How we handle your traces and access
An audit needs to see the system. Agent traces contain prompts, tool outputs and sometimes customer data; a cloud role can see everything. This page says exactly what we take, where it lives, who can see it and when it is gone. It applies to every audit unless a signed agreement says otherwise.
1. What we ask for
The minimum that answers the question. For an agent reliability audit that is an export of traces for the period we agree, typically two to four weeks, in whatever format you already have: OpenTelemetry spans, a Langfuse or LangSmith export, or plain logs. For an infrastructure audit it is a read-only role on one cloud account and one environment. For a field map we need nothing from you but the question.
We do not ask for write access, production credentials, database dumps or customer records. If a finding needs more, we ask for that specific thing in writing and you can say no.
2. Where it lives
Exports are copied once to an encrypted volume on a single machine in Portugal that we control. Nothing is uploaded to a third-party service, a shared drive or a model provider. Detectors run locally. The written report contains excerpts only where a reproduction needs them, and we redact identifiers, names and free text that is not needed to show the failure.
3. Who sees it
The engineer doing the audit, and nobody else. There is no team pool and no subcontracting. If two of us work on one engagement you are told who, by name, before access is granted.
4. What we never do
- Train, fine-tune or prompt any model on your data. Our detectors are rules and small classifiers we own; they do not send your traces to an external API.
- Keep anything after the engagement. See the deletion clause.
- Publish anything about your system. Our articles use our own systems and public research. A client case appears only with written permission, redacted, after you have read it.
- Reuse access. A role granted for an audit is used for that audit and you are asked to revoke it the day the report lands.
5. When it is deleted
Thirty days after the report is delivered, the export and every derived file are deleted from the volume and the deletion is confirmed to you by email. Earlier on request, same day. The report itself is yours; we keep one copy for our records for one year unless you ask us not to.
6. Regulation
We invoice from Portugal under EU business-to-business rules. Where an export contains personal data we act as a processor under your instructions; a short data processing agreement is available on request and can be signed before any access is granted. If your system falls under the EU AI Act's record-keeping duties, the audit output is written so it can serve as evidence for that logging.
Ready to have something looked at?
Tell us what you run and how we could see it. Written reply within one business day.
Tell us what you runRelated: the three audits and what they cost · everything we measured and published.