Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

TraceLockContinuous Trust. Immutable Evidence.

One control evaluation, reported against every framework you are held to — with evidence an auditor can verify rather than take on trust.

TraceLock is continuous control monitoring and evidence management. Connectors test your live environment, findings map through one unified control library, and every artifact lands in an append-only record with its own hash.

Audit readiness decays the moment the screenshot is taken

Point-in-time evidence describes a system that no longer exists, and every new framework means re-testing controls you already tested. The work is duplicated, the evidence is stale, and nobody can prove when it was collected.

  1. Evidence goes staleA folder of screenshots proves what was true on the day someone had time to collect them, not what is true now.
  2. Every framework re-tests the same controlAccess review, logging and change management get evaluated once per framework instead of once, mapped many.
  3. Nobody can verify the chainIf evidence can be edited after the fact, the auditor is trusting your word rather than checking a record.

Evaluate once, report many

Unified Control Library with a cross-framework crosswalk

Internal control codes map to SOC 2, ISO 27001, NIST CSF 2.0, NIST AI RMF, ISO/IEC 42001, the EU AI Act, HIPAA, SEC rules and CIS Controls v8, with fifteen regulated framework packs available on top. One evaluation populates every report it defensibly maps to.

Live connectors instead of questionnaires

AWS, GCP, GitHub, Cloudflare and custody connectors test the real environment on a schedule and raise findings against the controls they cover.

Append-only evidence with hashes

Every artifact is recorded write-once with a SHA-256 digest, so an auditor can confirm nothing changed after collection.

A read-only room for your auditor

Scoped, revocable access to exactly the evidence in scope — no shared drives, no mailbox attachments, no standing accounts.

AI inventory and governance

Discover the models and AI services in use, attach them to obligations, and keep the EU AI Act and ISO 42001 mappings current as the estate changes.

A Privacy Wall in front of connector data

Connectors return posture and findings, not payloads. What TraceLock stores is deliberately narrower than what it can see.

What is actually covered

Numbers you can check against the product rather than a maturity claim.

9frameworks in the core crosswalkSOC 2 · ISO 27001 · NIST CSF 2.0 · NIST AI RMF 1.0 · ISO/IEC 42001:2023 · EU AI Act (2024/1689) · HIPAA Security Rule · SEC rules · CIS Controls v8.
15regulated framework packsAttestation packs for financial-services, AML, sanctions and digital-asset regimes, sold per framework. Listed below.
Write-onceevidence recordsAppend-only with per-artifact SHA-256 digests and recorded custody.
Livecontrol testingCloud, code, custody and log-feed connectors run against the real environment on a schedule.

Core frameworks — every plan

  • SOC 2 (TSC 2017)
  • ISO/IEC 27001
  • NIST Cybersecurity Framework 2.0
  • HIPAA Security Rule
  • SEC Investment Adviser Rules
  • CIS Controls v8
Tested continuously by connectors against the live environment.

AI governance — Growth and Enterprise

  • NIST AI Risk Management Framework 1.0
  • ISO/IEC 42001:2023
  • EU AI Act (2024/1689)
Mapped at article, clause and function level; see the methodology note.

Regulated framework packs — financial services

  • NYDFS Part 500 Cybersecurity Requirements
  • SEC and FINRA books-and-records retention (17a-4)
  • Bank Secrecy Act record retention
  • UK FCA financial promotions regime
  • UCC Articles 8 and 12 — securities and controllable electronic records

Regulated framework packs — AML and sanctions

  • OFAC sanctions compliance
  • FinCEN money services business obligations
  • FATF Travel Rule and third-party reliance (R.16/17)
  • EU Anti-Money Laundering Regulation record-keeping
  • EU Transfer of Funds Regulation
  • UK Money Laundering Regulations 2017

Regulated framework packs — digital assets

  • FATF virtual asset service provider guidance
  • EU Markets in Crypto-Assets Regulation (MiCA)
  • NYDFS Part 200 virtual currency business activity (BitLicense)
  • US payment stablecoin requirements (GENIUS Act)
Each pack is one purchasable framework; Enterprise includes an allowance of two.

Methodology. EU AI Act, ISO 42001 and NIST AI RMF references are curated at article, clause and function level rather than sub-control, and are intended for a compliance reviewer to confirm before they are relied on as an audit deliverable. Where no defensible mapping exists the field is left empty rather than filled in. EU AI Act citations use the final adopted 2024 numbering. Regulated framework pack controls are attested — an owner records the review, the evidence and the date, and TraceLock tracks staleness against a 90-, 180- or 365-day interval. TraceLock does not screen transactions, exchange Travel Rule messages, determine regulatory status or verify reserves.

Plans

Priced per organization and billed by TraceLock. Every plan includes the core crosswalk, append-only evidence and the Privacy Wall.

Assurance Attach

$499/month or $5,988/year

SOC 2 and ISO 27001 monitoring for teams whose other regulatory program runs elsewhere.

  • SOC 2 and ISO 27001 only
  • 3 connectors
  • 20 monitored users
  • One read-only auditor room
Start a workspace

Starter

$1,299/month or $12,990/year

Continuous monitoring for a first audit, on a single environment.

  • 3 connectors
  • 20 monitored users
  • One read-only auditor room
  • Unified Control Library across the six core frameworks
  • Append-only evidence with SHA-256 digests
Start a workspace

Growth

$2,999/month or $29,990/year

For a live program: more estate, custody posture, AI governance.

  • 10 connectors and 100 monitored users
  • Three read-only auditor rooms
  • Custody posture and user access reviews
  • EU AI Act and ISO 42001 AI governance
  • Third-party risk and a custom trust-center domain
Start a workspace

Enterprise

$90,000/year

Multi-entity scope, auditor rooms, SSO and two regulated framework packs.

  • 100 connectors and 500 monitored users
  • Unlimited read-only auditor rooms
  • SAML single sign-on
  • Allowance of two regulated framework packs
  • Everything in Growth
Request a briefing

Add-ons

Added to any plan from TraceLock's billing settings.

Regulated framework pack$9,000/year per framework
One of the fifteen regulated frameworks above: its control set, attestation workflow, evidence and staleness tracking. The framework is chosen at checkout.
Extra connector pack$99/month
Three more connectors on top of your plan's allowance.
Extra auditor room$299/month
One more scoped, expiring read-only room for an external auditor.
Monitored-user overage$3/user/month
Each monitored identity beyond the plan's limit.
Premium support$500/month
Priority response from the TraceLock team through your audit window.
White-glove onboarding$2,500 one-time
Guided setup: connectors, control owners and your first evidence cycle, run with you.

Warden · By Odingard

Run it as a managed program

Warden builds the crosswalk out to your control set, operates evidence collection, and manages the auditor room through the examination.

Go deeper

Stop rebuilding the same evidence pack

See the control library and connectors against your own environment, or have Warden run the program.