Policy missing
High-risk egress and credentials default to deny when policy is missing.
Independent evidence. Controls outside the agent’s authority.
Per-sensor signing keys stay outside the agent sandbox.
Missing, invalid or stale policy never silently permits an action.
High-risk egress and credentials default to deny when policy is missing.
High-risk egress and credentials default to deny when policy is invalid.
High-risk egress and credentials default to deny when policy is stale.
The configured failure policy applies; a failed automatic stop escalates.
Local policy decides actions independently of console or analytics availability.
SHA-256 hash-linked actions. Signed origin.
A record you can check independently.
Try changing a record
000000e1f27ce1f27cb0a87fb0a87fb9e4f1b9e4f122b848Chain intact, verified
Interactive record model · shortened hashes
Check the outcome at the boundary under control.
See recording and containmentTransport identity and evidence authorship
stay separate.
Sensors and the breaker use mutual TLS (mTLS) to authenticate both ends of a connection.
Per-sensor Ed25519 keys sign evidence outside the sandbox, so its origin can be checked independently.
Evidence and controls have tenant-scoped permissions. Enterprise SSO: OIDC or SAML.
Humming Arms records redacted metadata by default.
Minimize and redact before storage.
Customer data is not used to train models.
Payload capture is opt-in per policy. TLS decryption stays off unless the customer explicitly enables it per policy. Without decryption, encrypted payload semantics remain unseen. Inspection does not authorize retaining every plaintext payload.
Pinned dependencies and build actions. License and advisory checks. Reviewed updates.
Sensors, SDKs and the verifier are Apache-2.0. Verification is console-independent.
Report vulnerabilities to
Send the component/version, steps to reproduce, expected and observed behavior, impact and a contact method. Remove secrets and personal data from the proof of concept.
We acknowledge reports, investigate them and keep you informed as we work toward a resolution.
Coordinate public disclosure with us so affected users can receive a fix.
Exact limits. Clear answers.
Instrument the tool, credential and network paths you need to control. Network-level default-deny egress prevents direct routes from bypassing the proxy. Coverage depends on the boundaries you instrument.
Integrity and signed origin, relative to trusted sensor keys and the checkpoints you check. The verifier checks supplied anchor proofs; missing proofs remain visible. Integrity cannot establish that every action was captured.
A stop request is checked at the boundary under control. A failed automatic stop escalates. Heartbeat loss follows the sensor’s configured failure policy; high-risk egress and credential actions default to deny.
Encrypted payload semantics remain unseen. Decryption and payload capture are separate policy choices, both off by default. Enabling inspection does not authorize retaining every plaintext payload.
Verifiable export is always included, even after cancellation. Preserve exported records, certificates and proofs together. Verification is independent of the commercial console.
Walk through coverage, failure policies
and evidence verification with Humming Arms.
prev: 000000hash: e1f27cprev: e1f27chash: b0a87fprev: b0a87fhash: b9e4f1