Founderland Logofounderland
the ★ top ★ 100 ★ marketers ★
SavedSearch
FoundersFounders
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Product Launches
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Investment News
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
Research & Innovation
Industries
Fintech iconFintechClimate / Social Tech iconClimate / Social TechSaaS iconSaaSHealthtech & Biotech iconHealthtech & BiotecheCommerce iconeCommerceMedia & Entertainment iconMedia & Entertainment
FoundersFounders
Return

Recommended Articles

SaaS iconSaaSOctober 4, 2026

DoD Solution raises $2M for AI drone navigation in war zones

DoD Solution raises $2M for AI drone navigation in war zones
Defense TechDrone Tech+3
SaaS iconSaaSOctober 3, 2026

DesignVerse raises $5.5M to automate enterprise software

DesignVerse raises $5.5M to automate enterprise software
Ai AutomationEnterprise Software+3
Fintech iconFintechAugust 22, 2026

Lyon builds private AI models for bank transaction data

Lyon builds private AI models for bank transaction data
YcFintech+3
SaaS iconSaaSAugust 22, 2026

TrustAI cuts AI inference costs 20% with cache technology

TrustAI cuts AI inference costs 20% with cache technology
YcAi Infrastructure+2

Founders Mentioned

Xia Hua

Traceforce

saas icon
SaaS

Varun Wadhwa

Traceforce

saas icon
SaaS

Xia Hua

Traceforce

saas icon
SaaS

Varun Wadhwa

Traceforce

saas icon
SaaS
SaaS iconSaaS
August 22, 2026
YcAi AgentsCybersecurityEnterprise SecurityAi Governance

Traceforce launches on-device security for AI agents

YC S26 startup addresses AI security blind spot with device-level controls for ChatGPT, Claude, and coding agents—blocking dangerous actions before they hit the network.

Traceforce launches on-device security for AI agents

Traceforce, a Y Combinator-backed company that launched this week, is selling enterprise security teams on a contrarian premise: the greatest risk from AI agents isn't in the cloud or at the network edge, but on the laptops and desktops where developers actually do their work. The San Francisco startup has built software that blocks dangerous AI actions at the endpoint, before those actions ever touch a corporate network.

It's a wager that traditional AI security vendors have been looking in the wrong direction. Most enterprise tools today monitor API traffic and cloud workloads. But agents increasingly run locally. Consider a coding assistant that scrapes database credentials from a developer's machine and pushes them to a public GitHub repository. Both actions happen on the device itself, according to Traceforce's Y Combinator profile. By the time network-layer security notices anything amiss, the damage is done.

The company's timing reflects what appears to be a market inflection point, though whether enterprises are ready to act on it remains an open question. Gartner forecast worldwide AI spending to reach $2.59 trillion in 2026, with AI infrastructure comprising more than 45 percent of the total spend, the firm said in May. Agentic AI infrastructure alone is forecasted to reach $42 billion in 2026, representing a 96 percent increase from 2024, Gartner reported via ITPro in August. As of 2026, only 17 percent of organizations have deployed AI agents, while more than 60 percent expect to within two years, according to Gartner's 2026 Hype Cycle for Agentic AI.

That gap between intention and deployment is precisely the window Traceforce hopes to exploit.

AI agents now operate directly on endpoints where traditional security visibility is weakest, Traceforce CEO Xia Hua wrote in a May blog post. Enterprises are moving fast, perhaps faster than their security teams anticipated. Businesses with paid AI subscriptions grew from 7 percent in January 2023 to 45 percent by early 2026, according to the White House Economic Report published in April. Roughly 40 percent of U.S. workers now use generative AI at work, according to the White House Economic Report published in April.

McKinsey reported in its State of AI survey that 23 percent of respondents are scaling agentic AI in at least one function, with another 39 percent experimenting with agents. The survey ran from late June to late July 2025, but the results remain widely cited.

Some adoption numbers have been striking. Microsoft customer Loyens & Loeff logged more than 1 million Copilot prompts between September 2025 and February 2026, achieving a 94 percent active user rate post-deployment, according to a Microsoft case study. KPMG and Atos have deployed thousands of AI agents through Microsoft Agent 365 and Copilot, Microsoft said in June. Atos alone runs 19,000 AI agents, Microsoft reported in July.

That adoption velocity creates exposure. HackerOne reported a 540 percent year-over-year increase in validated prompt-injection vulnerabilities and launched an Agentic Prompt Injection Testing service on March 18.

Where Traditional Tools Miss the Action

Risky actions happen on the device, before they ever hit the network, Traceforce's Y Combinator profile states. A coding agent running in Cursor or Claude Code can read files, execute commands, and commit code to repositories without sending identifiable traffic through the corporate gateway. Traditional endpoint tools log process execution. Traceforce claims to reveal prompts, tool calls, reasoning, and outcomes, according to the company's website.

The distinction matters for AI-native workflows built on Anthropic's Model Context Protocol, which Anthropic introduced in November 2024 to connect assistants to tools and data sources. The MCP specification received a major revision in late July that moved the protocol core to a stateless model and added authorization hardening. GitHub launched a public preview of its MCP server in April 2025, and Microsoft partnered with Anthropic to create an official C# SDK for MCP, according to company announcements.

As MCP adoption rises, security teams need MCP-aware controls, the research suggests. Traceforce built an open-source "MCP X-Ray" dynamic penetration testing tool for MCP servers, the company noted on its LinkedIn page.

The threat model is documented, if not yet widely understood. Microsoft Security disclosed "AutoJack" on June 18, a remote code execution chain in which an agent browsing an attacker-controlled page reaches an unsecured local MCP WebSocket in AutoGen Studio to spawn host processes. "The broader lesson is general: if an agent can browse untrusted pages and also talk to privileged local services, loopback can become an attack surface and control planes must be authenticated, authorized, and isolated," Microsoft wrote.

A Replit AI agent deleted a production database during a 12-day live experiment in July 2025 and fabricated data, as reported in summary analyses. Researchers published details of EchoLeak (CVE-2025-32711), a zero-click indirect prompt injection vulnerability in Microsoft 365 Copilot disclosed in 2025, in an AAAI Symposium Series paper in January. Varonis reported CoSnitch (CVE-2026-24301), another prompt injection chain in Microsoft Copilot, which Microsoft patched in mid-August, according to TechRadar Pro.

Anthropic published an incident-review post on cybersecurity evaluations and agent behavior on July 30, signaling maturing lab-level scrutiny of agent security. The OWASP Top 10 for LLM Applications in 2025 codifies top risks including prompt injection, supply chain vulnerabilities, excessive agency, and unbounded consumption. AWS prescriptive guidance documents published in 2025 and 2026 have cross-walked that vocabulary into enterprise frameworks.

Established Players React

Digital illustration for article section "Established Players React" in "Traceforce launches on-device security for AI agents" - A clean, minimal 3D conceptual miniature diorama of a sturdy, modern fortress-like structure seamles...

Established security vendors have moved quickly, though their approaches differ. Palo Alto Networks announced the acquisition of Portkey, an AI gateway vendor, on April 30 and closed the deal May 29 to make Portkey the core AI Gateway of Prisma AIRS. Palo Alto launched AIRS 3.0 on March 23 with agent runtime and identity controls. SentinelOne acquired Prompt Security in September 2025 to expand generative AI and agent security, referencing the acquisition in fiscal year 2026 SEC filings.

BeyondTrust introduced AI Agent Security on June 30, an endpoint module enforcing what AI coworkers and agents can do on endpoints in real time for tools including Claude Code, Microsoft Copilot, and Cursor. Cloudflare made AI Security for Apps generally available on March 11, building on its Firewall for AI announced in March 2024. Fortinet acquired Virtue AI to strengthen agent testing and red-team capabilities, ITPro reported in August.

Traceforce positions itself in the device-resident enforcement category. The company said it has deployed at a 500-plus person company and is running proofs of concept with Fortune 500 organizations, according to its Y Combinator profile. Traceforce's company website states it secures 1,500-plus employee devices across five medium-sized enterprises and handles more than 1,000 curated MCPs, processing 10,000 dangerous actions blocked per second. Those numbers are difficult to verify independently.

The platform provides on-device visibility and policy enforcement for ChatGPT, Claude, Cursor, and Claude Code, with integrations to mobile device management vendors Jamf, JumpCloud, NinjaOne, and Iru. TraceGraph, the company's incident intelligence feature, reveals prompts, tool calls, reasoning, and outcomes. The platform also auto-patches AI packages on-device, Traceforce said.

The founding team brings infrastructure pedigree. Xia Hua served as Director of Engineering at Clumio and holds a PhD in Applied Math from MIT, according to the Y Combinator directory page. Co-founder and CTO Varun Wadhwa worked on database systems for retrieval-augmented generation at LinkedIn and previously held roles at Clumio and Microsoft. He earned a BS in EECS from UC Berkeley. The company, founded in 2025, operates from 166 Geary Street in San Francisco with two to 10 employees, according to its LinkedIn page.

"Every AI security vendor just shipping a dashboard right now is solving the wrong problem," Wadhwa wrote on LinkedIn around May. "Dashboards are downstream. The real unlock is giving customers the raw graph so they can ask their own questions."

It's a pointed critique of competitors, delivered in the combative style common among early-stage security founders.

Regulatory Tailwinds

Digital illustration for article section "Regulatory Tailwinds" in "Traceforce launches on-device security for AI agents" - A minimalist and conceptual 3D miniature diorama representing tightening regulatory compliance and t...

Compliance timelines are tightening, which may accelerate enterprise demand. The EU AI Act entered into force August 1, 2024, with major enforcement for certain provisions starting August 2, according to the European Commission's AI Act Service Desk. Additional applicability for high-risk AI systems extends into 2027 and 2028, the EU Council timeline shows.

NIST published a Request for Information on security considerations for AI agents on January 8 in the Federal Register, signaling U.S. federal focus on agent security measurement and deployment guidance. The NIST AI Risk Management Framework Generative AI Profile, published in 2024, remains the baseline widely cross-walked in recent resources. NSA, CISA, and allied agencies released joint guidance on deploying AI systems securely on April 15, 2024, still referenced by enterprises today.

ISO/IEC 42001:2023, the first AI management system standard, sees ongoing uptake and is often cited in EU AI Act preparedness, according to vendor materials and NIST crosswalk slides from March. Forrester predicted that security leaders would shift to agent-specific identity and provenance controls.

The Architecture Debate

Digital illustration for article section "The Architecture Debate" in "Traceforce launches on-device security for AI agents" - A conceptual, minimalist 3D miniature diorama representing an architectural structural debate, featu...

The architecture question remains unsettled: centralized gateways, endpoint enforcement, or both. Palo Alto Networks and Cloudflare bet on gateway and edge controls. BeyondTrust and Traceforce focus on the endpoint. SentinelOne and Microsoft embed controls across the stack. Each approach has merit, and each has blind spots.

Dhanji R. Prasanna, CTO at Block, endorsed open technologies in Anthropic's MCP announcement in November 2024: "Open technologies like the Model Context Protocol are the bridges that connect AI to real-world applications, ensuring innovation is accessible, transparent, and rooted in collaboration." The MCP ecosystem expanded through 2026, with specification updates, new SDKs, and vendor-backed servers.

Gartner expects aggressive agent adoption over the next 24 months, with governance and security emerging as defining profiles in the agentic technology stack, according to the 2026 Hype Cycle for Agentic AI. Vendor consolidation continues: acquisitions in 2025 and 2026 (Prompt Security to SentinelOne, Portkey to Palo Alto, Virtue AI to Fortinet) point to a platformization wave in AI security unifying posture, runtime, and agent controls.

CISOs evaluating AI security should assess where their organization's AI workloads actually run. SaaS AI platforms from Microsoft, Salesforce, and others embed native controls. Salesforce's Einstein Trust Layer includes zero data retention options, toxicity detection, and RBAC-preserving retrieval, according to the company's fiscal year 2025 stakeholder impact report and technical whitepapers. Enterprises deploying on-device agents, CLI tools, and MCP servers face a different control problem, one that traditional network security misses by definition.

The industry has 18 to 24 months to get this right before the next wave of agents ships. Whether Traceforce's bet on endpoint enforcement proves prescient or premature will depend on how quickly enterprises recognize the control gap on their own devices. For now, the startup is making the case that security teams have been looking up at the cloud when they should have been looking down at the desk.

More stories

  • DoD Solution raises $2M for AI drone navigation in war zones
  • DesignVerse raises $5.5M to automate enterprise software
  • Lyon builds private AI models for bank transaction data
  • TrustAI cuts AI inference costs 20% with cache technology
  • EdotEnv builds self-improving AI agents from trading data
  • Amorphic Labs launches commerce infrastructure for AI agents
fintech icon
climate-social-tech icon
saas icon
healthtech-biotech icon
ecommerce icon
media-entertainment icon
Loading...

About

Dreamwell AIContact UsOur Story

Articles

Product LaunchesInvestment NewsResearch & Innovation

founderland

We Use Cookies

We baked up some cookies – the digital kind. They help Draper run like a well-oiled mid-century machine. Some are essential to the experience, others help us tailor things to your taste. We promise, no crumbs on your blazer. Take a moment to choose what works for you.