Verifiable Audit Evidence
Trust Artifacts are cryptographically hashed, machine-verifiable attestations that record your AI security scan results with tamper-evident SHA-256 digests. Embed them in READMEs, share with auditors, or verify programmatically via API.
Note: Trust Artifacts are a legacy/specialized artifact system. For the current HAIEC Assurance model, see U6 Assurance Packages with ALLOW/REVIEW/BLOCK dispositions.
Example Trust Artifact Badge Format
Try It On Your Repo
Install the GitHub App on your own repository, open a PR, and see your first artifact.
What Are Trust Artifacts?
Unlike traditional compliance certificates, Trust Artifacts are tamper-evident records of the scan results and scope represented by the legacy artifact—generated automatically from real scans.
Deterministic Evidence
Generated from scanner output and compliance checks. Deterministic, traceable results from the same inputs - designed for technical, executive, and assurance review.
Cryptographically Hashed
Each artifact includes a SHA-256 evidence hash. Tamper-evident and independently verifiable by anyone.
Machine-Readable
Full JSON payload available via API. Integrate into CI/CD pipelines, auditor workflows, or procurement checks.
What's Inside an Artifact
Each artifact contains structured, verifiable data about your scan results and evaluated scope
artifact_idtypestatusevidence_hashissued_atexpires_atscoperisk_postureEmbed in Your README
Add a verifiable trust badge to your repository in seconds
[](https://www.haiec.com/artifact/YOUR-ARTIFACT-ID)<a href="https://www.haiec.com/artifact/YOUR-ID"><img src="https://www.haiec.com/api/badge/YOUR-ID" alt="HAIEC Trust Artifact"></a>curl https://www.haiec.com/api/v1/artifacts/YOUR-ID.jsonHow It Works
Install GitHub App
Connect HAIEC to your repositories via GitHub Marketplace
Automatic Scanning
We scan on every PR for security signals using deterministic rules
Artifact Generated
Passing scans generate cryptographically hashed trust artifacts
Embed & Share
Add badges to READMEs, share with auditors, verify programmatically
Use Cases
Open Source Projects
Show contributors and users that your project follows security best practices with a verifiable badge.
Enterprise Procurement
Provide instant, verifiable evidence of scan results to procurement teams evaluating your software.
Auditor Handoff
Share machine-readable evidence with auditors. No more manual evidence collection.
Generate Your First Audit Evidence
Run a security validation scan and generate verifiable, tamper-evident compliance evidence. Start with a free self-audit.