TreeTrace
A visibility layer for AI coding-agent sessions: a structured, local, redacted record of what an agent did, what it was refused or denied, where a human stepped in, and what touched secrets or auth.
Coding agents touch authentication, secrets, access control, and production on their own, and the steering that shaped a session disappears when it ends. Git records what changed, not how the agent got there. EU AI Act, SOC 2, and ISO 42001 now expect a verifiable record, and most tooling answers with another black box graded by a model.
I built the record GRC and audit teams ask for. TreeTrace turns a raw session into a local, vendor-neutral evidence trail: prompt lineage, tools and files touched, secrets and auth contact, refusals and permission denials, and the human corrections that pulled the agent back. Every flag is a deterministic heuristic with evidence you can open and re-derive. No LLM judge anywhere, and redaction fails closed.
A deterministic, evidence-backed audit record that supports EU AI Act, SOC 2, and ISO 42001 reviews and runs entirely on the machine. Source-available and noncommercial.