TL;DR: AI agents are quietly pulling secrets off your employees' laptops — and your security gateway can't see it. Traceforce installs in under 5 minutes and gives you a full inventory of every AI app, MCP, and skill running on every device, then lets you block the dangerous stuff in real time. Built by the ex-Clumio engineering team. Traceforce is already deployed on 3,000+ devices across six enterprise customers, with 40+ active pilots worth $3M+ in ARR. Try it free at www.traceforce.ai.
The incident that started this
At our last company, an AI coding agent running on a developer's laptop scraped what looked like database credentials and pushed them straight into a public GitHub repo. It took us weeks to investigate, rotate credentials, and clean up the fallout. We got lucky — they were dev-environment creds, so no customer was affected. Next time, nobody will be that lucky.
That's the whole problem with AI at work now: ChatGPT, Claude, Cursor, and Claude Code are everywhere on employee devices, wired into your data through MCPs and skills that no one is tracking. The tools your security team already owns — gateways, proxies, enterprise APIs — never see any of it, because the risky action happens on the device, before it ever hits the network.
Why us
We're Xia and Varun. We ran engineering at Clumio, a cyber-resilience company acquired by Commvault in 2024, where Xia was Director of Engineering and Varun was tech lead. We've spent our careers building security infrastructure — and we validated this problem with 50+ CISOs and CIOs before writing a line of code. Every one of them said the same thing: _I need to see and control this without slowing my engineers down._
Why on-device — and why gateways can't do this
Competitors sit at the gateway or plug into enterprise APIs. That misses the self-adopted AI tools employees install themselves, and it can't see how an agent is actually connected to your data via MCPs. Traceforce runs on the endpoint, so we see the full picture — which AI apps are running, what MCPs and skills they're wired to, what data they can reach — and we can warn or block an unsafe action the moment it happens, not after it's already on the network.
What you get
Traction
https://www.youtube.com/watch?v=a0OPq8vdDV0\
Our ask