An agent took down an environment for 13 hours.
Kiro deleted and rebuilt an environment. No attacker, no software fault: an autonomous agent acted on what it understood to be the request.
Read the Engadget report43,280 AI events recorded on our own engineering fleet in the last 30 days.
AI security and governance
Tracelet helps security and platform teams govern AI coding tools on developer machines. Discover unapproved tools, enforce policy on supported actions, and keep a clear record of each decision.
We built Tracelet because AI tools now act with the same access as the people using them without the visibility, guardrails, or accountability enterprises need.
Charith De Silva
Founder, Tracelet · CEO, Insighture
Tracelet is built and operated by Insighture. These figures come from the company’s own engineering fleet, not a demo environment.
Check tool coverageProduction deployment · rolling 30 days · refreshed every five minutes
Every AI tool, agent, model and MCP server on every developer machine, captured live.
Policies decide in the moment: allow, warn, log, require justification, or block.
Spend, ROI and productivity finally attributable. Leadership scales AI with confidence.
AI coding tools now read credentials, change infrastructure and act inside production. The risk is no longer theoretical.
Most of it starts outside procurement: 78% of AI users bring their own AI tools to work, tools not provided or sanctioned by their employer (Microsoft & LinkedIn, 2024 Work Trend Index).
Kiro deleted and rebuilt an environment. No attacker, no software fault: an autonomous agent acted on what it understood to be the request.
Read the Engadget reportCursor and Claude were reported to have deleted a production database in seconds, leaving no audit trail for the action.
Read the The Register reportAsked to remove test and build artifacts, Claude Code ran rm -rf with a trailing ~/. The home directory went with it: documents, photos, years of project files and the Keychain.
Read the Docker reportAgents now plan, execute and self-correct for hours without a human in the loop.
Thousands of MCP servers now wire agents into databases, cloud and internal tools.
Cloud tools watch the vendor's cloud. Nothing watches the machine holding the tokens.
Three scenarios from the product: the code editor, the desktop AI app and the Tracelet dashboard.
Each planned action is checked against policy before it executes.
Production backups remain protected.
Credentials are removed from tool output.
The feature branch push is allowed.
Tools discovered on your machines.
Discover activity where AI tools run.
MachineA new endpoint is visible before it has an owner or an approved policy.
Type an intent, preview the rules, dry-run before enforcing. One engine for guardrails, MCP control and data protection.
Incident at 2am? Access is granted, scored 1–10 for blast radius. Low auto-approves, high needs sign-off. Time-boxed, audited.
Approved servers only, permissions scoped per employee down to the action. Shadow installs flagged and quarantined.
PII, secrets and custom patterns stripped before the model sees them. OCR catches what is smuggled in screenshots.
Adoption, kept-code rate and cost per kept line. Value, not volume; coaching, not surveillance.
Describe the behaviour you want to govern. The assistant drafts rules you can preview and dry-run before enforcing.
Block or warn on risky agent actions.
Gate MCP tool calls behind approval.
Strip sensitive data before the model sees it.
Install the Tracelet agent on a developer machine. Telemetry appears here the moment it checks in.
Enforcement is the visible part. Three engines run underneath it.
Reasons about session context and policy intent when no rule or regex matches, then applies the configured response.
Turns AI activity into a clear view of adoption, output quality and spend, by team and project.
Gives every developer the same approved skills, rules and project standards in every supported IDE.
Deploy through Intune, use your existing identity provider, and govern AI access across device and browser.
11 coding tools · 4 browser assistants
AI tools appear without a shared inventory.
Enrolled machines and browsers report installed tools and connections.
Shared MCP tokens live in configuration files.
Each user’s credential is fetched from Vault for every MCP call.
Written policy cannot stop an unsafe action.
Block, hold for approval, warn, redact or require a reason before execution.
Agent actions are hard to trace to a person.
Every decision logged with its policy and the person behind it.
Start with two weeks of real usage, then shape the first policies around how your team works.
Run Tracelet in your own cloud, before any machines connect.
Enroll the team’s machines. Keep their existing tools and workflows.
Build a picture of real AI activity. Nothing is blocked.
Review findings together and agree what needs a guardrail.
Draft, simulate and refine the first rule before enabling it.
Observe-onlyDiscover and review. No actions blocked.
Scoped enforcement
Short answers, with links to the detail.
Tracelet applies policy to supported activity from AI coding tools on enrolled machines. Coverage depends on the tool, operating system and action. The coverage table shows which controls apply.
Tracelet works with supported coding tools already in use. We review your tools and the required integrations before planning a rollout.