Know what your AI can do.
See what the evidence supports.
HAIEC evaluates AI systems within an explicit boundary, collects evidence from source, runtime, and governance, and produces structured assurance with a verifiable Decision Receipt.
AI System
Payments Support Agent
Evidence Sources
Coverage
PARTIAL
Authority / Capability
Assurance Result
REVIEW
Within evaluated scope. Missing evidence remains UNKNOWN.
Decision Receipt
Integrity record · SHA-256 bound
Binds the decision and supporting package. Structured scope binding is under development.
AI systems increasingly connect to everything.
Code, tools, data, APIs, infrastructure, shared systems. Organizations need more than scanner results, prompt guardrails, and checklists. They need bounded assurance tied to evidence.
Scanners
Point-in-time snapshots, not bounded evaluation
Prompt Guardrails
Runtime filters, not evidence of control
Checklists
Self-attestation, not deterministic proof
From AI System to Decision Receipt.
HAIEC evaluates within an explicit boundary. Evidence is collected from available sources. Assurance is computed deterministically. The result is a verifiable integrity record, not a probabilistic claim.
AI System
The system under evaluation
Connected Assets
Code, tools, APIs, data
Evaluated Boundary
Explicit scope, not unlimited
Evidence
Source, runtime, governance
Assurance
ALLOW / REVIEW / BLOCK
Decision Receipt
SHA-256 integrity bound
Evaluated Scope is currently structured at the contract level. Structured scope binding and receipt-bound verification are under development.
Permission is not delegation.
HAIEC compares authority and capability across five evidence planes. Missing evidence remains UNKNOWN, not safe.
REQUESTED
What was asked for
POLICY_AUTHORIZED
What policy permits
EFFECTIVELY_GRANTED
What was actually granted
CODE_CAPABLE
What the code can do
OBSERVED
What was seen in runtime
Not every plane currently has a native evidence producer. POLICY_AUTHORIZED is not the same as DELEGATED. A gap between policy and effective grant is a control finding, not a safe state.
Current SaaS evidence. Explicit coverage.
SaaS Static & CI Evidence
Source-code analysis and CI-pipeline evidence from the HAIEC SaaS scanner. Covers AI code, agents, and pipeline-integrated findings.
Learn moreAuthorized Runtime Testing
Adversarial runtime testing against authorized live endpoints. Tests model behavior under attack conditions that static analysis cannot reach.
Learn moreDeclared & External Evidence
Compliance wizard outputs, regulatory framework mappings, and uploaded or external evidence where current.
Learn moreBoundary is an important model concept for connected-asset analysis. MCP producers are registered but held; MCP evidence does not currently feed canonical SaaS evidence. Independent local developer-security engines are covered separately below.
What you receive is what was evaluated.
ALLOW
Available evidence supports an ALLOW disposition for the evaluated claim or scope
REVIEW
Evidence is incomplete, conflicting, or requires human review
BLOCK
Evaluated evidence does not support an ALLOW disposition and triggers a BLOCK under the applicable Assurance profile
Coverage
What was complete, partial, unknown, or not assessed
Limitations
What was not evaluated and why
Reason Codes
Deterministic explanation, not probabilistic
Decision Receipt
A Decision Receipt binds the HAIEC decision and supporting package to a verifiable integrity record. It records what evidence was available and what the deterministic result was. Structured Evaluated Scope binding is still being integrated.
Independent developer engines. Separate from SaaS evidence.
These local engines remain independent and do not currently feed canonical SaaS Evidence unless or until a portable evidence bridge is admitted. MCP ingestion remains held.
Bounded enterprise evaluation. Not a self-hosted platform.
HAIEC operates as a SaaS platform. Enterprise engagements follow the canonical workflow: AI System, Evidence, Assurance, Decision Receipt. We do not offer a fully self-hosted HAIEC deployment.
Bounded Evaluation
One AI System, one bounded Assurance question, authorized evidence sources, explicit coverage and limitations.
Customer-Controlled Evidence
HAIEC SaaS where applicable, independent local developer-security engines where supported, prepared for auditor, legal, and regulatory review.
Deterministic evaluation. Traceable output.
Five-Plane Authority & Capability Model
REQUESTED, POLICY_AUTHORIZED, EFFECTIVELY_GRANTED, CODE_CAPABLE, OBSERVED. Missing evidence is UNKNOWN.
Evidence Envelope
Structured evidence packaging with provenance and coverage metadata for evaluated claims.
Interface Profile Compiler
Internal deterministic compiler for supported interface specifications. Not every connected asset is compiled.
Canonical Serialization
Canonical serialization produces stable semantic digests for equivalent inputs under the same versioned semantics.
SHA-256 Semantic Digests
Contract-level scope digests and artifact hashing for content integrity. Scope binding is under development.
Action Witness
ACTIVE_INTERNAL / PRODUCTION_INTEGRATION_LIMITED. Provenance tracked, not assumed.
Assurance is the output of deterministic evaluation across system boundary, available evidence, assurance profile, and operating constraints. Internal and research-only components are not advertised as finished customer features.
Permission is not delegation.
This is the core research thesis. AI Action Assurance is the research territory. The following are active research directions, not currently deployed product capabilities.
Permission ≠ Delegation
A policy that permits an action is not the same as a delegation of authority to perform it.
Delegation ≠ Safe Consequence
Delegating authority does not guarantee the consequence of exercising it is safe.
Individually Acceptable ≠ Safe Trajectory
Actions that are individually acceptable may produce unsafe trajectories when composed.
DCI, MinResolve, Effect Contracts, invariants, and trajectory gates are active research directions. They are not currently deployed product capabilities.
View ResearchMapped to standards. Not defined by them.
HAIEC maps evidence to recognized frameworks and regulations. The frameworks do not define the company. They are mappings and specialized workflows.
Don't trust us. Verify us.
AI is operational
infrastructure now.
Validate it like it is.
If your AI is influencing outcomes, it must withstand examination. The gap between what you've deployed and what you can prove closes in one of two ways: you close it, or someone else discovers it.