running on endpoints.” | press | 2026-07-28 |
| s19 | Commvault announcement of the Clumio acquisition “Sep 24, 2024 ... announced it will acquire Clumio, a technology leader in data protection for critical cloud data in AWS” | press | 2026-07-28 |
| s20 | Traceforce TraceGraph Agent SDK announcement on LinkedIn “we're excited to introduce the TraceGraph Agent SDK, enabling our customers to build their own agents on top of this rich data engine” | official | 2026-07-28 |
| s21 | Traceforce quickstart guide: registration and free trial (2026-07-28 fetch) “The free trial supports up to 10 devices for 30 days and requires a Google or Microsoft Workspace email.” | official | 2026-07-28 |
| s22 | The Security Podcast of Silicon Valley episode 72: first customer, design partner, and MIT lines verified verbatim in the served page HTML (2026-07-28 fetch) “we sort of nailed our first customer, figured out that first product we want to build, right. After speaking with like two dozen design partners, right. ... That, that was just like last month, right. We started in February. ... much harder than getting a 4. 0 GPA at MIT” | press | 2026-07-28 |
| s23 | Traceforce homepage: MDM partner network and platform counters (2026-07-28 fetch) “Preferred MDM partner network ... Integrates with Jamf, JumpCloud, NinjaOne, and Iru ... Devices ... 1K+ ... MCPs Curated ... 1K+ ... dangerous actions blocked per sec ... 10K” | official | 2026-07-28 |
| s24 | Traceforce homepage compliance badges (2026-07-28 fetch, img filename manifest; the rendered badge lettering reads AICPA SOC 2 Type 2, see s34) “img src "ISO 27001.svg" and img src "SOC2 Type 3.svg", both with empty alt text, in the homepage Compliance and Certifications block” | official | 2026-07-28 |
| s25 | Traceforce pricing page: three published tiers, per-device figures carried in the page's structured data (2026-07-28 fetch) “$12/month billed yearly or $15/month billed monthly per device” | official | 2026-07-28 |
| s26 | Traceforce Trust Center probe (linked from the legal page, rendered in a browser 2026-07-28, audit documents behind sign-in) “View audit documents” | official | 2026-07-28 |
| s27 | Launch HN: Traceforce, company-wide security monitoring for AI apps (founder post, July 2026) “Hey HN, we're Xia and Varun, the founders of Traceforce ... Traceforce is currently deployed across more than 1,000 devices at 10 organizations. On average, we discover over 15 AI applications per device with each application connected to 5-10 MCPs.” | official | 2026-07-28 |
| s28 | Traceforce launch page on Y Combinator (founder-authored, published 2026-07-28) “Securing 1500+ employee devices across 5 medium-sized enterprises. ... Customer quote from a leading database provider with over 500 employees” | official | 2026-07-28 |
| s29 | Traceforce launch page on Y Combinator: founder backgrounds and batch (2026-07-28) “We ran engineering at Clumio, a cyber-resilience company acquired by Commvault in 2024, where Xia was Director of Engineering and Varun was tech lead. ... Summer 2026” | official | 2026-07-28 |
| s30 | Traceforce About Us page: founder listing (2026-07-28 fetch) “Xia Hua Co-Founder & CEO ... Daniel Seixas Co-Founder & CEO” | official | 2026-07-28 |
| s31 | Independent developer walkthrough of the MCP X-Ray scanner, tinyash.com, July 2026 “今天介绍 MCP X-Ray ,一款由 Traceforce(YC S26) 开源的 MCP 服务器安全扫描和渗透测试工具。” | press | 2026-07-28 |
| s32 | Probe of the Traceforce customer-stories page linked from site navigation, HTTP 404 on 2026-07-28 | official | 2026-07-28 |
| s33 | Traceforce: Platform Overview (2026-07-28 fetch) “Unlike competitors that rely on enterprise APIs, gateways, or EDR/CASB extensions, we operate on-device” | official | 2026-07-28 |
| s34 | Traceforce legal page badges (agent-browser render 2026-07-28, capture at scratchpad/traceforce/legal-render-2026-07-28.png, no auditor, scope, or period shown) “badge images served as ISO 27001.svg and SOC2 Type 3.svg render as "ISO 27001" and "AICPA SOC2 TYPE 2" beneath the Legal & Compliance header” | official | 2026-07-28 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.