HomeCompaniesTraceforce

CrowdStrike for AI Agents

AI apps such as ChatGPT and Claude have become part of everyone's daily workflow, but they introduce new security risks that traditional security tools weren't built to handle. Security teams at companies from startups to Fortune 500s, are struggling to keep up. Traceforce gives a company’s security team visibility of how AI apps are being used across company’s devices, and the ability to detect and prevent security breaches and unsafe actions as early as possible.
Active Founders
Xia Hua
Xia Hua
Founder/CEO
Founder at Traceforce. Previously Director of Engineering at Clumio, managing all flagship ransomware protection products. PhD in Applied Math from MIT.
Varun Wadhwa
Varun Wadhwa
Founder/CTO
Co-founder & CTO at TraceForce. Previously Senior Software Engineer at LinkedIn, leading high-performance database systems for RAG. Before that, Staff Software Engineer at Clumio, leading distributed data infrastructure and backup. Earlier built distributed payments systems at Microsoft. BS in EECS, UC Berkeley.
Company Launches
Traceforce — Catch risky agent actions your security gateway will never spot
See original launch post

****

TL;DR: AI agents are quietly pulling secrets off your employees' laptops — and your security gateway can't see it. Traceforce installs in under 5 minutes and gives you a full inventory of every AI app, MCP, and skill running on every device, then lets you block the dangerous stuff in real time. Built by the ex-Clumio engineering team. Traceforce is already deployed on 3,000+ devices across six enterprise customers, with 40+ active pilots worth $3M+ in ARR. Try it free at www.traceforce.ai.

The incident that started this
At our last company, an AI coding agent running on a developer's laptop scraped what looked like database credentials and pushed them straight into a public GitHub repo. It took us weeks to investigate, rotate credentials, and clean up the fallout. We got lucky — they were dev-environment creds, so no customer was affected. Next time, nobody will be that lucky.

That's the whole problem with AI at work now: ChatGPT, Claude, Cursor, and Claude Code are everywhere on employee devices, wired into your data through MCPs and skills that no one is tracking. The tools your security team already owns — gateways, proxies, enterprise APIs — never see any of it, because the risky action happens on the device, before it ever hits the network.

Why us
We're Xia and Varun. We ran engineering at Clumio, a cyber-resilience company acquired by Commvault in 2024, where Xia was Director of Engineering and Varun was tech lead. We've spent our careers building security infrastructure — and we validated this problem with 50+ CISOs and CIOs before writing a line of code. Every one of them said the same thing: _I need to see and control this without slowing my engineers down._

Why on-device — and why gateways can't do this
Competitors sit at the gateway or plug into enterprise APIs. That misses the self-adopted AI tools employees install themselves, and it can't see how an agent is actually connected to your data via MCPs. Traceforce runs on the endpoint, so we see the full picture — which AI apps are running, what MCPs and skills they're wired to, what data they can reach — and we can warn or block an unsafe action the moment it happens, not after it's already on the network.

What you get

  • Install in <5 min. Full inventory of every AI app, MCP, and skill across your devices within 30 minutes.
  • Discover shadow AI and see exactly how each agent connects to your data sources.
  • Real-time controls: warn and block unsafe actions (like uploading a client list to a chatbot) before they happen.
  • Open-source MCP pentesting: we also built mcp-xray to dynamically detect vulnerable MCPs — try it today.


Traction

  • Securing 3000+ employee devices across 6 medium-sized enterprises.
  • Customer quote from a leading database provider with over 500 employees: “To govern AI, we need full visibility into AI usage before we can place any type of controls. Traceforce gives us both visibility and control we needed”.
  • 40+ Active pilots including multiple Fortunate 500 enterprises.

https://www.youtube.com/watch?v=a0OPq8vdDV0\


Our ask

  • Intros to security engineers, security architects, DevSecOps teams, or CISOs securing AI adoption. (We're the ex-Clumio team — that's usually enough to get a conversation.)
  • Try Traceforce free on your own laptop — <5 min to install, and we want candid feedback, good or bad.
  • Challenge us: tell us which AI apps, MCPs, or workflows we should support next.
  • Share with anyone wrestling with security over ChatGPT, Claude, Cursor, Claude Code, or custom MCPs.
Traceforce
Founded:2025
Batch:Summer 2026
Team Size:2
Status:
Active
Location:San Francisco
Primary Partner:Brad Flora