Getting Started with HAIEC
Evidence-bound assurance for consequential AI systems
The HAIEC Workflow
Define, connect, collect evidence, map actions, evaluate, assure, and verify.
Define
5 minCreate or select an AI System in HAIEC. HAIEC organizes evidence and assurance around a bounded AI System, so every evaluation, action, and receipt is scoped to a specific system.
Go to AI SystemsConnect
10 minRegister and connect the supported evidence sources relevant to that system. Examples include source repositories, application access, provider/IAM evidence, and runtime evidence where connected. Registered does not mean connected. Connected does not mean evaluated.
View Evidence SourcesCollect Evidence
VariesRun or attach supported evidence producers: static analysis, runtime evidence where connected, policy, provider/IAM evidence, or self-reported/uploaded evidence where supported. Missing evidence remains missing — it does not silently become PASS.
View EvidenceSee the System Constellation
10 minReview what the AI system can reach: identities, application access, credential evidence, actions, APIs/tools, potential consequences, policy context, and unknown relationships. HAIEC does not promise universal discovery — the map shows what available evidence establishes.
Open System ConstellationRun Evaluation
VariesUse Evaluation Runs to coordinate evidence collection and evaluation across supported producers. An evaluation run produces operational evidence and scores. An evaluation run is not an Assurance decision.
Go to Evaluation RunsAssure
5 minReview the canonical Assurance outcome: ALLOW, REVIEW, or BLOCK. ALLOW means the system is permitted within the evaluated scope and available evidence — it is not a universal safety or compliance claim. UNKNOWN, NOT_ASSESSED, PARTIAL, FAILED, TIMEOUT, UNSUPPORTED, and NOT_RUN never silently become PASS.
Go to AssuranceVerify
5 minReview the Decision Receipt and public verification where supported. Verification confirms bounded record integrity and the recorded decision. It does not certify compliance, regulatory approval, or universal safety.
Go to VerifyKey Concepts
Evidence-Bound Assurance
HAIEC connects source, identity, access, policy, permissions, evidence, and observed behavior to show what AI systems and agents can reach, change, and trigger, and what the evidence actually establishes.
Evaluated Scope
ALLOW means within evaluated scope and available evidence. It is not a universal safety or compliance claim. The evaluated scope is captured with each Assurance decision.
Missing Evidence Stays Missing
UNKNOWN, NOT_ASSESSED, PARTIAL, FAILED, TIMEOUT, UNSUPPORTED, and NOT_RUN never silently become PASS. If evidence is not collected, the gap is visible.
Evaluation Run ≠ Assurance
Evaluation Runs coordinate evidence collection and produce operational evidence. The canonical Assurance Decision Engine independently produces ALLOW / REVIEW / BLOCK. They are distinct.
Decision Receipt ≠ Certification
A Decision Receipt is a tamper-evident record of a bounded Assurance decision. Public verification confirms record integrity and the recorded decision. It is not compliance certification, regulatory approval, or a legal opinion.
Framework Mapping ≠ Assurance
Framework and regulation guides (GDPR, HIPAA, NYC LL144, SOC 2) help you understand requirements. Mapping controls to a framework is not an Assurance decision and not a certification.
Ready to Get Started?
Create your free account and define your first AI system to start collecting evidence.