Launch HN: Traceforce (YC S26) – Company-wide security monitoring for AI apps
Hacker News XiaHua
A YC-backed startup called Traceforce just launched security monitoring software for AI apps like ChatGPT and Claude inside companies. It watches what AI tools employees use and how they connect to sensitive data, catching leaks before they happen.
Every company these days has a shadow IT problem, except now it's shadow AI. Employees are installing ChatGPT plugins, wiring up Claude to internal databases, and connecting random MCP servers to get their jobs done faster, all without security teams having any idea it's happening. Traceforce, launched by founders Xia and Varun through YC's current batch, is built to close that gap.
The product installs as a small Go binary plus a browser extension, and within half an hour it starts feeding a company dashboard with a live map of every AI agent and app running across the fleet of devices. More importantly, it traces the connections those apps make through MCP, the increasingly common protocol that lets AI tools talk to other services and data sources. Xia says the idea grew out of her time as Director of Engineering at Clumio, a startup Commvault acquired in October 2024, where keeping tabs on AI usage without choking productivity became an unexpected headache.
The technical problem turns out to be nastier than it sounds. Endpoint detection tools can see processes running on a laptop, and cloud access brokers can see network traffic, but neither one understands what's actually happening inside an AI app's tool calls. Traceforce had to reverse-engineer the configs and logs of dozens of different applications individually, a grind made worse by how often AI vendors ship new features. The payoff, according to the founders, is real: across more than 1,000 devices at ten organizations, they're finding an average of 15 AI applications per device, each hooked into 5 to 10 MCP connections.
What they're catching isn't hypothetical either. The company says it's flagged plaintext secrets sitting in MCP configuration files, stopped API keys from leaking out through AI-generated code, and warned developers in real time before they let an AI agent run something like a DROP TABLE command. That last bit, what they call a "warn and acknowledge" model, seems to be the detail winning over engineering teams, since it doesn't just lock things down but gives people a chance to catch their own mistakes.
On privacy, Traceforce says it defaults to metadata and telemetry only, with prompt content inspected locally and never stored unless an admin explicitly turns that on. Whether security teams and employees actually trust that boundary at scale, especially once a company enables deeper inspection for high-risk actions, is the kind of thing that will get tested hard as adoption grows past the current 200-plus-employee sweet spot they're targeting.
My take
This is the natural next step after the AI coding assistant boom outran every governance policy companies wrote for it, and it's frankly overdue. The bigger question nobody's asking loudly enough is whether local-only inspection promises hold up once a CISO decides they want more visibility than "metadata," because that's usually when the trust erodes and the surveillance creep begins.
Read more about this at: Hacker News
Related stories
Launch HN: Prized (YC S26) – Let non-engineer staff build secure internal tools
prized.dev · 1 week ago ·
40
Launch HN: Hyper (YC P26) – Company brain to power agentic development
Hacker News · 2 months ago ·
47
Launch HN: HyperProbe (YC S26) – Agents that do read-only debugging in prod
hyperprobe.co · 1 day ago ·
31