Skip to content

Traceforce

Traceforce is a YC S26 startup that installs on employee devices to inventory and control AI apps and their MCP connections in real time.

Visit Website ↗ + Add to Compare Claim This Company
40/100Emerging / Unranked

Overview

Traceforce is an endpoint security startup, part of Y Combinator’s Summer 2026 batch, built to give enterprises visibility into which AI applications (ChatGPT, Claude, Copilot, CLI coding agents) run on employee devices and exactly what data sources those tools are wired into via the Model Context Protocol (MCP). The product installs a lightweight agent and browser extension that inventories AI usage and enforces policy locally, blocking risky actions such as exposed secrets or destructive commands before they leave the device.

Its stated differentiator is running at the endpoint rather than inspecting network or cloud-API traffic, which lets it catch shadow AI and local-agent activity that gateway-based competitors like Wing Security and Grip Security can’t see. The company has also released an open-source MCP security scanner (mcp-xray), a credible signal of engineering substance beyond marketing.

Founders Xia Hua (ex-Clumio engineering director, MIT PhD) and Varun Wadhwa (ex-LinkedIn, ex-Clumio, ex-Microsoft) give the team real enterprise-infrastructure pedigree, but the company is only months old and all customer and traction figures currently come solely from the vendor.

Innovation Matrix Assessment

Innovation Velocity 6/10

A genuine technical angle (on-device interception of AI/MCP activity versus network-only visibility), plus a public open-source scanner as evidence of real engineering output.

Operational Value 5/10

Addresses a concrete, current gap in shadow AI and MCP sprawl with fast onboarding claims, but no independent proof of deployment ease or false-positive rates.

Market Momentum 2/10

A days-old post-demo-day company with no disclosed funding beyond standard YC terms and no named enterprise customers.

Category Disruption 4/10

An interesting endpoint-first framing in an already crowded AI-security-posture space; not yet proven to shift buyer behavior.

Real-World Efficacy 2/10

All traction figures (device counts, pilots, ARR) are vendor-asserted with zero independent corroboration found.

Enduring Relevance 5/10

The underlying problem of unmanaged AI apps and MCP connections on employee devices is durable and growing, independent of this company's own survival odds.

Why CISOs Should Care

CISOs are losing visibility as employees adopt AI tools and MCP integrations outside IT's purview; Traceforce targets exactly that blind spot at the device level, where network-based tools can't see.

What Makes It Different

Rather than inspecting cloud API or network traffic, it instruments the endpoint directly, catching local AI-agent and MCP activity before it ever reaches a network boundary.

The Matrix Verdict

40/100 — EMERGING / UNRANKED

Traceforce scores 40/100, placing it in the Emerging/Unranked tier — a credible founding team and a real, differentiated technical approach, but with essentially no independently verifiable market or efficacy evidence given its days-old post-demo-day status.

Editorial Note: Claims vs. Verified Findings

Traction figures (device counts, pilot counts, ARR) come exclusively from Traceforce's own YC and launch materials with no third-party confirmation; founder backgrounds and the open-source tooling are the most independently verifiable facts available.

Sources