Trust-Boundary Architecture
Strict Local-First Perimeter
01Local Invariant

Local Repository & CLI

Local Environment

Raw source code stays strictly on machine (0 bytes transmitted)

02Strict Gate

Approved Record Boundary

Verification Gate

Only signed metadata & .trace artifacts allowed across boundary

03View Lens

TRACE Dashboard

Presentation Layer

Ephemeral view of project memory; Git remains sole authority

Data Transmission Perimeter Invariants:
sourceCodeIncluded: false

Raw file contents and private buffers are excluded at the parser AST boundary.

codeSnippetsIncluded: false

Context snippets and inline code extracts are redacted from synchronized payloads.

Secrets & Prompts Redacted

API keys, credentials, and raw model conversations are forbidden from .trace outputs.

Structured boundary matrix & invariants.

Precise mapping of operational behavior versus explicit non-claims across every system layer.

Local Engine & WorkspaceActive Invariant · 0 bytes source transmitted

Local mode

Current Behavior

Local analysis executes entirely within the project environment. AST symbol extraction, conflict scanning, and deterministic checks run without requiring source-code upload to TRACE Cloud.

What is Excluded / Not Claimed

Zero required source-code transmission. Raw repository files, uncommitted buffers, and local environment variables never leave your machine.

Cloud Ingestion & ProcessingControlled Boundary · Configured scopes only

Cloud mode

Current Behavior

Cloud coordination requires explicitly configured repository and model-provider boundaries. Only signed summaries, conflict digests, and approved .trace records are processed.

What is Excluded / Not Claimed

Retention, deletion policies, and third-party model provider behaviors are documented and auditable before production claims are made.

Credential & Content SanitizationSanitization Rule · Zero secret persistence

Secrets

Current Behavior

Credentials, tokens, prompts, raw source duplication, and private model conversations must not be written to .trace artifacts. Server-side secrets are kept outside browser and repository bundles.

What is Excluded / Not Claimed

Automatic runtime secret remediation or unverified DLP guarantees are not claimed; developers remain responsible for local credentials.

Enterprise Governance & PolicyRoadmap · Implementation in progress

Planned controls

Current Behavior

Future phases introduce tenant authorization, tamper-evident audit logs, safe Markdown sandboxing, secret scanning, prompt-injection hardening, and quarantine workflows.

What is Excluded / Not Claimed

SOC 2, ISO 27001, HIPAA, or formal regulatory compliance certifications are not claimed.

Explicit limits & certification transparency

Auditable Boundaries

TRACE does not currently claim SOC 2, ISO 27001, GDPR certification, zero retention, compliance guarantees, or a completed enterprise security program. Operational boundaries reflect verified software invariants, not external regulatory attestations.

No external compliance certifications

TRACE does not currently claim SOC 2, ISO 27001, HIPAA, GDPR certification, or a completed enterprise security audit.

No zero-retention third-party claims

External LLM model providers may retain temporary logs according to their enterprise terms unless self-hosted or network-isolated.

No absolute vulnerability immunity

AST parsers and tree-sitter bindings operate on untrusted input; sandboxing and memory limits are enforced but zero-day immunity is not claimed.

No developer surveillance metrics

TRACE will never implement individual developer rankings, keystroke logging, time tracking, or productivity scoring.

Responsible disclosure

If you discover a security issue, vulnerability, or potential leak in the TRACE specification or implementation, please report it responsibly through our GitHub Security Advisory channel.