Trust Center

Security, privacy, and data residency information for enterprise evaluations.

Data Processing Agreement (DPA)

Traccia processes trace metadata on behalf of customers as a processor under GDPR. Enterprise customers receive a standard DPA covering subprocessors, breach notification, and data subject request assistance. Contact support@traccia.ai for the current DPA template.

EU data residency

Production deployments can be configured for EU-region data processing. Trace payloads are stored according to your workspace retention tier; legal hold prevents purge during investigations. EU-only storage is confirmed in your contract during onboarding.

Governance & compliance posture

Traccia provides audit logs, an AI system registry, evidence exports, and opt-in modules for the EU AI Act and HIPAA-oriented agent governance. We help teams collect evidence for regulations; we are not a conformity assessment body or a HIPAA certification authority. See and .

HIPAA shared responsibility

Traccia does not currently offer a signed Business Associate Agreement. You can still use Traccia to inventory PHI-capable agents, draft safeguard notes, track yourvendors' BAAs, and export CFR-labeled evidence. Prefer minimum necessary data and SDK redaction. Enabling the HIPAA module does not make your organization HIPAA compliant.

You ownTraccia contributes
CE/BA determination, counsel, BAAs with your LLM and cloud vendors, OCR filings, workforce trainingOpt-in Hub module, PHI flags, soft warnings (warn, do not block), checklist drafts, labeled evidence packs
What PHI enters prompts, tools, and traces; minimum necessary designBest-effort SDK redaction helpers and hipaa.* span attributes — not medical NER
Breach investigation and patient/partner notification under your policiesInternal Hub incidents and audit exports (not OCR breach notification)

Healthcare onboarding / BAA roadmap: support@traccia.ai or use Contact Traccia in the app (Settings → Compliance or Governance Hub → HIPAA). Full guide: .