TRACE CONTINUITY LABS

Every Decision Begins With Authority.

Execution-time authority, governance and verifiable evidence for AI agents and enterprise systems.

Trace Continuity determines whether an actor is authorized to perform a specific action at the moment of execution, enforces that decision at the execution boundary, and produces verifiable evidence of what was authorized and what occurred.

Don't take our word for it. Try to break it.

IdentitiesHumans · Agents · Systems
RequestsExact actions
PoliciesGovernance evaluation
DataSensitive-data protection
EXECUTION BOUNDARY
AllowExecute with controls
DenyBlocked with evidence
TransformModify with governance
Signed evidenceVerifiable records

Execution-time authorization

Not just authentication.

Governance over agents and data

Policies you can enforce.

Sensitive-data protection

Detect. Tokenize. Isolate.

Legal governance

Matters, ethical walls, legal holds.

Governed execution boundary

Protected actions behind enforcement points.

Verifiable, signed evidence

Checkpoints and retained anchors.

Execution-time authority · governance · evidence

One governed path. From identity to evidence.

Trace Continuity is an execution-time authority, governance and evidence layer for AI agents and enterprise systems. It determines whether an actor is authorized to perform a specific action at the moment of execution, enforces that decision at the execution boundary, and produces verifiable evidence of what was authorized and what occurred.

1
Identity
2
Authority
3
Governance
4
Exact Action
5
Human Approval
6
Live Recheck
7
Execution Boundary
8
Evidence

Human approval applies when the action requires it. Authority, governance and approval are re-checked live at the boundary — a permission issued earlier is refused if the authority behind it is gone.

Authority at the moment of execution
  • ▸Authority verified on every governed request, not cached from login
  • ▸Delegation chains enforced — a delegate can never exceed its grantor
  • ▸Reversible suspension and permanent, irreversible revocation
  • ▸Person offboarding: suspend a person and the authority, keys, agents and pending approvals that depend on them
  • ▸Governed API keys with required expiration; legacy keys flagged for review
  • ▸Registered agents with ownership, purpose and suspension
Governance that cannot be quietly weakened
  • ▸Allow / Deny / Transform on every governed decision
  • ▸Legal matters, ethical walls and legal holds
  • ▸Governed derived information and reported lineage
  • ▸Second-person approval before anyone can weaken an important protection
  • ▸Stale-access visibility: unused, expired and orphaned access surfaced for review
  • ▸Tenant isolation and sensitive-data tokenization before storage
Human approval for high-risk actions
  • ▸Approvers see the exact governed action they are approving
  • ▸No self-approval; a dependent of the requester cannot be the second person
  • ▸Approval binds one exact action — change the action and the approval no longer applies
  • ▸Approval is re-checked if authority, policy or matter status changes
Exact-action authorization at the execution boundary
  • ▸Permission bound to one exact action by a canonical fingerprint
  • ▸Single-use and time-limited
  • ▸Live authority recheck immediately before execution
  • ▸Redeemed only by the registered enforcement point it was issued for
  • ▸Outcome evidence: authorized, executed, failed and could-not-establish stay distinct
Evidence you can verify without trusting us
  • ▸Cryptographically signed evidence packages (Ed25519)
  • ▸Offline verification against Trace's published public keys
  • ▸Tenant-wide signed evidence checkpoints, chained in sequence
  • ▸Checkpoint anchors you retain outside Trace
  • ▸Deletion or rewriting of committed history is detectable against retained checkpoints
  • ▸Trace refuses to sign new evidence when committed history no longer matches
  • ▸Compromised signing keys handled with a fixed, narrow-only trusted boundary
One governed path
  • ▸Every governed read, write and action passes the same execution-time decision
  • ▸A build-blocking scanner fails the build if code reaches governed data around it
  • ▸Fail closed: “could not establish” is never treated as “allowed”

Stated precisely: external-action enforcement is non-bypassable when the protected credential or action is placed behind the Trace enforcement point; a credential left outside it can be used without Trace. Signed checkpoints do not stop a database owner from changing data — they make later alteration or deletion of committed history detectable against checkpoints retained outside Trace. Signing keys are held in platform secret storage today, not an HSM. No certification is claimed.

Independent Qualification Record
Run 2 Final Determination: Pass

A failure was found. It was fixed. Then the same test was run again.

Independent testing identified a material boundary failure during Run 1. The implementation was remediated and independently retested against the same frozen criteria.

Run 2 received a final determination of PASS against the frozen criteria for the tested trajectory and scope.

The original Run 1 baseline and Run 2 independent retest have been preserved as a completed qualification record.

RUN 1

Boundary failure identified

↓
REMEDIATION

Implementation corrected

↓
RUN 2

Same frozen criteria retested

↓
PASS

Independent final determination

Scope note: this is a qualification record, not a certification. The PASS applies to the frozen criteria for the specific tested trajectory and scope — it is not a statement that the platform as a whole has been certified, universally validated, or proven secure.

Independent Security & Architecture Evaluation

August 22, 2026 · Chimezie Emmanuel Uzochukwu, Independent Security & Architecture Reviewer

A separate independent evaluation of the Trace Continuity Sandbox covering runtime authority revocation, governed writes, PII handling and tokenization, safe retrieval, audit evidence, fail-closed behavior, and adversarial payload testing — including the evaluator’s documented limitations, weaknesses, recommendations, and scoped technical conclusion. This evaluation is independent of, and did not perform or validate, the Run 1 / Run 2 qualification testing above. It is not a certification or a guarantee of security.

View Independent Evaluation (PDF)
The Playground

Don't believe the marketing.
Try to break it yourself.

Four live surfaces. Real authority evaluation. Real tokenization. Real audit evidence. Hand it your worst inputs and watch the governance layer respond.

Open the Playground

Experience governed memory firsthand.

Authority Trace
EVALUATED
actor: agent_med_42 → user_clinician_18
tenant: medicore.health
scope: patient.read · memory.write
delegation: verified · 3 hops
decision: AUTHORITY OK · proceed to governance
Governance Decision
TRANSFORM
input: "...SSN 456-78-9012, email schen@..."
detected: SSN · EMAIL
policy: PHI/PII · tokenize · retain 7y
verdict: TRANSFORM
evt: evt_a8c3
Tokenization
SEALED
raw_ssn: 456-78-9012
→ token: trace_tok_ssn_a7b3
raw_email: schen@medicore.health
→ token: trace_tok_email_x9f2
raw_pii_at_rest: false
Audit Evidence
APPENDED
chain: evt_a8c3 → evt_a8c7
stages: authority · governance · tokenize · store
hash: sha256:9f2a…c8d1
evidence: signed · verifiable
export: HIPAA · legal hold · DoD review

Authority Trace · Governance Decision · Tokenization · Audit Evidence

Authority Continuity

Most systems authenticate once.
Trace Continuity verifies authority at execution time.

A session token at login is not authority. In hospitals, legal, and defense, the question is not "did this user sign in?" — it is "is this user, this agent, this delegated identity, allowed to do this exact thing, right now, against this exact tenant?" Trace evaluates that on every call. No cached trust. No implicit bypasses.

Per-call evaluation

Authority is re-checked on every read, write, and retrieval. Immediately suspend a governed agent at execution time: previously issued keys are refused on the next governed request. Lift removes suspension when otherwise authorized; permanent revocation cannot be undone.

Delegation aware

Registered agents are linked to ownership, purpose and authority-bound keys—not discovered enterprise-wide. The full authority lineage fails closed on a missing, suspended, revoked, expired, cross-tenant, cyclic or over-deep link. Applicable suspension cannot be bypassed through delegation.

Tenant by construction

Cross-tenant access cannot happen by mistake. The cross-tenant probe used by the public Break Arena is a separate demo-only entry point and is not reachable from the production gate.

Action Admissibility

Valid authority does not always mean an action should proceed.

Trace separately checks the material conditions that exist at execution time, including consent, risk, jurisdiction, compliance, and other governed conditions. If those conditions make the action inadmissible, Trace stops it even though authority remains valid. Every decision produces audit evidence. On the read path this happens twice: once before anything protected is fetched, and again at the last instant before disclosure.

Separate decision

Runtime Authority Verification and Action Admissibility are two independent checks, evaluated and audited on their own.

Material conditions

Consent state, risk score, jurisdiction, legal hold, compliance status and other governed facts. Each assertion is written atomically with a revisioned, hash-chained history row, so the state a decision relied on can be replayed.

Fail closed

If a required condition is missing or stale, the action is refused — not assumed admissible. Trace evaluates the state that has been reported to it; it does not poll outside systems to discover a change nobody told it about.

Authority: verified · Action admissibility: denied — both are real outcomes.

Architecture Flow
1
Identity
2
Authority
3
Governance
4
Exact Action
5
Human Approval
6
Live Recheck
7
Execution Boundary
8
Evidence

Authority and governance are separate decisions, both evaluated at execution time on reads, writes and external actions. Authority can pass while governance denies. Governed memory and safe retrieval run through the same path — memory is one of the things Trace governs, not the whole of it.

Governance follows reported derivation

When governed information produces AI memory, summaries, embeddings or extracted facts, Trace can preserve the reported source-to-derivative lineage in append-only, tamper-evident records — and evaluate the current upstream authority and conditions before those derivatives are later used. Source A permitted, memory D created from A, consent on A later revoked: D is denied at the next request.

Where lineage is required, a lineage walk that cannot be completed is a refusal, never treated as no lineage. Lineage-required mode is opt-in per organization. Trace governs reported lineage only — the integrating system reports the derivation; Trace preserves and evaluates it afterward.

Identity & Authority (Steps 1–2)
  • ▸Credential pinned to one authority; keys expire
  • ▸Person, authority and agent suspension checked at use
  • ▸Delegation chain verified fail-closed
  • ▸Permanent revocation can never be undone
Governance & Exact Action (Steps 3–4)
  • ▸Allow / Deny / Transform
  • ▸Material conditions, matters, ethical walls, legal holds
  • ▸Action bound by canonical fingerprint
  • ▸Weakening protections needs a second person
Approval & Live Recheck (Steps 5–6)
  • ▸Approver sees the exact action
  • ▸No self- or dependent approval
  • ▸Single-use, time-limited permission
  • ▸Authority re-checked right before execution
Boundary & Evidence (Steps 7–8)
  • ▸Registered enforcement point redeems once
  • ▸Outcome reported as evidence
  • ▸Signed, offline-verifiable packages
  • ▸Tenant-wide signed checkpoints
Step 1 — Authority First

Authority runs before everything else.

Before any data is scanned, tokenized, or stored — Authority evaluates who is making the request and what they are allowed to do. No bypasses.

6 questions Authority evaluates
1
Who is making the request?

API key, agent, or delegated identity

2
Who is receiving the request?

Target user or resource context

3
What permissions exist?

Scopes, roles, delegation chain

4
What actions are allowed?

Read, write, retrieve, export

5
Tenant boundary intact?

Cross-tenant blocked by construction

6
Final verdict?

Allow · Transform · Deny — with evidence

Break Me Challenge

We invite you to attack it.

This is not a game. There is no leaderboard. The Break Me Challenge exists so you can verify, with your own input, that the governance layer behaves the way we say it does. The expected result is not success — it is the platform visibly governing the data and exposing exactly how through "How Was This Governed?"

  • Insert an SSN, credit card, or API key
  • Insert raw passwords or email + phone combos
  • Attempt unsafe retrieval across tenants
  • Attempt authority failures and delegation gaps
  • Attempt policy violations and prompt-style bypasses
attempt_001 DENIED
cross-tenant read · authority failure
attempt_002 TRANSFORMED
raw SSN → tk_9f2a · vault sealed
attempt_003 AUDITED
evidence chain evt_a8c3 → evt_a8c9
Verifiable Evidence

Evidence you can check without trusting us.

Signed & offline-verifiable

Evidence packages are signed with Ed25519 and verified offline against Trace's published public keys. Verification reports VERIFIED, FAILED or INCOMPLETE — anything it cannot establish is never shown as verified.

Tenant-wide checkpoints

Signed checkpoints commit to a tenant's entire evidence history, in an ordering the database assigns. Retain an anchor outside Trace: later deletion of an action, rewriting of history or deletion of checkpoints is detectable against it.

Refuses altered history

Before signing a package or extending its checkpoint chain, Trace re-verifies committed history. If it no longer matches, Trace refuses, records the refusal and reports FAILED VERIFICATION.

Compromised-key handling

A compromised signing key can never sign again or return to active. Its trusted period is pinned by a replacement key and can only be narrowed. Old public keys stay published so past evidence remains verifiable.

Runtime visibility

Allow / Deny / Transform, denial reasons, agent activity and stale access. Monitoring summaries are views of evidence, not authoritative evidence.

Stated precisely

Checkpoints do not stop a database owner from changing data; they make changes to committed history detectable. Activity after the most recent retained checkpoint is protected only once a later checkpoint is retained. Evidence is not certification.

Governance vs Memory

Memory systems remember. Trace governs what may happen.

Mem0 and Zep are excellent at remembering. Trace started as governed memory and now governs execution itself — who may do what, at the moment it happens, with evidence — for environments where acting without authority is the liability: hospitals, law firms, financial services and defense.

CapabilityMem0ZepTCL
Long-term memoryYesYesYes
Authority verified at the moment of executionNoNoYes
Policy verdicts (allow / deny / transform)NoNoYes
Exact-action authorization at an enforcement pointNoNoYes
Human approval of the exact actionNoNoYes
Matters, ethical walls & legal holdsNoNoYes
PII detection & tokenizationNoNoYes
Signed, offline-verifiable evidenceNoNoYes

Comparison reflects publicly documented capabilities at the time of publication.

Built for

Where governance is not optional.

Healthcare

PHI tokenized at intake. Authority chains map to clinician scopes. Evidence to support HIPAA review.

Legal

Privileged content stays tokenized in storage. Matter-scoped authority. Evidence chains for legal hold.

Defense

Classification-aware governance. Per-tenant keys. Cross-tenant retrieval is structurally impossible.

Enterprise

Bring your own policy. Bring your own keys. Bring auditors — every stage emits evidence.

Pricing

Enterprise pricing available.

Priced by governance posture, not memory count. Tiers for evaluation through regulated production deployments.

Who governs? How is it enforced?

Before you trust it —
you need to understand this.

The Playground is the proof. Test the architecture yourself.