메뉴
HN
Hacker News 12일 전

Traceforce (YC S26): AI 앱을 위한 전사적 보안 모니터링

IMP
7/10
핵심 요약

Traceforce는 ChatGPT, Claude 같은 생성형 AI 앱과 에이전트가 기업 내 기기에서 어떻게 작동하는지 실시간으로 모니터링하고 통제하는 보안 솔루션입니다. AI 모델이 사내 데이터와 연결되는 구간(MCP)의 취약점을 추적하고 사전에 보안 위협을 차단할 수 있어, AI 도입 속도를 저하하지 않으면서도 기업의 보안 통제력을 확보해야 하는 IT 실무자에게 유용합니다.

번역된 본문

안녕하세요 HN, 저는 Traceforce(https://www.traceforce.ai/)의 공동 창업자인 Xia와 Varun입니다. Traceforce는 ChatGPT, Claude 등과 같은 AI 앱이 단순히 어떤 것들이 사용되고 있는지뿐만 아니라 MCP를 통해 다른 데이터 소스와 어떻게 연결되어 있는지 파악하여, 노트북, 샌드박스, 가상 머신 등 모든 기기에서 직접적인 가시성과 통제력을 제공합니다. 또한 취약한 MCP를 탐지하기 위해 오픈소스 동적 MCP 모의해킹(Pentesting) 도구(https://github.com/traceforce/mcp-xray)도 제공하고 있습니다.

Traceforce의 목적은 다음과 같습니다:

  • 기업 직원들에게 기기에서 실행되는 AI 소프트웨어가 안전하게 작동하는지 보장할 수 있는 표준화된 방법을 제공합니다.
  • 기업의 보안 팀이 회사 기기 내 AI 소프트웨어의 활동에 대한 가시성을 확보하고, 안전하지 않은 행위 및 보안 위반을 최대한 조기에 탐지하고 예방할 수 있도록 돕습니다.

Traceforce 작동 방식:

  1. Traceforce는 각 기기에 가벼운 바이너리(실행 파일)와 브라우저 확장 프로그램으로 설치됩니다.
  2. 30분 이내에 기기의 라이브 데이터가 회사 프로필로 업로드되어, 회사의 모든 기기에서 실행 중인 AI 에이전트 및 앱을 대시보드에서 모두 볼 수 있게 됩니다.
  3. 회사 보안 담당자는 모든 에이전트의 활동을 실시간으로 모니터링하고 통제 권한을 적용하며, 보안 위험이 발생하는 즉시 알림을 받을 수 있습니다.

데모 영상은 다음과 같습니다: https://youtube.com/watch?v=IdK2WKg7kaM

Traceforce의 영감은 Xia가 Clumio라는 스타트업(2024년 10월 Commvault에 인수됨)에서 엔지니어링 디렉터로 근무했던 경험에서 비롯되었습니다. 팀원들이 작업 속도를 저하시키지 않으면서 AI를 어떻게 사용하고 있는지 모니터링하는 것은 Clumio의 최우선 과제였습니다. 50명 이상의 최고 정보 보안 책임자(CISO) 및 최고 정보 책임자(CIO)와 대화한 후, 이것이 현재 전 산업군에 걸쳐 시급하게 필요한 솔루션이라는 것이 분명해졌습니다.

원문 보기
원문 보기 (영어)
Hey HN, we’re Xia and Varun, the founders of Traceforce (<a href="https:&#x2F;&#x2F;www.traceforce.ai&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.traceforce.ai&#x2F;</a>). Traceforce provides visibility and control over AI apps such as ChatGPT, Claude etc directly on all devices (laptops, sandboxes, virtual machines) by discovering not just which apps are being used but also how they are connected to other data sources via MCPs. We also have an open-source dynamic MCP pentesting tool <a href="https:&#x2F;&#x2F;github.com&#x2F;traceforce&#x2F;mcp-xray" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;traceforce&#x2F;mcp-xray</a> to detect vulnerable MCPs.<p>The purpose of Traceforce is to:<p>- Give a company’s employees a standardized way to ensure that AI software running on their device is operating safely<p>- Give the company’s security team visibility of the activities of AI software on the company’s devices, and to detect and prevent unsafe actions and security breaches as early as possible.<p>How Traceforce works<p>1. Traceforce is installed on each device as a lightweight binary and browser extension.<p>2. Within 30 minutes, the device is uploading live data to the company profile, displaying all the AI agents&#x2F;apps running across all company devices on a dashboard.<p>3. Company security staff can monitor the activity of all the agents in real time, implement controls, and be alerted to any security risks as soon as they arise.<p>Here’s the video demo: <a href="https:&#x2F;&#x2F;youtube.com&#x2F;watch?v=IdK2WKg7kaM" rel="nofollow">https:&#x2F;&#x2F;youtube.com&#x2F;watch?v=IdK2WKg7kaM</a><p>The inspiration for Traceforce came via Xia’s experience as Director of Engineering at a startup called Clumio (which was acquired by Commvault in Oct 2024). Being able to monitor how team members are using AI without slowing them down was a top priority at Clumio. After speaking with 50+ CISOs and CIOs, it became clear that this is a much-needed solution right now acro