Traceable
Traceable provides an AI-powered API security platform for enterprises, offering API discovery, vulnerability testing, and runtime threat protection. It serves financial services, healthcare, government, and technology customers and now operates as part of Harness Inc. following a March 2025 merger.
- Company typePrivate
- Founded2018
- HeadquartersSan Francisco, United States
- Headcount101–250
- GTM typeB2B
- OfferingSoftware
What Traceable does
Traceable is an enterprise API security company founded by Jyoti Bansal and Sanjay Nagaraj and headquartered in San Francisco, California. The company provides a context-aware API security platform designed to help large organizations discover, test, and protect their APIs across the software development lifecycle. Its customer base consists primarily of large enterprises in financial services, healthcare, government, and high technology, with named customers including Informatica, Jobvite, Axos Bank, Bullish, Navan, Credit Karma, Lemonade, Lineage Logistics, Zolve, Altana, and Falcon. The go-to-market targets enterprise security leadership (CISOs, CIOs, and governance/risk/compliance teams) through direct field sales, with a stated emphasis on quote-based subscription contracts.
The platform is built on two proprietary technical foundations: the OmniTraceEngine, which captures and analyzes all API traffic across actors, infrastructure, and dependencies, and the API Data Lake, a central repository that stores comprehensive API call data over time to enable context-aware, behavioral threat detection. Core capabilities are organized into three integrated modules, namely Application & API Posture Management for continuous API discovery and risk assessment, Application & API Security Testing for vulnerability identification integrated into CI/CD pipelines, and Application & API Protection for real-time defense against OWASP API Top 10 threats, bots, and zero-day exploits. Supporting offerings include the Securing Gen-AI APIs module for protecting LLM-powered applications, a Zero Trust API Access module, the API Catalog for audit compliance, and the ASPEN Labs security research division. AI and machine learning establish behavioral baselines of normal API activity and generate high-confidence alerts for anomalies, including specialized detection for prompt injection and OWASP LLM Top 10 risks.
Traceable operates a subscription-based SaaS revenue model with enterprise field sales and quote-based annual pricing, and no publicly disclosed price points. The company has raised approximately $110 million in venture funding across rounds in 2020, 2022 (a $60 million Series B at a $450 million-plus post-money valuation led by IVP), and 2024 ($30 million led by IVP). In March 2025, Traceable merged with Harness, another company founded by CEO Jyoti Bansal, to form a unified AI DevSecOps platform; the combined entity was valued at $5.5 billion in late 2025 following a $240 million Series E. Traceable now operates as a subsidiary within Harness Inc., with the parent subsequently acquiring Qwiet AI in September 2025 to expand its application security portfolio.
Traceable firmographics
Firmographics- Name
- Traceable
- Legal name
- Traceable Inc.
- Website
- https://traceable.ai
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Short description
- Traceable provides an AI-powered API security platform for enterprises, offering API discovery, vulnerability testing, and runtime threat protection. It serves financial services, healthcare, government, and technology customers and now operates as part of Harness Inc. following a March 2025 merger.
- Ownership category
- akta.pro rank
Traceable industry classification
Industry- Product category
- API Security
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- API Security (Discovery, Testing, Runtime Protection) (HDADACAB)
- akta.pro secondary industry
- Application & API Security for Digital Health (WAF/RASP/API gateways) (HLACAJAH)
Keywords
Where Traceable is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices3 records
Markets served
Traceable business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- API Security Platform Subscription: SaaS-based API security platform delivered as subscription licensing. The platform includes Application & API Posture Management, Application & API Security Testing, and Application & API Protection capabilities.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform subscription with comprehensive API security capabilities |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
Traceable product offering
Product offeringCore offering
Traceable provides an AI/ML-powered API security platform that delivers API discovery, security posture management, vulnerability testing, and real-time runtime protection across the software development lifecycle. The platform is anchored by the OmniTraceEngine and API Data Lake, which capture all API traffic and provide context-aware threat detection, including specialized protection for generative AI and LLM-powered APIs.
Product overview
Traceable is an intelligent API security platform that provides comprehensive protection across the entire software development lifecycle. The platform operates on a unified architecture built around the API Data Lake (OmniTraceEngine), which captures and correlates ALL API transactions to power context-aware security. The core platform consists of three integrated capabilities: Application & API Posture Management for continuous discovery and risk assessment, Application & API Security Testing for vulnerability identification and remediation, and Application & API Protection for real-time threat defense. Supporting modules include the API Catalog for audit compliance, Zero Trust API Access for advanced data protection, and specialized Securing Gen-AI APIs for AI-specific threats. The platform is complemented by ASPEN Labs, the company's security research division that conducts vulnerability research and publishes threat intelligence. The platform supports deployment across self-managed (on-prem or cloud), major cloud providers (AWS, GCP, Azure), and SaaS models, serving enterprises across financial services, healthcare, government, retail, and high technology verticals.
Differentiator
Problem solved
Functional benefit
Products and services
- Application & API Posture Management Continuous discovery and posture insights for APIs and MCP tools that identify and manage security risks across modern AI applications, providing visibility into all APIs, sensitive data flows, and overall API risk posture.
- Application & API Security Testing Vulnerability identification and remediation from code to runtime, integrating API and AI application security testing into the SDLC with dynamic payloads and live-traffic analysis that delivers rapid scans with virtually zero false positives.
- Application & API Protection Real-time runtime defense against OWASP Top 10, API vulnerabilities, bots, and DDoS attacks, protecting critical applications, APIs, and users across any environment with automated detection and blocking.
- Securing Gen-AI APIs Specialized solution for discovering, inventorying, and securing generative AI and LLM APIs, addressing shadow AI risk, sensitive data flows to AI systems, and OWASP LLM Top 10 vulnerabilities such as prompt injection and data disclosure.
- Zero Trust API Access Zero Trust solution that reduces API attack surface by minimizing or eliminating implied and persistent trust, providing advanced data protection deployed at the API edge.
Quantifiable outcome
- 60+ FTE hours saved weekly for enterprise customers
- +5 more outcomes
Companies that use Traceable
Customer profileNamed customers11 records
Segments6 records
Ideal customer profiles3 records
Traceable technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability5 records
Feature6 records
Traceable partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core and flagship.
- Qwiet AIcoreHarness (parent company of Traceable post-merger) acquired Qwiet AI, a leader in AI-powered vulnerability detection, in September 2025. This acquisition builds on Harness's expanded application security portfolio as its security business approaches $50 million ARR.
- HarnessflagshipTraceable merged with Harness in March 2025, creating a unified AI DevSecOps platform. Jyoti Bansal, CEO and founder of both companies, leads the combined organization. This merger combines Traceable's API security capabilities with Harness's AI DevOps platform to provide security across the entire software development lifecycle.
- HarnessflagshipPost-merger, Traceable operates as part of Harness Inc., leveraging combined capabilities for AI-driven DevSecOps. The merger valued Harness at $5.5 billion following a $240M Series E funding round.
Scale indicators10 records
Recent moves6 records
Expansion highlights6 records
Traceable competitors and assessment
Company assessmentDirect peers
- APIsec: APIsec provides automated API security testing and continuous vulnerability scanning, overlapping with Traceable's Application & API Security Testing module. It is a relevant peer particularly on the testing side of the API security stack.
- Wallarm: Wallarm is an API security platform offering discovery, testing, and runtime protection for APIs, microservices, and serverless workloads. It competes head-to-head with Traceable across financial services and SaaS enterprise customers, with comparable AI/ML-based threat detection positioning.
- AppSentinels: AppSentinels is an API security specialist focused on runtime API threat detection and behavioral analytics. It targets enterprise digital channels and overlaps directly with Traceable's API Data Lake and anomaly-detection capabilities.
- Cequence Security: Cequence Security provides API discovery, risk assessment, and runtime bot/API protection. It targets the same enterprise buyers as Traceable and competes directly in API threat detection and fraud prevention for financial services and digital-native companies.
Broad incumbents
- Akamai: Akamai has built out a full API security offering via its acquisitions of both Salt Security and Noname Security, competing directly with Traceable at enterprise scale while leveraging Akamai's global CDN and edge footprint.
- Palo Alto Networks: Palo Alto Networks offers API security through Prisma Cloud and its broader application security platform, leveraging its installed base of next-gen firewalls and CNAPP customers. It is a key platform incumbent competing for the same enterprise security budget.
- Imperva: Imperva offers API Security as part of its application and data security suite, combining WAF, bot management, and runtime API protection. It competes with Traceable particularly in regulated industries where Imperva has incumbent relationships.
- Cloudflare: Cloudflare bundles API Shield and API discovery into its global edge security platform, offering an integrated alternative for buyers already standardizing on Cloudflare's WAF, DDoS, and bot management services.
- F5: F5's NGINX App Protect and Distributed Cloud API Security provide API discovery, testing, and runtime protection, integrated with F5's broader app delivery and ADC portfolio. It is a frequent incumbent competing against Traceable in large enterprise environments.
Emerging players
- DataDome: DataDome focuses on bot management and API abuse prevention, with growing API security capabilities. It overlaps with Traceable's bot mitigation and account-takeover protection features and is a credible emerging challenger in the API abuse space.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Traceable social profiles
Digital presenceTraceable compliance and trust
Trust signalCompliance3 records
Traceable financial estimates
Financial estimateRevenue estimate
Valuation estimate
Traceable leadership team
Management profileNumber of profiles
Profiles12 records
Traceable funding detail
Funding detailFunding overview
Funding rounds3 records
Investors7 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Traceable M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Traceable
What does Traceable do?
Traceable provides an AI/ML-powered API security platform that delivers API discovery, security posture management, vulnerability testing, and real-time runtime protection across the software development lifecycle. The platform is anchored by the OmniTraceEngine and API Data Lake, which capture all API traffic and provide context-aware threat detection, including specialized protection for generative AI and LLM-powered APIs.
Is Traceable a public or private company?
Traceable is a private company. It is classified as corporate owned and is currently operating.
When was Traceable founded?
Traceable was founded in 2018. It employs 101 to 250 people.
Where is Traceable based?
Traceable is headquartered in San Francisco, United States, in the North America region.
How does Traceable make money?
One revenue line is on record: API Security Platform Subscription.
Who are Traceable's main competitors?
Direct peers on record are APIsec, Wallarm, AppSentinels and Cequence Security. Broad incumbents are Akamai, Palo Alto Networks, Imperva, Cloudflare and F5. DataDome is listed as an emerging player.
Does Traceable have an API?
Yes. Traceable exposes a public API. Developer documentation is at docs.traceable.ai.
What industry is Traceable in?
Traceable's product category is API Security. Its primary akta.pro industry code is HDADACAB, API Security (Discovery, Testing, Runtime Protection), with a secondary code of HLACAJAH, Application & API Security for Digital Health (WAF/RASP/API gateways). Its SIC code is 7370.