TLDRocket
Sign in

Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps

Hacker News XiaHua

Traceforce, a YC S26 startup, watches how AI apps like ChatGPT and Claude connect to company data via MCPs. It gives security teams a real-time view they didn't have before.

Based on reporting by Hacker News, XiaHua — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Every company right now has a shadow fleet of AI tools quietly wiring themselves into internal systems, and almost nobody in IT knows the full shape of it. That's the gap Traceforce is built to close. Founders Xia and Varun install a lightweight Go binary plus a browser extension on employee devices, and within 30 minutes the thing is streaming live data back to a company dashboard showing every AI agent and app running across the fleet.

The idea grew out of Xia's time as Director of Engineering at Clumio, a startup acquired by Commvault in October 2024, where keeping tabs on how the team used AI without getting in their way was a constant balancing act. After talking to more than 50 CISOs and CIOs, the founders concluded that adoption of AI features is outrunning security visibility almost everywhere, not just at one company.

What makes this different from existing tools is the focus on connections, not just processes. EDRs can see what's running; CASBs can see network traffic. Neither sees what's happening inside an AI app or how it's linked to other data sources through MCPs. Traceforce built that connectivity graph by digging into the configuration files and logs of individual apps one by one, a slow, manual slog because every app behaves differently and AI features keep shifting underneath them. They've also open-sourced a companion tool, mcp-xray, for dynamically pentesting MCPs for vulnerabilities.

On privacy, the default is metadata and telemetry only. Security admins can opt into deeper inspection of tool calls to catch high-risk or destructive actions, but that inspection happens locally on the device, and user prompts aren't stored unless an org explicitly turns that on. The company says once end-users understand what's actually being collected, most find it reassuring rather than invasive.

Traceforce is running on more than 1,000 devices across 10 organizations right now, and the numbers hint at just how sprawling this problem already is: over 15 AI applications discovered per device on average, each hooked into 5 to 10 MCPs. Customers have used it to catch exposed plaintext secrets sitting in MCP configs, stop API keys from leaking out through AI-generated code, and get warned before an agent runs something like a DROP TABLE command. That warn-and-acknowledge model, letting developers proceed but flagging the risk first, seems to be the part customers actually like.

My take — AI-written commentary, not fact-checked reporting

The fact that a startup can find 15-plus AI apps per device, each wired into a handful of MCPs nobody signed off on, says everything about how fast this stuff got deployed without anyone asking permission. Security teams built entire toolchains around processes and network traffic, and none of it looks inside the AI layer itself, so of course a company like this exists now. The warn-and-acknowledge approach is the right instinct too: block everything and developers route around you, ignore it and someone eventually leaks a key or drops a production table.

Read more about this at: Hacker News

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.