Skip to content
Trace

Trace

Category: DAST
License: Commercial
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated October 5, 2026
16 min read
Key Takeaways
  • $4,000 per test covers one application up to 500,000 billable lines of code; $12,000 covers up to 5 applications and 2 million lines; Enterprise above 2 million lines is custom.
  • $19,000 or $48,000 per year buys continuous coverage on the Startup or Scale tier, including one official pentest report a year that the vendor says can replace the annual test.
  • 4 vulnerability classes are validated by live exploitation on staging: injection (SQL, command, template), XSS, authorization bypass (IDOR, missing checks, role confusion), and SSRF plus open redirects.
  • 1 OSCP-certified engineer signs off on every finding, and the 29-page sample report names the tester (OSCP, CISSP) and a separate approver.
  • 0 standing copies of your source: each engagement clones repositories into an ephemeral sandbox that is destroyed afterwards, and LLM provider contracts prohibit training on customer content, with models configured for zero data retention.

Trace is an AI-native whitebox penetration testing service in the DAST family.

In a Trace pentest, AI agents read your source code and cloud configuration, then attempt real exploits against a staging environment you designate.

The service is operated by Clerk Technologies, Inc. under the Trace name, and its terms are governed by Delaware law. Pricing is public, starting at $4,000 per test.

The site lists Flagright, LlamaIndex, Metal, DevRev, Candid Health, MuralPay, Bastion, PointOne, and Credal among its customers.

Trace dashboard home showing a pentest in remediation with 8 findings, two applications, three connected GitHub repositories, and the GitHub integration

What is Trace?

Trace runs a whitebox pentest. It clones your repository into an isolated, ephemeral environment and reads the auth model, the data flows across services, and the business logic before it attacks.

The vendor contrasts this with black-box testing, which guesses at what sits behind an endpoint. Reading the handler behind each request is how Trace finds business-logic flaws, broken object-level authorization, and cross-tenant gaps.

Detection is half the pipeline. A validation sub-agent logs in to your staging stack and tries each candidate exploit, and an OSCP-certified engineer signs off before anything reaches the dashboard.

CapabilityDetails
Testing approachWhitebox: read-only clone of source plus a live environment with credentials
SurfacesStartup covers one web app or API; Scale adds network, desktop, mobile, CLI, cryptography, and LLM surfaces such as MCP servers and AI chat
ValidationLive exploitation on staging for injection, XSS, authorization bypass, SSRF, and open redirects
Human reviewOSCP-certified engineer reviews every finding; private Slack channel with the Trace team
ScoringSeverity tier plus CVSS score and vector, CWE, and OWASP Top 10 mapping (web, LLM, mobile, API)
DeliverablesPenetration test report and signed letter of attestation for SOC 2, ISO 27001, HIPAA; PCI DSS and CASA on Scale and Enterprise
RetestsUnlimited; results in minutes after a fix is deployed
Purchase modesOne-time engagement priced per test, or continuous coverage priced per year

How much does Trace cost?

Trace publishes its prices on its pricing page . Every tier is sold as a one-time engagement priced per test or as continuous coverage priced per year.

TierOne-timeContinuousScope
Startup$4,000 per test$19,000 per yearUp to 500,000 billable lines; one application (a web app or API)
Scale$12,000 per test$48,000 per year500,000 to 2 million lines; up to 5 applications; network, web, desktop, mobile, CLI, cryptography, and LLM surfaces; PCI and CASA coverage
EnterpriseCustomCustomOver 2 million lines with no application cap; bring-your-own-key inference; self-hosted deployment
Managed RemediationQuoted add-onQuoted add-onTrace engineers ship fixes as reviewed pull requests and retest on pre-production

Both purchase modes include unlimited retests. Continuous coverage adds one official pentest report a year, which the vendor says can stand in for an annual pentest.

Trace’s documentation compares Startup to a focused two-week manual pentest and Scale to a broader four-week one. Treat both as vendor positioning when you weigh them against a consultancy quote.

Billable lines are first-party code that is neither blank nor a comment. Tests, documentation, configuration and data files, and vendored or generated code are excluded.

The count is reproducible. Trace runs the open-source scc counter with ignore files disabled, and the dashboard shows how the total splits across each excluded bucket.

cd /path/to/your/repo
scc --no-gitignore --no-ignore --no-scc-ignore .

Admins and analysts can trigger a recount up to 10 times in 24 hours. A repository excluded from scanning drops out of the billable total.

How does a Trace pentest work?

Trace models the target with three objects: an application, an environment, and a credential. The application links to the repositories Trace reads.

The environment is a deployed instance with a reachable URL, typically staging. The credential is how Trace signs in as a real user.

Supported credential types include email and password, bearer and JWT tokens, session cookies, API keys, passphrases, saved session state, and SSH private keys.

For logins that send a magic link or one-time code, Trace’s agents have a dedicated inbox. They receive the message and complete the sign-in the way a person would.

Once analysis produces a candidate finding, a validation sub-agent takes over in a sandbox with short-lived, scoped access. The vendor documents four steps:

  1. Read the finding: the attack vector, the affected endpoint or code path, and the expected impact.
  2. Authenticate to the designated environment with the configured credential.
  3. Send the request, payload, or sequence of operations the finding describes.
  4. Observe the outcome. If the impact reproduces, the finding is marked verified and the reproduction is captured. If nothing reproduces, it is dropped or routed to human review.
Note
What gets exploited and what does not

Trace validates only findings it can reproduce safely. Anything that could cause data corruption, persistent state changes, or production impact is not exploited.

Those findings still ship with code citations, a threat-model write-up, and engineer review, but without an exploitation artifact.

Pentests are manual by design. Trace never starts an engagement automatically; testing runs only when you or the Trace team launch it against the application, environment, and time you choose.

Trace findings table listing 32 findings with ID, severity marker, title, category tag, and CWE for one pentest

What does a Trace finding contain?

Each finding carries a severity tier from Informational to Critical, with a CVSS score and vector. It also carries the vulnerability category, its CWE, and its OWASP Top 10 classification.

The root cause section names the affected repository, file, and line range. The attack scenario lists the attacker’s steps and the requests and responses Trace captured to prove them.

A remediation section states what to change and what Trace observed on retest.

Trace finding detail for a cross-tenant report export, showing description, root cause analysis with file and function, CVSS 9.6, CWE-639 and CWE-285, and a linked attack chain

For findings validated by exploitation, the Evidence tab holds the reproduction artifact. Depending on the finding type, that is an HTTP capture, a browser video, or an agent transcript.

It also records the data or access actually gained, not what analysis inferred.

Trace Evidence tab showing two HTTP transcripts and a data export captured during validation, each with caption, file size, and download link

Findings move through a documented lifecycle. Every state change records the actor, action, and timestamp for audit.

StatusMeaning
OPENReported and not yet worked
IN_PROGRESSA developer has picked it up
REMEDIATEDFix shipped, ready for retest
VERIFIED_FIXEDTrace retested and the exploit no longer fires
VERIFIED_OPENTrace retested and the issue still reproduces
PARTIALLY_FIXEDThe original exploit is closed, but a variant still reproduces
ACCEPTED_WITH_CONTROLSYou accept the risk; a written rationale is required and appears in the report
CONTESTEDYou dispute the finding; Trace decides whether to dismiss it, accept it, or keep it open
DISMISSTrace closes the finding

Findings surface in three places: the dashboard, the CLI, and Slack or email notifications.

What does the Trace report look like?

Trace publishes a 29-page sample report .

It opens with an engagement block naming the testing window, the methodology (white-box, exploit-gated, CVSS v3.1), the tester with certifications (OSCP, CISSP), and an approver.

The body has four numbered sections: an executive summary with findings by severity, key themes and recommendations, the threat ranking methodology, and a findings summary table.

That table lists each finding’s ID, severity, CWE, CVSS score, and status. The sample engagement lists 10 findings, 8 of them remediated and verified.

Severity follows the standard CVSS v3.1 bands: 9.0 and above is Critical, 7.0 to 8.9 High, 4.0 to 6.9 Medium, 0.1 to 3.9 Low, and 0.0 Informational.

Every vector in the sample starts with CVSS:3.1, and so does the one in the docs’ dashboard screenshot. A report-cover graphic on the homepage says CVSS v4.0, so confirm the version if your risk register expects v4.0 scores.

Three appendices follow: assessment scope, Trace methodology, and per-finding detail. The methodology appendix describes five phases: reconnaissance, threat modeling, exploit-gated discovery, triage and scoring, then reporting and retest.

Each per-finding entry carries the CVSS vector, root cause, impact, attack scenario, proof of concept, remediation, and what the retest observed.

The report ships with a signed letter of attestation. Trace positions both documents for SOC 2, ISO 27001, HIPAA, PCI DSS, and vendor security reviews.

What does Trace integrate with?

Trace’s position is that the more context you connect, the deeper the test. Source code is mandatory. Everything else is optional but changes what the agents can reason about.

LayerIntegrationsAccess model
Source codeGitHub App, Bitbucket Cloud (Forge app); GitLab shown on the siteRead-only; clone tokens are short-lived and requested per engagement
Cloud inventoryAWS, GCP, Vercel, Convex (Azure on the roadmap)Read-only; AWS through a cross-account IAM role, GCP keyless through Workload Identity Federation. Convex has no read-only key, so Trace stores a full-access deploy key and enforces read-only in its own code
Knowledge baseSlack, Confluence, NotionIntended behavior, so a real flaw can be told from expected functionality
Issue trackingLinear, JiraOne ticket per finding, linked back to the report
NotificationsSlack, emailCritical findings as they land
Logs and telemetrySentry, Datadog, GrafanaMarked “coming soon” on the vendor site

The AWS integration inventories accounts, regions, and key resource types on a recurring basis and tags internet-facing resources. During an engagement, Trace uses that topology to confirm whether a weakness is reachable.

The Linear integration is the documented tracker path. Tickets are created singly or in bulk (up to 10 per request), and moving a ticket to Done marks the finding REMEDIATED in Trace.

Linear tickets carry the fix guidance but not the proof of concept. Exploit steps and evidence stay inside Trace’s access controls, even when the ticket is visible across your workspace.

Trace’s llms.txt also names CircleCI, Jenkins, Kubernetes, Terraform, and the compliance platforms Vanta, Drata, and Secureframe. None has a documentation page yet, so I would confirm each before relying on it.

Connects to
GitHub GitHub
Bitbucket Bitbucket
AWS AWS
GCP GCP
Vercel
Convex
Linear Linear
Jira Jira
Slack Slack
Notion

How does the Trace CLI work?

Trace ships a terminal client, tracecli, as an npm package. It runs on the Bun runtime, so bun needs to be on your PATH.

It covers authentication, organization context, application and environment setup, credentials, repositories, source uploads, code-size measurement, and pentest findings.

npm install -g securewithtrace
tracecli --help

Two credential sources are supported. A long-lived TRACE_API_KEY (prefixed trace_sk_) is the path for CI and other non-interactive use.

tracecli auth login runs a device-flow login instead. It stores a WorkOS JWT and refresh token under ~/.trace/.

Some commands require a human session and reject API keys: application, environment, and credential writes, source uploads, and org update. The API returns 403 Human principal required for this operation for those.

Command groupWhat it does
auth login / logout / statusDevice-flow login, token removal, current session; status exits 1 when not logged in
org list / current / switchPick the active organization; switch refuses to run while TRACE_API_KEY is set
application, environment, credentialCreate and manage the three target primitives
inboxDedicated mailboxes the agents use to receive magic links and one-time codes
repo list / filter / cloneWork with synced repositories
uploadPush a source archive when a repository cannot be connected directly
pentest questionnaireView or fill the optional intake questionnaire that helps scope an engagement
pentest findings list / get / status-updatePull findings, with --detail for full write-ups, and move one to IN_PROGRESS, REMEDIATED, or ACCEPTED_WITH_CONTROLS

The --detail flag returns every prose section of each finding. The docs present this as a way to hand a whole engagement to a coding agent, which then marks each fix REMEDIATED for retest.

List commands render through an interactive pager on a TTY. Passing --output json or --output tsv, or setting NO_PAGER=1, skips it for scripts.

How does Trace handle your source code?

A whitebox pentest hands the vendor your code, so this section matters more than it would for a black-box scanner.

Trace documents the controls on its data handling page .

The repository clone lives only for the engagement and is destroyed afterwards. What persists is the findings, the report, and reproduction artifacts, with a small code snippet at each affected location.

Trace states that its LLM provider contracts prohibit training on customer content and that the models are configured for zero data retention.

ControlVendor statement
Source retentionEphemeral clone, destroyed after the engagement; snippets only in findings
Model trainingProhibited by contract; zero data retention configured with LLM providers
GitHub App scopeRead-only; no write to contents, no org settings, no ungranted repositories
Cloud accessRead-only; AWS role with a per-organization external ID, GCP metadata-only with no service-account keys
CredentialsManaged secret store, scoped to one environment, never written to logs or audit trails
Encryption and isolationTLS 1.2 or higher in transit, encrypted at rest; tenant isolation enforced at the database layer
Internal accessRestricted, audited, customer permission required beyond aggregate diagnostics
IdentitySSO via WorkOS: SAML 2.0 (Okta, Entra, OneLogin, JumpCloud, Auth0, Ping), OIDC, Google, Microsoft; SCIM on enterprise plans
RolesDeveloper, Analyst, Admin, each a superset of the previous
Audit logForwarded to WorkOS Audit Logs; in-product view on the roadmap

The trust center lists four documents shared on request: a penetration test summary, an information security policy, a subprocessor list, and a data processing agreement. Some are NDA-gated.

It does not list a SOC 2 report. I would ask whether one exists, and what it covers, before granting repository access.

How do you get started with Trace?

You can sign up with a work email or book a 30-minute demo. Onboarding is hands-on: Trace’s team runs the first engagement alongside you and calibrates scope before you rely on the output.

  1. Account provisioning in WorkOS, with SSO and SCIM wired up if you need them.
  2. Install the Trace GitHub App or connect a Bitbucket Cloud workspace, then select repositories.
  3. Define the application, its environment URL, and a credential; optionally connect AWS, GCP, or Vercel.
  4. Trace runs the engagement, validates each finding, and an engineer reviews the report.
  5. Work findings in the dashboard or Linear, ship fixes, and let Trace retest each one.

The minimum to prepare is repository access and a staging or production URL. Staging is the better choice, because exploitation runs against whichever environment you designate.

Trace vs Strix

Strix is an open-source autonomous pentesting agent under Apache 2.0 with about 67,000 GitHub stars. You install it with one curl command and supply Docker plus an LLM API key.

It works with OpenAI, Anthropic, Google, Bedrock, Azure, or a local model, and it validates findings with proofs-of-concept. It also runs headless in CI with pull-request diff scoping.

Trace is a paid service rather than a tool you operate. The vendor supplies the inference, the sandbox, the OSCP-certified reviewer, and the attestation letter.

The cost models differ in kind. Strix’s CLI is free and its hosted Platform starts at $29 per seat per month, with pentests billed separately per test. Trace charges $4,000 or $12,000 per engagement.

Pick Strix if you want a developer-run agent inside your own pipeline and can review its output yourself.

Pick Trace if an auditor, a customer, or a PCI assessor needs a report with a named tester and a signed letter.

Trace vs RunSybil

RunSybil is an AI-native offensive security platform built around an agent called Sybil. It tests black-box, without source code access.

Sybil explores applications, APIs, cloud, and infrastructure from the outside and chains findings the way an attacker would. The company raised $40M led by Khosla Ventures and lists Cursor and Notion among its customers.

Trace takes the opposite access model. It reads the code, which the vendor argues is how you reach business-logic flaws and cross-tenant gaps that outside probing misses.

Both tools end with exploitation evidence, but from different starting points. RunSybil publishes no pricing and sells through a demo; Trace publishes per-test and per-year tiers plus a downloadable sample report.

Pick RunSybil if you want attacker-style testing on every deployment and cannot share source.

Pick Trace if you can grant read-only repository access and want a scoped engagement at a published price.

Trace vs Darkmoon

Darkmoon is an open-source autonomous pentesting platform under GPL-3.0, maintained by ASC-IT in Toulouse. An orchestrator agent fingerprints the stack and dispatches specialist sub-agents, with 50 agent definitions in the repository.

Darkmoon keeps sensitive values away from the model. The model never executes tools directly, and real IP addresses are swapped for placeholders before a prompt leaves the machine.

Trace runs the models on the vendor side under contractual zero-retention terms, and its agents execute requests against your environment from a sandbox. Enterprise customers can bring their own inference key or deploy self-hosted.

Darkmoon is black-box and self-hosted; Trace is whitebox and vendor-operated by default. Darkmoon reports the request, payload, and response; Trace adds code citations and a human reviewer.

Pick Darkmoon if you need to keep targets and prompts on your own machines and can run the platform yourself.

Pick Trace if you want source-level findings, a compliance-ready report, and someone else operating the tooling.

When should you use Trace?

Trace fits a team that needs a pentest report for SOC 2, ISO 27001, HIPAA, or a customer security review and wants findings that were exploited, not a scanner export.

The vendor’s own framing is AppSec engineers and CISOs who need defensible evidence, and engineering teams who want to fix real issues.

It also fits codebases where the risk sits in authorization logic. IDOR, cross-tenant leaks, and role confusion are hard for a black-box tool to find, and they are what whitebox reading targets.

It is a poor fit if you cannot share source. Trace has no black-box mode.

One-time engagements are also a poor fit for per-commit testing. Continuous testing as code changes is sold separately, at $19,000 or $48,000 a year.

What are alternatives to Trace?

  • Strix : open-source Apache 2.0 AI pentest agent you run yourself, with a hosted Platform from $29 per seat.
  • RunSybil : black-box AI offensive security that runs on every deployment, no source access needed.
  • Darkmoon : GPL-3.0 self-hosted agent platform with a privacy-first execution model.
  • Beagle Security : AI-powered pentesting platform for web apps, APIs, and GraphQL with public pricing from $99 per month.
  • Bright Security : developer-first DAST built for CI/CD pipelines, with LLM Top 10 coverage.

For the wider field, see the DAST tools hub and the AI pentesting agents research page.

What are Trace’s limitations?

The strengths are easy to check: public pricing, a sample report you can read before a sales call, exploitation evidence per finding, and a named certified reviewer. The limitations below matter as much.

Whitebox access is a hard requirement. If legal, procurement, or a customer contract blocks sharing source with a third party, Trace does not apply.

Exploitation stays inside a safe subset. Four classes are validated live; anything with persistent side effects ships as reviewed analysis without a reproduction artifact, so read the “verified” label per finding.

The homepage says there are no false positives to triage. The terms of service state that AI-generated findings may include false positives, which is the more useful planning assumption.

The terms also put production-testing risk on the customer and recommend staging. Point the environment at staging unless you have a reason not to.

Bitbucket support is Cloud only; Data Center and Server are not supported. The Convex integration stores a full-access deploy key, because Convex offers no read-only credential, and Trace enforces read-only in its own API.

Azure inventory and the in-product audit log are on the roadmap, and log integrations are marked coming soon. If those are gating requirements, ask for dates.

I found no funding details on the vendor site, and no benchmark published or linked by the vendor. Ask for reference calls, not only logos.

Tip
Best For
Engineering-led teams that can grant read-only repository access and need an exploit-verified pentest report with a named certified tester, at a published per-test price, in days rather than weeks.
Note: Commercial service with public per-test and per-year pricing. Whitebox only: Trace needs read access to your repositories and a reachable staging or production URL. Not fully automated; a certified engineer reviews every finding.

Frequently Asked Questions

What is Trace?
Trace is an AI-native whitebox penetration testing service. It clones your repositories into an isolated sandbox, reads the code and cloud configuration, and attempts each candidate exploit against a staging environment you designate. An OSCP-certified engineer signs off on every finding, and each engagement ends with a penetration test report and a signed letter of attestation.
How much does Trace cost?
Startup is $4,000 per test, or $19,000 a year for continuous coverage, for one application up to 500,000 billable lines of code. Scale is $12,000 per test or $48,000 a year for up to 5 applications and 2 million lines, and adds PCI and CASA coverage. Enterprise is custom, and Managed Remediation is a quoted add-on.
Is Trace fully automated?
No. AI agents run the testing, but a certified security engineer reviews every finding before the report reaches you. One-time pentests also never start on their own: an engagement runs only when you or the Trace team launch it against the scope you chose.
What does Trace exploit on a live system?
Trace validates four classes against the running environment: injection (SQL, command, template), reflected, stored, and DOM XSS, authorization bypasses such as IDOR and role confusion, and SSRF plus open redirects. Anything that could corrupt data or change persistent state is not exploited. Those findings ship with code citations and expert review but no exploitation artifact.
Which CVSS version does Trace use?
CVSS v3.1, based on Trace’s published material. The 29-page sample report lists its methodology as CVSS v3.1, and every vector in it, like the one in the documentation’s dashboard screenshot, starts with CVSS:3.1. A report-cover graphic on the homepage reads CVSS v4.0, so confirm the version with Trace if your risk register expects v4.0 scores.
How does Trace compare to Strix?
Strix is an open-source Apache 2.0 CLI with about 67,000 GitHub stars that you run yourself with Docker and your own LLM API key. Trace is a paid service at $4,000 or $12,000 per test with whitebox source access, an OSCP-certified reviewer on every finding, and a signed attestation letter. Pick Strix for self-run, developer-driven testing; pick Trace when an auditor needs a report with a named tester.
What does Trace need access to?
At minimum, your GitHub repositories and a staging or production URL. Trace asks for as much context as you can give: a login credential for the environment, read-only AWS, GCP, or Vercel access, and optionally Slack, Confluence, or Notion documentation. The GitHub App is read-only, and clones use a short-lived installation token.
How long does a Trace pentest take?
Trace states that most pentests complete within a few days, depending on scope. Its documentation compares the Startup tier to a focused two-week manual pentest and Scale to a broader four-week one. Retests after a fix return results in minutes, and they are unlimited on every tier.