We build theindependent recordand the off switchfor AI agents.

AI agents act with real tools, data and credentials. We build independent evidence and local control outside the run.

Read the articles of the Humming Arms charter

Our charter for
AI agent security.

Commitments that govern what we build, how we verify it, and what we claim.

Article I

The record sits outside the agent.

We record where decisions become actions: tools, networks, files, execution and credentials. The record must stand apart from the run it describes. An agent’s explanation can add context; its cooperation cannot be the foundation of the evidence.

Proviso. Coverage follows the instrumented boundaries of each deployment.

Ratified
Article II

Permission must not wait for a round trip.

We keep policy evaluation and enforcement decisions local. No network call and no LLM call belongs on the critical path. Deterministic rules govern that path; any assisted triage runs asynchronously, away from the decision to allow or deny.

Proviso. Network controls must close routes that bypass the policy boundary.

Ratified
Article III

Uncertainty is never silent permission.

Missing, invalid or stale policy must never silently permit an action. High-risk egress and credential actions default fail-closed. Heartbeat loss has a defined response, and a failed automated stop triggers escalation.

Proviso. Other failure modes require explicit policy; incomplete policy can interrupt legitimate work.

Ratified
Article IV

Evidence must survive scrutiny.

We build on append-only, hash-chained records and sensor signatures. Signing keys stay outside the agent’s sandbox. The open-source verifier checks integrity and signatures without our servers, so inspection can be independent of the system under examination.

Proviso. Integrity alone proves neither complete capture nor a successful stop.

Ratified
Article V

Collection is a deliberate choice.

We design for redaction and tokenization at sensors, with action metadata and hashes as the default recording surface. Payload capture and HTTPS decryption are opt-in per policy. Customer-held keys, self-hosting and tenant isolation belong in the data boundary.

Proviso. Capture policy and deployment determine the actual data path.

Ratified
Article VI

A claim needs a record, too.

We call a capability shipped only when the public changelog says so. Numerical claims are tagged fact, estimate or target. Facts need reproducible evidence, estimates state assumptions, and targets identify a goal.

Proviso. Report the verification actually run and what remains unproven.

Ratified
Article VII

The boundary includes our build inputs.

We audit dependencies and licenses, keep lockfiles current, and review supply-chain changes. Our release architecture calls for immutable references, signing, provenance and reproducible builds. We never weaken a lint, test or security control to obtain a passing result.

Proviso. Origin evidence is not a promise of vulnerability-free software.

Ratified
Article VIII

Policy sets authority. The breaker acts.

We separate the breaker from the server, with independent health checks and a heartbeat-based dead-man’s switch. Pause, termination, credential revocation, egress cut and quarantine belong to the containment design. Human involvement is explicit for high-impact actions.

Proviso. A stop command needs outcome evidence; unresolved failure must escalate.

Ratified

We build

We will not

Record actions

Connect actions to identity, context, policy and outcomes. Reconstruct what happened at the boundaries the deployment covers.

Never judge a mind

We record and control actions. Reasoning is optional context; hidden intent is not the basis of enforcement.

Control the boundary

Pair local policy with an independent breaker. Check the stop’s outcome, and escalate when the control fails.

No remote permission

No LLM or network call on the enforcement hot path. No silent permits when policy is missing, invalid or stale.

Keep evidence checkable

Open formats and an open-source verifier keep independent inspection separate from commercial management. Evidence must stand on its own.

No evidence lock-in

Checking record integrity must not require our servers. Verification remains a check on the record, with its limits explicit.

Open core
AI agent security.

The inspection surface stays open. Commercial management has a clear boundary. Explore a component to see its role.

Apache-2.0

The independent trust surface

Observe actions at instrumented boundaries.

Queue records between collection and delivery.

Evaluate allow and deny rules locally.

Match actions against deterministic rules.

Bind action records to integrity and signatures.

Define the shared event and command schema.

Check integrity and signatures independently.

Instrument agent tool calls and their context.

The open-source verifier lets anyone check integrity and signatures without trusting our servers.

Licence cut

Commercial

The management surface

Collect records and correlate across agents.

Carry out policy-driven containment commands.

Review evidence, policy and containment outcomes.

Licensing follows the component boundary. Released availability follows the public changelog.

How we work.

A release needs a decision trail and a verification boundary. We keep the record.

Humming ArmsRelease discipline
  • CHANGE: focused

    ✓
  • DECISION: recorded (ADR)

    ✓
  • TEST: failure paths included

    ✓
  • CLAIM: tagged fact / estimate / target

    ✓
  • SHIP: when the changelog says so

    ✓
Review the reason, the verification and the remaining limits.
Facts need evidence. Estimates need assumptions. Targets need a goal.
No dates promised. No claim without a record.

Questions about
Humming Arms.

The company, the control boundary and the evidence.

What does Humming Arms do?

Humming Arms is an AI agent security company building an independent flight recorder and circuit breaker. We work at the action layer: tools, networks, files, execution and credentials. The architecture connects recording, detection, policy-driven containment and reconstruction. We record what happened, bind it to policy and identity, and keep the authority to stop separate from the run. Coverage follows instrumentation and deployment.

Is Humming Arms open source?

Humming Arms uses an open-core model. Sensors, buffer, policy, detection, evidence, protocol, verifier and SDKs sit on the Apache-2.0 side. Server, breaker and console sit on the commercial side. The open-source verifier lets anyone check evidence integrity and signatures without trusting our servers. Open components stay independent of commercial implementation. The licensing boundary describes the architecture; the public changelog records released availability.

Why is independent AI agent monitoring necessary?

A record should not depend on the cooperation of the system it records. We separate evidence custody and enforcement from the controlled agent, and keep signing keys outside its sandbox. Agent reasoning can add context; action evidence is the foundation. The verifier checks integrity and signatures independently. Capture coverage, policy correctness and containment outcomes need their own checks. These are separate questions in an evaluation.

Do you use AI to make enforcement decisions?

No LLM call belongs on the enforcement hot path. We use local policy evaluation and deterministic rules, without a network round trip for permission. Any assisted triage runs asynchronously, away from enforcement. Console availability cannot be the condition for an allow or deny decision. Configured policy defines authority, and missing, invalid or stale policy must never silently permit an action. Other failure behavior requires an explicit choice.

Where does our agent data go?

Our data architecture supports self-hosting and a hosted service, with customer-held keys. Sensor-side redaction and tokenization reduce collection before storage. Action metadata and hashes are the default; payload capture and HTTPS decryption are opt-in per policy. Capture policy and deployment determine the actual data path. In an evaluation, examine those settings, the recorder’s location, key custody and tenant boundaries together. There is no universal location to assume.

How do we evaluate an AI agent governance company?

Book a demo around your agent environment, action boundaries and policy. Examine recording and verification alongside the breaker’s outcomes. Include unavailable policy, heartbeat loss, bypass paths and failed stops. Review the security model and ask which released capabilities apply to your deployment. A useful evaluation records what was exercised, the evidence behind each result and the remaining limits. Use the product, solutions and pricing pages to explore the scope.

The record.
The boundary.
The responsibility.