Skip to main content
Live

575K+ AI events recorded on our own engineering fleet in the last 30 days.

Tracelet / Security & privacy

Private by design.
Yours to control.

AI governance in your environment, on your terms. Minimal data capture. Clear accountability for every decision.

ORGANISATION / AI ACTIVITY

How machines authenticate and where policy runs.

Three things to check first.

  1. 01

    Each machine proves its identity

    Each enrolled agent creates its own key pair and connects to the control plane over mutual TLS. The private key never leaves the machine.

    mTLS agent identity
  2. 02

    Policy is checked where the action happens

    Supported file, shell and MCP actions are evaluated on the enrolled machine, before the action completes.

    Local policy enforcement
  3. 03

    Capture is minimal by default

    File content is not stored. Prompt capture is off by default; opted-in prompt content is encrypted at ingest.

    Data minimisation by default
TRACELET.AISecurityIllustrative overview
Deployment boundary

Your infrastructure. A clear trust boundary.

Single tenant
Enrolled machine

Local policy enforcement

Supported actions are checked where they happen. The private key stays here.

Mutual TLS
Your cloud or on premises

Private control plane

Manage policies and review decision records inside your environment.

Private keys
Stay on your machine
File content
Never stored
Prompt capture
Off by default
Where it runs

One dedicated deployment.
In the environment you already govern.

The control plane is installed single-tenant into infrastructure you own. Choose the environment your security team already reviews, and Tracelet lands inside the compliance boundary that environment already has.

  • AWS

    Your AWS account

  • Google Cloud

    Your Google Cloud project

  • Azure

    Your Azure subscription

  • On premises

    Your data centre

  • Single tenant. Dedicated to your organisation.
  • Inside the compliance boundary you already have. Because Tracelet runs in your account, project, subscription or data centre, it falls within the controls, network perimeter and audit scope your team already maintains there, under SOC 2, ISO 27001, HIPAA or whichever framework applies to that environment. No data leaves your boundary to reach a vendor, so there is no new external data flow to document and no separate vendor system to bring into scope.

What a reviewer sees for one decision.

Action, policy, outcome and owner context, kept together in one record. Tracelet is not presenting a certification; documented status as of 11 September 2026:

SOC 2 Type IIIn progress. Not yet certified.
ISO 27001Controls aligned to the standard. Not certified.
GDPRData-handling controls in place to support a review. Not a certification.
Internal control standardsMapped together during the security review.
Decision evidenceReview ready
AI activity · GOV-4827Credential request held before accessPolicy applied
Decision
Action
Read ~/.aws/credentials
Tool
Claude Code
Ownership
Team
Platform engineering
Machine
macOS · enrolled
Policy
Policy
Production credential boundary
Verdict
Held · access prevented
Evidence
Attached
Policy evaluation and action context
Review status
Record complete
Where a record can support a review
ISO 27001Access · logging
SOC 2Monitoring · control
GDPRProcessing · records

See a policy decision on the machine.

The agent checks a planned action against your policy and records the decision before anything runs. Illustrative example.

TRACELET · GOVERNED SESSIONILLUSTRATIVE DEMO
Developer promptclaude-code · dev-04 · production

Waiting for the developer’s request…

1
AGENT$ mcp connect https://unknown-mcp.example/ssethen: write → prod.customers
2
TRACELETShadow MCP detectedUnregistered endpoint · Production write
ALERT
3
TRACELETConnection blocked by policyRegister and verify the connector before proceeding.
BLOCKED

Capture, retention and access are your settings, not ours.

  1. 01

    Control what is captured

    Prompt content is not stored by default. File content is not stored.

    Minimal capture by default
  2. 02

    Control how long it is kept

    Retention is set by data class and agreed during the security review.

    Configurable retention
  3. 03

    Control who can see it

    Record access is scoped to the people who need it, and is itself reviewable.

    Role-scoped record access

What is captured, and what is not.

Tracelet records activity and decision context. File content is not stored, and prompt capture is off by default.

Data boundaryInside your environment
Your machine

AI activityAction reaches the policy boundary

Policy context
Data classification
Decision outcome
File contentNot stored×
Tracelet record

Decision contextActor, tool, time and policy result

Decision recordContext stays with the decision

Prompt contentOff by default · explicit organisation opt-in
Your infrastructure Your policies Your data

Bring the security, audit and privacy questions your teams will ask.

We review these four with your security team before a partnership starts, along with your exposure from unsanctioned AI tools (see the State of Shadow AI report). Questions: tracelet@insighture.com.

Become a design partner
  1. 01

    Deployment boundary and data residency

  2. 02

    Machine identity, enrolment and access model

  3. 03

    Policy coverage for your tools and actions

  4. 04

    Capture, retention and record access