The AI-native,
whitebox pen test

Reviewed by a security expert and audit-ready for your SOC 2.

acme-corp
Showing 8 of 8 findings
IDTitleFound
Open5
In Progress1
Fixed2
FlagrightMetalCluesoBastion
We needed a new penetration test report for a 3rd party with high urgency, and Trace turned it around faster than a traditional firm could even get us on the calendar. Every finding came with a working exploit and clear remediation — no list of maybes to chase down. They surfaced real, exploitable issues we hadn’t caught.

Director of EngineeringDirector of EngineeringAnti-fraud FinTech SaaS firm
Our customers are private equity firms who are extremely sensitive about their data. Unlike our legacy pen testers, Trace mapped our code and cloud configurations and ran a 30-minute onboarding call to understand the risks I was most worried about. The result was findings that mattered and helped us improve our security posture for customers.

Sergio PradaSergio PradaCo-Founder & CTO, Metal
Trace found vulnerabilities in our product that earlier pen tests missed entirely. They proved each vulnerability with an actual exploit, so there was nothing to second-guess. The signal quality was good enough that we run Trace on every pull-request for ongoing coverage.

Prajwal PrakashPrajwal PrakashCo-Founder & CTO, Clueso
Trace is the first truly capable penetration testing system I’ve seen. It goes far beyond security theater and actually surfaces real threats. I highly recommend Trace to any company that cares about security.

Madhu G NadigMadhu G NadigCo-Founder & CTO, Flagright

Everything included
in your pen test

Every finding proven, reviewed by a human, and audit-ready.

Verified findings

Every vulnerability is proven with a working exploit, reproduction steps, and remediation guidance. If it’s in the report, it’s real — nothing to triage.

Worklog
 
Cloning repository

Full white-box coverage

Trace connects to your source code, cloud configurations, and product documentation to map every attack path. Unlike a human pen tester, an agent can gather context at scale to find holes across your system.

CodeConnected
GitHub logoGitHub
GitLab logoGitLab
CloudConnected
AWS logoAWS
GCP logoGCP
Azure logoAzure
Vercel logoVercel
Supabase logoSupabase
Render logoRender
Cloudflare logoCloudflare
DocumentationConnected
Notion logoNotion
Slack logoSlack

Human in the loop

A certified OSCP offensive-security expert reviews every engagement and signs off on each finding. You also get a dedicated Slack channel to go back and forth with the Trace team throughout.

Slack#trace-yourcompany
Your private channel with the Trace team

Audit-ready report

Every engagement ends with a full penetration test report and a signed letter of attestation — ready to hand to auditors and prospects, and accepted for SOC 2, HIPAA, ISO 27001, and customer security reviews.

trace-pentest-report.pdf29 pages
Penetration test report page 1Penetration test report page 2Penetration test report page 3Penetration test report page 4Penetration test report page 5Penetration test report page 6

On-demand retests

Retest a remediation at any time. Trace re-runs the original exploit against your fix and confirms the vulnerability can no longer be reproduced.

About
Retests
Retest
StatusDurationRun
Fixed2m 30sJul 10, 2:14 PM
Open5m 02sJul 9, 4:22 PM
Open3m 45sJul 6, 10:11 AM
Open1m 58sJul 2, 9:03 AM

Continuous Scanning

Add-on

Trace runs on every pull request, catching security issues before they reach production — ongoing coverage between pen tests.

feat: add user search endpoint#247
claudecodepusheda1f3c2d
claudecodepushede7b9a01
Some checks were not successful
1 failing, 4 successful checks
Lint (pull_request)
Successful in 10s
Test (pull_request)
Successful in 24s
Type Check (pull_request)
Successful in 17s
Trace Security Scan
2 issues detected
Vercel
Deployment has completed

Integrates with
your entire stack

GitHub logo
GitHub
GitLab logo
GitLab
Bitbucket logo
Bitbucket
CircleCI logo
CircleCI
Jenkins logo
Jenkins
Docker logo
Docker
AWS logo
AWS
GCP logo
GCP
Azure logo
Azure
Vercel logo
Vercel
Supabase logo
Supabase
Cloudflare logo
Cloudflare
Kubernetes logo
Kubernetes
Terraform logo
Terraform
Vanta logo
Vanta
Drata logo
Drata
Secureframe logo
Secureframe
Slack logo
Slack
Jira logo
Jira
Linear logo
Linear
Datadog logo
Datadog
Sentry logo
Sentry
Grafana logo
Grafana
Tailscale logo
Tailscale
Confluence logo
Confluence
Notion logo
Notion
Request an integration