Launch HN:Traceforce (YC S26) – 一次一个设备,安全地构建 AI 应用
2 分•作者: XiaHua•3 个月前
大家好,我是 Xia 和 Varun,Traceforce(<a href="https://www.traceforce.ai/" rel="nofollow">https://www.traceforce.ai/</a>)的创始人。Traceforce 可以在所有设备(笔记本电脑、沙盒、虚拟机)上提供对 ChatGPT、Claude 等 AI 应用的可见性和控制,它不仅能发现正在使用哪些应用,还能通过 MCP(多云平台)发现它们是如何连接到其他数据源的。我们还提供一个开源的动态 MCP 渗透测试工具 <a href="https://github.com/traceforce/mcp-xray" rel="nofollow">https://github.com/traceforce/mcp-xray</a> 来检测易受攻击的 MCP。
Traceforce 的目的是:
* 为公司员工提供标准化的方式,确保设备上运行的 AI 软件安全运行。
* 让公司的安全团队能够了解 AI 软件在公司设备上的活动,并尽早检测和阻止不安全操作及安全漏洞。
Traceforce 的工作原理:
1. Traceforce 以轻量级二进制文件和浏览器扩展的形式安装在每台设备上。
2. 30 分钟内,设备就会将实时数据上传到公司资料,并在仪表板上显示所有公司设备上运行的 AI 代理/应用。
3. 公司安全人员可以实时监控所有代理的活动,实施控制,并在出现安全风险时立即收到警报。
演示视频:<a href="https://youtu.be/IdK2WKg7kaM" rel="nofollow">https://youtu.be/IdK2WKg7kaM</a>
Traceforce 的灵感来源于 Xia 在初创公司 Clumio(2024 年 10 月被 Commvault 收购)担任工程总监的经历。在 Clumio,能够监控团队成员如何使用 AI 而不减慢他们的工作速度是一个首要任务。在与 50 多位 CISO 和 CIO 交流后,我们发现这在各行业都是一个迫切需要的解决方案。我们不断听到新的 AI 功能被采用的速度如此之快、范围如此之广,以至于可见性和控制根本跟不上。
Traceforce 对我们监控和收集的内容保持透明。默认情况下,Traceforce 只收集设备上运行的 AI 应用、MCP 和工具的元数据和遥测数据。安全团队可以启用选项来检查工具调用,以检测、警告或阻止预定义的、高风险的或潜在的破坏性操作。所有内容检查都在设备本地进行。除非组织的安全管理员明确配置,否则用户提示永远不会被存储。
我们与产品的最终用户密切合作,一旦他们了解了正在监控/共享的内容,他们就会感到非常放心,因为他们的设备上有一层强大的保护措施,可以防止安全事件的发生。这使他们能够专注于工作,而无需担心潜在的泄露和漏洞在他们不知情的情况下发生。
Traceforce 目前已部署在 10 个组织的 1,000 多台设备上。平均而言,我们每台设备发现超过 15 个 AI 应用,每个应用连接到 5-10 个 MCP。我们帮助客户识别 MCP 配置中暴露的明文密钥,防止 API 密钥通过 AI 生成的代码泄露,并在执行“DROP TABLE”等潜在破坏性命令之前警告开发人员。我们“警告并确认”的方法尤其受到好评,它在让开发人员自由工作的同时,帮助他们避免了代价高昂的错误。
我们正在寻找那些正在快速采用 AI 编码助手、ChatGPT、Claude 和 MCP 的中小型企业(200 名以上员工)的安全、IT 和 AI 平台团队进行合作。如果您正在努力了解人们使用哪些 AI 工具来提高生产力,或者需要一种实用的方法来降低与 AI 相关的安全风险而不减慢工作速度,我们很乐意与您交流。
您可以通过免费试用 <a href="https://www.traceforce.ai" rel="nofollow">https://www.traceforce.ai</a> 开始使用,或直接联系我们安排演示并讨论您的环境。
查看原文
Hey HN, we’re Xia and Varun, the founders of Traceforce (<a href="https://www.traceforce.ai/" rel="nofollow">https://www.traceforce.ai/</a>). Traceforce provides visibility and control over AI apps such as ChatGPT, Claude etc directly on all devices (laptops, sandboxes, virtual machines) by discovering not just which apps are being used but also how they are connected to other data sources via MCPs. We also have an open-source dynamic MCP pentesting tool <a href="https://github.com/traceforce/mcp-xray" rel="nofollow">https://github.com/traceforce/mcp-xray</a> to detect vulnerable MCPs.<p>The purpose of Traceforce is to:<p>- Give a company’s employees a standardized way to ensure that AI software running on their device is operating safely<p>- Give the company’s security team visibility of the activities of AI software on the company’s devices, and to detect and prevent unsafe actions and security breaches as early as possible.<p>How Traceforce works<p>1. Traceforce is installed on each device as a lightweight binary and browser extension.<p>2. Within 30 minutes, the device is uploading live data to the company profile, displaying all the AI agents/apps running across all company devices on a dashboard.<p>3. Company security staff can monitor the activity of all the agents in real time, implement controls, and be alerted to any security risks as soon as they arise.<p>Here’s the video demo: <a href="https://youtu.be/IdK2WKg7kaM" rel="nofollow">https://youtu.be/IdK2WKg7kaM</a><p>The inspiration for Traceforce came via Xia’s experience as Director of Engineering at a startup called Clumio (which was acquired by Commvault in Oct 2024). Being able to monitor how team members are using AI without slowing them down was a top priority at Clumio. After speaking with 50+ CISOs and CIOs, it became clear that this is a much-needed solution right now across industries. We keep hearing that new AI features are being adopted so quickly and so broadly that visibility and control just can't keep up.<p>Traceforce is transparent about what we monitor and collect. By default, Traceforce collects only metadata and telemetry about the AI applications, MCPs, and tools running on a device. Security teams can enable options to inspect tool calls for the purpose of detecting, warning on, or blocking predefined high-risk or potentially destructive actions. All content inspection happens locally on the device. User prompts are never stored unless explicitly configured by the organization's security administrators.<p>We work closely with end-users of the product, and once they understand what is being monitored/shared, they actually have great comfort that they have a powerful layer of protection on their device to prevent security incidents. It enables them to just focus on their work without worrying about what leaks and breaches may be happening under the hood without their awareness.<p>Traceforce is currently deployed across more than 1,000 devices at 10 organizations. On average, we discover over 15 AI applications per device with each application connected to 5-10 MCPs. We've helped customers identify exposed plaintext secrets in MCP configurations, prevent API keys from leaking through AI-generated code, and warn developers before executing potentially destructive commands such as “DROP TABLE”. Our "warn and acknowledge" approach has been especially well received, giving developers the freedom to work while helping them avoid costly mistakes.<p>We're looking to work with security, IT, and AI platform teams at small to medium enterprises (200+ employees) that are rapidly adopting AI coding assistants, ChatGPT, Claude, and MCPs. If you're struggling to understand what AI tools people use to boost their productivity or need a practical way to reduce AI-related security risk without slowing folks down, we'd love to talk.<p>You can get started with a free trial at <a href="https://www.traceforce.ai" rel="nofollow">https://www.traceforce.ai</a> or reach out directly to schedule a demo and discuss your environment.