Traceforce
Traceforce is a YC S26 startup that installs on employee devices to inventory and control AI apps and their MCP connections in real time.
Visit Website ↗ + Add to Compare Claim This CompanyOverview
Traceforce is an endpoint security startup, part of Y Combinator’s Summer 2026 batch, built to give enterprises visibility into which AI applications (ChatGPT, Claude, Copilot, CLI coding agents) run on employee devices and exactly what data sources those tools are wired into via the Model Context Protocol (MCP). The product installs a lightweight agent and browser extension that inventories AI usage and enforces policy locally, blocking risky actions such as exposed secrets or destructive commands before they leave the device.
Its stated differentiator is running at the endpoint rather than inspecting network or cloud-API traffic, which lets it catch shadow AI and local-agent activity that gateway-based competitors like Wing Security and Grip Security can’t see. The company has also released an open-source MCP security scanner (mcp-xray), a credible signal of engineering substance beyond marketing.
Founders Xia Hua (ex-Clumio engineering director, MIT PhD) and Varun Wadhwa (ex-LinkedIn, ex-Clumio, ex-Microsoft) give the team real enterprise-infrastructure pedigree, but the company is only months old and all customer and traction figures currently come solely from the vendor.
Innovation Matrix Assessment
A genuine technical angle (on-device interception of AI/MCP activity versus network-only visibility), plus a public open-source scanner as evidence of real engineering output.
Addresses a concrete, current gap in shadow AI and MCP sprawl with fast onboarding claims, but no independent proof of deployment ease or false-positive rates.
A days-old post-demo-day company with no disclosed funding beyond standard YC terms and no named enterprise customers.
An interesting endpoint-first framing in an already crowded AI-security-posture space; not yet proven to shift buyer behavior.
All traction figures (device counts, pilots, ARR) are vendor-asserted with zero independent corroboration found.
The underlying problem of unmanaged AI apps and MCP connections on employee devices is durable and growing, independent of this company's own survival odds.
Why CISOs Should Care
CISOs are losing visibility as employees adopt AI tools and MCP integrations outside IT's purview; Traceforce targets exactly that blind spot at the device level, where network-based tools can't see.
What Makes It Different
Rather than inspecting cloud API or network traffic, it instruments the endpoint directly, catching local AI-agent and MCP activity before it ever reaches a network boundary.
The Matrix Verdict
40/100 — EMERGING / UNRANKED
Traceforce scores 40/100, placing it in the Emerging/Unranked tier — a credible founding team and a real, differentiated technical approach, but with essentially no independently verifiable market or efficacy evidence given its days-old post-demo-day status.
Editorial Note: Claims vs. Verified Findings
Traction figures (device counts, pilot counts, ARR) come exclusively from Traceforce's own YC and launch materials with no third-party confirmation; founder backgrounds and the open-source tooling are the most independently verifiable facts available.
Sources
Alternatives to Traceforce
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Alice (formerly ActiveFence)
Israeli AI security company (rebranded from ActiveFence in January 2026) offering a lifecycle platform to test, guard, and…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…