How HAIEC Works
HAIEC works through a clear lifecycle: Define → Connect → Collect Evidence → See → Assure → Verify → Monitor.
Every step is evidence-bound. What is not connected stays not connected. What is unknown stays unknown. What is not evaluated stays not evaluated.
The HAIEC Lifecycle
Seven phases, each truthfully bounded by what is actually connected and established.
Define the AI system, the bounded assurance question, and the operating context where supported.
Start by identifying the AI system or agent you need to understand. Define what assurance question matters — what can it reach, what can it change, what should it be allowed to do.
Connect repository, supported evidence sources, providers, and runtime sources.
Connect the evidence sources that are available. This may include source code repositories, identity and access configuration, policy documents, provider IAM, and runtime sources where supported. Not every source is always available — what matters is that what is connected is clearly distinguished from what is not.
Source, identity/access, policy, credential evidence, capability, and runtime evidence where connected.
HAIEC collects evidence from connected sources. Evidence retains provenance so reviewers can trace it back to where it came from and what produced it. Coverage is classified as established, partial, unknown, or not evaluated.
The AI Action & Access Map shows what the AI can reach, change, and trigger.
The map is the product centerpiece. It shows reach paths from the AI system to tools, credentials, applications, network paths, and service controls — and what consequences those paths could result in. The map is built from connected evidence, not from guessing.
Bounded deterministic evaluation. ALLOW, REVIEW, BLOCK where applicable.
Assurance evaluates what the evidence establishes within a defined scope. ALLOW means ALLOW within the evaluated scope and available evidence — it is not universal safety, certification, or deployment approval. REVIEW and BLOCK remain as produced. UNKNOWN and NOT ASSESSED remain explicit.
Evidence package, decision receipt, and integrity verification where supported.
Where supported, assurance packages and decision receipts preserve the evaluation output. Tamper-evident, hash-bound integrity allows reviewers to verify that artifacts have not been modified after generation.
Only from supported connected evidence and runtime sources.
Monitoring is available from connected runtime sources where supported. HAIEC does not imply that all systems are continuously monitored. What is not connected remains not connected — it does not become “monitored” by default.
Evidence Sources
Depending on what is connected and available, evidence may come from:
Not every source is always available. What matters is that what is available is clearly distinguished from what is not.
Permanent boundaries
Technical Foundations
The lifecycle is supported by deterministic engines and tools that produce traceable, reproducible evidence. These are implementation details — the customer lifecycle above is how HAIEC works.
Source Analysis
Static source code analysis for AI security findings and action surface identification.
Evidence Core
Evidence collection, provenance preservation, and coverage classification.
Topology Projection
Projects connected evidence into the AI Action & Access Map.
Assurance Decision Engine
Bounded evaluation producing ALLOW, REVIEW, BLOCK within evaluated scope.
Package & Receipt Layer
Tamper-evident packages and decision receipts where supported.
Audit Orchestrator
Coordinates evidence collection across producers. Not the assurance decision engine.
See it in action
Explore the sample AI Action & Access Map to see how evidence becomes understanding.