Skip to content
Tray.ai

Moving from n8n / Governance and compliance

Governing AI takes a rock solid foundation.
Are you sure n8n is it?

Governing AI requires audit trails, versioning, compliance and trust. It is why n8n customers move to Tray.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

Govern integrations and AI confidently, with Tray

Policy on every agent call

Scope and policy are set on every agent and MCP call, then logged. Not a node somebody remembered to add.

mcp:crm.read allow
mcp:billing.write deny
agent:ticket.create allow
logged · scope set at platform

Who can change what

Access control and roles are operated by Tray, so who can build, edit and publish is a setting your team changes.

role buildeditpublish
admin
builder
viewer
a setting · not a rebuild

Every change is a version

Workflow versioning and history, so what changed, when and by whom is a matter of record rather than a reconstruction.

v12 r.patel 2h
v11 j.kim 1d
v10 r.patel 3d
reconstruction needed none

Secrets stay out of the build

Authentications are held and managed by the platform, not pasted into a workflow, a script or a prompt.

in the workflow auth.salesforce
held by the platform ••••••••
pasted into a prompt never

A record of every run

What ran, what it reached and what triggered it, kept as a platform record and available to stream into your SIEM.

ran enrich-accounts
reached salesforce
triggered by schedule
your SIEM

Evidence a reviewer accepts

SOC 1 and SOC 2 Type 2 with annual penetration testing, HIPAA, GDPR and CCPA, US, EU or APAC residency, signed DPAs and a published subprocessor list.

SOC 1 Type 2
SOC 2 Type 2
pen test
signed DPA
subprocessors
residency US EU APAC
reviewer pack ready

Why enterprises choose Tray

CiscoAirbnbFedExNotionNetAppApollo.ioYextLife360

What a reviewer asks, and how Tray answers

What a reviewer wants to know How it works on Tray.ai
Where is policy applied? On every agent and MCP call, by the platform, rather than in a step someone added to a workflow.
Who has to remember to turn it on? Nobody. Coverage does not depend on whoever built each workflow.
What does the record show? Every call: what ran, what it reached and what triggered it, kept as a platform record and available to stream into your SIEM.
Who keeps the controls working? Tray. They are set up, kept configured and evidenced for you, not by your team.
How is access removed? Access is granted through managed authentications and roles, so revoking one removes the access it granted rather than leaving it embedded in whatever used it.

Industry recognized

Gartner 3× Visionary Gartner Magic Quadrant for iPaaS, 2024, 2025 and 2026
Nucleus Research 7× Leader Nucleus Research iPaaS Value Matrix, seven consecutive years
Gartner Pioneer Gartner Emerging Market Quadrant for No-Code Agent Builders, 2026
Gartner 14 Hype Cycles Gartner inclusions in 2026, including Agentic AI and Agentic Automation

Controls you never configure

Tray.ai is the AI orchestration platform. We run the controls, you do not configure them.

  • Access control you do not maintain, so limiting who can edit what is a setting rather than a purchase.
  • Audit-log streaming, into the SIEM you already run, with retention following the policy you already have.
  • Workflow versioning, so what changed, when, and by whom is a matter of record.
  • Scope and policy on every agent and MCP call, evaluated by the platform and kept as a platform record.
How governance works across the platform

Audited and certified

The evidence a reviewer accepts

SOC 1

audited annually

SOC 2 Type 2

with penetration testing

HIPAA

PHI handling

GDPR

EU data residency

CCPA

US data residency

700+

connectors managed

across integration, automation, and agents

1T+

processes run per year

on the platform

100%

workflow execution uptime

over the trailing 90 days

US, EU, and APAC data residency · Annual penetration testing, tested by independent assessors, with a bug bounty programme alongside. Signed DPAs and a published subprocessor list are available. Uptime measured on status.tray.ai and publicly checkable there. As of August 2026.

Visit the trust center

Contents

01 02
02 04
03 06
04 08
05 10

tray.ai · 12 pages

Five signs you've outgrown n8n — guide cover

The guide · 12 pages

Five signs you've outgrown n8n

Five signs, what each one costs, and where your setup stands.

Get the guide

Why enterprises love Tray

“With Tray, we're now building agents that can troubleshoot access issues, automate provisioning, and reduce manual load on our IT teams. With a more agile and cost-effective integration strategy, Yext is now well-equipped to drive innovation, improve operations, and scale automation at an enterprise level.”

— Tulasi Dhonthireddy, Director of IT and Business Applications, Yext
Read the study →

Frequently asked questions

Does n8n have governance features? +

Yes. There is a Guardrails node that enforces policy on text, and per-tool approval that the workflow builder configures. Those are real features and they work. The structural question is where the control lives: inside a workflow, added and configured by whoever built it, rather than as a platform property applied to every call whether anyone remembered or not.

How is policy enforced on Tray.ai? +

On the call itself. Scope and policy sit on every agent and MCP call, and every call is kept as a platform record. Nothing depends on a builder having added the right node to the right workflow, which means coverage is not a function of who built what and when.

Are RBAC, SSO, and audit logs standard or tier-gated? +

The controls exist on both platforms. What differs is who operates them. On a self-hosted install you configure them, keep them configured, and produce the evidence yourself. On Tray that work is the platform’s, which is what a reviewer is actually asking about when they ask who is responsible.

Is there a SOC 2 report for the platform running my automations? +

Yes. Tray.ai is SOC 1 Type 2 and SOC 2 Type 2 audited, with annual penetration testing. The reports cover the platform your workflows actually run on, which is the scope a reviewer cares about. Current documentation is on the trust center.

What about an MCP server with authentication left off? +

n8n’s MCP Server Trigger documents authentication as optional, with a random URL path as the default protection. That is a documented design choice, not a flaw, and it makes for a fast start. It also means the security posture of an MCP endpoint depends on what the person who created it selected, which is a different assurance model from a platform where the policy is not optional.

Still governing it workflow by workflow?

Let's discuss your governance gaps.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

GARTNER is a registered trademark and service mark, HYPE CYCLE and MAGIC QUADRANT are registered trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.