
TRACE CONTINUITY LABS
Execution-time authority, governance and verifiable evidence for AI agents and enterprise systems.
Trace Continuity determines whether an actor is authorized to perform a specific action at the moment of execution, enforces that decision at the execution boundary, and produces verifiable evidence of what was authorized and what occurred.
Don't take our word for it. Try to break it.
Not just authentication.
Policies you can enforce.
Detect. Tokenize. Isolate.
Matters, ethical walls, legal holds.
Protected actions behind enforcement points.
Checkpoints and retained anchors.
Trace Continuity is an execution-time authority, governance and evidence layer for AI agents and enterprise systems. It determines whether an actor is authorized to perform a specific action at the moment of execution, enforces that decision at the execution boundary, and produces verifiable evidence of what was authorized and what occurred.
Human approval applies when the action requires it. Authority, governance and approval are re-checked live at the boundary — a permission issued earlier is refused if the authority behind it is gone.
Stated precisely: external-action enforcement is non-bypassable when the protected credential or action is placed behind the Trace enforcement point; a credential left outside it can be used without Trace. Signed checkpoints do not stop a database owner from changing data — they make later alteration or deletion of committed history detectable against checkpoints retained outside Trace. Signing keys are held in platform secret storage today, not an HSM. No certification is claimed.
Independent testing identified a material boundary failure during Run 1. The implementation was remediated and independently retested against the same frozen criteria.
Run 2 received a final determination of PASS against the frozen criteria for the tested trajectory and scope.
The original Run 1 baseline and Run 2 independent retest have been preserved as a completed qualification record.
Boundary failure identified
Implementation corrected
Same frozen criteria retested
Independent final determination
Scope note: this is a qualification record, not a certification. The PASS applies to the frozen criteria for the specific tested trajectory and scope — it is not a statement that the platform as a whole has been certified, universally validated, or proven secure.
August 22, 2026 · Chimezie Emmanuel Uzochukwu, Independent Security & Architecture Reviewer
A separate independent evaluation of the Trace Continuity Sandbox covering runtime authority revocation, governed writes, PII handling and tokenization, safe retrieval, audit evidence, fail-closed behavior, and adversarial payload testing — including the evaluator’s documented limitations, weaknesses, recommendations, and scoped technical conclusion. This evaluation is independent of, and did not perform or validate, the Run 1 / Run 2 qualification testing above. It is not a certification or a guarantee of security.
View Independent Evaluation (PDF)Four live surfaces. Real authority evaluation. Real tokenization. Real audit evidence. Hand it your worst inputs and watch the governance layer respond.
Experience governed memory firsthand.
actor: agent_med_42 → user_clinician_18
tenant: medicore.health
scope: patient.read · memory.write
delegation: verified · 3 hops
decision: AUTHORITY OK · proceed to governance
input: "...SSN 456-78-9012, email schen@..."
detected: SSN · EMAIL
policy: PHI/PII · tokenize · retain 7y
verdict: TRANSFORM
evt: evt_a8c3
raw_ssn: 456-78-9012
→ token: trace_tok_ssn_a7b3
raw_email: schen@medicore.health
→ token: trace_tok_email_x9f2
raw_pii_at_rest: false
chain: evt_a8c3 → evt_a8c7
stages: authority · governance · tokenize · store
hash: sha256:9f2a…c8d1
evidence: signed · verifiable
export: HIPAA · legal hold · DoD review
Authority Trace · Governance Decision · Tokenization · Audit Evidence
A session token at login is not authority. In hospitals, legal, and defense, the question is not "did this user sign in?" — it is "is this user, this agent, this delegated identity, allowed to do this exact thing, right now, against this exact tenant?" Trace evaluates that on every call. No cached trust. No implicit bypasses.
Authority is re-checked on every read, write, and retrieval. Immediately suspend a governed agent at execution time: previously issued keys are refused on the next governed request. Lift removes suspension when otherwise authorized; permanent revocation cannot be undone.
Registered agents are linked to ownership, purpose and authority-bound keys—not discovered enterprise-wide. The full authority lineage fails closed on a missing, suspended, revoked, expired, cross-tenant, cyclic or over-deep link. Applicable suspension cannot be bypassed through delegation.
Cross-tenant access cannot happen by mistake. The cross-tenant probe used by the public Break Arena is a separate demo-only entry point and is not reachable from the production gate.
Trace separately checks the material conditions that exist at execution time, including consent, risk, jurisdiction, compliance, and other governed conditions. If those conditions make the action inadmissible, Trace stops it even though authority remains valid. Every decision produces audit evidence. On the read path this happens twice: once before anything protected is fetched, and again at the last instant before disclosure.
Runtime Authority Verification and Action Admissibility are two independent checks, evaluated and audited on their own.
Consent state, risk score, jurisdiction, legal hold, compliance status and other governed facts. Each assertion is written atomically with a revisioned, hash-chained history row, so the state a decision relied on can be replayed.
If a required condition is missing or stale, the action is refused — not assumed admissible. Trace evaluates the state that has been reported to it; it does not poll outside systems to discover a change nobody told it about.
Authority: verified · Action admissibility: denied — both are real outcomes.
Authority and governance are separate decisions, both evaluated at execution time on reads, writes and external actions. Authority can pass while governance denies. Governed memory and safe retrieval run through the same path — memory is one of the things Trace governs, not the whole of it.
When governed information produces AI memory, summaries, embeddings or extracted facts, Trace can preserve the reported source-to-derivative lineage in append-only, tamper-evident records — and evaluate the current upstream authority and conditions before those derivatives are later used. Source A permitted, memory D created from A, consent on A later revoked: D is denied at the next request.
Where lineage is required, a lineage walk that cannot be completed is a refusal, never treated as no lineage. Lineage-required mode is opt-in per organization. Trace governs reported lineage only — the integrating system reports the derivation; Trace preserves and evaluates it afterward.
Before any data is scanned, tokenized, or stored — Authority evaluates who is making the request and what they are allowed to do. No bypasses.
API key, agent, or delegated identity
Target user or resource context
Scopes, roles, delegation chain
Read, write, retrieve, export
Cross-tenant blocked by construction
Allow · Transform · Deny — with evidence
This is not a game. There is no leaderboard. The Break Me Challenge exists so you can verify, with your own input, that the governance layer behaves the way we say it does. The expected result is not success — it is the platform visibly governing the data and exposing exactly how through "How Was This Governed?"
Evidence packages are signed with Ed25519 and verified offline against Trace's published public keys. Verification reports VERIFIED, FAILED or INCOMPLETE — anything it cannot establish is never shown as verified.
Signed checkpoints commit to a tenant's entire evidence history, in an ordering the database assigns. Retain an anchor outside Trace: later deletion of an action, rewriting of history or deletion of checkpoints is detectable against it.
Before signing a package or extending its checkpoint chain, Trace re-verifies committed history. If it no longer matches, Trace refuses, records the refusal and reports FAILED VERIFICATION.
A compromised signing key can never sign again or return to active. Its trusted period is pinned by a replacement key and can only be narrowed. Old public keys stay published so past evidence remains verifiable.
Allow / Deny / Transform, denial reasons, agent activity and stale access. Monitoring summaries are views of evidence, not authoritative evidence.
Checkpoints do not stop a database owner from changing data; they make changes to committed history detectable. Activity after the most recent retained checkpoint is protected only once a later checkpoint is retained. Evidence is not certification.
Mem0 and Zep are excellent at remembering. Trace started as governed memory and now governs execution itself — who may do what, at the moment it happens, with evidence — for environments where acting without authority is the liability: hospitals, law firms, financial services and defense.
| Capability | Mem0 | Zep | TCL |
|---|---|---|---|
| Long-term memory | Yes | Yes | Yes |
| Authority verified at the moment of execution | No | No | Yes |
| Policy verdicts (allow / deny / transform) | No | No | Yes |
| Exact-action authorization at an enforcement point | No | No | Yes |
| Human approval of the exact action | No | No | Yes |
| Matters, ethical walls & legal holds | No | No | Yes |
| PII detection & tokenization | No | No | Yes |
| Signed, offline-verifiable evidence | No | No | Yes |
Comparison reflects publicly documented capabilities at the time of publication.
PHI tokenized at intake. Authority chains map to clinician scopes. Evidence to support HIPAA review.
Privileged content stays tokenized in storage. Matter-scoped authority. Evidence chains for legal hold.
Classification-aware governance. Per-tenant keys. Cross-tenant retrieval is structurally impossible.
Bring your own policy. Bring your own keys. Bring auditors — every stage emits evidence.
Priced by governance posture, not memory count. Tiers for evaluation through regulated production deployments.
The Playground is the proof. Test the architecture yourself.