Traceforce

Security for AI

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software.
Founded 2025
Last updated 2026-07-17

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Traceforce watches the AI assistants, agents, and MCP servers running on employee computers, a layer that endpoint and network security products were not built to see. Clumio alumna Xia Hua co-founded the San Francisco company in February 2025, it sits in Y Combinator's S26 batch, and by mid-2026 it had shipped an endpoint sensor, a browser extension, an open-source MCP scanner, a curated risk registry, and customer-owned scan storage. The July 2026 quickstart documents Windows 10 and 11 and Microsoft Edge alongside macOS and Chrome. The founders' July 2026 Launch HN post reports 1,000-plus devices across 10 organizations, none named. Its edge today is being early to a surface incumbents miss, while the same discovery is software an EDR vendor could fold into sensors already running.

Sourced Details

Description Traceforce runs on company devices to secure browser AI, desktop apps, and CLI agents, giving security teams full visibility into how those AI tools get used across the fleet. [f1]
Founded 2025 [f2]
HQ San Francisco, California, US [f3]
Latest funding Y Combinator S26 batch participation, no priced round disclosed, 2026 [f4]
Deployment SaaS [f5]
Compliance ISO 27001, SOC 2 Type 1 [f5]

Products

Product What it does
Traceforce Traceforce: Endpoint AI security posture management that discovers the AI tools, agents, MCP servers, and skills running on devices, scores context-aware risk, and automates remediation.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

TraceForce is endpoint AI security posture management that discovers the AI tools, agents, MCP servers, and skills running on devices, scores context-aware risk, and automates remediation. It is mapped to the AI Defense Matrix. [f6]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Emerging 21 /40 Emerging: Market readiness of 24 or below. Below the typical band, where few analyzed companies sit.
Dimension Score
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. 3/5
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 3/5
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 3/5
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 2/5
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 2/5
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5

Unlock the Full Analysis

The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.

One-time purchase: $20 per profile.

Unlock

Reading several? Unlock the entire catalog.

Business Risks
Problem & Market
Product Capabilities
Competitive Positioning
Go-to-Market & Traction
Team & Credibility
Trust Readiness
Competitors

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Exposed 9 /21 Exposed: Defensibility of 12 or below. The position is exposed as AI lowers the cost of building commodity software. pivot urgently

Dimension Score
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 1/3
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 2/3
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 2/3
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 1/3
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3

Unlock the Full Analysis

The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.

One-time purchase: $20 per profile.

Unlock

Reading several? Unlock the entire catalog.

Strategic Market Segmentation
Product Capabilities & AI Advantages
Sales Engagement & Go-to-Market
Pricing Model
Product Delivery & Operations
Earning Customers' Trust
Platform Strategy & Ecosystem Positioning
Team & Execution Capability

Sources

Company Detail Sources (6)
Id Source Tier Accessed
f1 Traceforce: AI Security & Control Platform for Devices official 2026-07-09
f2 The Security Podcast of Silicon Valley episode 72 with the Traceforce founders press 2026-06-11
f3 Traceforce contact page official 2026-07-02
f4 Launch HN: Traceforce (YC S26), founder post, July 2026 press 2026-07-17
f5 AI Defense Matrix Catalog entry other 2026-06-09
f6 AI Defense Matrix Catalog mapping other 2026-06-23
Profile Analysis Sources (19)
Id Source Tier Accessed
s1 Traceforce homepage
“EDR monitors processes. CASB monitors network traffic. Neither sees AI running locally on your devices.”
official 2026-06-12
s2 Traceforce contact page (relocated from /contact, which now returns 404)
“Reach us at 166 Geary Street, San Francisco, CA 94108.”
official 2026-07-02
s3 Traceforce legal page official 2026-06-12
s4 Traceforce documentation index official 2026-06-12
s5 Traceforce documentation on AI agents
“Traceforce tracks not just agents but also the plan they run on to identify any gap in security controls.”
official 2026-06-12
s6 Traceforce documentation on MCP servers
“Traceforce Scout can discover these custom MCP servers and detect security vulnerabilities such as secrets exposure and unpinned versions.”
official 2026-06-12
s7 MCP X-Ray repository on GitHub
“Atlas has over 600 MCPs in its registry, providing a comprehensive security assessment database for the MCP ecosystem.”
official 2026-06-12
s8 Traceforce GitHub organization official 2026-06-12
s9 The Security Podcast of Silicon Valley: Episode 72 with the Traceforce founders (lines verified verbatim in the served page HTML on 2026-07-02)
“we sort of nailed our first customer, figured out that first product we want to build, right. After speaking with like two dozen design partners, right. ... That, that was just like last month, right. We started in February. ... much harder than getting a 4. 0 GPA at MIT”
press 2026-07-02
s10 Podbean listing of the Traceforce podcast episode (published July 1, 2025)
“TraceForce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries.”
press 2026-06-12
s11 Ken Huang on agentic security posture management via Traceforce (Traceforce-sponsored)
“Thanks you TraceForce for Sponsoring this article.”
research 2026-06-12
s12 Ken Huang on discovering shadow AI agents (Traceforce-sponsored)
“Unless a monitoring agent is also installed inside the container, which Scout Lite does automatically, the host-level EDR sees only the Docker daemon, not the Claude Code process, not the MCP servers, not the tool calls.”
research 2026-06-12
s13 Traceforce partner listing at Cyber Security & Cloud Congress North America 2026 press 2026-06-12
s14 Commvault announcement of the Clumio acquisition
“announced it will acquire Clumio, a technology leader in data protection for critical cloud data in AWS”
press 2026-06-12
s15 Traceforce quickstart guide: supported OS architectures and browsers (2026-07-02 fetch)
“Apple Silicon/arm64, macOS versions 15.x (Sequoia), 26.x (Tahoe) ... Windows/arm64, Windows versions 10, 11 ... Chrome Browser Stable/Extended Stable v. 138 and above ... Microsoft Edge Browser Stable v. 138 and above”
official 2026-07-02
s16 Traceforce homepage: MDM partner network and platform counters (2026-07-02 fetch)
“Preferred MDM partner network ... Integrates with Jamf, JumpCloud, NinjaOne, and Iru ... Devices ... 1K+ ... MCPs Curated ... 1K+”
official 2026-07-02
s17 Traceforce homepage footer badges (2026-07-02 fetch, img alt and filename manifest)
“img alt "ISO logo" beside img src SOC2%20Type%202.svg with alt "SOC2 logo" in the homepage badge block”
official 2026-07-02
s18 Traceforce Scout documentation
“Traceforce can discover and perform deep inspection of over 500 publicly known MCP servers.”
official 2026-07-02
s19 Traceforce: Platform Overview (2026-07-02 fetch)
“Unlike competitors that rely on enterprise APIs, gateways, or EDR/CASB extensions, we operate on-device”
official 2026-07-02
Deep-Dive Sources (27)
Id Source Tier Accessed
s1 Traceforce homepage
“EDR monitors processes. CASB monitors network traffic. Neither sees AI running locally on your devices.”
official 2026-06-11
s2 Traceforce contact page (relocated from /contact, MSP/MSSP PORT1 route verified 2026-07-17)
“Reach us at 166 Geary Street, San Francisco, CA 94108.”
official 2026-07-02
s3 Traceforce legal page
“Vulnerability Disclosure Policy ... Free Trial Data Processing Addendum ... Mutual Non-Disclosure Agreement”
official 2026-06-15
s4 Traceforce documentation index
“Release 1.0.5 ... Release 1.0.33”
official 2026-07-17
s5 Traceforce documentation on AI agents
“Traceforce tracks not just agents but also the plan they run on to identify any gap in security controls.”
official 2026-06-11
s6 Traceforce documentation on MCP servers
“Traceforce Scout can discover these custom MCP servers and detect security vulnerabilities such as secrets exposure and unpinned versions.”
official 2026-06-11
s7 Traceforce quickstart guide: supported OS architectures and browsers, expanded from macOS and Chrome (2026-07-02 fetch)
“Apple Silicon/arm64, macOS versions 15.x (Sequoia), 26.x (Tahoe) ... Windows/arm64, Windows versions 10, 11 ... Chrome Browser Stable/Extended Stable v. 138 and above ... Microsoft Edge Browser Stable v. 138 and above”
official 2026-07-02
s8 Traceforce Scout documentation
“Traceforce can discover and perform deep inspection of over 500 publicly known MCP servers.”
official 2026-06-11
s9 Traceforce X-Ray documentation
“Executes security test plans by making actual tool calls against MCP servers. Test plans are LLM-generated”
official 2026-06-11
s10 Traceforce storage provider integration guide
“Traceforce does not store scan data on its own infrastructure.”
official 2026-06-11
s11 MCP X-Ray repository on GitHub
“Atlas has over 600 MCPs in its registry, providing a comprehensive security assessment database for the MCP ecosystem.”
official 2026-06-11
s12 Traceforce GitHub organization official 2026-06-11
s13 Traceforce trial signup portal
“Use your company address (Google Workspace or Microsoft 365). Personal @gmail.com, @outlook.com, and similar consumer accounts are not supported.”
official 2026-06-11
s14 The Security Podcast of Silicon Valley episode 72 with the Traceforce founders
“Traceforce is actually an AI data security company that she started with her co-founder, Glenn, back in February 2025. Prior to Traceforce, Shia was the director of engineering at Clumio”
press 2026-06-18
s15 Podbean listing of the Traceforce podcast episode (published July 1, 2025)
“Traceforce.ai founders Xia Hua and Glenn Mulvaney reveal the next big security risk: autonomous agents that operate beyond permission boundaries.”
press 2026-06-11
s16 Ken Huang on agentic security posture management via Traceforce (Traceforce-sponsored)
“Thanks you Traceforce for Sponsoring this article.”
research 2026-06-11
s17 Ken Huang on discovering shadow AI agents (Traceforce-sponsored)
“Unless a monitoring agent is also installed inside the container, which Scout Lite does automatically, the host-level EDR sees only the Docker daemon, not the Claude Code process, not the MCP servers, not the tool calls.”
research 2026-06-11
s18 Traceforce partner listing at Cyber Security & Cloud Congress North America 2026 press 2026-06-11
s19 Commvault announcement of the Clumio acquisition
“announced it will acquire Clumio, a technology leader in data protection for critical cloud data in AWS”
press 2026-06-11
s20 Traceforce TraceGraph Agent SDK announcement on LinkedIn
“we're excited to introduce the TraceGraph Agent SDK, enabling our customers to build their own agents on top of this rich data engine”
official 2026-06-18
s21 Traceforce quickstart guide: registration and free trial (2026-07-02 fetch)
“The free trial supports up to 10 devices for 30 days and requires a Google or Microsoft Workspace email.”
official 2026-07-02
s22 The Security Podcast of Silicon Valley episode 72: first customer, design partner, and MIT lines verified verbatim in the served page HTML (2026-07-02 fetch)
“we sort of nailed our first customer, figured out that first product we want to build, right. After speaking with like two dozen design partners, right. ... That, that was just like last month, right. We started in February. ... much harder than getting a 4. 0 GPA at MIT”
press 2026-07-02
s23 Traceforce homepage: MDM partner network and platform counters (2026-07-02 fetch)
“Preferred MDM partner network ... Integrates with Jamf, JumpCloud, NinjaOne, and Iru ... Devices ... 1K+ ... MCPs Curated ... 1K+”
official 2026-07-02
s24 Traceforce homepage footer badges (2026-07-02 fetch, img alt and filename manifest)
“img alt "ISO logo" beside img src SOC2%20Type%202.svg with alt "SOC2 logo" in the homepage badge block”
official 2026-07-02
s25 Traceforce: Pricing Plans (2026-07-17 fetch, figures in the JSON-LD offer data, visible Pro card figure-free)
“$12/month billed yearly or $15/month billed monthly per device”
official 2026-07-17
s26 Traceforce Trust Center (cyberbase-hosted, linked from the legal page, JS app, no attestation text in the raw fetch, 2026-07-17)
“Traceforce Trust Center”
official 2026-07-17
s27 Launch HN: Traceforce (YC S26), company-wide security monitoring for AI apps (founder post, July 2026)
“Hey HN, we're Xia and Varun, the founders of Traceforce ... Traceforce is currently deployed across more than 1,000 devices at 10 organizations. On average, we discover over 15 AI applications per device with each application connected to 5-10 MCPs.”
official 2026-07-17

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Do not republish its content or share access without the operator's permission.