The same mechanism, proven against what a security or compliance review actually demands.
What this costs, by tier →Every decision sealed in a tamper-evident record — self-host and none of it leaves your perimeter. Reproduce any incident. Gate every release.
If an autonomous system moves money, changes infrastructure, approves a customer, or writes production code — can you prove what it did?
Without a reproducible record, you can't demonstrate control of your own system.
“Are our AI systems in scope? Do we have compliant logs?”
Every figure here is arithmetic on the numbers you set, including how long you'd expect an investigation to take with a reproducible run — we have no customer data to average and we haven't substituted a guess of our own. Engineering time only: it doesn't price the exposure of an agent decision you can't reproduce for a regulator, the line item that doesn't show up until it's a finding.
A dashboard built for deterministic software can tell you a call was made; it can't re-derive the reasoning, because the context was never captured as a re-executable unit.
Four failure classes matter in regulated production — none visible in a log, all visible in a replay:
Not hypothetical: in July 2026, Anthropic needed a retrospective sweep of cybersecurity-evaluation runs to find three incidents where a misconfiguration let Claude reach live infrastructure. Anthropic's writeup → That's the cost of an instrumentation gap at scale — a six-figure manual sweep, not a query.
Swipe to see all columns →
Verified September 2026 — reviewed quarterly.
One SDK wrap. Your existing systems untouched. Your data never leaves your perimeter.
Enterprise: fully self-hosted — Runback platform runs in your cloud, data never leaves your perimeter · Cloud: Runback-managed, PII stripped before ingest, encrypted in transit
Swipe to see all columns →
| Tier | Where traces go | EU / AU residency | DPA |
|---|---|---|---|
| Community (self-hosted) | Your Postgres, your infra | ✓ your region | n/a |
| Starter · Growth · Scale · Pro | Runback cloud (US) | Enterprise only | On request |
| Enterprise (self-hosted) | Your Postgres in your VPC | ✓ your region | Included |
Cloud posture tools, guardrail filters, and SIEM platforms are all real — most security teams run more than one. None capture a specific agent decision, enforce your own rules before it executes, or seal it into a signed record. That's the layer Runback adds underneath whatever you already run.
Scores cloud resources and model endpoints against config rules. Doesn't see: what a specific agent decided on a specific call.
Captures traces so you can read what an agent did after the fact. Doesn't see: traces are read-only — no re-execution, no tamper-evident export. /vs →
Blocks unsafe input/output in real time. Doesn't see: your business logic — "never refund over $100" isn't unsafe content.
Ingests logs everywhere for search and correlation. Doesn't see: an agent decision as more than a log line — nothing re-executable to replay.
Hashes and signs a payload to prove it existed unchanged. Doesn't see: anything upstream — no captured context, no rule enforced beforehand.
Scope can be widened in transit. No proof of who called or what was permitted.
Every delegation edge sealed. Chain exports as a verifiable artifact.
Same signing primitive as the per-run audit record above — Ed25519 where a keypair is configured, HMAC-SHA256 fallback without one. (The separate org-wide ledger checkpoint uses HMAC plus independent RFC 3161 timestamping — see Security.)

This page describes how Runback's capabilities map to named regulatory controls. It is not legal advice, and it is not an assessment of your organisation's compliance. Whether an obligation applies to you, and whether you meet it, is a determination for your own advisers, assessor or regulator.
We'll join your security review call, answer questions directly, and provide a DPA on request. Most reviews complete in one session.