
Overview

Product video
Traceable AI continuously secures your APIs by bringing you real time protection and threat analytics. Traceable AI combines distributed tracing and advanced context based behavioral analytics to deliver modern API security to your cloud native and API based applications. It operates out of band or inline and does not require agents or changes to application code
For custom pricing, EULA, or a private contract, please contact marketplace@traceable.ai for a private offer
Highlights
- API Security
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Discovery | 250 API Endpoints | $20,000.00 |
Protection | 50M API Calls/Month | $70,000.00 |
Vendor refund policy
No Refunds
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
https://support.traceable.ai/hc/en-us Please reach out to our team either by email at support@traceable.ai or using our contact form at
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

Standard contract
Customer reviews
Improved API data protection and threat detection have reduced manual work but reporting still needs refinement
What is our primary use case?
In a legal project, we are using a third-party call. First of all, we are using a SaaS portal that is similar to ServiceNow and Salesforce in the legal project. From the legal project, we are connected with Endure, which is a third-party system. From Endure, many data flow through ADF through our legal portal. We are using Traceable AI for real-time threat detection. If there is a missing API or something called differently that we need to call, we use it in those cases. We also have some privacy considerations, including company privacy, company legal policy, and data privacy. For that protection, we are using Traceable AI . We are also protecting our customers, which means real-time legal lawyers, real-time legal analysts, and financial analysts and financial specialists. Those roles and responsibilities we have, and we are protecting them through Traceable AI.
Let me take an example of our project. Endure is a third-party system with which we are renting or collaborating. Our real-time project is a SaaS portal in our organization portfolio. In between, we have the ADF function and ADF service, which manages to take the APIs. It calls the APIs from the ADF site, and the data from Endure to our SaaS portal gets floated. We are real-time production users in Salesforce and ServiceNow , but we need data, and the data is flowing from Endure. Before taking the data from Endure to our portal or vice versa, sending from our portal to Endure portal, we have installed Traceable AI. It helps us protect data privacy. Whenever we are going to share any data from our system to a third-party system, it first detects whether the data contains any personal identifiable data or health insurance data or card information. If something is there, then it will create a matrix and send us a warning that we are going to share this kind of data through ADF to Endure, which it detects as a data privacy breach. The second use case is that we are getting many customer details from Endure to our portal. We have a set of customers for which we are getting the data. Traceable AI stops us and says that these are the IPs from where users want to log in, or we are getting a user ID and password from Endure. If it looks safe, then we are going to proceed; if not, then it stops there. These are the two use cases we are basically using while receiving the data from Endure and while sending from our side to Endure.
We are using Traceable AI for our web application and mobile application, which is a SaaS portal. We have our APIs as well. In real-time, if we got some threat or bot malfunctions that attacked our internal SaaS portal through Endure, Traceable AI detects the challenges and how we are going to mitigate them. It discovers the APIs and customer details that it already stored. Based on this function or capability, it learns, and if something comes differently, such as abnormal user behavior or a different API that wants to interact, it shows a threat. It will create a risk matrix, saying what is the severity, what are the sensitive data coming, what are the impacts from that, and what is the scope, meaning how it is going to fit into our portal. From there, we see a report that shows the incoming values from Endure and based on the matrix, it shows all our risks. We analyze that, saying that out of five, two functions are safe to send, and for the other three or four functions, we ask the third-party vendor why they shared this data or if it is a mistake or a real-time attack. This is how we are protected by this AI tool. It has a learning capability, and over time, it learns from previous inputs, working more accurately.
In our project with APIs and API calls, the end-to-end process goes from Endure to ADF and from ADF to our SaaS portal, and vice versa. We have many API calls there. From Endure, we used to get customer data, user ID, and password. If something beyond the list of users from our organization wants to log in or see our private data, the person logs into Endure, submits the API call, and it is triggered into ADF where we have Traceable AI installed. The Traceable AI matrix analyzes and checks if it is a valid user or password. If it finds an invalid user ID and password, it captures that data, along with the IP data, and creates a matrix to inform us about attempted logins to our portal from Endure. It always saves bulk APIs, such as data privacy APIs, financial APIs, and legal policy update APIs in ADF. If a threat destroys the front-line APIs, Traceable AI has a backup API copy. If you command Traceable AI, it retrieves the last active APIs, allowing you to reinstall that API into Azure and use it.
For accuracy, it is essential to provide the AI with proper rules, regulations, and a good algorithm. During real-time monitoring or UAT, we implement boundary analysis and negative values to ensure it acts appropriately in a real-time environment. Accurate training, prompts, and source data are vital for minimizing human intervention. In my project, we trained the LLM with 80 policies. Through monitoring, we identified additional policies to refine our sourcebook and inject those updates back into the LLM for improved performance.
What is most valuable?
A few features are there. Traceable AI helps us protect customers' data and customers' sensitive information, and whenever some suspicious values are coming from a third party to our system, it detects and alerts us about a malfunction or unknown data. It also helps us discover the APIs.
Feature-wise, Traceable AI helps safeguard organizational policies. If somebody wants to edit a policy, it captures the editor's details and sends it to us for validation. If it is a valid person or predefined user, that is fine; if not, we check why this person wants to change it. We use Traceable AI for incidents involving policy, finance, or private information.
Traceable AI reduces manpower and time. It creates a matrix for human review that specifies the threat, its severity, and its impact on the organization, enabling legal personnel to easily detect and implement crucial measures. This has significantly helped us.
Previously, for any incoming IPs or threat detections, we created a matrix to analyze threats and implement recovery functions. This process would roughly take two to three weeks, but Traceable AI allows us to complete it within a few hours. We save roughly ten days per cycle, with four or five cycles depending on the organization curve.
What needs improvement?
The documents for the initial setup are very limited, making us rely heavily on the vendor to install the setup, which can be costly. Each license costs a lot for our organization, and while we placed a few licenses in a confidential project, using it broadly requires more licenses, which is not financially feasible. Proper training is also crucial; we spent around two and a half years in a UAT environment to train the AI to understand our organization's policies before deploying it in production. While this approach has worked smoothly, we identified a need for better and more user-friendly reporting.
If we discuss national IDs, different countries have different national ID formats. Whenever we install Traceable AI, we need to inject our own configurations for the national IDs of various countries. If they use a real-time social security number or national ID sites in the future, it would be easier for us if the process were more flexible.
For how long have I used the solution?
I have been using Traceable AI in my legal and finance project for three and a half years.
What do I think about the stability of the solution?
Traceable AI is stable in its deployment and within a few minutes, it can be deployed. For low or medium-level cases, deployment is smooth and quick, while higher cases take longer for LLM adjustments or new models.
What do I think about the scalability of the solution?
Scalability for Traceable AI is high, enabling its use in real-world applications, particularly in legal cases or monitoring of private and public information.
How are customer service and support?
Customer support is satisfactory. We contact them for reports or dashboards, as creating a risk matrix from an API is not easy. We reach out for downtime situations as well, rating their support around eight or nine out of ten. I rate customer support as eight out of ten.
Which solution did I use previously and why did I switch?
We did not have a previous solution but used manual processes. A security team tracked IPs and tokens, checking encryption to inform us on safe or unsafe items.
How was the initial setup?
The documents for the initial setup are very limited, making us rely heavily on the vendor to install the setup, which can be costly. Each license costs a lot for our organization, and while we placed a few licenses in a confidential project, using it broadly requires more licenses, which is not financially feasible. Proper training is also crucial; we spent around two and a half years in a UAT environment to train the AI to understand our organization's policies before deploying it in production. While this approach has worked smoothly, we identified a need for better and more user-friendly reporting.
What about the implementation team?
We did not purchase Traceable AI through the AWS Marketplace . We directly contacted the vendor after performing market analysis, also considering tools from Palo Alto, before choosing Traceable AI. The vendor provided a demo and a free UAT environment for testing prior to purchase.
What was our ROI?
We have seen a return on investment from Traceable AI due to improvements in accuracy and security. It enhances our legal processes, reduces human intervention, and has shortened the time spent gathering data from three to four weeks to one to two days, which translates into direct and indirect benefits.
What's my experience with pricing, setup cost, and licensing?
The licensing and price cost depend on the organization and the volume of purchases. I am part of the SME and technical team, but I do not handle budgeting and cost-related cases, which is managed by a different team.
Which other solutions did I evaluate?
We evaluated other options, including Prisma Cloud from Palo Alto and Sequence Security, prior to selecting Traceable AI.
What other advice do I have?
I would rate Traceable AI seven out of ten.
My rating is based on its good learning curve. When we purchase this product, we give our own data and algorithms, and while we want additional features to enhance security integrations and recognize national IDs, the reporting sections also need improvement. The costs should be adjusted as well because if it remains high, it will not be beneficial for low to medium companies to use it.
Regarding governance and security, Traceable AI stores data in accordance with policies such as GDPR and HIPAA. It recognizes sensitive data upon entry or exit from our organization, sharing a matrix indicating which data is sensitive and should not be shared, thus safeguarding our company.
I advise organizations to choose Traceable AI if they utilize APIs, interact with third parties, or handle sensitive data or policy-related issues, as it assists with data governance, API capture, recovery, and identifying sensitive information. My overall rating of seven out of ten reflects Traceable AI's strong learning capabilities and security features, tempered by considerations regarding costs and the need for enhanced reporting and flexible national ID configurations.