+The request path
Your agent
Any client, SDK or framework. Bearer itr_rt_* key.
Intertrace edge
Gateway
LLM · MCP · A2A · Inference · Service planes
Security kernel
Identity, floors, intent, judge, fusion, authorize, permits. Fails closed.
Approved upstream
Model, tool, MCP server, service or agent.
Control plane
Dashboard, policy, approvals, inventory, graph and decision records — isolated per organisation.
+Principles
Five properties that hold on every request
Identity from the key
The runtime key determines the tenant and agent. Nothing the caller sends can claim to be someone else.
Decide before acting
Prompts are inspected before the model sees them, and tool calls are authorized before they run.
Fail closed
If the kernel can't reach a decision, the request is denied — never passed through.
One final authority
AI models and third-party policy engines are inputs. The kernel owns the verdict, and inputs can only make it stricter.
Isolated by organisation
Every record is scoped to your organisation, enforced in the database, not just the app.
+Planes
One edge for all agent traffic
LLM
OpenAI-compatible /v1 for chat, responses and embeddings.
MCP
Every tools/call authorized; tool lists inspected and pinned.
A2A
Agent-to-agent messages inspected before delegation.
Inference
Self-hosted and third-party model endpoints.
Service
Internal APIs your agents call, under the same policy.
+Data
What goes where
Runtime key
Verified at the edge
The key identifies your organisation and agent. Headers sent by the caller can't override it.
Prompts and responses
Inspected in the request path
Checked before they reach the model or return to the agent. Not used to train public foundation models.
Tool calls
Decided before execution
Tool, arguments, agent and tenant are checked against policy. Allowed calls get a single-use permit.
Decision records
Your organisation's workspace
Verdict, reason, agent and context, isolated per organisation. Retention follows your plan and configuration.
Upstream credentials
Broker or vault
Agents get the integrations they're allowed; secrets stay out of prompts and configs.
Traces
Metadata only
Observability exports carry timing and identifiers, not prompt content.
See the privacy policy and security page for data handling commitments. Subprocessor details and questionnaires are available on request.
+Deployment
Managed, or in your own cloud
+Fully managed
Point your agents at the hosted edge.
- Live in minutes — change one base URL
- Upgrades and detection updates handled for you
- Start in monitor mode, enforce per agent
+Customer-hosted
Run the edge and kernel in your cluster.
- Gateway and security kernel deployed with Helm
- Traffic stays inside your network boundary
- Connected to the same control plane for policy and review
+For reviewers
+ Security review
Bring your questionnaire.
We'll walk your team through the architecture and answer the hard questions directly.