TRACE
TRACE is an open specification for hardware-attested AI agent governance records, hosted at the Linux Foundation and currently in Developer Preview. It defines a record format, anchoring protocol, and verification rules that bind agent execution claims to silicon attestation roots from AMD SEV-SNP, Intel TDX, or NVIDIA H100. Records can be anchored to transparency ledgers via SCITT, enabling third parties to verify what model ran, where, under which policy, and what data it touched without trusting the operator. The specification profiles IETF and IRTF standards including RFC 9711 (EAT) and RFC 9334 (RATS), and includes a conformance test suite for validating governance implementations.
TRACE is an open specification for hardware-attested AI agent governance records, integrating with AMD SEV-SNP, Intel TDX, NVIDIA H100, and Microsoft AGT. InnovaAI scores it 4/10 for agency adoption, best for Founder, Operations, and Infrastructure/DevOps roles.
Agency Audit
TRACE is an open specification for binding AI agent execution claims to hardware attestation roots, enabling third-party verification of what model ran, where, under which policy, and what data it touched without trusting the operator. For digital agencies deploying custom AI agents in client work or internal operations, TRACE provides a governance audit trail anchored to silicon attestation (AMD SEV-SNP, Intel TDX, NVIDIA H100) and transparency ledgers via SCITT. Adopt if your team runs AI agents that touch sensitive client data or operate under compliance constraints; skip if your agency uses only third-party SaaS AI tools with no custom agent deployment.
3recommended
15/mo
No paid plan published
High
Illustrative scenario. Not a guarantee. Net capacity needs a verified paid base plan, and none is published for this service, so it is not modeled. Hours saved come from the service estimate; implementation, taxes, and unprovided usage charges are excluded.
- Founder handling AI agent governance audit and compliance verification
- Operations handling client contract sign-off on AI execution integrity
- Infrastructure/DevOps handling internal policy enforcement validation
- Your agency uses only third-party SaaS AI tools (ChatGPT, Claude API, Gemini) without deploying custom agents, making hardware attestation and governance records irrelevant to your workflow.
- Your team has no infrastructure or AI engineering capacity to integrate TRACE with agent runtimes and attestation platforms, and you lack budget for external implementation support.
- Your client contracts do not require independent verification of AI agent execution or policy compliance, and internal logging and operator attestation satisfy your audit and governance needs.
Internal Adoption Path
No paid plan published
15 hr/mo
3 seats × 5 hr each
$1,125/mo
modeled at $75/hr labor rate
No paid plan published
Illustrative scenario. Not a guarantee. No verified paid base plan is published for this service, so subscription cost and net capacity are not modeled. Implementation, taxes, and unprovided usage charges are excluded.
Platform Features
Core capabilities of TRACE
Hardware-attested execution records
Binds AI agent execution claims to silicon attestation roots from AMD SEV-SNP, Intel TDX, or NVIDIA H100, enabling your infrastructure team to generate cryptographically verifiable proof of what model ran, where, and under which policy without relying on operator claims.
Transparency ledger anchoring via SCITT
Anchors trust records to a transparency ledger using the SCITT protocol, allowing your Founder or compliance lead to maintain an immutable audit trail that third parties (clients, auditors) can independently verify without accessing your infrastructure.
Conformance test suite
Scores your agent governance implementation against standardized conformance rules, helping your DevOps or AI engineering team validate that deployed agents meet policy and attestation requirements before client handoff.
Agent runtime integration
Integrates with agent governance toolkits and runtimes (cMCP, NVIDIA OpenShell), allowing your infrastructure team to embed TRACE record generation into existing agent deployment pipelines without rebuilding from scratch.
Third-party verification without operator trust
Enables clients or auditors to verify agent execution claims directly against hardware attestation platforms and transparency ledgers, reducing your agency's liability for unverified operator attestation in compliance-sensitive engagements.
Standards-based record format
Uses IETF and IRTF standards (RFC 9711 EAT, RFC 9334 RATS, SCITT draft), ensuring your governance records are interoperable with enterprise security tools and future compliance frameworks without vendor lock-in.
What Makes TRACE Different
Unique advantages vs similar tools in this niche
Hardware-rooted attestation
vs Software-only audit logsTrust Records are signed inside a TEE and checked against a hardware root, so the operator cannot author them after the fact.
Standards-based approach
vs Proprietary governance formatsProfiles RFC 9711 (EAT), RFC 9334 (RATS), and SCITT rather than replacing them.
Independent verifiability
vs Operator-trusted audit logsAny third party can verify claims without trusting the operator.
Latest Updates
Recent releases and improvements for TRACE
[Unreleased], Added
NewUnreleased additions to the TRACE specification.
[Unreleased], Security
FixUnreleased security fixes to the TRACE specification.
[Unreleased], Fixed
FixUnreleased bug fixes to the TRACE specification.
[0.9.0], Documentation
Improvement2026-08-09Documentation updates shipped in the 0.9.0 release.
[0.9.0], Added
New2026-08-09New features and additions shipped in the 0.9.0 release.
Value Equation
Outcome-likelihood-time-effort assessment for TRACE
Value math requires real pricing
The Value Equation (dream outcome × likelihood ÷ time × effort) feeds directly into ROI math. TRACE has no published pricing, so we hold this section until real numbers are available.
Contact TRACEPricing
Pricing data not yet available for TRACE.
Reality Check
TRACE is a specification and conformance framework, not a plug-and-play tool. Implementation requires infrastructure integration with hardware attestation platforms and agent runtimes, making it most valuable for agencies with dedicated infrastructure or AI engineering capacity. Smaller teams using off-the-shelf agent platforms will see minimal ROI.
High effort: requires technical configuration and team training
How This Accelerates White-Label Services
Who It's For
- ✓ai-infrastructure-providers
- ✓enterprise-security-teams
- ✓compliance-focused-agencies
Acceleration Steps
- 1Schedule onboarding with the vendor
- 2Configure generate hardware-attested trust records for ai agent actions
- 3Connect AMD SEV-SNP
- 4Launch your first client project
Academy for TRACE
Work through it in order: the course for this service first, then the modules behind it.
No Academy modules are published for this service yet. Browse the full Academy
Core concepts
The mental model you need to price and scope the work.
- Inference Cost Pass-Through CeilingConcept
Inference Cost Pass-Through Ceiling is the point at which an agency can no longer absorb a model provider's price or latency change inside a fixed retainer, so the cost has to move to the client or the work has to shrink. The framework asks three questions per client engagement: what share of delivery cost is metered inference, how fast can that share be re-routed to a cheaper model, and what contract language lets you reprice. Forrester's 2027 predictions flag AI growth colliding with energy and infrastructure limits, which converts compute scarcity into API price movement on agency tools. A concrete case: an agency running document analysis on a frontier API can shift bulk classification to a smaller open-weight model served through Ollama or a gateway like Helicone, keeping the frontier model only for reasoning steps. That split is the ceiling defense.
- Provider Substitution WindowConcept
Provider Substitution Window is the interval during which an agency can move a client workload from one model provider to another without rewriting prompts, evals, or integration code. The window is widest at the orchestration layer and narrowest at the fine-tuned weights layer: a gateway swap takes hours, a retrained model takes a quarter. Agencies that measure this window per client account know exactly when they hold pricing leverage and when a vendor holds it. Forrester's 2027 predictions flag compute and energy constraints pushing API pricing upward, which turns a wide substitution window into a margin defense rather than an engineering nicety. A concrete case: an agency routing Claude and GPT traffic through a gateway such as Helicone or Portkey can shift a client's summarization workload in an afternoon when one provider raises rates, while a competitor with hardcoded SDK calls absorbs the increase on a fixed retainer.
- Margin Defense StackConcept
Margin Defense Stack treats AI infrastructure as a layered cost structure rather than a single line item. The bottom layer is raw compute and API tokens, the middle layer is routing and caching, and the top layer is the client-facing retainer price. Agencies that only negotiate the top layer absorb every shock from the layers beneath. Forrester's 2027 predictions flag that AI expansion is colliding with energy and infrastructure limits, which translates into API price increases for agency tools and compresses margins on AI-inclusive retainers. A concrete defense: route repeat prompts through a gateway such as Helicone or Portkey so cached responses cut token spend before it reaches the client invoice, and keep a local fallback like Ollama for privacy-sensitive work. When a client asks why the AI retainer costs what it does, the stack shows exactly which layer each dollar covers.
Decision and risk
How to judge the fit, and the ways it goes wrong.
- When AI Margins Depend on Third-Party Compute, Price the Dependency Before You Sign the RetainerEvaluation Rule
Map every AI dependency in the delivery stack to a named provider, a fallback route, and a pass-through cost clause before quoting fixed-fee client work.
- AI Infrastructure Rule: Route Across Providers Before You Standardize on OneEvaluation Rule
Put a routing or gateway layer between your application and every model provider before any client deliverable depends on one vendor's endpoint.
- Multi-Model Orchestration vs Single-Provider CommitmentDecision Framework
IF client work spans more than one model family, more than one pricing tier, or more than one data-residency requirement, THEN route every request through an orchestration layer so a provider price change or capability shift becomes a routing edit rather than a rebuild. IF a single provider's model is the product itself and switching cost is already sunk into fine-tunes and evals, THEN a direct integration is cheaper and simpler than adding a gateway. The frame is not which vendor wins; it is whether the agency owns the routing decision or rents it.
- The Single-Provider Lock-In Trap in AI InfrastructureFailure Pattern
- The Token Bill Creep: Why AI Infrastructure Costs Outrun Agency RetainersFailure Pattern
Delivery system
Blueprints and procedures for running it as a service.
- Multi-Model Routing Layer Build (10-14 days)Implementation Blueprint
A delivery pattern for agencies that stand up a provider-agnostic routing and observability layer between client applications and frontier model APIs, so pricing changes, deprecations, or safety-policy shifts at any single lab become a config edit rather than a rebuild.
- Model Routing and Failover Drill (QA)Operating Procedure
- Multi-Provider Cost and Lock-In Review (Retention)Operating Procedure
- Provider Onboarding and Credential Isolation (Onboarding)Operating Procedure
13 modules selected for TRACE
Frequently Asked Questions
Answers about pricing, setup, implementation
TRACE is an open specification that defines a record format, anchoring protocol, and verification rules for binding AI agent execution claims to hardware attestation roots. It enables your agency to generate cryptographically verifiable proof of what model ran, where, under which policy, and what data it touched, without requiring third parties to trust your operator attestation. Records can be anchored to transparency ledgers via SCITT for independent audit.
TRACE is an open specification hosted at the Linux Foundation and currently in Developer Preview. Pricing information is not published; adoption is typically driven by infrastructure integration costs and conformance testing rather than per-seat licensing.
Infrastructure and AI engineering teams benefit most, as they integrate TRACE with agent runtimes and hardware attestation platforms. Operations and Founder-level roles benefit from the audit trail and compliance verification capabilities, especially in client engagements requiring independent proof of AI governance. Compliance-focused agencies see the highest ROI.
TRACE does not reduce manual labor directly; it compresses the compliance and audit workflow. For agencies managing 3+ client projects with AI agents and compliance requirements, TRACE can save 4-6 hours per month per infrastructure team member by automating governance record generation and eliminating manual attestation documentation. Savings scale with the number of agent deployments and audit cycles.
Implementation depends on your existing infrastructure. If your team already uses AMD SEV-SNP, Intel TDX, or NVIDIA H100 hardware and has agent runtimes in place, integration typically takes 4-8 weeks. If you are starting from scratch, plan 3-4 months for infrastructure setup, conformance testing, and team training.
TRACE integrates with agent governance toolkits and runtimes including cMCP and NVIDIA OpenShell. If your agency uses custom agents built on these platforms, integration is straightforward. If you use third-party SaaS AI tools (ChatGPT, Claude API), TRACE is not applicable unless you deploy custom agents on your own infrastructure.