Back to products
Trace-AI

Trace-AI

Know What You Ship. Secure What You Depend On.

Website trace-ai.dev
Overview

What it is

Trace-AI predicts and prevents supply-chain attacks via metadata-driven analysis of open-source dependencies, registries, and maintainer activity, no source code needed. Built by engineers who scaled to millions, it helps teams ship fast and secure.

Intent

I need it when

Generate accurate software bill of materials (SBOMs) for compliance and security audits

Trace-AI automatically generates real-time SBOMs in CycloneDX and SPDX formats directly from repositories, tracking both direct and transitive dependencies. This enables audit-ready evidence mapped to ISO 27001, SOC 2, PCI-DSS, HIPAA, and GDPR requirements without manual spreadsheet maintenance.

Audit and customize security policies with transparent, open-source logic rather than black-box tools

Trace-AI publishes all classification logic, risk scoring, and compliance policies as open, forkable YAML or JSON. Teams can review the model, customize thresholds, and contribute improvements, with ZSBOM available on GitHub for local execution and complete control.

Prioritize and fix actual security vulnerabilities rather than managing alert fatigue from CVE dumps

Trace-AI provides exploit-aware vulnerability scanning that prioritizes CVEs with known exploits in the wild using multiple threat intelligence sources. This reduces noise by focusing teams on real, exploitable risks with full context rather than reporting all CVEs indiscriminately.

Gain visibility into third-party vendor dependencies, APIs, SDKs, and SLA compliance

Trace-AI tracks vendor APIs, SDKs, SLA expiry dates, and breach history alongside code dependencies in a unified dashboard. This provides comprehensive vendor visibility and security posture monitoring in real-time as code evolves.

Ensure license compliance and avoid legal surprises during enterprise software reviews

Trace-AI automatically identifies GPL, LGPL, and other copyleft licenses across dependencies, provides license distribution dashboards, and includes a customizable policies library. Teams can audit license compliance instantly and generate evidence for enterprise procurement reviews.

Drop

Not a fit when

  • Organization requires on-premise or self-hosted SBOM generation without any cloud component
  • Team uses only private package managers or internal registries not connected to GitHub or GitLab
  • Project needs real-time scanning for compiled binaries or container images rather than dependency manifests
  • Organization requires pricing transparency with exact per-repository costs before signup
  • Team needs support for package managers beyond npm, pip, Maven, Gradle, Go, RubyGems, NuGet, and Cargo
Commercials

Pricing

Freemium with per-repository paid tiers. First 5 repositories free. Predictable per-repo pricing as you scale. View pricing