Everything your agents touch, governed.

TraceMem checks every action your AI agents take before it happens, holds the ones a person should approve, and keeps the record that answers for each one. Self-hosted, inside your own network.

An illustration of agent requests passing through TraceMem. Each request is checked as it crosses: sensitive values are tokenized or masked, identities are verified, some actions proceed, some are held for a person to approve, some are stopped, and every one is recorded.


Your agents already have access. Nothing decides what they may do with it.

In financial services, healthcare, law enforcement, critical infrastructure and the public sector, agents are already reading case files, moving money, changing records and calling systems a regulator will audit. They reach them through service accounts with standing access, under no verified identity and no per-action authority.

The controls you have were written for people and for applications. They sit at the edge of systems the agent is already inside, they never see a prompt, and they cannot hold one action and ask a person first. A policy that cannot refuse at the moment of the action is documentation.


Put your agents to work. Keep every decision yours.

Every action is checked before it happens, so agents can reach the systems that matter while your people stay in charge of what they do there.

See how it all fits together

Your agents don’t change. Their authority does.

Without TraceMem

Every agent finds its own way in

Each agent, framework and integration arrives with its own credentials, its own connection and its own idea of what it may do.

Approval rules live inside each agent

Every team decides for itself what needs a human. The rules drift, they contradict each other, and nobody can state the real policy.

The answer takes days to assemble

Identity sits in one system, the prompt in another, the approval in a chat thread. Reconstructing a single action is a project of its own.

With TraceMem

One governed path in

Model calls, data reads and tool calls all arrive the same way, so a control covers every one of them rather than the ones a team remembered.

One set of rules, applied everywhere

Rules are written once and versioned. Needing a human means the same thing for every agent, and the request reaches someone who can answer it.

The answer is already written down

Who it was for, what was checked, who approved it and what changed sit on one record, because they all happened in the same request.


TraceMem runs inside your network.

It deploys into your environment and your team operates it. Your data and your traces stay on your side of the boundary, and the only traffic that leaves is traffic your own policy let out.

A secure building seen through glass: turnstiles at the entrance, a hall of server racks, a row of fan-cooled racks, and a vault beside an archive of sealed boxes.

Your network


Every governed action is recorded in this much detail.

A trace carries the detection layers that ran, the products and purposes touched, the policy version and hash that applied, who approved what, and what changed as a result.

This one decision produced seventy-three events, each written before the step it records was allowed to proceed. Nothing is assembled from logs afterwards, and the chain makes a later edit detectable.

An evidence counter: bagged documents, a phone, a drive and a key laid out in a line, each with its own numbered tag, and a gloved hand placing a photograph at the near end.
seq 000–07210 of 73 events itemised

TRACEMEM

Decision receipt

tracemem.trace.v3

decision_id
DENV_01M1YQV8HAA6EVQ4RYPN7SR6N0
intent
credit_limit_increase
actor
m.lindqvist@northgate.example
automation_mode
propose
status
committed
seq · eventtime
  1. 000–015 · 16 events
  2. 016pii_detection_hit20:09:43

    PII detected in the inbound prompt (IBAN)

    layer
    stage_1_pattern
    pii_type
    iban
    confidence
    0.95
  3. 017pii_policy_decided20:09:43

    Configured policy applied to the detected spans: tokenize

    direction
    input
    mode
    tokenize
    tokens_minted_count
    4
  4. 018–020 · 3 events
  5. 021pii_obfuscation_applied20:09:43

    IBAN replaced with a reversible pointer token

    pii_type
    iban
    strategy
    pointer
    token_ref
    tracemem_token:tok_42OXOEB3ER2M
  6. 022–053 · 32 events
  7. 054read20:09:47

    Read executed by TraceMem on the agent's behalf

    product
    bank_customer_profile_read
    purpose
    credit_limit_assessment
    entities
    CUST_1001
  8. 055–057 · 3 events
  9. 058read20:09:48

    Second read, under a different declared purpose

    product
    bank_risk_signals_read
    purpose
    financial_crime_gating
  10. 059–061 · 3 events
  11. 062policy_eval20:09:48

    Published policy evaluated to require_exception

    policy_id
    credit_limit_increase_v1
    policy_hash
    280bc423eb4bae18
    result
    require_exception
    reason_code
    INCREASE_NEEDS_APPROVAL
  12. 063approval_requested20:09:48

    Exception routed to the configured approval channel

    channel
    slack
    approval_route_id
    credit_risk_approvals
  13. 064approval20:10:04

    Exception resolved by the named approver

    approved
    true
    approver
    d.moriarty <U0B75QUM1DK>
    comment
    approved
  14. 065–066 · 2 events
  15. 067write_completed20:10:04

    Write executed on the source system

    product
    bank_credit_facilities_update_limit
    operation
    update
    duration_ms
    86
  16. 068–071 · 4 events
  17. 072outcome20:10:05

    Envelope finalized as committed

    outcome
    human_allow
events recorded
73
events itemised
10
Outcome
human_allow
scheme
decisiondb.envelope.v1
algorithm
SHA-256
content_hash
e69b43108070d46cbb26b56afeefcce8

chain_hash f9827e632ab8a3ca73b5db98855605eb

Each line written before its step proceeded. Anyone you hand it to can verify it.

73 events
Chain verified


You already have the agents. This is the part that makes them defensible.

Tell us what your agents touch today. We will walk through what a governed path around them looks like in your environment.

What would you like?
When do your agents act on production systems?

Optional. A sentence is enough.

45days, free

Free for 45 days on our Docker-based trial image, inside your own network. When you are ready, it upgrades to the full enterprise product.

Forward-deployed engineers, ours or our partners', can set it up in days and help you define policies and integrations. This may be charged separately.