Evidence-Bound Assurance
for Consequential AI
HAIEC connects source, identity, policy, effective authority, code capability, runtime evidence, and observed effects to show what an AI system can cause — and exactly what the available evidence can support.
Run the same Assurance workflow from the HAIEC workspace, a connected GitHub repository, the Assurance API, or an MCP-enabled AI agent.
HAIEC complements existing security, IAM, observability, CI/CD, and governance tooling. Where supported, their evidence can contribute to a HAIEC Evaluation. HAIEC does not replace those systems or convert their findings directly into Assurance truth.
How HAIEC Works
Define → Connect → Collect Evidence → Assure → Verify → Monitor
See the System
The AI Action & Access Map shows how identities, permissions, AI actions, APIs, data, and consequences connect.
- AI execution → action surface → consequence
- Credential evidence and access paths
- What controls apply
1. Collect Evidence
Source, identity, access, policy, capability, and runtime evidence where supported.
- Source code analysis (AI AppSec)
- AI inventory and identity evidence
- Runtime observation where connected
2. Compare
Five evidence questions: what you intend, what policy allows, what credential evidence establishes, what the application can do, and what was observed.
- Requested vs. authorized vs. granted
- Code-capable vs. observed
- Unknown and partial made explicit
3. Assure
Bounded evaluation with explicit limitations. ALLOW means ALLOW within evaluated scope — not “safe” or “certified.”
- ALLOW / REVIEW / BLOCK evaluation
- Unknown never silently becomes PASS
- Coverage and limitations stated
Verify
Assurance packages and decision receipts with tamper-evident integrity and traceable provenance where supported.
- Evidence packages with provenance
- Tamper-evident integrity
- Reviewer handoff and export
Monitor
Re-evaluate as systems, credentials, and code change. Continuous monitoring where connected — not universally claimed.
- CI/CD integration and GitHub App
- Re-scan on change
- Evidence refresh where supported
Capabilities
Evidence and security tools that feed the assurance lifecycle
AI Security
Deterministic Source Analysis
Source analysis for AI-specific security findings, action surfaces, capability paths, and code-capable evidence.
Learn moreRuntime Security
Authorized Runtime Testing
Controlled runtime testing against supported endpoints after explicit authorization. Runtime results become evidence; they do not independently determine Assurance.
Learn moreCompliance Twin
Evaluation Records
Versioned assurance evaluation records with audit trails for compliance history tracking.
Learn moreEvidence Generator
Automated Artifacts
Generate audit-ready evidence packages for SOC 2, ISO 27001, GDPR, and more frameworks.
Learn moreCompliance Wizard
Guided Assessments
Step-by-step compliance assessments for SOC 2, ISO 27001, EU AI Act, NYC LL144, and more.
Learn moreAI Inventory
Discovery Engine
Automatically discover and catalog all AI systems, models, and data sources across your organization.
Learn moreGitHub Integration
CI/CD Native
Auto-scan pull requests, flag code that may not meet your policies, and generate compliance reports in your workflow.
Learn moreREST API
Programmatic Access
Full API access for custom integrations, automated workflows, and enterprise deployments.
Learn moreOpen Source SDKs
npm & PyPI
Runtime monitoring packages for Node.js and Python. Install, instrument, and monitor in minutes.
Learn moreLLMverify
Free Tool
Free online tool to test your prompts for injection attacks, jailbreaks, and security vulnerabilities.
Try freeAI Exposure Score
Free Assessment
25-question assessment to measure your AI compliance readiness across 5 critical domains.
Get scoreBias Detector
NYC LL144 Bias Audit Support
Detect and measure bias in AI hiring tools. NYC Local Law 144 bias audit support.
Learn moreWhy Teams Choose HAIEC
See how we compare to traditional approaches
| Feature | HAIEC | OneTrust | Manual |
|---|---|---|---|
| AI Security Scanning | Built-in | Add-on | N/A |
| Evidence Collection | Automatic | Manual | Spreadsheets |
| GitHub Integration | Native | None | N/A |
| Pricing | $0-$999/mo | $50k+/year | Staff cost |
| Setup Time | 5 minutes | 3-6 months | Ongoing |
| Open Source SDKs | npm/PyPI | Closed | N/A |
Ready to Build Defensible Assurance?
Choose your path to get started