Assessment Workspace ?
Kestrel demo · Acme Corp · Last updated 2 minutes ago. Every source you add unlocks more of the report. You can run with just source code — deeper evidence makes the report deeper, not wider.
✓ Recommended met: telemetry + IAM
⚠ Best-practice missing: runtime endpoint, DAI evidence, alerts
Estimated time: 45 seconds
Evidence Coverage ?
Every source HAIEC can use. Each shows status, last updated, and the next action. ✓ configured · ⚠ partial · ✗ missing.
AI Inventory ?
Connect provider admin keys to auto-discover AI models, agents, and API usage across your org. Read-only access. Keys stored as references only.
| Asset | Provider | Type | Owner | Used by | Last seen | Status |
|---|---|---|---|---|---|---|
| gpt-4o | OpenAI | Model | ml-platform | 4 agents | 2 min ago | IN USE |
| claude-3-7-sonnet | Anthropic | Model | support-ai | 2 agents | 8 min ago | IN USE |
| kestrel-agent-01 | Internal | Agent | rApp-team | — | Live | ACTIVE |
| legacy-embed-001 | OpenAI | Model | unknown | 0 | 90 days ago | ORPHAN |
| sk-…7f2a | OpenAI | Key | — | — | 14 days ago | UNATTRIBUTED |
Kill Switch BETA ?
Emergency control plane. Revoke credentials, halt agents, or block endpoints. Every action creates a `kill_switch_event` evidence record.
| Agent | Owner | Current action | Last heartbeat | Action |
|---|---|---|---|---|
| kestrel-agent-01 | rApp-team | Reading cell metrics | 2s ago | |
| mobility-optimizer | ran-ops | Idle | 14s ago | |
| policy-enforcer | core-team | Idle | 1m ago |
Revokes an active credential at the source. Caller must confirm.
Adds an egress block at the runtime transport layer for one URL.
Compliance Twin ?
Digital twin of your system. Reconstructs AL0 (design) → AL1 (authorized) → AL2 (observed). Shows the first deterministic divergence.
What the architecture says exists.
What policy allows. 5 resources excluded.
3 observed outside AL1. Divergence flagged.
Behavioral divergence: The rApp declared policy.read; observed policy.admin write at 14:22:11.
Integrity divergence: Post-state hash b4e1… does not match pre-state hash a3f2… for the same resource.
Correlation ≠ causation: Three divergences share a timestamp. HAIEC surfaces them together. It does not claim one caused another.
| Row | AL0 | AL1 | AL2 | Evidence | Status |
|---|---|---|---|---|---|
| Intent | Autonomous mobility tuning | Policy allows | Tuning executed | 3 refs | MATCH |
| Authority | policy.read | policy.read | policy.admin observed | 4 refs | DIVERGED |
| Reachability | 43 cells | 43 cells | 43 cells | 2 refs | MATCH |
| Operation / State | Baseline hash a3f2… | — | Hash b4e1… | 2 refs | INTEGRITY |
| Consequence | Within envelope ±10 pp | 15 min window | ±12 pp observed | 3 refs | DRIFT |
| Evidence closure | — | — | 3 of 4 closed | — | OPEN |
Hiring Bias Detection ?
Required for NYC LL144 and Colorado AI Act. Evaluates AI-driven hiring, promotion, and screening systems for disparate impact across protected classes.
Below 0.80 = adverse impact flag (EEOC 4/5ths rule).
Race, sex, age, disability, veteran, religion, national origin.
Only 62% of decisions have demographic data. Partial.
| Protected class | Selection rate | Reference rate | Impact ratio | Status |
|---|---|---|---|---|
| Sex · Female | 34.2% | 42.1% | 0.81 | PASS |
| Race · Black | 29.8% | 42.1% | 0.71 | ADVERSE |
| Age · 40+ | 33.3% | 42.1% | 0.79 | AT RISK |
| Veteran status | 39.9% | 42.1% | 0.95 | PASS |
Required artifacts: bias audit summary, demographic data methodology, published results. You have 2 of 3. Demographic data methodology is missing.
Audit-Ready Artifacts ?
Generate audit-ready evidence packages. Each package is Merkle-anchored, offline-verifiable, and framework-mapped.
| Framework | Generated | Size | Verify |
|---|---|---|---|
| SOC 2 CC7.2 | 2h ago | 4.2 MB | |
| NIST AI RMF 2.4 | 1d ago | 2.8 MB | |
| NYC LL144 | 3d ago | 1.1 MB |
AI AppSec OPEN SOURCE ?
Open-source scanner for AI applications. Static + runtime. Deterministic detection families. CI/CD-ready. SARIF output.
14 families: PROMPT, RAG, MCP, TELECOM, etc.
TM Forum SID, O-RAN, 3GPP, DFIR, cloud.
SEMGREP_PINNED = 1.52.0
LLMVerify OPEN SOURCE ?
Deterministic verification of LLM input/output. Schema validation, PII detection, jailbreak patterns, policy conformance. No LLM in the canonical path.
MCP Tenant Isolation OPEN SOURCE ?
Verifies Model Context Protocol servers enforce tenant boundaries. Detects cross-tenant leakage, shared state, and capability bleed.
| MCP server | Finding | Evidence | Status |
|---|---|---|---|
| mcp-filesystem | Cross-tenant path traversal (tenant-b → /tenant-a/…) | 3 refs | OPEN |
| mcp-database | Query scope not tenant-filtered on `list_tables` | 2 refs | OPEN |
| mcp-k8s | Namespace scope correctly bound | 1 ref | SAFE |
Teams ?
Manage who can see and change your assessment. Roles: Viewer · Editor · Admin. Every action is logged.
| Member | Role | Last active | Actions | |
|---|---|---|---|---|
| Sam Rivera | sam@acme-demo.com | ADMIN | 2 min ago | — |
| Jane Chen | jane@acme-demo.com | EDITOR | 1h ago | |
| Rafael Ortiz | rafael@acme-demo.com | EDITOR | Yesterday | |
| SOC team | soc@acme-demo.com | VIEWER | 2h ago | |
| Auditor (external) | auditor@big4.com | VIEWER | 3d ago |
| Name | Scope | Last used |
|---|---|---|
| ci-scanner | scan:write | 10m ago |
| siem-ingest | evidence:ingest | Live |
| report-reader | report:read | 1d ago |
Plan & Usage ?
Current plan, seat usage, scan quotas, and overage. All usage resets monthly.
1 seat · 10 scans/mo · 1 GB telemetry
10 seats · 500 scans/mo · 200 GB telemetry
Unlimited seats · SSO/SCIM · on-prem option
Settings ?
Organization settings, security defaults, integrations, and audit trail.
Notifications ?
All alerts and system events for the last 7 days. Filter by severity or source.
Why it matters: Slice boundaries are contractual. This session crossed a boundary that should never have been crossed.
Evidence strength: STRONG — 3 independent sources agree (slice monitor + transport telemetry + KPI).
What closes the gap: Restore approved slice policy; re-run canary probe to confirm isolation.
Why it matters: Would fail SOC 2 CC7.2 audit readiness.
Evidence strength: TAMPERED — hash chain broken but corroboration survives.
What closes the gap: Re-issue state observation from authoritative source; enable hash-chain alerting.
Why it matters: The agent did something different from what it was delegated to do.
What closes the gap: Update delegation scope or restrict the agent's credential.
Why it matters: The agent can do far more than declared. Not yet exploited, but a real risk.
What closes the gap: Reduce credential scope; add guardrail that blocks admin operations.