I'm building DetectTrace in the open: one person, an AI agent workforce, six months of runway, in a category where funded startups have already raised tens of millions. Watch it succeed or fail, week by week, with the numbers attached.
One issue a week. No hype, no growth hacks. Unsubscribe in one click.
DetectTrace is the context layer above whatever detection stack you already run. It takes the alert, assembles the context that decides it, and hands back a case with the evidence attached. Every alert, with the context to decide it.
Can an alert carry its own context? DetectTrace, built from the first case up, and detect-forge, the open-source CLI that keeps the rules underneath it honest.
Can agents replace headcount? Every system shipped is an episode. The agent org chart is the org chart.
Who pays first, and why? The first design partner, the first cases worked by hand, the first retainer. Win or miss, it gets reported.
Readers, stars, cases, revenue, hours. Published every week, including the ones that hurt.
Can I validate this claim? Can it even be validated? Where's the code proof? Is it feasible at scale, in a real security environment? Researchers publish claims they never have to run. Practitioners run tools whose claims they never get to check. Building DetectTrace means checking both. Papers, vendor claims, and benchmarks get reproduced and graded, and everything the company ships is held to the same rubric, with reproducibility manifests, holdout splits, and frozen predictions.