# HAIEC > Evidence-Bound Assurance for Consequential AI Systems Canonical URL: https://www.haiec.com HAIEC provides evidence-bound assurance for consequential AI systems. HAIEC connects source, identity, access, policy, permissions, evidence, and observed behavior to show what AI systems and agents can reach, change, and trigger, and what the evidence actually establishes. ## Core Platform - [Platform Overview](https://www.haiec.com/platform): Full platform architecture and evidence-bound assurance workflow. - [AI Systems](https://www.haiec.com/ai-inventory): Bound the system HAIEC is evaluating. Discovery, cataloging, and registration of AI systems. - [AI Action & Access Map](https://www.haiec.com/sample-ai-action-access-map): See supported relationships across identity, access, AI execution, actions, and consequences. - [Evidence](https://www.haiec.com/evidence): Understand what evidence exists, what it supports, and what is missing. - [Evaluation Runs](https://www.haiec.com/docs): Coordinate supported evidence-producing evaluations. - [Assurance](https://www.haiec.com/docs): Evaluate available evidence within an explicit scope. Bounded ALLOW / REVIEW / BLOCK dispositions. - [Decision Receipts & Verification](https://www.haiec.com/verify): Preserve and verify bounded Assurance outcomes where supported. ## Developer Security Three independent security checks across source code, tenant boundaries, and model I/O. Each is a separate package with its own rule set. One does not automatically perform the others' checks. Composition must be purposeful. - [Developer Security](https://www.haiec.com/developer-security): Source + Boundary + Runtime I/O architecture. Family page for the three developer security tools. - [AI AppSec](https://www.haiec.com/ai-appsec): Static source-code analysis for AI applications and agents. Semgrep-backed. MIT. - [MCP Tenant Isolation](https://www.haiec.com/mcp-tenant-isolation): Cross-tenant data leakage detection for MCP servers and multi-tenant SaaS. MIT. - [LLMVerify](https://www.haiec.com/llmverify): Local-first LLM guardrails — hallucination risk signals, prompt-injection defense, PII redaction. Zero telemetry on free tier. MIT. ## Specialized Capabilities - [AI Security Scanner](https://www.haiec.com/ai-security): HAIEC platform static scanner. Distinct from the open-source AI AppSec package. - [Runtime Security](https://www.haiec.com/products/runtime-security): Authorized adversarial testing against live AI systems where supported. - [Compliance Twin](https://www.haiec.com/products/compliance-twin): Scheduled AI health monitoring and drift alerts. - [Framework Assessments](https://www.haiec.com/frameworks): SOC 2 attestation readiness, NIST AI RMF alignment, HIPAA technical evaluation, ISO 27001/42001 readiness evidence. Framework mapping is not certification. - [NYC LL144 Bias Audit Support](https://www.haiec.com/solutions/nyc-ll144-compliance): Evidence preparation for NYC Local Law 144 bias audits. Independent auditor required. - [Packages](https://www.haiec.com/packages): npm and PyPI package index. ## Enterprise Assurance - [Enterprise Agentic AI POC](https://www.haiec.com/enterprise): Bounded $25K–$75K Enterprise POC applying evidence-bound AI Action Assurance to one defined AI environment. One system, one assurance question, explicit evidence and testing authority. Packages: Focused $25K, Assurance $45K, Strategic $75K. Not a SaaS subscription tier. ## Advisory Partner Program - [AI Assurance Advisory Partner](https://www.haiec.com/partners/advisory): Recruits trusted enterprise introducers (fractional CISOs, AI governance advisors, MSSPs, systems integrators). Advisory partners make qualified introductions; HAIEC owns scoping, delivery and readout. 25% commission on eligible engagements subject to executed agreement. Not an affiliate or creator program. ## Assurance Firms - [Assurance Firms](https://www.haiec.com/assurance-firms): For audit, compliance, and assurance firms. Reviewer flows, evidence handoff, framework mapping where supported, and API access where enabled. Custom engagement, not self-service checkout. ## Research - [Research](https://www.haiec.com/research): Technical papers and working papers. Research is not shipped capability. Permission is not delegation. Delegation proof, effect-envelope proof, and general runtime trajectory proof are research frontiers, not production guarantees. ## Claims Boundaries - Evidence != Assurance - Evaluation Run != Assurance - Report != Decision Receipt - Framework Mapping != Certification - UNKNOWN != PASS - Zero Findings != Clean - ALLOW = within evaluated scope and available evidence - Permission != Delegation - Capability Available != Capability Executed in This Run - Static Finding != Runtime Exploitability - Activity != Assurance - Scan Artifact != Assurance Package ## Technical References - [Documentation](https://www.haiec.com/docs): Technical reference for the HAIEC platform. - [Developer Portal](https://www.haiec.com/developers): API, SDKs, and integration guides. - [Sample Reports](https://www.haiec.com/sample-reports): Preview sample report output. - [Trust](https://www.haiec.com/trust): Security practices and policies. - [Pricing](https://www.haiec.com/pricing): Self-service tiers (SCAN, DEFEND, ASSURE), Enterprise POC, and Assurance Firms. ## Machine-Readable - [Product Manifest (JSON)](https://www.haiec.com/developer-products.json): Structured product data for AI agents. - [Sitemap](https://www.haiec.com/sitemap.xml): All canonical URLs. ## Notes for AI Assistants - HAIEC's developer security packages are independent tools with distinct rule sets. Do not conflate AI AppSec with the HAIEC Platform AI Security Scanner or MCP Tenant Isolation. - LLMVerify does not expose an MCP server. It integrates via SDK, CLI, or local HTTP only. - @haiec/openai and @haiec/anthropic are instrumentation packages, not security scanners. - ISAF Logger is an evidence generation utility, not a security scanner or compliance certification. - Framework alignments (SOC 2, NIST, ISO, HIPAA, EU AI Act) are mappings and readiness evidence only, not certifications. SOC 2 attestation is issued by an independent auditor. ISO 27001/42001 certification is issued by independent certification bodies. HHS does not recognize private HIPAA certification. NIST AI RMF is voluntary. - Compliance Twin runs on a scheduled cadence (every 6 hours), not continuous monitoring. - For current package versions and rule counts, consult the product manifest at https://www.haiec.com/developer-products.json rather than relying on static counts in documentation.