Trace

An execution debugger for AI agents

11 of 15 vendors decided, 4 waiting at the review gate.

Worklist

15 vendors
SummaryActions
Meridian Data Services
Revoke access
Low · 61% Needs attentionSOC 2 Type II expired 2026-05-31 and no replacement report is on file. Processor-tier access requires a current SOC 2. Recommending revocation of customer PII and billing export access pending a valid report.
Solstice CRM
Revoke access
Low · 67% Needs attentionNo DPA returned for Solstice CRM. Prior reviews read back a DPA signed 2026-01-20; this run found no record of one — not an expiry, an absence. That is either a lapsed agreement or an incomplete registry response, and the record does not say which. Processor tier with customer PII access, so recommending revocation on the unmet requirement — but the evidence itself should be confirmed at the source before acting.
Ledgerline Analytics
Retain access
Low · 58% Needs attentionAll three processor-tier requirements are satisfied on their face. The SOC 2 is current through 2027-03-31, but its scope statement covers the analytics platform and names the billing-export pipeline as out of scope — and billing-exports is an access scope under review here. The criterion is met; what the report attests to may not reach the access it is being used to justify. Recommending retain, but the scope gap needs a human read.
Ferrous Distribution
Retain access
Low · 64% Needs attentionRegistered at vendor tier, so the processor-tier SOC 2 and DPA requirements were treated as out of scope and the W-9 is the one requirement assessed — it is current. But the access scope now includes customer PII, added this quarter, which is the condition those two requirements exist to cover. The tier field and the access scope disagree, and the criteria were selected by tier. Recommending retain on the assessment as scoped; whether that scoping is right is not the agent’s call.
Northwind Logistics
Retain access
High · 94% CompletedVendor tier, with no access to customer data — the processor-tier SOC 2 and DPA requirements do not apply here. Tax documentation is the one requirement in scope and the W-9 is current. A SOC 2 Type II valid through 2027-02-28 and a signed DPA are on file regardless.
Calyx Analytics
Retain access
High · 91% CompletedProcessor-tier requirements fully satisfied: current SOC 2, signed DPA, current W-9, and a recent penetration test. No exceptions found.
Bellhaven Print
Retain access
Moderate · 88% CompletedLow-risk tier with no access to customer data or financial systems. SOC 2 is not required at this tier; W-9 and MSA are both current.
Orillion Cloud
Revoke access
High · 96% CompletedNo DPA on file, SOC 2 expired 2025-09-30, and tax documentation lapsed 2025-12-31. Processor tier with customer PII access and no current controls evidence. Unambiguous revocation.
Vantage Payroll
Retain access
High · 93% CompletedProcessor-tier requirements fully satisfied: current SOC 2, signed DPA, current W-9. No exceptions found.
Pinecrest Support
Retain access
Moderate · 89% CompletedProcessor-tier requirements fully satisfied: current SOC 2, signed DPA, current W-9. No exceptions found.
Driftwood Integrations
Revoke access
High · 93% CompletedSOC 2 Type II expired 2026-07-15 and tax documentation lapsed 2026-07-31, both since the last review. Signed DPA remains on file but does not cover the other two gaps. Processor tier with customer PII and telemetry access — recommending revocation pending renewed reports.
Halcyon Metrics
Revoke access
High · 92% CompletedSOC 2 Type II expired 2026-07-25 and tax documentation lapsed 2026-07-15, both since the last review. Signed DPA remains on file but does not cover the other two gaps. Processor tier with telemetry access — recommending revocation pending renewed reports.
Cobalt Freight
Retain access
High · 93% CompletedVendor tier, with no access to customer data — the processor-tier SOC 2 and DPA requirements do not apply here. Tax documentation is the one requirement in scope and the W-9 is current.
Willowmere Promo
Retain access
Moderate · 87% CompletedLow-risk tier with no access to customer data or financial systems. SOC 2 is not required at this tier; W-9 and MSA are both current.
Briarcliff Events
Retain access
Moderate · 86% CompletedLow-risk tier with no access to customer data or financial systems. SOC 2 is not required at this tier; W-9 and MSA are both current.