File-access history · Mac · Windows · Linux

Every file open
leaves a trace.

Tracewell records which program opened which folder on every computer you run, and lets you answer who read this? in seconds, weeks after it happened.

Each ripple is one file open. Move your pointer to make your own.

01 The question

Something happened to your files. What touched them, when, and on which machine?

A client file leaked

Which programs read that folder in the last month, and on whose laptop?

Someone is leaving

Any unusual reading of shared or confidential folders before the last day?

A new AI tool is installed

What did it actually read? Only the project, or the whole Documents folder?

The operating system sees every file open for a split second. Then the history is gone. Security tools watch for malware, not for who read your contracts. So after an incident, most companies are left with guesses.

02 How it works

A flight recorder
for file access.

A small collector on each computer. A compressed history in the region you choose. An answer in your browser.

capture
  1. 1 / 4

    Capture

    The collector reads the operating system's own file-event feed: Apple Endpoint Security on Mac, ETW on Windows, fanotify on Linux. It observes only. It can't block, change or delay a file.

  2. 2 / 4

    Condense

    Repeated opens become one row per program × folder every ten minutes, then compressed. A noise filter can drop operating-system housekeeping before anything leaves the machine.

  3. 3 / 4

    Upload

    Encrypted, to storage isolated per company, in the EU or the US. Each machine has its own identity. A machine that is offline keeps recording and catches up later.

  4. 4 / 4

    Answer

    Open the console and ask. Search by folder, program or process. See which programs are behind the reads, and which of them are new this week.

03 Try it

Ask it a question.
Go on.

This is how the search works in the console. Pick a question.

console · searchdemo data

04 The console

Every machine.
One screen.

The Fleet page: five machines with their state, CPU and memory

05 The cost

Measured on real machines.
Not promised.

99.75%

smaller. 38.9 million file opens over three days on a developer's Mac: 6.5 GB of raw events, stored as 16 MB.

6.5 GB
raw events

← 16 MB stored. Drawn to scale.

<3%

of one CPU core, median, on a busy developer Mac. About 0.3% of an 8-core machine.

~25 MB

of memory for the collector.

~5 MB

stored per busy machine per day. About 150 MB a month.

5 min

from an enrollment token to the first machine on your dashboard.

The cost is never hidden: the console shows every machine's CPU and memory use of the collector, live.

06 Privacy

It knows the folder.
Never the contents.

Built to be acceptable to the people whose computers it runs on, and to the auditors who ask about it.

/Users/alex/Documents/contracts/acme-2026.docx

recorded: folder, program, timenever read: the file itself

What is recorded

  • The program's path and process ID
  • The folder that was read, the time and the size
  • The machine's health: CPU, memory, version, state

What never is

  • File contents
  • Screenshots or keystrokes
  • Browsing, emails or messages
  • Anything the noise filter excludes: it is dropped on the machine

Isolated

Each organization's data is separate, in the EU or the US. The two regions are separate services with nothing shared.

By invitation

Colleagues join as viewer, admin or owner. Every admin action is logged: who, what, when.

No keys on machines

A machine enrolls with a one-time token and gets its own identity. Deactivate any machine in about a minute.

Observe-only

It can't block, change or delay a file. A signed and notarized Mac app; releases with checksums.

Monitoring employees' devices must be disclosed to them and needs a legal basis (GDPR and local labour law). We give you a notice template for the pilot.

07 What it's for

Six questions it
answers.

  1. 01

    Incident scoping

    Ransomware, a leaked file or a stolen laptop: which programs read which folders, on which machines, before and after.

  2. 02

    AI tools and agents

    See what an AI assistant or a coding agent actually read on a machine, before you allow it company-wide.

  3. 03

    Departing employees

    Check for unusual reading of shared or confidential folders in the last weeks, with a documented process.

  4. 04

    New software

    A tool that never touched Documents starts reading it: an email the same hour, not a surprise months later.

  5. 05

    Audit evidence

    Show file-access monitoring for ISO 27001, NIS2, TISAX and client security questionnaires.

  6. 06

    IT and MSP operations

    One health view for Mac, Windows and Linux. Spot machines that are silent, outdated or misconfigured.

08 Where it fits

Next to your security tools,
not instead of them.

Your EDR stops malware. Tracewell keeps the file-access history you need when something happens anyway.

TracewellEDR / antivirusDLP suitesEmployee monitoringFile-server auditing
Main questionWho read which files?Is this malware?Is data leaving?What are people doing?Who changed the share?
Laptops and local filesYesYesYesYesNo
Searchable file-read historyWeeks to monthsDays, limitedPolicy hits onlyVariesServers only
InvasivenessLow: folders onlyLowMediumHigh: screens, keysLow
RolloutMinutesDaysWeeks to monthsDaysDays
Blocks threatsNo, observe-onlyYesYesNoNo

09 Where it runs

Your region.
Your machines.

Your organization's history is stored and processed in the European Union. Accounts, machines and data never leave the region.

Tracewell.app

      

10 Pricing

Per machine.
Nothing else.

You pay for the machines that reported in a month. No minimum, no setup fee. Indicative prices for the pilot phase, excluding VAT.

50

per month

€300

Pilot

Free

30 days, up to 25 machines. We install together and review the findings with you every week.

Starter

€3 per machine / month

Fleet, Search, Insights, email alerts, noise filter. 90 days of history. No minimum: one machine is fine.

Business

€6 per machine / month

Everything in Starter, plus one year of history, alerts on chosen folders, audit-log export and priority support.

Enterprise / MSP

Custom

Volume pricing, single sign-on, SIEM export, your own storage, a service-level agreement.

11 The pilot

Try it on your own machines.
Free for 30 days.

Pick 5 to 25 computers. We install together in 30 minutes.

  1. Day 1

    Generate a token and install: one command, or the Mac app. Machines appear on Fleet within minutes.

  2. Week 1

    We look at what is normal on your machines, turn on the noise filter and the email alerts.

  3. Weeks 2–3

    Real questions: a sensitive folder, an AI tool, a new hire's laptop. Alerts start to mean something.

  4. Week 4

    Review: questions answered, alerts that mattered, cost on the machines. You decide what's next.

We agree upfront what success means

At least one real question answered, alerts you would keep, and no slowdown your users notice.

Ask for a pilot

12 Questions

The ones we
always hear.

Is this spying on employees?

No contents, no screens, no keystrokes: only which program read which folder. It has to be disclosed to staff, and we give you a notice template. It protects employees too: it shows what a tool did, not just who sat at the machine.

Will it slow our machines down?

Under 3% of one CPU core on a busy Mac (median) and about 25 MB of memory. You don't have to take our word for it: the console shows the collector's cost on every machine.

We already have antivirus or an EDR.

Keep it. An EDR stops malware. Tracewell keeps the file-access history you need when something happens anyway, for weeks or months instead of days.

Where is our data?

In Google Cloud, in the region you choose: the EU or the US. The two are separate services with nothing shared. Data is isolated per organization and encrypted in transit and at rest.

How long is the history kept?

During a pilot, for the whole pilot. On a plan, 90 days or one year; longer on request.

What does installing need?

Admin rights, once per machine. On a Mac: the app and one Full Disk Access grant, which the app walks you through. On Windows and Linux: one command with your token. You can remove it at any time.

What if a machine is offline?

It keeps recording and uploads when it is back.

What doesn't it do?

It doesn't block anything, it doesn't read file contents, and it doesn't watch the network or email. Search runs per machine and day today; search across all machines at once is planned. Sign-in is with a Google account or an email address and password.

Let's find out what
touches your files.

A free 30-day pilot on 5 to 25 of your computers. Setup takes 30 minutes.