AI Briefing
KO

Launch HN: Traceforce (YC S26) – Enterprise-Wide Security Monitoring for AI Apps

·2026.07.17 01:52

Key point

An enterprise security tool that monitors and controls AI apps like ChatGPT, Claude, and MCP connections in real time

Details

Problem: As AI apps like ChatGPT and Claude are rapidly adopted, security teams' visibility can't keep up. Existing tools like EDR or CASB can't detect activity inside AI applications, especially tool connections made via MCP (Model Context Protocol).

Solution: Traceforce deploys a lightweight binary and browser extension to each device, discovering all AI apps and MCP connections within 30 minutes. Security teams can monitor activity in real time and warn about or block risky operations (e.g., "DROP TABLE").

Technical features:

  • Dynamically builds a connection graph between AI apps and MCP
  • Open-source tool mcp-xray: detects vulnerabilities in MCP such as code execution, SSRF, path traversal, and authentication bypass
  • All content inspection is performed locally on-device (protecting privacy)

Deployment status: Running on 1,000+ devices across 10 organizations. An average of 15+ AI apps discovered per device, with 5-10 MCP connections per app.

Representative use cases: Preventing API key leaks, blocking exposure of secrets in AI-generated code, warning developers before dangerous commands are executed.

Executive background: Co-founder Xia was Director of Engineering at Clumio (acquired by Commvault, October 2024). Confirmed this is an urgently needed solution after interviewing 50+ CISOs/CIOs.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.