Trust center / Built for scrutiny
Autonomous, and bounded in code rather than policy.
Every probe runs inside the authorization you signed. Below is what enforces that, and an honest list of what we have not finished.
Controls
These are engagement-level controls in effect today, not roadmap items.
- Scope governor, fail-closed
- Your engagement becomes a hard allowlist, enforced at the API, the worker and every outbound request. It can be tightened mid-run and never widened. Adding a target requires re-authorization.
- Signed rules of engagement
- Scope, targets and timing are bounded by exactly what you signed. Nothing acts outside it.
- Dry-run preview
- See precisely what will be touched before a single request is sent.
- Entitlement-bounded execution
- Every capability is gated to your plan. Nothing runs that you did not buy.
- Spend hard-capped
- The cost governor caps AI spend per run. No runaway, no surprise bill.
- Complete audit ledger
- Every decision is scored and logged. The scope ledger records every allow and deny, so any call can be audited after the fact.
- Non-destructive by default
- Exploitability is confirmed with non-destructive techniques. The objective is proof, not damage.
Not finished
A proof-first company should be legible about its own gaps.
- SOC 2
- In progress, not achieved. We will say so until it is.
- SSO and credential vault
- Rolling out. Authenticated testing works today when credentials are provided for the engagement.
- Continuous auto-trigger
- Rolling out. Continuous cadence is operator-scheduled today.
- One-click executive report
- Rolling out. Full assessment reports and evidence bundles ship today.
Found something in GhostTrace itself? Write to [email protected] with the evidence and we will respond within one business day. A DPA is available on request, with data-residency options for regulated environments.