HAIECDocumentation
Learn how to define AI systems, connect evidence sources, understand AI actions and access, run evaluations, review bounded Assurance, and verify Decision Receipts.
Start typing to search
Press ESC to clear
Start Here
Foundational guides for the HAIEC evidence-bound assurance workflow.
What is HAIEC?
Evidence-bound assurance for consequential AI systems
Getting Started
Define, connect, collect evidence, map actions, evaluate, assure, verify
AI Systems
Define and govern bounded AI systems
System Constellation
See what AI systems can reach, change, and trigger
Evidence
Organization-wide evidence library
Assurance
Canonical ALLOW / REVIEW / BLOCK dispositions
Decision Receipts & Verification
Public verification of decision receipt integrity
Developers & Agents
Run HAIEC from your IDE, GitHub, API, or workspace. Your AI operates the workflow; HAIEC evaluates the evidence.
AI Security Scanner
Static code analysis for AI attack surfaces
AI AppSec (Open Source)
Semgrep-backed static source-code analysis package
MCP Tenant Isolation
Tenant isolation boundary checks
LLMVerify
LLM input/output verification
CI/CD Integration
GitHub App, CI/CD, and CLI setup
GitHub Integration
GitHub App setup and repository signals
Detection Catalog
Every detection rule shipped — evidence class, hard negatives, executable vs register-only
Ingest Adapters
Every evidence format HAIEC accepts, normalized to one envelope
Agent & Capability Model
Five evidence planes, capability chain, delegation chain, DAI
Local & IDE Assurance
Scan an existing workspace locally, submit qualified evidence, and start the canonical pipeline
Connected GitHub Assurance
Recommended: trigger remote HAIEC scans through a GitHub-App-verified Source Asset
Run HAIEC from Cursor
Project rule + env setup so Cursor triggers remote Assurance via the same API
Run HAIEC from Claude Code
CLAUDE.md instructions so Claude Code triggers remote Assurance via the same API
Run HAIEC from Devin
AGENTS.md instructions so Devin triggers remote Assurance via the same API
Run HAIEC from Any Agent
Generic instructions for Windsurf, Copilot, CI scripts, and other coding agents
Agent Integration
Rules and discovery for coding agents calling the Assurance API
Assurance API Quickstart
Four env values to a first persisted evaluation — minimal external integration path
Assurance Runs API
One REST API for scan → evidence → evaluation → report links
Evidence Sources & Connections
Supported evidence producer categories. Registered does not mean connected; connected does not mean evaluated.
Standards & Frameworks
Framework and regulation documentation. Framework mapping is not Assurance and not certification.
Reference
Evidence semantics, coverage limitations, assurance dispositions, and verification.
Technical Reference
Technical index, engine documentation, and API reference
Detection Rules Reference
Detector definitions and security checks
Runtime Engine Guide
Runtime security engine documentation
SDK Installation
SDK setup and integration
Framework Mappings
Real ATLAS, ASI, NIST AI RMF, WG11, STIX IDs on real rules
Remediation Playbooks
Plain-language fix steps plus verification — never auto-applied
Relation & Entity Vocabulary
Evidence-qualified relation types and telecom entity reference
Ready to Get Started?
Define your first AI system and start collecting evidence.