Skip to main content
TRW

Define the evidence boundary

Preserve project-local requirements, reported checks, delivery state, and recoverable context. Evaluate the open framework locally, in your cloud, or air-gapped—independent of model or IDE.

Agents proliferated. Org-level accountability did not.

As AI-assisted work spreads across repositories and teams, access and spend records answer only part of the review. Requirements, observed checks, retained knowledge, and exception decisions need their own inspectable trail.

Spendlogged
Workmissing

usage may be recorded — delivery evidence still needs its own contract

Usage records are not delivery evidence

Seat and token reports can show who used a tool and how much it cost. They do not, by themselves, bind a requirement to the repository checks reported for a delivery.

One team is not the organization

A team-local record cannot answer an organization-wide question unless projects use compatible ownership, evidence, and handoff contracts.

Knowledge stops at project boundaries

Useful discoveries remain local unless they meet an explicit validation and recall policy. Sharing everything would create a different governance failure.

Governance across time, not governance of access

Access governance and work evidence answer different questions. TRW focuses on the second: preserving requirements, reported checks, delivery state, and recoverable context across sessions without replacing your coding client or assurance stack.

Access tells you the bill. Work tells you what you bought.
How typical access records differ from TRW work evidence
DimensionHost-locked access governanceTRW work governance
Unit of analysisUsers, seats, spend — activity measured by the hostRequirement paired with a content-bound, reporter-supplied build receipt
What the record containsThat a tool was used, with its activity and cost metadataThe claimed result, scope, and receipt metadata—not independent execution of the check
Vendor couplingUsually scoped to activity visible within one hostAbove any IDE, model, or host via MCP — governance is not hostage to one vendor
Where it runsOften a vendor-managed serviceOpen framework on your infrastructure—local, your cloud, or air-gapped

What you can evaluate today

These surfaces are available now, with their boundaries stated directly. Use them as the starting inventory for security and procurement review.

AVAILABLE

Org & roles

Team workspace

Single-org team workspace — invite teammates by email with a role, create sub-teams, add and remove members

Roles

Owner / admin / member, with cross-tenant privilege-escalation guards

Data model

Org / team / membership entities; architecture designed for N-level org hierarchy

Analytics

Org-scoped analytics summary

Evidence & data rights

Audit trail

Persisted, org-scoped audit trail of org and membership activity

Content hashing

Configurable memory provenance can add a SHA-256 content hash and Ed25519 signature; legacy, disabled, or fail-open records may remain explicitly unsigned (the platform audit trail is persisted without content hashing today)

Data subject rights

GDPR JSON export and erasure

Identity & deployment

Identity & keys

Per-org API keys; JWT / OAuth / 2FA authentication

Open framework

trw-mcp and trw-memory run repo-local; off-machine platform telemetry is off by default while local tool telemetry remains enabled

Runs where you do

On the developer’s machine, in your own cloud, or fully air-gapped

Vendor review surface

Source-available BSL-1.1 codebase with OWASP-focused security checks—readable for vendor review

Run TRW in your environment

The open framework runs on infrastructure you control today. The hosted platform is currently TRW-managed; an in-perimeter platform deployment is not a current offering or commitment.

YOUR PERIMETER

Air-gapped

AVAILABLE NOW

Offline install from embedded wheels with no PyPI access; hosts pre-stage Python dependencies and keep networked tools disabled.

On-prem / your cloud

AVAILABLE NOW

Open framework on your own AWS, VPC, or on-prem host. Repo-local memory.

Hosted platform BYOC

NOT CURRENT

Not currently offered. The deployment model is still under evaluation; do not plan a rollout around this surface.

hosted SaaS stores org data outside your perimeter

TRW-managed SaaS

OPT-IN

The hosted platform, run by TRW. Opt-in; org-scoped audit recorded server-side.

Engineering evidence your assurance stack can inspect

TRW can supply an engineering-side record for broader assurance workflows. Each mapping is an evaluation prompt—not a certification, legal conclusion, or automatic compliance.

Generators
Your coding clients and models
Produce the work
TRW
The engineering-side record
Records selected requirements, reported checks, and handoff state
Assurance layer
Your GRC and audit process
Evaluates the evidence

Coding clients produce the work. TRW records selected requirements, reported checks, and handoff state. Your assurance process decides how that evidence maps to policy. TRW does not replace either layer.

EU AI Act

Maps to

Aligns with audit-trail and transparency readiness. Whether AI-assisted coding is high-risk is an open question we do not assert.

NIST AI RMF

Maps to

Maps to Map / Measure / Manage review questions through risk-scaled run records, requirements traceability, and persisted audit events—a readiness signal, not a certification.

ISO/IEC 42001

Maps to

Aligns with the AI-management-system evidence expectations — run governance, role ownership, documented reversion. TRW supplies the underlying record, not the certificate.

Questions a security and procurement review will ask

TERMINAL // ORG_ROLLOUT_FIT
requirement → build receipt → explicit handoffVERIFIED

Define the evidence boundary before you expand the rollout

Start with a scoped evaluation: choose the projects, evidence boundary, deployment surface, identity requirements, and exception policy. We will document what is available now, what remains local to the open framework, and what requires a design-partner engagement.

Keep going

If you haven't installed yet, start with the quickstart. If you have, the lifecycle page explains what TRW actually does once it's running.