AppSecNews
API Security Commercial Established

Traceable AI

by Harness

API security platform that uses distributed tracing to capture full request context, driving discovery, threat detection and API security testing.

Visit harness.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Traceable AI in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Product packaging and naming following the Harness acquisition: confirm with vendor
  • The supplied vendor URL points to Harness Security Testing Orchestration, a distinct product. Verify the correct destination for Traceable before publishing
  • Current language agent coverage: verify against vendor docs

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Traceable's approach comes out of distributed tracing. Rather than sampling traffic at a gateway, it collects spans across a request's full path through a system, using in process agents, service mesh and proxy integrations, or OpenTelemetry compatible collection. A single external API call is reconstructed along with the internal calls it triggered, the parameters passed at each hop, and the identity of the user or token behind it. That context is the foundation: findings are attributed to a user and a call chain, not to an anonymous request hitting an endpoint.

From that trace data it builds an API catalog covering external and internal endpoints, classifies the sensitive data each handles, and tracks how that data propagates between services. Runtime protection analyzes traces for attack patterns and behavioral anomalies attributed to a specific actor over time: enumeration, authorization probing, account takeover, abuse of business workflows. A testing component reuses recorded traces to replay realistic request sequences against pre production environments, including authorization tests that swap credentials between recorded user contexts.

Where it fits

Agents and collectors run in staging and production, making this a platform engineering project as much as a security one. Discovery and detection are security team functions; testing runs from a pipeline as a pre release check. Following the Harness acquisition it sits alongside that company's delivery and security tooling, which matters if you already run Harness pipelines. The prerequisite is instrumentation broad enough that traces are complete, because partial coverage produces broken call chains and weakens everything built on them.

Strengths

  • Full trace context links an external call to the internal services and data it touched, which traffic based tools cannot reconstruct.
  • User and session attribution makes detection of slow, distributed abuse far more precise than source address based analysis.
  • Covers internal service to service APIs, not only edge traffic.
  • Recorded traces seed realistic tests, so testing reflects how the API is actually used rather than how a spec describes it.

Limitations

  • Instrumentation is the cost. Deploying agents across a large estate takes real engineering effort, and coverage gaps quietly degrade results.
  • In process agents carry performance overhead and a change control burden some teams will not accept in production.
  • Trace collection at volume means significant data handling, storage and privacy considerations.
  • The acquisition leaves naming, packaging and roadmap in flux, worth pinning down before committing.

Who it suits

Organizations running microservice architectures with existing observability practice, where full call chain context justifies the instrumentation work. Teams with monolithic applications, limited platform capacity, or a straightforward edge facing API surface will find simpler traffic based tools deliver most of the benefit for far less effort.

Used Traceable AI? Recommend it under your own name and title.

Recommend this tool