Traccia turns agent telemetry into compliance evidence. Built on OpenTelemetry, it records transparency disclosures, risk tiers, integrity-hashed audit trails, and human-review sign-off — with opt-in modules for the EU AI Act and HIPAA, without changing your agent code.
Both modules are disabled by default and never auto-enabled by region. Turn on what you need — they can run together.
Registry fields, article-mapped exports, transparency hooks, and documentation drafts for teams that deploy or provide AI in the EU. It helps you collect and organize evidence.
Registry fields, safeguard checklists, and labeled exports for teams governing healthcare AI agents. It helps you inventory and document — it does not certify HIPAA compliance, and we do not offer a signed BAA yet.
The EU AI Act mandates that users be informed when interacting with an AI system. Record the evidence automatically.
Records immutable evidence of when users are told they're interacting with AI.
Stamp every execution trace with its designated framework and risk tier to ensure appropriate downstream handling.
Automatically attaches governance metadata to every span.
Prevent tampering and ensure non-repudiation of your system's execution records.
A dedicated Governance Hub for compliance teams to review and export evidence.
What the HIPAA module does — and, just as importantly, what it doesn't.
Declare which AI systems may handle PHI, with categories and role hints. Soft warnings only — Traccia warns, it does not hard-block ingestion.
Draft administrative, technical, and physical safeguard notes, and track your vendors' BAA status for model APIs and vector databases.
Export audit bundles with labels for 164.308, 164.312, 164.502(b), and more — operational evidence to feed your compliance program.
Disclaimer: Traccia provides decision-support tooling and technical infrastructure, not legal advice. It helps you collect and organize evidence — it does not classify your systems, perform conformity assessment, or file with any authority. Please consult qualified legal counsel regarding specific EU AI Act or HIPAA requirements for your systems.