About
Traceforce builds an endpoint-based AI security and control platform for enterprise security teams, providing visibility into AI apps, MCPs, skills, prompts, tool calls, and outcomes across employee devices. It differentiates through on-device monitoring and runtime controls that can warn about or block unsafe actions, rather than relying primarily on enterprise APIs, gateways, or network-based tools.
Market
Traceforce competes in enterprise AI security posture management and shadow-AI governance, with a specific focus on securing AI agents, MCPs, browser copilots, desktop applications, and CLI tools across employee devices. It differentiates from gateway-, API-, EDR-, and CASB-oriented approaches by running on the endpoint, building an application-level graph of AI apps, MCPs, skills, tools, prompts, and outcomes, and blocking or remediating unsafe behavior where it executes. Its competitive set includes enterprise AI-DLP and AI-access-security offerings from dope.security, Microsoft, Netskope, Zscaler, Nightfall, and Palo Alto Networks, although Traceforce's MCP and device-layer specialization is narrower and more application-aware than many general-purpose controls.
Traceforce targets small-to-medium enterprises with 200+ employees that are rapidly adopting AI coding assistants, ChatGPT, Claude, and MCPs. Its primary buyers and users are security, IT, and AI-platform teams that need organization-wide visibility and control over AI applications on employee devices; the company also reports pilots or deployments involving larger enterprises.
At a Glance
Problem
Traceforce addresses the security blind spot created when employees use AI applications and agents outside traditional browser, network, and enterprise-API controls. ChatGPT, Claude, coding agents, MCPs, and locally installed tools can access sensitive data and take consequential actions directly from laptops and other devices, while security teams struggle to see what is running or how it is connected. The pain is both preventative and incident-driven: a single agent can expose credentials or sensitive data, and the resulting investigation, credential rotation, and cleanup can take weeks.
The killer use case is stopping an unsafe agent action at the endpoint before it becomes a breach—for example, preventing an AI coding agent from extracting database credentials and publishing them to GitHub, or blocking an agent from uploading a client list, altering financial records, or deleting a production database. Traceforce is designed for security teams at companies ranging from startups to Fortune 500 enterprises that need to govern rapidly expanding, employee-adopted AI usage without relying solely on after-the-fact network monitoring.
Product / Service
Traceforce is an AI security posture management and control platform that operates directly on devices. It connects to an organization’s mobile-device-management system, inventories AI applications, agents, MCP servers, and skills across the fleet, maps what data they can reach, and applies security policies and risk ratings. The platform provides continuous monitoring, real-time warnings or blocks for unsafe actions, and automatic remediation of device-level risks, with integrations including Jamf, JumpCloud, NinjaOne, and Iru.
The delivery model emphasizes lightweight deployment: the company says organizations can connect their MDM and begin securing a fleet in roughly 15 minutes, while its launch materials describe installation in under five minutes and an inventory within 30 minutes. Its benefit is visibility plus enforcement at the point where the action occurs, rather than merely logging activity after it has traversed the network; Traceforce also offers an MCP registry and an open-source MCP security-testing tool for identifying vulnerable connectors.
Market
Traceforce competes in the emerging AI security, AI security posture management, shadow-AI governance, and agent/MCP runtime-security markets. Its endpoint-first positioning differentiates it from gateway- and API-centered tools that may miss self-installed applications and the precise connections an agent makes to local data. Adjacent alternatives include Obsidian Security’s shadow-AI controls and broader AI-security offerings such as Cyberhaven, Microsoft Purview, Palo Alto Networks’ AI Access Security, and Varonis; these should be viewed as overlapping category competitors rather than proof of direct feature parity.
The company appears to have early commercial traction rather than being merely pre-launch: its Y Combinator profile reports deployments across more than 1,500 employee devices at five medium-sized enterprises, a deployment at a 500-plus-person company, and proof-of-concept work with Fortune 500 companies. The profile identifies Traceforce as a Summer 2026, active San Francisco startup with two employees and one open role. The reviewed company materials do not disclose a verified revenue figure or funding total, so the strongest public traction signals are its customer deployments, pilots, and reported enterprise validation.
Founders & Leadership
Funding History
Antler
Recent News
Traceforce launched on Y Combinator’s Launch YC, presenting an endpoint-based AI security platform that inventories AI apps, MCPs, and skills across devices and blocks dangerous actions in real time. The launch says the product was already deployed at a 500-plus-person company and in Fortune 500 proofs of concept.
Traceforce’s product update describes securing browser AI copilots, desktop AI applications, CLI agents, MCP servers, and skills directly on employee devices. It highlights inventory, automated vulnerability remediation, runtime control, and investigation capabilities.
Traceforce’s official site identified a preferred MDM partner network integrating with Jamf, JumpCloud, NinjaOne, and Iru. The integrations are positioned as a way to deploy Traceforce through existing IT management tools.
Active Roles
1Business Model
Traceforce appears to monetize through an enterprise SaaS security subscription priced per protected device. Public pricing discussion indicated that the company was considering approximately $15 per device per month, although the amount was not finalized; the company also offers a free trial.