Security with
a clear boundary.

Independent evidence. Controls outside the agent’s authority.

Independent custody

SEPARATE AUTHORITY
Agent sandboxThe agent acts.

Per-sensor signing keys stay outside the agent sandbox.

Fail-safe
by default.

Missing, invalid or stale policy never silently permits an action.

Explore a failure condition

Policy missing

High-risk egress and credentials default to deny when policy is missing.

Change one record.
Leave a trace.

SHA-256 hash-linked actions. Signed origin.
A record you can check independently.

The record chain

Try changing a record

  1. 1SIGNED
    tool.call
    prev:
    000000
    hash:
    e1f27c
  2. 2SIGNED
    file.read
    prev:
    e1f27c
    hash:
    b0a87f
  3. 3SIGNED
    dns.query
    prev:
    b0a87f
    hash:
    b9e4f1
  4. 4SIGNED
    policy.check
    prev:
    b9e4f1
    hash:
    22b848

Chain intact, verified

Interactive record model · shortened hashes

A stop request
is not proof
of containment.

  1. 1Stop requested
  2. 2Checked at the boundary
  3. 3Contained or escalated

Check the outcome at the boundary under control.

See recording and containment

Two keys.
Two different questions.

Transport identity and evidence authorship
stay separate.

1

Who is connecting?

Sensors and the breaker use mutual TLS (mTLS) to authenticate both ends of a connection.

AT CONNECTION TIME
2

Who produced this record?

Per-sensor Ed25519 keys sign evidence outside the sandbox, so its origin can be checked independently.

WHEN CHECKING EVIDENCE

Tenant-scoped permissions.

Evidence and controls have tenant-scoped permissions. Enterprise SSO: OIDC or SAML.

Less data.
Explicit permission.

Humming Arms records redacted metadata by default.
Minimize and redact before storage.

The defaults

READ ONLY
  • Redacted metadataMinimized before storage
    ON
  • Payload captureOpt-in per policy
    OFF
  • TLS decryptionOpt-in per policy
    OFF
  • Training on customer dataLocked
    NEVER

Customer data is not used to train models.

Payload capture is opt-in per policy. TLS decryption stays off unless the customer explicitly enables it per policy. Without decryption, encrypted payload semantics remain unseen. Inspection does not authorize retaining every plaintext payload.

Trace the build.
Inspect the trust surface.

Reviewable releases

DependenciesLicensesAdvisories
Signed releaseSigstore · SLSA provenance

Pinned dependencies and build actions. License and advisory checks. Reviewed updates.

An inspectable core

APACHE-2.0
SensorsPython + TypeScript SDKsVerifier

Sensors, SDKs and the verifier are Apache-2.0. Verification is console-independent.

Signing and provenance show origin. They do not establish freedom from vulnerabilities.

Help protect
the boundary.

Report vulnerabilities to

1

Report

Send the component/version, steps to reproduce, expected and observed behavior, impact and a contact method. Remove secrets and personal data from the proof of concept.

2

Acknowledge

We acknowledge reports, investigate them and keep you informed as we work toward a resolution.

3

Coordinate the fix

Coordinate public disclosure with us so affected users can receive a fix.

Good-faith research safe harbour.

  • Research that follows this policy is authorized; we will not pursue legal action for it.
  • Test only systems you own or have permission to test. Avoid disruption and other people’s data.
  • Stop and report sensitive information; do not retain it.
  • This permission covers Humming Arms systems within our authority and excludes third-party systems.

Ask the
boundary questions.

Exact limits. Clear answers.

Can an agent bypass the proxy?

Instrument the tool, credential and network paths you need to control. Network-level default-deny egress prevents direct routes from bypassing the proxy. Coverage depends on the boundaries you instrument.

What does a valid record prove?

Integrity and signed origin, relative to trusted sensor keys and the checkpoints you check. The verifier checks supplied anchor proofs; missing proofs remain visible. Integrity cannot establish that every action was captured.

What happens when an automatic stop fails?

A stop request is checked at the boundary under control. A failed automatic stop escalates. Heartbeat loss follows the sensor’s configured failure policy; high-risk egress and credential actions default to deny.

What remains unseen without TLS decryption?

Encrypted payload semantics remain unseen. Decryption and payload capture are separate policy choices, both off by default. Enabling inspection does not authorize retaining every plaintext payload.

Can we verify evidence after cancellation?

Verifiable export is always included, even after cancellation. Preserve exported records, certificates and proofs together. Verification is independent of the commercial console.

Bring the boundaries
you need to trust.

Walk through coverage, failure policies
and evidence verification with Humming Arms.

The record chain

INDEPENDENT EVIDENCE
  1. 1
    tool.callprev: 000000hash: e1f27c
  2. 2
    file.readprev: e1f27chash: b0a87f
  3. 3
    dns.queryprev: b0a87fhash: b9e4f1