
Traceforce
Security monitoring for AI apps and agents running on your team's devices, not just the browser.
Overview
Traceforce is a Y Combinator S26 startup (founders Xia Hua and Glenn Mulvaney) built around a specific gap: employees now run AI coding agents, MCP servers, and desktop AI apps directly on their machines, and none of that activity passes through a browser or network gateway that traditional EDR/CASB tools can see. Traceforce inspects that activity on-device instead, giving IT and security teams a live registry of every AI app and MCP in use, blocking risky tool calls before they execute (the company cites stopping a Cursor SQL injection attempt as an example), and auto-remediating known-vulnerable AI packages without manual scripts. Its "TraceGraph" feature ties an incident's prompts, tool calls, and outcome together for investigation, and setup is billed as roughly 15 minutes by riding on MDM tools IT teams already run, like Jamf, JumpCloud, and NinjaOne. It's ISO 27001 and SOC 2 Type II certified, and reported real deployments across 1,000+ devices at 10 organizations as of its August 2026 Hacker News launch, modest numbers reflecting how early it still is.
Key Features
Real-time registry of every AI app, agent, and MCP connector running on a device
Runtime blocking of dangerous tool calls/destructive commands before execution
Automatic remediation/patching of known-vulnerable AI packages, no manual scripts
TraceGraph: links prompts, tool calls, and outcomes for incident investigation
Sensitive-data leak detection (API keys, secrets) inside Claude, ChatGPT, Copilot, Cursor, Claude Code, Codex
Self-serve setup (about 15 minutes) via existing MDM tools: Jamf, JumpCloud, NinjaOne
ISO 27001 and SOC 2 Type II certified
API access to raw telemetry
Pros
Covers a real, specific blind spot — on-device AI/agent/MCP activity that browser- or network-based tools genuinely can't see
Cites concrete, real catches (blocked a Cursor SQL injection attempt, flagged a leaked AWS key, auto-patched a vulnerable LiteLLM version) rather than vague claims
Fast, self-serve deployment through MDM tools IT teams already use (Jamf, JumpCloud, NinjaOne)
Y Combinator-backed (S26) and already ISO 27001 + SOC 2 Type II certified, unusually early for its stage
Inspection happens locally on-device; founders say prompts aren't stored by default
Cons
No published price for its actual paid tier — "Pro" is per-device but the number is hidden behind a signup/contact flow, and Enterprise is a fully custom quote
Very early-stage: about 1,000 devices across 10 organizations as of its own August 2026 HN launch, and no G2/Capterra reviews exist yet to check independently
At its own Hacker News launch, commenters pointed to competitors already in the space (Runlayer, Bluerock) and pressed founders on what's actually different
Founders themselves acknowledged manual tuning to cut false positives is still "very hard"
No real self-serve free tier — only a time-boxed 30-day/10-device trial; ongoing use requires a sales conversation
What Makes It Unique
Most AI-security tools watch network or browser traffic; Traceforce inspects activity directly on the device instead, which is what lets it see inside desktop apps and CLI agents (Claude Code, Cursor, Codex) that never touch a browser or gateway. That vantage point is also what lets it auto-patch a vulnerable package or block a dangerous command before it runs, not just log it afterward.
Kay Score
6.5
/ 10
Tool Information
Pricing
Custom/undisclosed — quote required (per-device Pro tier, no published dollar figure; 30-day/10-device free trial available)
Category
Coding & Development
Platform
Web / iOS / Android
Last Updated
