For security, risk & compliance

AI agents your auditors will sign off on.

Reproduce any incident. Gate every release. Keep a tamper-evident record — none of it leaves your perimeter.

Maps toAPRA CPS 230EU AI Act Art. 12NIST AI RMF
support-agent · refund · blocked at gateclick any step ↓
Policy gate · issue_refund — blocked
amount
$250
rule
no_refund_over_100
blocked call
issue_refund({ amount: 250, customer_id: 8842 })
Gate blocked this: a $250 refund on a disputed charge breaks two policies. Caught before it reached the customer.
Incident
Agent runs
3 days
Customer complaint
Logs only — can't prove

Without a reproducible record, you can't demonstrate control of your own system.

Audit
Auditor“Show me every agent decision, last 90 days. Tamper-evident.”
Log lines don't qualify
Runback — sealed, verifiable export
Board
EU AI Act

“Are our AI systems in scope? Do we have compliant logs?”

Most enterprises have no honest answer today.
The cost of doing nothing

The exposure is already on your books.

$69,120
/ year investigating incidents the slow way
$8,294
with reproducible runs — minutes, not days
$60,826
recovered per year — before a single failed audit

Engineering time only. It doesn't price the exposure of an agent decision you can't reproduce for a regulator— the line item that doesn't show up until it's a finding.

Why existing tools don't cover you

A log tells you what happened. It can't tell you why.

Observability tools were built for deterministic systems — software runs the same way twice, so a trace is enough to understand what happened. AI agents don't. Every decision is a function of a context assembled at runtime: the retrieval that ran, the tool output that landed in the prompt, the exact messages[] the model saw. A log records the outcome. Only a re-executable run reveals the reasoning.

The four failure classes that matter in regulated production: policy violation (the rule was present — the model ignored it), context contamination (retrieval skewed the decision), prompt injection (user input overrode the system prompt), model drift (a silent upstream update shifted edge-case behaviour). None are visible in a log. All are visible in a replay. See the exact scenario →

How it works

One record. From decision to proof.

01 · Observe
failedloan-approval-agent
6 steps · 1,030 tok · gpt-4o
↳ PII: 2 fields redacted in-process
Every model call — context, tools, tokens — captured at the boundary.
02 · Replay
gpt-4o→ escalate(dispute)pass
llama-3.3→ issue_refund(250)regression
Re-run from exact context. Different output = behaviour changed.
03 · Gate
issue_refund({ amount: 250 })
✗ BLOCKED · no_refund_over_100
sealed · seq: 4 · hash: 09c4…
Policy check fires before the call. Block sealed into the record.
04 · Audit
$schemarunback.cassette/v1
entries6 · chained
algooracle-chain/sha256
sig✓ verified
SHA-256 chained, HMAC-signed. Verify without a Runback account.
Architecture

Where Runback sits in your stack.

One SDK wrap. Your existing systems untouched. Your data never leaves your perimeter.

Model ProviderOpenAI · Anthropic · Azure · on-prem
Your Tools & Systemscore banking · CRM · credit bureau · case management
API & tool calls
Your org · your VPC · your infrastructure
Your Agent Applications+ Runback SDK
Loan Agentissue_approval
Fraud Agentflag_transaction
Compliance Agentcheck_policy
3 lines · post-hook only · real model calls run untouched · zero latency impact
PII stripped in-processasync · non-blocking
Your Postgresruns · spans · policies · audit trail · your encryption keys · your retention rules
reads only · Runback never writes to your data
Runback Platformself-hosted in your VPC
ObserveReplayGateAuditEvalsGolden
secure access · role-scoped
Risk & Eng Teamsdebug · replay · root cause
CI / Release Gateeval suite · regression block
Auditors & Regulatorscassette export · verify offline

Enterprise: fully self-hosted — Runback platform runs in your cloud, data never leaves your perimeter  ·  Cloud: Runback-managed, PII stripped before ingest, encrypted in transit

Data perimeter

Your traces. Your keys. Your building.

Self-host in your VPC
A Next.js app + Postgres. Traces never touch our servers.
Redact before egress
Keys, emails, card numbers, SSNs — scrubbed inside your process.
You own the store
You set retention and access. Delete a run — it's gone.
Open format
SDK + OTel, documented schema. Export and keep your history.

Swipe to see all columns →

TierWhere traces goEU / AU residencyDPA
Community (self-hosted)Your Postgres, your infra✓ your regionn/a
Starter · Growth · ProRunback cloud (US)Enterprise onlyOn request
Enterprise (self-hosted)Your Postgres in your VPC✓ your regionIncluded
Policy gates fail open by default — your agent is never blocked by an outage. Enterprise can configure fail-closed. Traces buffer locally and sync on reconnect.
vs. DIY logging & observability tools

Logs let you read what happened. Runback lets you prove it.

Swipe to see all columns →

DIY logging
LangSmith · Langfuse
Runback
Read the full trace after the fact
partial
Built-in evals & datasets
Re-execute the exact captured step
Signed, tamper-evident audit export
Self-host · data never leaves your perimeter
partial
Maps to regulated controls (CPS 230 · EU AI Act)

Verified July 2026 — reviewed quarterly.

Inter-agent trust fabric

Every delegation is signed. The chain is provable.

The gap
Orchestrator
delegates to ↓no cryptographic proof
Subagent

Scope can be widened in transit. No proof of who called or what was permitted.

With Runback
Orchestrator
HMAC-SHA256 token ↓scope: read:customer
Subagent

Every delegation edge sealed. Chain exports as a verifiable artifact.

Trust chain · runback:trust-chain:v1✓ verified
loan-orchestratordepth 0a3f8c2d1…b9e4
delegates · scope: *
kyc-subagentdepth 17b2e9f4a…c1d8
delegates · scope: read:customer
credit-check-agentdepth 24d1c8b3e…f2a9
POST to /api/trust/verify — no account required.
Regulatory coverage

The evidence your controls require.

APRA CPS 230
Operational risk & incident management
  • Incident capture + sealed record
  • Reproducible audit trail
  • Continuous monitoring data
EU AI Act
Art. 12 · Logging & traceability
  • Tamper-evident decision log
  • Human oversight record
  • Verifiable export for regulators
NIST AI RMF
Govern · Map · Measure · Manage
  • Policy simulation against real data
  • Behavioral drift detection
  • Defensible decision record
EnterpriseEU AI Act Annex III, ISO/IEC 42001, and NIST AI RMF mapped to Runback capabilities — status computed live from your actual run data.Talk to us →

Deploy AI agents with proof of control — not just proof of deployment.

We'll join your security review call, answer questions directly, and provide a DPA on request. Most reviews complete in one session.