Companies

Traceforce

traceforce.ai

Traceforce secures enterprise AI applications on employee devices with visibility, remediation, and real-time runtime controls.

HQSan Francisco, California, United States
Employees1-50
1 active role
Jobs checked 18h ago
CybersecurityB2B SaaS

About

Traceforce builds an endpoint-based AI security and control platform for enterprise security teams, providing visibility into AI apps, MCPs, skills, prompts, tool calls, and outcomes across employee devices. It differentiates through on-device monitoring and runtime controls that can warn about or block unsafe actions, rather than relying primarily on enterprise APIs, gateways, or network-based tools.

Market

Traceforce competes in enterprise AI security posture management and shadow-AI governance, with a specific focus on securing AI agents, MCPs, browser copilots, desktop applications, and CLI tools across employee devices. It differentiates from gateway-, API-, EDR-, and CASB-oriented approaches by running on the endpoint, building an application-level graph of AI apps, MCPs, skills, tools, prompts, and outcomes, and blocking or remediating unsafe behavior where it executes. Its competitive set includes enterprise AI-DLP and AI-access-security offerings from dope.security, Microsoft, Netskope, Zscaler, Nightfall, and Palo Alto Networks, although Traceforce's MCP and device-layer specialization is narrower and more application-aware than many general-purpose controls.

Target Customers

Traceforce targets small-to-medium enterprises with 200+ employees that are rapidly adopting AI coding assistants, ChatGPT, Claude, and MCPs. Its primary buyers and users are security, IT, and AI-platform teams that need organization-wide visibility and control over AI applications on employee devices; the company also reports pilots or deployments involving larger enterprises.

At a Glance

Problem

Traceforce addresses the security blind spot created when employees use AI applications and agents outside traditional browser, network, and enterprise-API controls. ChatGPT, Claude, coding agents, MCPs, and locally installed tools can access sensitive data and take consequential actions directly from laptops and other devices, while security teams struggle to see what is running or how it is connected. The pain is both preventative and incident-driven: a single agent can expose credentials or sensitive data, and the resulting investigation, credential rotation, and cleanup can take weeks.

The killer use case is stopping an unsafe agent action at the endpoint before it becomes a breach—for example, preventing an AI coding agent from extracting database credentials and publishing them to GitHub, or blocking an agent from uploading a client list, altering financial records, or deleting a production database. Traceforce is designed for security teams at companies ranging from startups to Fortune 500 enterprises that need to govern rapidly expanding, employee-adopted AI usage without relying solely on after-the-fact network monitoring.

Product / Service

Traceforce is an AI security posture management and control platform that operates directly on devices. It connects to an organization’s mobile-device-management system, inventories AI applications, agents, MCP servers, and skills across the fleet, maps what data they can reach, and applies security policies and risk ratings. The platform provides continuous monitoring, real-time warnings or blocks for unsafe actions, and automatic remediation of device-level risks, with integrations including Jamf, JumpCloud, NinjaOne, and Iru.

The delivery model emphasizes lightweight deployment: the company says organizations can connect their MDM and begin securing a fleet in roughly 15 minutes, while its launch materials describe installation in under five minutes and an inventory within 30 minutes. Its benefit is visibility plus enforcement at the point where the action occurs, rather than merely logging activity after it has traversed the network; Traceforce also offers an MCP registry and an open-source MCP security-testing tool for identifying vulnerable connectors.

Market

Traceforce competes in the emerging AI security, AI security posture management, shadow-AI governance, and agent/MCP runtime-security markets. Its endpoint-first positioning differentiates it from gateway- and API-centered tools that may miss self-installed applications and the precise connections an agent makes to local data. Adjacent alternatives include Obsidian Security’s shadow-AI controls and broader AI-security offerings such as Cyberhaven, Microsoft Purview, Palo Alto Networks’ AI Access Security, and Varonis; these should be viewed as overlapping category competitors rather than proof of direct feature parity.

The company appears to have early commercial traction rather than being merely pre-launch: its Y Combinator profile reports deployments across more than 1,500 employee devices at five medium-sized enterprises, a deployment at a 500-plus-person company, and proof-of-concept work with Fortune 500 companies. The profile identifies Traceforce as a Summer 2026, active San Francisco startup with two employees and one open role. The reviewed company materials do not disclose a verified revenue figure or funding total, so the strongest public traction signals are its customer deployments, pilots, and reported enterprise validation.

Founders & Leadership

Xia HuaFounder
Co-founder and CEO
Varun WadhwaFounder
Co-founder and CTO

Funding History

2026-05
Seed$200K

Antler

Recent News

2026-07-28product
Traceforce — Catch risky agent actions your security gateway will never spot

Traceforce launched on Y Combinator’s Launch YC, presenting an endpoint-based AI security platform that inventories AI apps, MCPs, and skills across devices and blocks dangerous actions in real time. The launch says the product was already deployed at a 500-plus-person company and in Fortune 500 proofs of concept.

2026-07-14product
Secure AI-Native Apps on Employee Devices

Traceforce’s product update describes securing browser AI copilots, desktop AI applications, CLI agents, MCP servers, and skills directly on employee devices. It highlights inventory, automated vulnerability remediation, runtime control, and investigation capabilities.

2025-10-06partnership
Traceforce adds integrations with Jamf, JumpCloud, NinjaOne, and Iru

Traceforce’s official site identified a preferred MDM partner network integrating with Jamf, JumpCloud, NinjaOne, and Iru. The integrations are positioned as a way to deploy Traceforce through existing IT management tools.

Active Roles

1
San Francisco, CA, US / Remote (US)/Engineering/32d ago

Business Model

Traceforce appears to monetize through an enterprise SaaS security subscription priced per protected device. Public pricing discussion indicated that the company was considering approximately $15 per device per month, although the amount was not finalized; the company also offers a free trial.

Products

Traceforce AI Security & Control Platform: an on-device agent and management dashboard for AI-app inventory, vulnerability remediation, runtime controls, and agentic investigationTraceforce Atlas: an MCP and AI-agent registry plus centralized security management, scoring, policy, and tracking platformMCP X-Ray: an open-source MCP security scanner and penetration-testing tool that produces SARIF reports and can upload results to Atlas

Customers

No named enterprise customers publicly disclosed

Tech Stack

Go for the Traceforce endpoint binaryNode.js for the browser extensionLightweight on-device agent and browser-extension architectureModel Context Protocol (MCP) discovery, registry, and connectivity graphingLLM integrations for MCP analysis and penetration testing, including Anthropic, OpenAI, and AWS BedrockRule-based token analysis and YARA scanningSARIF reporting for security-tool and CI/CD integration

Competitors

dope.security
Microsoft Purview
Netskope
Zscaler
Nightfall AI
Palo Alto Networks AI Access Security