Interactive preview · demo data haiec.com ↗
Systems OK
EDITOR
S

Assessment Workspace ?

Kestrel demo · Acme Corp · Last updated 2 minutes ago. Every source you add unlocks more of the report. You can run with just source code — deeper evidence makes the report deeper, not wider.

⏱
Report is 2 hours old · 3 sources added since last run
Evidence coverage ?
65%
7 of 11 evidence sources configured · 4 recommended additions See full coverage →
🎯 What do you want to do? ?
📊 What you'll get with current evidence ?
Ready to run? ?
✓ Minimum met: source code + configuration
✓ Recommended met: telemetry + IAM
⚠ Best-practice missing: runtime endpoint, DAI evidence, alerts
Estimated time: 45 seconds

Evidence Coverage ?

Every source HAIEC can use. Each shows status, last updated, and the next action. ✓ configured · ⚠ partial · ✗ missing.

🔍
Scan Source Code
⏱ 3 min REQUIRED
1 Choose source
2 Configure
3 Confirm
📡
Connect Telemetry (OTLP)
⏱ 4 min RECOMMENDED
1 Token
2 Endpoints
3 Collector
4 Test
🔐
Connect IAM / Policy
⏱ 5 min RECOMMENDED
1 Provider
2 Credential
3 Import
⚔️
Configure Runtime Endpoint
⏱ 6 min OPTIONAL
1 Endpoint
2 Auth
3 Preflight
📋
Upload DAI Evidence
⏱ 3 min OPTIONAL
1 Upload
2 Confirm
🎯
Define Operating Envelope
⏱ 4 min OPTIONAL
1 Bounds
2 Confirm
🔔
Configure Alerts
⏱ 2 min RECOMMENDED
1 Presets
2 Channels

AI Inventory ?

Connect provider admin keys to auto-discover AI models, agents, and API usage across your org. Read-only access. Keys stored as references only.

🔌 Connect provider
OpenAI
Admin API key (read)
Anthropic
Admin API key (read)
AWS Bedrock
Read-only role
Azure OpenAI
App registration
GCP Vertex
Service account
Custom
OpenAI-compatible API
We never store raw keys. We resolve them at scan time from your secret store.
📦 Discovered inventory
LIVE
14
Models in use
7
Agents
23
API keys
4
Unattributed
Discovered AI Assets
AssetProviderTypeOwnerUsed byLast seenStatus
gpt-4oOpenAIModelml-platform4 agents2 min agoIN USE
claude-3-7-sonnetAnthropicModelsupport-ai2 agents8 min agoIN USE
kestrel-agent-01InternalAgentrApp-team—LiveACTIVE
legacy-embed-001OpenAIModelunknown090 days agoORPHAN
sk-…7f2aOpenAIKey——14 days agoUNATTRIBUTED
Inventory ≠ compliance. HAIEC shows what exists. Whether each asset should exist is a governance decision.

Kill Switch BETA ?

Emergency control plane. Revoke credentials, halt agents, or block endpoints. Every action creates a `kill_switch_event` evidence record.

🚨 Active agents
3 RUNNING
AgentOwnerCurrent actionLast heartbeatAction
kestrel-agent-01rApp-teamReading cell metrics2s ago
mobility-optimizerran-opsIdle14s ago
policy-enforcercore-teamIdle1m ago
🔑 Revoke credential

Revokes an active credential at the source. Caller must confirm.

🚫 Block endpoint

Adds an egress block at the runtime transport layer for one URL.

KILL_SWITCH != REMEDIATION. Halting an agent stops the action. It does not fix the root cause. HAIEC records the event, the reason, and who acted — the rest is your runbook.

Compliance Twin ?

Digital twin of your system. Reconstructs AL0 (design) → AL1 (authorized) → AL2 (observed). Shows the first deterministic divergence.

AL0 · Design
43
Declared resources

What the architecture says exists.

AL1 · Authorized
38
Policy-authorized

What policy allows. 5 resources excluded.

AL2 · Observed
41
Actually observed

3 observed outside AL1. Divergence flagged.

🔍 First Deterministic Divergence
EVIDENCE · BEHAVIORAL · INTEGRITY
Triad divergence detected at 2026-10-27 14:22:11 UTC
Evidence divergence: Slice monitor says slice-DFW-043 remains isolated. Transport telemetry shows cross-slice packets from the same session.
Behavioral divergence: The rApp declared policy.read; observed policy.admin write at 14:22:11.
Integrity divergence: Post-state hash b4e1… does not match pre-state hash a3f2… for the same resource.
Correlation ≠ causation: Three divergences share a timestamp. HAIEC surfaces them together. It does not claim one caused another.
State matrix
RowAL0AL1AL2EvidenceStatus
IntentAutonomous mobility tuningPolicy allowsTuning executed3 refsMATCH
Authoritypolicy.readpolicy.readpolicy.admin observed4 refsDIVERGED
Reachability43 cells43 cells43 cells2 refsMATCH
Operation / StateBaseline hash a3f2…—Hash b4e1…2 refsINTEGRITY
ConsequenceWithin envelope ±10 pp15 min window±12 pp observed3 refsDRIFT
Evidence closure——3 of 4 closed—OPEN

Hiring Bias Detection ?

Required for NYC LL144 and Colorado AI Act. Evaluates AI-driven hiring, promotion, and screening systems for disparate impact across protected classes.

Impact ratios
0.79
Min impact ratio

Below 0.80 = adverse impact flag (EEOC 4/5ths rule).

Categories evaluated
7
Protected classes

Race, sex, age, disability, veteran, religion, national origin.

Data sufficiency
62%
Decision coverage

Only 62% of decisions have demographic data. Partial.

Impact analysis
Protected classSelection rateReference rateImpact ratioStatus
Sex · Female34.2%42.1%0.81PASS
Race · Black29.8%42.1%0.71ADVERSE
Age · 40+33.3%42.1%0.79AT RISK
Veteran status39.9%42.1%0.95PASS
⚠ NYC LL144 audit readiness
PARTIAL

Required artifacts: bias audit summary, demographic data methodology, published results. You have 2 of 3. Demographic data methodology is missing.

IMPACT_RATIO < 0.80 != LEGAL VIOLATION. It's a flag. Legal review determines next step. HAIEC presents the numbers; it does not adjudicate.

Audit-Ready Artifacts ?

Generate audit-ready evidence packages. Each package is Merkle-anchored, offline-verifiable, and framework-mapped.

📦 Generate package
Framework
Time range
Include
✅ Recent artifacts
VERIFIED
FrameworkGeneratedSizeVerify
SOC 2 CC7.22h ago4.2 MB
NIST AI RMF 2.41d ago2.8 MB
NYC LL1443d ago1.1 MB
What this proves: The evidence existed, was produced by named sources, and has not been altered since capture. Merkle roots let third parties verify offline.
What this does NOT prove: That the underlying system was compliant. Artifacts document evidence state; they are not certifications.

AI AppSec OPEN SOURCE ?

Open-source scanner for AI applications. Static + runtime. Deterministic detection families. CI/CD-ready. SARIF output.

86
Detections

14 families: PROMPT, RAG, MCP, TELECOM, etc.

126
Semantic relations

TM Forum SID, O-RAN, 3GPP, DFIR, cloud.

v1.2.4
Latest release

SEMGREP_PINNED = 1.52.0

🚀 Quick start
npx @haiec/appsec scan --repo github.com/owner/repo --format sarif
# GitHub Actions - uses: haiec/appsec-action@v1 with: sarif-upload: true fail-on: critical
Detection families

LLMVerify OPEN SOURCE ?

Deterministic verification of LLM input/output. Schema validation, PII detection, jailbreak patterns, policy conformance. No LLM in the canonical path.

✅ Verifications
✓ PASS
Schema conformance
Output matched declared JSON schema
✓ PASS
PII scan
No SSN, phone, email leakage detected
⚠ WARN
Jailbreak pattern
1 near-match (score 0.87, threshold 0.90)
✓ PASS
Policy conformance
All 12 policy rules evaluated
📋 Verify an output
Input
Output
Deterministic: Same input → same output. Every verdict has a reason code.

MCP Tenant Isolation OPEN SOURCE ?

Verifies Model Context Protocol servers enforce tenant boundaries. Detects cross-tenant leakage, shared state, and capability bleed.

🔴 Active findings
2 CRITICAL
MCP serverFindingEvidenceStatus
mcp-filesystemCross-tenant path traversal (tenant-b → /tenant-a/…)3 refsOPEN
mcp-databaseQuery scope not tenant-filtered on `list_tables`2 refsOPEN
mcp-k8sNamespace scope correctly bound1 refSAFE
MCP_SERVER_TRUST != TENANT_ISOLATION. An MCP server can be trusted code and still fail to enforce isolation. HAIEC checks the boundary, not the reputation.

Teams ?

Manage who can see and change your assessment. Roles: Viewer · Editor · Admin. Every action is logged.

👥 5 members
MemberEmailRoleLast activeActions
Sam Riverasam@acme-demo.comADMIN2 min ago—
Jane Chenjane@acme-demo.comEDITOR1h ago
Rafael Ortizrafael@acme-demo.comEDITORYesterday
SOC teamsoc@acme-demo.comVIEWER2h ago
Auditor (external)auditor@big4.comVIEWER3d ago
🔑 API keys
NameScopeLast used
ci-scannerscan:write10m ago
siem-ingestevidence:ingestLive
report-readerreport:read1d ago
📜 Recent activity
14:22 sam@ started evaluation HAIEC-SES-2026-10-27-001
14:18 jane@ added runtime endpoint
13:55 rafael@ enabled 11 alert presets
12:40 soc@ viewed report (viewer role)
11:02 auditor@ logged in (viewer role)

Plan & Usage ?

Current plan, seat usage, scan quotas, and overage. All usage resets monthly.

💼 Current plan
PRO
$2,400
Monthly · billed annually
Seats
5 / 10
Scans/mo
187 / 500
Telemetry GB/mo
42 / 200
📈 Usage this month
37%
of quota consumed
187
Scans
42 GB
Telemetry
1.2M
Findings
Available plans
Starter
$0
Free

1 seat · 10 scans/mo · 1 GB telemetry

Pro
CURRENT
$2,400
per month

10 seats · 500 scans/mo · 200 GB telemetry

Enterprise
Custom
Contact sales

Unlimited seats · SSO/SCIM · on-prem option

Settings ?

Organization settings, security defaults, integrations, and audit trail.

🏢 Organization
Name
Default region
Data residency
🔒 Security defaults
✓ ON
Enforce MFA
All admins require MFA on next login
✓ ON
Session TTL
8 hours (event-day duration)
⚠ OFF
IP allowlist
Not configured — recommended for admin roles
✓ ON
Audit log
Every action recorded with evidence ref
🔌 Integrations
✓ CONNECTED
Slack
#soc-alerts channel
✓ CONNECTED
GitHub
kestrel-demo org
✗ MISSING
Jira
Create tickets from findings
✗ MISSING
Splunk
Forward evidence to SIEM
📜 Audit trail
2026-10-27 14:22 sam@ started evaluation
2026-10-27 14:18 jane@ added runtime endpoint
2026-10-27 13:55 rafael@ enabled alert presets
2026-10-27 12:40 sam@ changed security defaults

Notifications ?

All alerts and system events for the last 7 days. Filter by severity or source.

🔴 CRITICAL · last 24h
3
Cross-slice isolation violation SLICE
slice-DFW-043 · 14:22 UTC · Evidence: 3 refs
Audit-trail tampering detected INTEGRITY
Hash chain broken at resource slice-DFW-043 · 14:22 UTC
🟡 HIGH · last 24h
5
Energy rApp observed outside delegation DAI
cell-DFW-101 · 13:48 UTC
Policy Control App has admin scope CAPABILITY
policy.admin reachable · 12:01 UTC
BANNER_DISMISS != FINDING_RESOLVED. Dismissing a banner hides it in this view for 24h. The finding stays in the report until the evidence frontier closes.
Master Assurance Report
Session HAIEC-SES-2026-10-27-001 · Kestrel · 65% coverage · Generated 2 min ago
86
Detections Run
47
Findings
3
Critical
12
High
16
Surfaces
4
Evidence Families
🎯 Material Stories — 4 primary findings
🔴 Cross-slice isolation violation CRITICAL
What happened: An eMBB session on slice-DFW-043 accessed the URLLC namespace. Violates 3GPP TS 23.501 slice isolation.
Why it matters: Slice boundaries are contractual. This session crossed a boundary that should never have been crossed.
Evidence strength: STRONG — 3 independent sources agree (slice monitor + transport telemetry + KPI).
What closes the gap: Restore approved slice policy; re-run canary probe to confirm isolation.
🔴 Audit-trail tampering detected CRITICAL
What happened: Post-state hash b4e1… does not match pre-state hash a3f2… for slice-DFW-043. Independent sources contradict the record.
Why it matters: Would fail SOC 2 CC7.2 audit readiness.
Evidence strength: TAMPERED — hash chain broken but corroboration survives.
What closes the gap: Re-issue state observation from authoritative source; enable hash-chain alerting.
⚠ Energy rApp observed outside delegation HIGH
What happened: Energy rApp executed cell.lifecycle.write on cell-DFW-101. Declared capability was cell.power.write. DAI state: OBSERVED_OUTSIDE_DELEGATION.
Why it matters: The agent did something different from what it was delegated to do.
What closes the gap: Update delegation scope or restrict the agent's credential.
⚠ Policy Control App has admin scope HIGH
What happened: Policy Control App declared policy.read but code-capable and reachable include policy.admin. DAI state: CAPABILITY_OUTSIDE_DELEGATION_UNMEDIATED.
Why it matters: The agent can do far more than declared. Not yet exploited, but a real risk.
What closes the gap: Reduce credential scope; add guardrail that blocks admin operations.
⚖️ What changed since last run
NEW 3 new CRITICAL findings since 12:00 UTC
RESOLVED 2 findings closed (evidence frontier closed via runtime probe)
CHANGED 1 finding severity upgraded HIGH → CRITICAL
UNCHANGED 41 findings stable
Welcome to HAIEC
Step 1 of 5
HAIEC Assurance Workspace — interactive preview · all data shown is synthetic · no live connection haiec.com · Production interface shows real persisted evidence only