Trust center / Built for scrutiny

Autonomous, and bounded in code rather than policy.

Every probe runs inside the authorization you signed. Below is what enforces that, and an honest list of what we have not finished.

Controls

These are engagement-level controls in effect today, not roadmap items.

Scope governor, fail-closed
Your engagement becomes a hard allowlist, enforced at the API, the worker and every outbound request. It can be tightened mid-run and never widened. Adding a target requires re-authorization.
Signed rules of engagement
Scope, targets and timing are bounded by exactly what you signed. Nothing acts outside it.
Dry-run preview
See precisely what will be touched before a single request is sent.
Entitlement-bounded execution
Every capability is gated to your plan. Nothing runs that you did not buy.
Spend hard-capped
The cost governor caps AI spend per run. No runaway, no surprise bill.
Complete audit ledger
Every decision is scored and logged. The scope ledger records every allow and deny, so any call can be audited after the fact.
Non-destructive by default
Exploitability is confirmed with non-destructive techniques. The objective is proof, not damage.
Not finished

A proof-first company should be legible about its own gaps.

SOC 2
In progress, not achieved. We will say so until it is.
SSO and credential vault
Rolling out. Authenticated testing works today when credentials are provided for the engagement.
Continuous auto-trigger
Rolling out. Continuous cadence is operator-scheduled today.
One-click executive report
Rolling out. Full assessment reports and evidence bundles ship today.

Found something in GhostTrace itself? Write to [email protected] with the evidence and we will respond within one business day. A DPA is available on request, with data-residency options for regulated environments.