TwinEthos homeAPI access

Control

AI inputs, outputs and tool calls not recorded as redacted, retained security telemetry

Every model call and agent tool call on a user-facing path emits a security event (who or what called, when, which model, the tool calls and their arguments, guard verdicts, token counts) to a trace or audit pipeline, with prompt and output content redacted or minimised before it reaches general application logs or third-party observability, access restricted, retention bounded, and the record protected against tampering.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Family: AI decisions cannot be reconstructed after the fact · control id cond.ai-calls-without-security-telemetry

Reach

2items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

Trust and provenance

How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.

This control
Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
Lanes
Standard / soft law 1 TwinEthos recommendation (not law) 1
Verification
Sources last verified 2 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.4, data as of 3 Oct 2026, schema 0.3.10. This page also reflects corpus changes made after that release; they ship in the next one.
Legal review
None of the 2 rules has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice.
Audit standard
2 of 2 rules audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
4 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.

The guard to add

Trace every model and tool call as a security event, and keep raw prompt and output text out of general logs.

Instrument the model client and the agent's tool executor once, where every call passes: OpenTelemetry GenAI instrumentation (opentelemetry-instrumentation-openai-v2, OpenLLMetry Traceloop.init(), OpenInference), Langfuse (@observe or langfuse.openai) or LangSmith tracing, or an audit-log call in the tool dispatcher. Record the caller (user or agent identity), time, model, tool names and arguments, guard verdicts and token counts. Turn message content capture off or pass it through a redaction step (OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false, Langfuse mask=, LangSmith hide_inputs), never write raw prompts, messages or completions to application loggers or print statements, set a retention period on the telemetry store, restrict who can read it, and write security events to append-only or signed storage so an attacker who gains access cannot erase their trail.

Where it goes: 1 application source code, 3 config and feature flags, 10 logs and telemetry, 15 agent action surface.

What reviewers look for: an instrumentor, tracing decorator or audit-log call that covers every model and tool call; content capture disabled or a redaction function applied before export; no logger.info / console.log of prompt, messages, completion or user input variables; a retention setting and an access policy for the telemetry store.

Example (Python + OpenAI + OpenTelemetry), before:

logger.info(f"prompt={messages} reply={completion.choices[0].message.content}")

After:

# once at startup
from opentelemetry.instrumentation.openai_v2 import OpenAIInstrumentor
OpenAIInstrumentor().instrument()   # gen_ai.* spans for every call
# environment: OTEL_INSTRUMENTATION_GENAI_CAPTURE_MESSAGE_CONTENT=false

logger.info('chat call', extra={'user': user_id, 'model': MODEL,
            'tokens': completion.usage.total_tokens})

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)

TwinEthos recommendation (not law) (1)

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.