Skip to main content

Local & IDE Assurance

If the application is already on your computer, this is the shortest path into HAIEC. HAIEC analyzes the workspace locally, creates a deterministic qualified Evidence Bundle, submits that evidence to your organization, and starts the same Assurance Pipeline used by dashboard and remote-repository scans. You do not need to connect GitHub for this workflow.

Status: Preview — Enterprise POC. The local scanner and submission flow are implemented and tested, but coverage is bounded relative to the remote stack and @haiec/cli is not published — do not run npm install @haiec/cli. For the recommended full-coverage path, use Connected GitHub.

Minimum setup

  • A Dashboard API key with the Local / IDE purpose: scan:submit, scan:create, scan:read, and report:read.
  • An existing organization-bound aiSystemId.
  • A local workspace. Git remote and GitHub access are optional.
HAIEC_BASE_URL=https://www.haiec.com
HAIEC_API_KEY=haiec_live_xxx
HAIEC_AI_SYSTEM_ID=SYSTEM_ID

Run locally

# Run from a HAIEC source checkout while the distributable CLI is being packaged
export HAIEC_BASE_URL=https://www.haiec.com
export HAIEC_API_KEY=haiec_live_xxx
export HAIEC_AI_SYSTEM_ID=SYSTEM_ID

npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --json

The command runs lib/ai-security/ci/scan-orchestrator.ts, submits to POST /api/v1/scans, then creates a canonical run with executionMode: ci-attached. It returns a scan ID, run ID, and—when you use --wait—the evaluation ID and disposition.

No remote or dirty workspace

A workspace without a remote is valid. A Git commit is optional. The submission includes sourceKind: LOCAL_WORKSPACE, optional remote/commit/branch, dirty, a workspace digest, and a path-set digest. For a dirty workspace, the evaluation records the limitation; it does not claim that a clean commit exactly represents the submitted files.

# No Git repository is required
npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --json

# Dirty worktrees remain explicit; do not reset or clean them automatically
npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --wait

CI runner usage

# The same primitive is suitable for a customer CI runner
CI=true HAIEC_API_KEY=... HAIEC_AI_SYSTEM_ID=... \
  npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --json

The preferred CI architecture is checkout → local scanner → qualified Evidence Bundle → /api/v1/scans → canonical Assurance Run. No GitHub token is sent to the HAIEC API in this local-runner mode.

Coverage and privacy boundaries

  • The local scanner currently provides Python, Go, and JavaScript/TypeScript sidecars plus regex fallback.
  • Semgrep parity, Joern, capability extraction, relation/constellation extraction, and deeper action/authority projections are not available in the local primitive yet.
  • Those missing analyzers are persisted as limitations; they are not translated into PASS.
  • The submitted bundle contains hashes, paths, findings metadata, and sidecar status — not a repository archive or raw source snippet field.
  • Sensitive paths such as .env*, private keys, credential/secret files, and generated/cache directories are excluded or rejected.