Local & IDE Assurance
If the application is already on your computer, this is the shortest path into HAIEC. HAIEC analyzes the workspace locally, creates a deterministic qualified Evidence Bundle, submits that evidence to your organization, and starts the same Assurance Pipeline used by dashboard and remote-repository scans. You do not need to connect GitHub for this workflow.
Status: Preview — Enterprise POC. The local scanner and submission flow are implemented and tested, but coverage is bounded relative to the remote stack and @haiec/cli is not published — do not run npm install @haiec/cli. For the recommended full-coverage path, use Connected GitHub.
Minimum setup
- A Dashboard API key with the Local / IDE purpose:
scan:submit,scan:create,scan:read, andreport:read. - An existing organization-bound
aiSystemId. - A local workspace. Git remote and GitHub access are optional.
HAIEC_BASE_URL=https://www.haiec.com
HAIEC_API_KEY=haiec_live_xxx
HAIEC_AI_SYSTEM_ID=SYSTEM_IDRun locally
# Run from a HAIEC source checkout while the distributable CLI is being packaged
export HAIEC_BASE_URL=https://www.haiec.com
export HAIEC_API_KEY=haiec_live_xxx
export HAIEC_AI_SYSTEM_ID=SYSTEM_ID
npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --jsonThe command runs lib/ai-security/ci/scan-orchestrator.ts, submits to POST /api/v1/scans, then creates a canonical run with executionMode: ci-attached. It returns a scan ID, run ID, and—when you use --wait—the evaluation ID and disposition.
No remote or dirty workspace
A workspace without a remote is valid. A Git commit is optional. The submission includes sourceKind: LOCAL_WORKSPACE, optional remote/commit/branch, dirty, a workspace digest, and a path-set digest. For a dirty workspace, the evaluation records the limitation; it does not claim that a clean commit exactly represents the submitted files.
# No Git repository is required
npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --json
# Dirty worktrees remain explicit; do not reset or clean them automatically
npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --waitCI runner usage
# The same primitive is suitable for a customer CI runner
CI=true HAIEC_API_KEY=... HAIEC_AI_SYSTEM_ID=... \
npx tsx scripts/haiec-scan.ts --repo . --submit --system "$HAIEC_AI_SYSTEM_ID" --jsonThe preferred CI architecture is checkout → local scanner → qualified Evidence Bundle → /api/v1/scans → canonical Assurance Run. No GitHub token is sent to the HAIEC API in this local-runner mode.
Coverage and privacy boundaries
- The local scanner currently provides Python, Go, and JavaScript/TypeScript sidecars plus regex fallback.
- Semgrep parity, Joern, capability extraction, relation/constellation extraction, and deeper action/authority projections are not available in the local primitive yet.
- Those missing analyzers are persisted as limitations; they are not translated into PASS.
- The submitted bundle contains hashes, paths, findings metadata, and sidecar status — not a repository archive or raw source snippet field.
- Sensitive paths such as
.env*, private keys, credential/secret files, and generated/cache directories are excluded or rejected.