TRACE does not currently claim SOC 2, ISO 27001, GDPR certification, zero retention, compliance guarantees, or a completed enterprise security program. Operational boundaries reflect verified software invariants, not external regulatory attestations.
—No external compliance certifications
TRACE does not currently claim SOC 2, ISO 27001, HIPAA, GDPR certification, or a completed enterprise security audit.
—No zero-retention third-party claims
External LLM model providers may retain temporary logs according to their enterprise terms unless self-hosted or network-isolated.
—No absolute vulnerability immunity
AST parsers and tree-sitter bindings operate on untrusted input; sandboxing and memory limits are enforced but zero-day immunity is not claimed.
—No developer surveillance metrics
TRACE will never implement individual developer rankings, keystroke logging, time tracking, or productivity scoring.