Skip to main content
How HAIEC Works

How HAIEC Works

HAIEC works through a clear lifecycle: Define Connect Collect Evidence See Assure Verify Monitor.

Every step is evidence-bound. What is not connected stays not connected. What is unknown stays unknown. What is not evaluated stays not evaluated.

The HAIEC Lifecycle

Seven phases, each truthfully bounded by what is actually connected and established.

Define

Define the AI system, the bounded assurance question, and the operating context where supported.

Start by identifying the AI system or agent you need to understand. Define what assurance question matters — what can it reach, what can it change, what should it be allowed to do.

Connect

Connect repository, supported evidence sources, providers, and runtime sources.

Connect the evidence sources that are available. This may include source code repositories, identity and access configuration, policy documents, provider IAM, and runtime sources where supported. Not every source is always available — what matters is that what is connected is clearly distinguished from what is not.

Collect Evidence

Source, identity/access, policy, credential evidence, capability, and runtime evidence where connected.

HAIEC collects evidence from connected sources. Evidence retains provenance so reviewers can trace it back to where it came from and what produced it. Coverage is classified as established, partial, unknown, or not evaluated.

See

The AI Action & Access Map shows what the AI can reach, change, and trigger.

The map is the product centerpiece. It shows reach paths from the AI system to tools, credentials, applications, network paths, and service controls — and what consequences those paths could result in. The map is built from connected evidence, not from guessing.

Assure

Bounded deterministic evaluation. ALLOW, REVIEW, BLOCK where applicable.

Assurance evaluates what the evidence establishes within a defined scope. ALLOW means ALLOW within the evaluated scope and available evidence — it is not universal safety, certification, or deployment approval. REVIEW and BLOCK remain as produced. UNKNOWN and NOT ASSESSED remain explicit.

Verify

Evidence package, decision receipt, and integrity verification where supported.

Where supported, assurance packages and decision receipts preserve the evaluation output. Tamper-evident, hash-bound integrity allows reviewers to verify that artifacts have not been modified after generation.

Monitor

Only from supported connected evidence and runtime sources.

Monitoring is available from connected runtime sources where supported. HAIEC does not imply that all systems are continuously monitored. What is not connected remains not connected — it does not become “monitored” by default.

Evidence Sources

Depending on what is connected and available, evidence may come from:

Source analysis
Static analysis of application code
Identity and access
Identity records and access configuration
Policy evidence
Policy documents and operating envelopes
Provider IAM
Provider IAM evidence where supported
Runtime evidence
Runtime observations where connected
Uploaded / declared
Uploaded or declared evidence where supported

Not every source is always available. What matters is that what is available is clearly distinguished from what is not.

Permanent boundaries

ALLOW is within evaluated scope
Not universal safety, certification, or deployment approval.
Permission is not delegation
Having permission to call a tool does not prove the consequential choice was delegated.
Missing evidence is not a pass
Unknown stays unknown. Absence is never silently converted to approval.
Evidence is not assurance
Evidence is input. Assurance is the bounded evaluation of that input.
Framework mapping is not assurance
Mapping to SOC 2 or ISO 42001 supports assurance but does not equal it.
Observation absent is not ‘did not happen’
No runtime observation means exactly that.

Technical Foundations

The lifecycle is supported by deterministic engines and tools that produce traceable, reproducible evidence. These are implementation details — the customer lifecycle above is how HAIEC works.

Source Analysis

Static source code analysis for AI security findings and action surface identification.

Evidence Core

Evidence collection, provenance preservation, and coverage classification.

Topology Projection

Projects connected evidence into the AI Action & Access Map.

Assurance Decision Engine

Bounded evaluation producing ALLOW, REVIEW, BLOCK within evaluated scope.

Package & Receipt Layer

Tamper-evident packages and decision receipts where supported.

Audit Orchestrator

Coordinates evidence collection across producers. Not the assurance decision engine.

See it in action

Explore the sample AI Action & Access Map to see how evidence becomes understanding.