Skip to content

Enterprise deploymentCustomer-hosted or fully managed.Contact salesView pricing

+Architecture

Where Intertrace sits, and what it sees.

For security reviewers: the request path, the trust boundaries, what data goes where, and how to run it — fully managed or in your own cloud.

+The request path

Your agent

Any client, SDK or framework. Bearer itr_rt_* key.

Intertrace edge

Gateway

LLM · MCP · A2A · Inference · Service planes

Security kernel

Identity, floors, intent, judge, fusion, authorize, permits. Fails closed.

Approved upstream

Model, tool, MCP server, service or agent.

Control plane

Dashboard, policy, approvals, inventory, graph and decision records — isolated per organisation.

+Principles

Five properties that hold on every request

Identity from the key

The runtime key determines the tenant and agent. Nothing the caller sends can claim to be someone else.

Decide before acting

Prompts are inspected before the model sees them, and tool calls are authorized before they run.

Fail closed

If the kernel can't reach a decision, the request is denied — never passed through.

One final authority

AI models and third-party policy engines are inputs. The kernel owns the verdict, and inputs can only make it stricter.

Isolated by organisation

Every record is scoped to your organisation, enforced in the database, not just the app.

+Planes

One edge for all agent traffic

LLM

OpenAI-compatible /v1 for chat, responses and embeddings.

MCP

Every tools/call authorized; tool lists inspected and pinned.

A2A

Agent-to-agent messages inspected before delegation.

Inference

Self-hosted and third-party model endpoints.

Service

Internal APIs your agents call, under the same policy.

+Data

What goes where

Runtime key

Verified at the edge

The key identifies your organisation and agent. Headers sent by the caller can't override it.

Prompts and responses

Inspected in the request path

Checked before they reach the model or return to the agent. Not used to train public foundation models.

Tool calls

Decided before execution

Tool, arguments, agent and tenant are checked against policy. Allowed calls get a single-use permit.

Decision records

Your organisation's workspace

Verdict, reason, agent and context, isolated per organisation. Retention follows your plan and configuration.

Upstream credentials

Broker or vault

Agents get the integrations they're allowed; secrets stay out of prompts and configs.

Traces

Metadata only

Observability exports carry timing and identifiers, not prompt content.

See the privacy policy and security page for data handling commitments. Subprocessor details and questionnaires are available on request.

+Deployment

Managed, or in your own cloud

+Fully managed

Point your agents at the hosted edge.

  • Live in minutes — change one base URL
  • Upgrades and detection updates handled for you
  • Start in monitor mode, enforce per agent

+Customer-hosted

Run the edge and kernel in your cluster.

  • Gateway and security kernel deployed with Helm
  • Traffic stays inside your network boundary
  • Connected to the same control plane for policy and review

+For reviewers

+ Security review

Bring your questionnaire.

We'll walk your team through the architecture and answer the hard questions directly.