Traceforce, a San Francisco security startup, claims to have deployed software on more than 3,000 corporate laptops to track every interaction employees have with AI agents — including ChatGPT, Claude, and coding assistants like Cursor. The company, backed by Y Combinator, says it now has 40 pilots in progress representing over $3 million in potential contracts.
The premise is straightforward: AI agents running locally on desktops often slip past the perimeter defenses most companies rely on. Traceforce says it installs a lightweight monitor directly onto employee machines, promising to catch risky behavior at the moment it happens rather than after data has already left the building.
"Competitors sit at the gateway or plug into enterprise APIs," CEO Xia Hua wrote when the company launched publicly in July. "Traceforce runs on the endpoint, so we see the full picture."
Whether enterprises will embrace yet another piece of software running silently on their workforce's laptops remains an open question, but the company is betting that the risk of unmonitored AI usage outweighs the friction of adding another security layer.
Watching Prompts and Tool Calls in Real Time
The software arrives as a binary and browser extension compatible with macOS and Windows. According to the company, it completes an initial scan within 30 minutes, uploading an inventory of every AI application, Model Context Protocol server, and connected skill it finds. Security teams can then write policies to either warn users or block actions outright when an employee attempts something risky.
That might mean stopping a chatbot from uploading a customer list to an external service, or preventing an AI coding assistant from executing a DROP TABLE command against a production database. Traceforce says its dashboard can correlate seemingly unrelated events, such as AWS credentials leaking during a Claude Code session.
The platform includes TraceGraph, a visual map that links user prompts to the tool calls those prompts trigger, creating an audit trail that security teams can review after an incident. In theory, this provides the kind of forensic visibility that has long been standard for malware and insider threats but has lagged for AI tooling.
Installation, the company says, takes about five minutes. Organizations can deploy it through mobile device management platforms including Jamf, JumpCloud, NinjaOne, and Iru.
An Open-Source Scanner for MCP Servers

Alongside its commercial offering, Traceforce released MCP X-Ray, an Apache-licensed scanner that hunts for vulnerabilities in Model Context Protocol servers. The tool, available on GitHub, checks for code execution flaws, server-side request forgery, path traversal bugs, authentication bypasses, injection vulnerabilities, and denial-of-service risks.
Scans produce results in SARIF format and can optionally feed findings into Traceforce Atlas, a hosted registry the company maintains. Atlas now tracks more than 600 MCP servers, according to Hua, who noted in a Hacker News thread that the company runs its own version of the scanner continuously to pentest MCPs and their supply chains.
The move to open-source part of the platform is a familiar play for security startups: build trust through transparency, generate community contributions, and create a funnel for commercial adoption.
The Founders and Early Momentum

Hua earned a Ph.D. from MIT and previously led engineering at Clumio, a data protection startup that raised over $300 million before being acquired. Co-founder and CTO Varun Wadhwa also came from Clumio, where he worked on high-performance database systems for retrieval-augmented generation. Before that, Wadhwa spent several years as a senior software engineer at LinkedIn.
The team is still small. LinkedIn lists between two and ten employees, though the company recently hired a founding engineer. At launch in July, Traceforce reported 1,000 devices deployed across ten organizations. A few weeks later, that figure jumped to 3,000 devices, six enterprise customers, and the pipeline of 40 pilots. These figures come from the company's own marketing materials and have not been independently confirmed.
The company offers a free trial covering up to ten devices for 30 days, a standard entry point for endpoint security tools.
Crowded Space, Uncertain Timing

Traceforce enters a market that is both emerging and already contested. CrowdStrike rolled out its AI Detection and Response system to extend endpoint coverage to desktop AI tools. Microsoft previewed AI agent runtime protection in Defender for Endpoint, which inspects prompts and can block tool requests before they execute. Palo Alto Networks has added similar capabilities to its platform. Burrow, another startup, markets runtime security for AI agents with its own MCP server inventory and rule-based detection.
The competitive positioning hinges on where the software sits. Traceforce argues that running on the endpoint provides visibility that gateway appliances and SaaS-layer controls miss. But endpoint agents are not universally loved by IT teams, who worry about performance overhead, deployment complexity, and user pushback.
There is also a timing question. The rise of agentic AI has created genuine security gaps, but it is unclear how quickly enterprises will move to plug them versus waiting for their existing vendors to catch up. Traceforce is making a bet that the problem is urgent enough and differentiated enough to justify a standalone product.
For now, the company has traction that looks promising for an early-stage security startup — assuming the pipeline converts. Whether that momentum translates into a sustainable business or gets absorbed by larger platforms will depend on how fast the category matures and how willing buyers are to add another agent to their already crowded endpoint stack.
