01 / THE SIGNAL

我们发现了什么

发布 HN:Traceforce(YC S26)——面向 AI 应用的全公司安全监控。HN 大家好,我们是 Traceforce(https://www.traceforce.ai/)的创始人 Xia 和 Varun。

  • 来源:Hacker News发现于 2026-07-17
  • 证据等级:D · 发现产品或需求信号,暂未获得可核验的商业证据。
  • 商业模式:API / Usage-based
  • 主题:独立产品
  • 初筛评分:27.5/100 · 收录 1
#独立开发#待验证#产品发现
02 / SOURCE & EVIDENCE

证据,比故事更重要。

发现产品或需求信号,暂未获得可核验的商业证据。

规则清洗与初筛,未经人工商业核验。原文语境、实际客户和付费情况仍需自行验证。

引用与数字披露

来源类型(原作者自述/第三方测算/媒体转引)需采集端标注,本版尚未落字段。

短句引用
作者
未标注
抓取日期
来源类型
未标注
数字口径
币种
未标注
口径
未标注
披露主体
未标注
披露日期
未标注

中文辅助译文(全文)

大家好,我是 Xia 和 Varun,Traceforce(https://www.traceforce.ai/ )的创始人。Traceforce 通过发现不仅哪些 AI 应用程序正在被使用、还包括它们是如何通过 MCP 与其他数据源连接的,从而在所有设备(笔记本电脑、沙箱、虚拟机)上直接提供对 ChatGPT、Claude 等 AI 应用的可见性和控制能力。我们还有一个开源的动态 MCP 渗透测试工具 https://github.com/traceforce/mcp-xray,用于检测存在漏洞的 MCP。Traceforce 的目标是:- 为公司员工提供一种标准化方式,确保在其设备上运行的 AI 软件是安全运行的 - 为公司安全团队提供对公司设备上 AI 软件活动的可见性,并尽早检测和防止不安全操作及安全漏洞。Traceforce 的工作方式 1.Traceforce 作为轻量级二进制文件和浏览器扩展安装到每台设备上。2. 在 30 分钟内,设备就会将实时数据上传到公司配置文件,并在仪表板上显示跨所有公司设备运行的所有 AI 代理/应用程序。3. 公司安全人员可以实时监控所有代理的活动、实施控制,并在任何安全风险出现时立即收到警报。视频演示链接:https://youtube.com/watch?v=IdK2WKg7kaM 创立 Traceforce 的灵感来自 Xia 在一家名为 Clumio 的初创公司(已于 2024 年 10 月被 Commvault 收购)担任工程总监的经历。能够在不拖慢员工工作速度的前提下监控团队成员如何使用 AI,是 Clumio 的首要任务。

在与 50 多位 CISO 和 CIO 沟通后,很明显这是当下各行各业亟需的解决方案。我们不断听到这样的反馈:新的 AI 功能被采纳得如此迅速和广泛,以至于可见性和控制能力完全跟不上。Traceforce 对监控和收集的内容保持透明。默认情况下,Traceforce 仅收集关于设备上运行的 AI 应用程序、MCP 和工具的元数据和遥测信息。安全团队可以启用选项来检查工具调用,以便检测、警告或阻止预定义的高风险或潜在破坏性操作。所有内容检查都在设备本地完成。除非组织的安全管理员明确配置,否则用户提示永远不会被存储。我们与产品的最终用户密切合作,一旦他们了解正在被监控/共享的内容,他们实际上会感到非常安心,因为他们的设备上拥有一层强大的防护来防止安全事件。这使他们能够专注于工作,而不必担心在不知情的情况下可能发生的泄漏和违规事件。Traceforce 的二进制文件使用 Go 构建,浏览器扩展使用 Node JS 编写。最难的部分是构建 AI 应用程序、MCP 和工具之间的完整连接图谱,然后识别由这些连接引入的漏洞和攻击路径。Tr…

译文由上游机器翻译生成,可能有误;判断请以英文原文为准。

英文原文(来源本站未改写)

Hey HN, we’re Xia and Varun, the founders of Traceforce ( https://www.traceforce.ai/ ).Traceforce provides visibility and control over AI apps such as ChatGPT, Claude etc directly on all devices (laptops, sandboxes, virtual machines) by discovering not just which apps are being used but also how they are connected to other data sources via MCPs.We also have an open-source dynamic MCP pentesting tool https://github.com/traceforce/mcp-xray to detect vulnerable MCPs.

The purpose of Traceforce is to: - Give a company’s employees a standardized way to ensure that AI software running on their device is operating safely - Give the company’s security team visibility of the activities of AI software on the company’s devices, and to detect and prevent unsafe actions and security breaches as early as possible.How Traceforce works 1.Traceforce is installed on each device as a lightweight binary and browser extension. 2.Within 30 minutes, the device is uploading live data to the company profile, displaying all the AI agents/apps running across all company devices on a dashboard. 3.

Company security staff can monitor the activity of all the agents in real time, implement controls, and be alerted to any security risks as soon as they arise.Here’s the video demo: https://youtube.com/watch?v=IdK2WKg7kaM The inspiration for Traceforce came via Xia’s experience as Director of Engineering at a startup called Clumio (which was acquired by Commvault in Oct 2024).Being able to monitor how team members are using AI without slowing them down was a top priority at Clumio.After speaking with 50+ CISOs and CIOs, it became clear that this is a much-needed solution right now across industries.

We keep hearing that new AI features are being adopted so quickly and so broadly that visibility and control just can't keep up.Traceforce is transparent about what we monitor and collect.By default, Traceforce collects only metadata and telemetry about the AI applications, MCPs, and tools running on a device.Security teams can enable options to inspect tool calls for the purpose of detecting, warning on, or blocking predefined high-risk or potentially destructive actions.All content inspection happens locally on the device.User prompts are never stored unless explicitly configured by the organization's security administrators.

We work closely with end-users of the product, and once they understand what is being monitored/shared, they actually have great comfort that they have a powerful layer of protection on their device to prevent security incidents.It enables them to just focus on their work without worrying about what leaks and breaches may be happening under the hood without their awareness.The Traceforce binary is built using Go and the browser extension is written in Node JS.The hardest part is building a complete connectivity graph between AI applications, MCPs, and tools, then identifying the vulnerabilities and attack paths introduced by those connections.Tra

出处https://news.ycombinator.com/item?id=48937020抓取日期 · 采集源 Hacker News

03 / EVIDENCE GAPS

这条还缺什么证据?

下面每条都由本条已有字段推出(等级、理由、商业模式、来源次数、是否演示), 本站不生成推测性结论;通用验证方法放在方法论页。

  • 可核验的收入或付费证据查官网定价页与付费口径;第三方数据源(如 GetLatka)只作旁证,需标注来源与时点。
  • 只有单一来源找一手站点或其他渠道是否重复出现同一产品;社区热帖数量不等于商业进展。

通用验证清单(谁有这个问题/谁愿意付费/一个人能交付哪一小步)见我们的筛选方法

04 / SIGNAL HISTORY

发现时间线