Policy on every agent call
Scope and policy are set on every agent and MCP call, then logged. Not a node somebody remembered to add.
Moving from n8n / Governance and compliance
Governing AI requires audit trails, versioning, compliance and trust. It is why n8n customers move to Tray.
Thanks — someone from our team will be in touch soon.
Scope and policy are set on every agent and MCP call, then logged. Not a node somebody remembered to add.
Access control and roles are operated by Tray, so who can build, edit and publish is a setting your team changes.
Workflow versioning and history, so what changed, when and by whom is a matter of record rather than a reconstruction.
Authentications are held and managed by the platform, not pasted into a workflow, a script or a prompt.
What ran, what it reached and what triggered it, kept as a platform record and available to stream into your SIEM.
SOC 1 and SOC 2 Type 2 with annual penetration testing, HIPAA, GDPR and CCPA, US, EU or APAC residency, signed DPAs and a published subprocessor list.
Why enterprises choose Tray
| What a reviewer wants to know | How it works on Tray.ai |
|---|---|
| Where is policy applied? | On every agent and MCP call, by the platform, rather than in a step someone added to a workflow. |
| Who has to remember to turn it on? | Nobody. Coverage does not depend on whoever built each workflow. |
| What does the record show? | Every call: what ran, what it reached and what triggered it, kept as a platform record and available to stream into your SIEM. |
| Who keeps the controls working? | Tray. They are set up, kept configured and evidenced for you, not by your team. |
| How is access removed? | Access is granted through managed authentications and roles, so revoking one removes the access it granted rather than leaving it embedded in whatever used it. |
Industry recognized
Tray.ai is the AI orchestration platform. We run the controls, you do not configure them.
Audited and certified
SOC 1
audited annually
SOC 2 Type 2
with penetration testing
HIPAA
PHI handling
GDPR
EU data residency
CCPA
US data residency
700+
connectors managed
across integration, automation, and agents
1T+
processes run per year
on the platform
100%
workflow execution uptime
over the trailing 90 days
US, EU, and APAC data residency · Annual penetration testing, tested by independent assessors, with a bug bounty programme alongside. Signed DPAs and a published subprocessor list are available. Uptime measured on status.tray.ai and publicly checkable there. As of August 2026.
Visit the trust centerMore on moving from n8n:Risk and patchingOperational overheadScale and reliabilityMigrationStart from the top
Contents
tray.ai · 12 pages
The guide · 12 pages
Five signs you've outgrown n8n
Five signs, what each one costs, and where your setup stands.
Get the guideWhy enterprises love Tray
“With Tray, we're now building agents that can troubleshoot access issues, automate provisioning, and reduce manual load on our IT teams. With a more agile and cost-effective integration strategy, Yext is now well-equipped to drive innovation, improve operations, and scale automation at an enterprise level.”
Yes. There is a Guardrails node that enforces policy on text, and per-tool approval that the workflow builder configures. Those are real features and they work. The structural question is where the control lives: inside a workflow, added and configured by whoever built it, rather than as a platform property applied to every call whether anyone remembered or not.
On the call itself. Scope and policy sit on every agent and MCP call, and every call is kept as a platform record. Nothing depends on a builder having added the right node to the right workflow, which means coverage is not a function of who built what and when.
The controls exist on both platforms. What differs is who operates them. On a self-hosted install you configure them, keep them configured, and produce the evidence yourself. On Tray that work is the platform’s, which is what a reviewer is actually asking about when they ask who is responsible.
Yes. Tray.ai is SOC 1 Type 2 and SOC 2 Type 2 audited, with annual penetration testing. The reports cover the platform your workflows actually run on, which is the scope a reviewer cares about. Current documentation is on the trust center.
n8n’s MCP Server Trigger documents authentication as optional, with a random URL path as the default protection. That is a documented design choice, not a flaw, and it makes for a fast start. It also means the security posture of an MCP endpoint depends on what the person who created it selected, which is a different assurance model from a platform where the policy is not optional.
Let's discuss your governance gaps.
Thanks — someone from our team will be in touch soon.
GARTNER is a registered trademark and service mark, HYPE CYCLE and MAGIC QUADRANT are registered trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.