About TrailMQ

A self-hosted MQTT broker that enforces access policy and records who was allowed or denied, on which topic, and why.

Last updated: September 2026

What it is

TrailMQ is an MQTT broker. Standard clients — mosquitto, paho-mqtt, mqtt.js, a browser WebSocket client — connect to it directly over TLS or WebSocket, with no SDK, proxy or sidecar.

Two things happen at that boundary. Every publish and subscribe must pass both the role’s permission and a topic rule that brings the path into scope. And the resulting decision is recorded as it is made, with the actor, role, client id, topic, outcome and, for a refusal, a reason in prose.

Why it exists

Because a denied publish is unreasonably hard to explain afterwards.

The protocol gives the client almost nothing to work with: MQTT 3.1.1 has no way to say not authorized on a publish, so brokers drop the connection instead, and at QoS 0 the message is discarded while the client reports success. By the time anyone asks what happened, the answer has to already exist somewhere.

Most setups can enforce access perfectly well. What they tend to lack is a record of the decision that a reviewer can read months later without correlating an ACL file against a connection log. TrailMQ brings access enforcement and decision review into one workflow.

It is a technical control with stated limits, not a compliance outcome — the integrity chain covers system and action entries, and says so where MQTT decision records fall outside it.

Who runs it

TrailMQ is an independent project run by Florian Przybylak, working on the architecture of regulated industrial systems, data pipelines and trustworthy automation — LinkedIn.

It is not a company. The public evaluation distribution is published through the RainerGewalt GitHub account, which is the technical maintainer and repository role. Rights in the software are governed by the binding license text, which this site does not restate. Operator and contact details are on the imprint.

Where to go next

Evaluating TrailMQ?

Questions about evaluation, licensing or a regulated deployment.