Estate status · rendered from committed artifacts

Status, with its receipts attached.

Every number on this page comes from an artifact committed to the repository and carries the timestamp of that artifact. Data past its declared staleness budget is marked STALE rather than silently dated. Where a data source does not exist yet, the cell says so.

Ten-second read

Route health

11 targets · 9 healthy · 2 attention · data 2026-09-07T19:45:05Z · STALE

Synthetic monitor

Route health — last probe per smoke target

STALE since 2026-09-09T07:45:05Z (data: 2026-09-07T19:45:05Z) · 9 healthy / 2 unhealthy of 11 targets. History: not yet collected — this is the last committed probe only.

Target URL Status HTTP Latency (ms) Findings Observed at
hummbl apex https://hummbl.io/ healthy 200 304.5 — 2026-09-07T19:45:03Z
hummbl api health https://api.hummbl.io/health healthy 200 612.1 — 2026-09-07T19:45:04Z
dashboard https://dashboard.hummbl.io/ attention 200 129.9 missing required header 'content-security-policy'; missing required header 'x-frame-options' 2026-09-07T19:45:04Z
reuben apex https://reubenbowlby.com/ healthy 200 138.1 — 2026-09-07T19:45:04Z
agents health https://agents.hummbl.io/health healthy 200 87.8 — 2026-09-07T19:45:05Z
inbound mail health https://mail.hummbl.io/health healthy 200 133.0 — 2026-09-07T19:45:05Z
public mcp health https://mcp-public.hummbl.io/health healthy 200 89.8 — 2026-09-07T19:45:05Z
site chat health https://chat.reubenbowlby.com/health healthy 200 98.8 — 2026-09-07T19:45:05Z
contact form health Personal intake endpoint (hostname withheld) healthy 200 110.7 — 2026-09-07T19:45:05Z
hummbl commerce health https://commerce.hummbl.app/health healthy 200 114.1 — 2026-09-07T19:45:05Z
hummbl app apex https://hummbl.app/ attention 200 225.4 missing required header 'x-xss-protection' 2026-09-07T19:45:05Z

Upstream providers

4 observations · normalized degraded · data 2026-07-18T13:11:11Z · STALE

Vendor status observations

Upstream providers the estate depends on

STALE since 2026-07-18T15:11:11Z (data: 2026-07-18T13:11:11Z) · normalized: degraded. Anonymous public vendor-status observations only; not a HUMMBL API uptime, SLA, private-canary, or incident-completeness claim.

Provider Component Status Observed at
cloudflare cloudflare_platform degraded 2026-07-18T13:11:10Z
github github_actions green 2026-07-18T13:11:10Z
supabase supabase_api green 2026-07-18T13:11:10Z
vercel vercel_platform green 2026-07-18T13:11:11Z

Deploy receipts

15 surfaces · deploy times not recorded in artifacts

Deploy receipts

Last deploy receipt per surface

Each row is a committed provenance receipt from cloudflare/evidence/. Receipts record the deployed commit; they do not record when the deploy ran.

Surface Source repository Commit Receipt Deployed at
hummbl.app hummbl-io/hummbl-orientation 0f0e0168298f cloudflare/evidence/hummbl-app-0f0e016.json receipt time: not recorded in artifact
hummbl.app hummbl-io/hummbl-orientation eb115d1a3836 cloudflare/evidence/hummbl-app-eb115d1.json receipt time: not recorded in artifact
hummbl.dev hummbl-io/hummbl-orientation 0f0e0168298f cloudflare/evidence/hummbl-dev-0f0e016.json receipt time: not recorded in artifact
hummbl-dev.com hummbl-io/hummbl-orientation 0f0e0168298f cloudflare/evidence/hummbl-dev-com-0f0e016.json receipt time: not recorded in artifact
hummbl-dev.com hummbl-io/hummbl-orientation eb115d1a3836 cloudflare/evidence/hummbl-dev-com-eb115d1.json receipt time: not recorded in artifact
hummbl.dev hummbl-io/hummbl-orientation eb115d1a3836 cloudflare/evidence/hummbl-dev-eb115d1.json receipt time: not recorded in artifact
hummbl.house hummbl-io/hummbl-house 1d2cbc7372e1 cloudflare/evidence/hummbl-house-1d2cbc7.json receipt time: not recorded in artifact
hummbl.house hummbl-io/hummbl-house f7934c095a9a cloudflare/evidence/hummbl-house-f7934c0.json receipt time: not recorded in artifact
kernelclothing.com hummbl-io/kernelclothing fc190585b72f cloudflare/evidence/kernelclothing-com-fc19058.json receipt time: not recorded in artifact
krineia.com hummbl-io/krineia 6a82ada7581c cloudflare/evidence/krineia-com-6a82ada.json receipt time: not recorded in artifact
krineia.com hummbl-io/krineia ab2f5641686a cloudflare/evidence/krineia-com-ab2f564.json receipt time: not recorded in artifact
krineia.org hummbl-io/krineia 6a82ada7581c cloudflare/evidence/krineia-org-6a82ada.json receipt time: not recorded in artifact
krineia.org hummbl-io/krineia ab2f5641686a cloudflare/evidence/krineia-org-ab2f564.json receipt time: not recorded in artifact
rpbx.net hummbl-io/rpbx 2bece7e00c9e cloudflare/evidence/rpbx-2bece7e.json receipt time: not recorded in artifact
thebridgemethod.net hummbl-io/the-bridge-method 305a608894d1 cloudflare/evidence/the-bridge-method-305a608.json receipt time: not recorded in artifact

TLS and security headers

52 hosts · worst grade 6/6 (49 of 49 responding hosts) · 3 with no HTTPS response · data 2026-09-17T21:53:12Z

TLS and security headers

Per-apex transport and header grades

fresh until 2026-09-24T21:53:12Z (data: 2026-09-17T21:53:12Z) · grade = count of 6 tracked headers present (strict-transport-security, content-security-policy, x-frame-options, x-content-type-options, referrer-policy, permissions-policy). Source: cloudflare-estate audit probe (evidence/probes.json), 2026-09-17. Expand a host for its per-header detail.

hummbl.io6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 16 16:33:58 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl.app6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 5 01:59:02 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl.dev6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 5 01:59:01 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl-dev.com6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:58:10 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl.house6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 28 21:56:32 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
kernelclothing.com6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 5 01:57:57 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
krineia.com6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 5 01:57:58 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
krineia.org6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 5 01:58:01 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
reubenbowlby.com6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 1 22:16:42 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
rpbx.net6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 4 23:10:32 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
thebridgemethod.net6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Dec 4 23:56:15 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.hummbl.io6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Oct 20 15:02:03 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.hummbl.app6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:59:04 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.hummbl.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:58:16 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.hummbl-dev.com6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:59:24 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.hummbl.house6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Nov 28 21:59:44 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.kernelclothing.com6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:58:49 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.krineia.com6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:58:49 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.krineia.org6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:59:01 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.reubenbowlby.com6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Nov 2 04:58:49 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.rpbx.net6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 4 23:09:48 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
www.thebridgemethod.net6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 4 23:57:18 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
api.hummbl.io6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 2 14:48:43 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
mcp.hummbl.io6/6TLSv1.3missing: —

HTTPS 302 · cert valid until Oct 20 15:02:03 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
mcp-public.hummbl.io6/6TLSv1.3missing: —

HTTPS 302 · cert valid until Nov 22 17:57:06 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
dashboard.hummbl.io6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 12 08:58:28 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
agents.hummbl.io6/6TLSv1.3missing: —

HTTPS 404 · cert valid until Nov 18 05:22:46 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
mail.hummbl.io6/6TLSv1.3missing: —

HTTPS 404 · cert valid until Nov 18 05:22:17 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
mta-sts.hummbl.io6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 1 20:19:30 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
openpgpkey.hummbl.io6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 3 20:19:40 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
chat.reubenbowlby.com6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 18 05:33:42 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
Personal intake endpoint (hostname withheld)6/6TLSv1.3missing: —

HTTPS 302 · cert valid until Nov 18 05:34:12 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
mta-sts.reubenbowlby.com6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 1 20:16:16 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
commerce.hummbl.app6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 28 19:36:07 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
bus.hummbl-dev.com6/6TLSv1.3missing: —

HTTPS 401 · cert valid until Oct 23 12:41:48 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
floor-ready.hummbl-dev.com6/6TLSv1.3missing: —

HTTPS 307 · cert valid until Oct 23 12:41:48 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
thd-prototype.hummbl-dev.com6/6TLSv1.3missing: —

HTTPS 307 · cert valid until Oct 23 12:41:48 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
workday-governance.hummbl-dev.com0/6—missing: strict-transport-security (+5 more)

HTTPS no HTTPS response · cert valid until — · missing: strict-transport-security, content-security-policy, x-frame-options, x-content-type-options, referrer-policy, permissions-policy

strict-transport-security missing
content-security-policy missing
x-frame-options missing
x-content-type-options missing
referrer-policy missing
permissions-policy missing
mcp.workspace.hummbl.io0/6—missing: strict-transport-security (+5 more)

HTTPS no HTTPS response · cert valid until — · missing: strict-transport-security, content-security-policy, x-frame-options, x-content-type-options, referrer-policy, permissions-policy

strict-transport-security missing
content-security-policy missing
x-frame-options missing
x-content-type-options missing
referrer-policy missing
permissions-policy missing
mcp-public.workspace.hummbl.io0/6—missing: strict-transport-security (+5 more)

HTTPS no HTTPS response · cert valid until — · missing: strict-transport-security, content-security-policy, x-frame-options, x-content-type-options, referrer-policy, permissions-policy

strict-transport-security missing
content-security-policy missing
x-frame-options missing
x-content-type-options missing
referrer-policy missing
permissions-policy missing
hummbl-production.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Oct 19 02:20:58 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl-house.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Nov 28 21:51:17 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl-dashboard.pages.dev6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 12 00:11:04 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl-orientation.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:51:58 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
kernel-clothing.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:51:51 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
krineia.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 5 01:51:44 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
rpbx.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 4 22:57:14 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
the-bridge-method.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Dec 4 23:49:53 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
reubenbowlby-site.pages.dev6/6TLSv1.3missing: —

HTTPS 301 · cert valid until Nov 1 19:55:40 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
hummbl-agent-queue-router.hummbl.workers.dev6/6TLSv1.3missing: —

HTTPS 404 · cert valid until Nov 28 23:33:21 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
ai-entity.hummbl.workers.dev6/6TLSv1.3missing: —

HTTPS 200 · cert valid until Nov 28 23:33:21 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present
room.hummbl.house6/6TLSv1.3missing: —

HTTPS 302 · cert valid until Dec 10 21:17:52 2026 GMT · missing: —

strict-transport-security present
content-security-policy present
x-frame-options present
x-content-type-options present
referrer-policy present
permissions-policy present

Scheduled workflow freshness contract

6 workflows · 6 required

Detection-loss coverage

Scheduled workflow freshness contract

These are the declared staleness budgets from observability/workflow-heartbeats.json. Per-workflow last-run timestamps are checked live by the Workflow Heartbeat Monitor and are not yet published as an artifact — the page says so rather than guessing.

Workflow Staleness budget Coverage Last run
Synthetic Monitor 36 h required last successful run: not published — verified live by the heartbeat-monitor workflow
supabase-heartbeat 108 h required last successful run: not published — verified live by the heartbeat-monitor workflow
SSL Certificate Expiry Check 192 h required last successful run: not published — verified live by the heartbeat-monitor workflow
Public Surface Smoke 48 h required last successful run: not published — verified live by the heartbeat-monitor workflow
Estate Regression Suite 48 h required last successful run: not published — verified live by the heartbeat-monitor workflow
Route Health Probes 36 h required last successful run: not published — verified live by the heartbeat-monitor workflow

Claims register

331 claims across 28 pages · tier A: 259 · tier B: 41 · tier C: 31

Claims register

Every public claim, its tier, and its source

331 claims · tier A: 259 · tier B: 41 · tier C: 31 · fixed: 28 · unproven: 20 · validated: 283. Register: claims-provenance.json (generated 2026-06-23T15:28:03Z). Grouped by page — expand a page to read its claims.

/ (homepage MCP section)3 claims · B: 1 · C: 2
ID Page Claim Tier Status Source Verified
MCP-001 / (homepage MCP section) [as of 2026-06-23] recommend_models tool available in MCP server C fixed source ↗ 2026-06-23
MCP-002 / (homepage MCP section) [as of 2026-06-23] hummbl://models resource available C fixed source ↗ 2026-06-23
MCP-003 / (homepage MCP section) [as of 2026-06-23] 140 chaos tests, 100% pass (from case study) B validated source ↗ 2026-06-23
/ (homepage)17 claims · A: 15 · B: 2
ID Page Claim Tier Status Source Verified
HP-001 / (homepage) [as of 2026-06-23] EU AI Act Annex III enforcement target: December 2, 2027 A validated source ↗ 2026-06-23
HP-002 / (homepage) [as of 2026-06-23] OPEN SOURCE A validated source ↗ 2026-06-23
HP-003 / (homepage) [as of 2026-06-23] STDLIB-ONLY A validated source ↗ 2026-06-23
HP-004 / (homepage) [as of 2026-06-23] APACHE 2.0 A validated source ↗ 2026-06-23
HP-005 / (homepage) [as of 2026-06-23] pip install hummbl-governance A validated source ↗ 2026-06-23
HP-006 / (homepage) [as of 2026-06-23] 15,600+ Aggregate Validation Tests B fixed source ↗ 2026-06-23
HP-007 / (homepage) [as of 2026-06-23] 25 Modules A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
HP-008 / (homepage) [as of 2026-06-23] 0 Runtime Deps A validated source ↗ 2026-06-23
HP-009 / (homepage) [as of 2026-06-23] 120 Mental Models A validated hummbl_governance/data/base120_models.json 2026-06-23
HP-010 / (homepage) [as of 2026-06-23] < 50ms API Latency A fixed curl benchmarks against api.hummbl.io on 2026-06-23 2026-06-23
HP-011 / (homepage) [as of 2026-06-23] Published on PyPI A validated source ↗ 2026-06-23
HP-012 / (homepage) [as of 2026-06-23] npm install -g @hummbl/mcp-server A validated source ↗ 2026-06-23
HP-013 / (homepage) [as of 2026-06-23] 6 transformation types (P, IN, CO, DE, RE, SY) A validated hummbl_governance/data/base120_models.json 2026-06-23
HP-014 / (homepage) [as of 2026-06-23] dtm.issue(issuer=, subject=, operations=, resources=) A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
HP-015 / (homepage) [as of 2026-06-23] bus.append(agent=, action=, resource=) A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
HP-016 / (homepage) [as of 2026-06-23] OWASP 10/10 Coverage B validated source ↗ 2026-06-23
HP-017 / (homepage) [as of 2026-06-23] The Governance Tuple: CONTRACT ?-- DCT ?-- EVIDENCE A validated source ↗ 2026-06-23
/compliance.html2 claims · C: 2
ID Page Claim Tier Status Source Verified
CMP-001 /compliance.html [as of 2026-06-23] 30+ AI governance enforcement dates tracked C fixed not found 2026-06-23
CMP-002 /compliance.html [as of 2026-06-23] Track across US, EU, and APAC C unproven not found 2026-06-23
/owasp.html13 claims · A: 3 · B: 1 · C: 9
ID Page Claim Tier Status Source Verified
OWASP-001 /owasp.html [as of 2026-06-23] 10/10 Risks Covered B validated source ↗ 2026-06-23
OWASP-002 /owasp.html [as of 2026-06-23] 1032 Tests A fixed local pytest collection of hummbl-governance 1.1.0 2026-06-23
OWASP-003 /owasp.html [as of 2026-06-23] 26 Primitives A validated local inspection of hummbl_governance 1.1.0 2026-06-23
OWASP-004 /owasp.html [as of 2026-06-23] 0 Dependencies A validated source ↗ 2026-06-23
OWASP-005 /owasp.html [as of 2026-06-23] KillSwitch: 27 tests C unproven tests/test_kill_switch.py 2026-06-23
OWASP-006 /owasp.html [as of 2026-06-23] CapabilityFence: 27 tests C unproven tests/test_capability_fence.py 2026-06-23
OWASP-007 /owasp.html [as of 2026-06-23] DelegationTokenManager + AgentRegistry: 42 tests C unproven tests/test_delegation.py + tests/test_identity.py 2026-06-23
OWASP-008 /owasp.html [as of 2026-06-23] OutputValidator: 49 tests C unproven tests/test_output_validator.py 2026-06-23
OWASP-009 /owasp.html [as of 2026-06-23] BusWriter + AuditLog: 80 tests C fixed tests/test_coordination_bus.py + tests/test_audit_log.py 2026-06-23
OWASP-010 /owasp.html [as of 2026-06-23] LamportClock + ContractNetManager: 37 tests C fixed tests/test_lamport_clock.py + tests/test_contract_net.py 2026-06-23
OWASP-011 /owasp.html [as of 2026-06-23] CircuitBreaker + HealthProbe + CostGovernor: 63 tests C fixed tests/test_circuit_breaker.py + tests/test_health_probe.py + tests/test_cost_governor.py 2026-06-23
OWASP-012 /owasp.html [as of 2026-06-23] ReasoningEngine + ComplianceMapper: 41 tests C fixed tests/test_explain.py + tests/test_compliance_mapper.py 2026-06-23
OWASP-013 /owasp.html [as of 2026-06-23] BehaviorMonitor + GovernanceLifecycle: 37 tests C unproven tests/test_reward_monitor.py + tests/test_lifecycle.py 2026-06-23
/primitives/8 claims · A: 7 · B: 1
ID Page Claim Tier Status Source Verified
PRIM-001 /primitives/ [as of 2026-06-23] Seven load-bearing primitives B fixed source ↗ 2026-06-23
PRIM-002 /primitives/ [as of 2026-06-23] bus.write(actor=, action=, scope=) A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
PRIM-003 /primitives/ [as of 2026-06-23] ks.engage(mode=HALT_ALL, reason=) A validated local inspection of hummbl_governance 1.1.0 2026-06-23
PRIM-004 /primitives/ [as of 2026-06-23] cb.call(adapter, timeout=30) A validated local inspection of hummbl_governance 1.1.0 2026-06-23
PRIM-005 /primitives/ [as of 2026-06-23] dct = DCT.issue(scope=, depth=2) A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
PRIM-006 /primitives/ [as of 2026-06-23] dctx = DCTX(parent=tok, max_depth=3) A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
PRIM-007 /primitives/ [as of 2026-06-23] model = b120.get("P1") A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
PRIM-008 /primitives/ [as of 2026-06-23] attest.verify(server=, policy=ALLOWLIST) A fixed local inspection of hummbl_governance 1.1.0 2026-06-23
/readiness.html6 claims · A: 1 · B: 1 · C: 4
ID Page Claim Tier Status Source Verified
RDY-001 /readiness.html [as of 2026-06-23] 5 Frameworks Mapped C unproven not found 2026-06-23
RDY-002 /readiness.html [as of 2026-06-23] 15 Governance Capabilities C unproven not found 2026-06-23
RDY-003 /readiness.html [as of 2026-06-23] 6 Production Primitives B fixed source ↗ 2026-06-23
RDY-004 /readiness.html [as of 2026-06-23] 70-90% Cost Savings vs. Separate C unproven not found 2026-06-23
RDY-005 /readiness.html [as of 2026-06-23] 14 CI workflows across the full platform C fixed not found 2026-06-23
RDY-006 /readiness.html [as of 2026-06-23] 1032 dedicated governance tests in hummbl-governance itself A fixed local pytest collection of hummbl-governance 1.1.0 2026-06-23
/status.html4 claims · A: 1 · C: 3
ID Page Claim Tier Status Source Verified
STS-001 /status.html [as of 2026-06-23] API Status: Operational A validated curl benchmarks against api.hummbl.io on 2026-06-23 2026-06-23
STS-002 /status.html [as of 2026-06-23] /v1/recommend endpoint live C fixed not checked 2026-06-23
STS-003 /status.html [as of 2026-06-23] /v1/workflows/match endpoint live C fixed not checked 2026-06-23
STS-004 /status.html [as of 2026-06-23] /security/validate endpoint live C unproven not checked 2026-06-23
/validation.html6 claims · A: 3 · C: 3
ID Page Claim Tier Status Source Verified
VAL-001 /validation.html [as of 2026-06-23] 1,032 passing tests in hummbl-governance A fixed local pytest collection of hummbl-governance 1.1.0 2026-06-23
VAL-002 /validation.html [as of 2026-06-23] Arbiter audit score 99.5/100 C unproven not found 2026-06-23
VAL-003 /validation.html [as of 2026-06-23] hummbl.io served by Cloudflare Pages C unproven curl headers from hummbl.io 2026-06-23
VAL-004 /validation.html [as of 2026-06-23] hummbl-base120 tests: 148 C fixed not found 2026-06-23
VAL-005 /validation.html [as of 2026-06-23] hummbl-public-namespace.json manifest exists A fixed local filesystem check of hummbl-production/web/manifest/ 2026-06-23
VAL-006 /validation.html [as of 2026-06-23] public-boundaries.json manifest exists A fixed local filesystem check of hummbl-production/web/manifest/ 2026-06-23
docs/adr/ADR-002-issueops-teaching-surface.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
AD2-001 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] ADR-002 accepts the decision to build Phase 1 of the IssueOps teaching surface at hummbl.io/issueops A validated docs/adr/ADR-002-issueops-teaching-surface.md ?Decision (this ADR) 2026-06-23
AD2-002 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Phase 1 scope is the static teaching surface only: walkthrough, glossary, client-side verification widget A validated docs/adr/ADR-002-issueops-teaching-surface.md ?Scope (this ADR) + docs/artifacts/BUSINESS_CASE_issueops.md ?1 2026-06-23
AD2-003 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Phase 1 capital cost is $0 (static page on existing Cloudflare Pages) A validated docs/artifacts/BUSINESS_CASE_issueops.md ?4.1 + this ADR ?Cost 2026-06-23
AD2-004 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Phase 1 engineering effort is ~40 hours (1 week at 50% allocation) A validated docs/artifacts/BUSINESS_CASE_issueops.md ?1 + this ADR ?Cost 2026-06-23
AD2-005 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Phase 1 funding was approved 2026-06-23 per the business case status line A validated docs/artifacts/BUSINESS_CASE_issueops.md status line 2026-06-23
AD2-006 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Option B (defer to Phase 2 live receipt feed) was rejected because a live feed without a teaching surface is incomprehensible to non-expert buyers A validated docs/artifacts/BUSINESS_CASE_issueops.md ?3 Option B + this ADR ?Alternatives 2026-06-23
AD2-007 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Option C (do nothing) was rejected because it breaks the strategic plan's Q4 2026 exit gate (3 discovery calls) A validated docs/artifacts/BUSINESS_CASE_issueops.md ?3 Option C + this ADR ?Alternatives 2026-06-23
AD2-008 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Option D (buy) was not viable because no vendor sells an IssueOps teaching surface with KRINEIA receipt verification A validated docs/artifacts/BUSINESS_CASE_issueops.md ?3 Option D + this ADR ?Alternatives 2026-06-23
AD2-009 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] Phase 1 is the first public interactive proof artifact (vs prior public artifacts which are assertions) A validated docs/artifacts/BUSINESS_CASE_issueops.md ?5 + this ADR ?Consequences 2026-06-23
AD2-010 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] The IssueOps teaching surface closes the proof gap identified in the competitive analysis (Day 4) A validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md + docs/artifacts/BUSINESS_CASE_issueops.md ?2 2026-06-23
AD2-011 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] The ADR has 5 success metrics: page live, unique visitors, widget uses, discovery calls mentioning IssueOps, white paper CTA click-through A validated docs/adr/ADR-002-issueops-teaching-surface.md ?Success metrics (this ADR) + docs/artifacts/BUSINESS_CASE_issueops.md ?6 2026-06-23
AD2-012 docs/adr/ADR-002-issueops-teaching-surface.md [as of 2026-06-23] The implementation plan is 3 weeks: Week 1 draft, Week 2 build, Week 3 deploy, with ongoing quarterly review A validated docs/adr/ADR-002-issueops-teaching-surface.md ?Implementation plan (this ADR) 2026-06-23
docs/adr/ADR-003-game-engine-roadmap.md12 claims · A: 11 · B: 1
ID Page Claim Tier Status Source Verified
AD3-001 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] ADR-003 accepts the decision to fund Stage 0 of the game engine roadmap (doctrine + JSON Schema + Simulation Affordance for 8 primitives) A validated docs/adr/ADR-003-game-engine-roadmap.md ?Decision (this ADR) 2026-06-23
AD3-002 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] Stage 0 capital cost is $15-25K from HUMMBL's existing Q3 2026 operating budget (no new capital required) A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?4 + this ADR ?Cost 2026-06-23
AD3-003 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] Stage 0 engineering effort is 4-6 weeks A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?4 + this ADR ?Cost 2026-06-23
AD3-004 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] The game engine roadmap has 4 stages: Stage 0 (doctrine), Stage 1 (Minecraft), Stage 2 (multi-game), Stage 3 (Unreal) A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?2 + docs/product/GAME_ENGINE_ROADMAP.md 2026-06-23
AD3-005 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] The total roadmap cost estimate is $255-475K over 12-18 months A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?2 2026-06-23
AD3-006 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] Stage 0 funding was approved 2026-06-23 per the business case and is within the Q3 2026 engineering allocation A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?4 + this ADR ?Funding 2026-06-23
AD3-007 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] Option B (skip Stage 0, build Minecraft directly) was rejected because it leads to engine-coupled doctrine that cannot be re-used for Unreal A validated docs/artifacts/BUSINESS_CASE_game_engine.md + this ADR ?Alternatives 2026-06-23
AD3-008 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] The playable governance category is empty (zero vendors) as of 2026-06-23 B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md + docs/artifacts/BUSINESS_CASE_game_engine.md ?1 2026-06-23
AD3-009 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] The core principle is engine-agnostic doctrine, engine-specific embodiment A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?2 + this ADR ?Context 2026-06-23
AD3-010 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] Stage 0 exit criteria: 8 primitives have doctrine, 8 have JSON Schema, 8 have Simulation Affordance, schemas validate, PA reviews, KRINEIA receipt emitted A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?3 + this ADR ?Success metrics 2026-06-23
AD3-011 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] Stages 1-3 are separate funding decisions, each gated on the prior stage's exit criteria A validated docs/artifacts/BUSINESS_CASE_game_engine.md ?2 + this ADR ?Out of scope 2026-06-23
AD3-012 docs/adr/ADR-003-game-engine-roadmap.md [as of 2026-06-23] The implementation plan is 6 weeks: Weeks 1-2 doctrine for 4 primitives, Weeks 3-4 doctrine for 4 more + schemas, Weeks 5-6 simulation affordance + validation + PA review A validated docs/adr/ADR-003-game-engine-roadmap.md ?Implementation plan (this ADR) 2026-06-23
docs/adr/ADR-004-single-branch-workflow.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
AD4-001 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] ADR-004 adopts a single-branch workflow for the artifact stack buildout: commit directly to the wave branch, stop using the fix branch for artifact stack work A validated docs/adr/ADR-004-single-branch-workflow.md ?Decision (this ADR) 2026-06-23
AD4-002 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] F10 (cherry-pick receipt file conflicts) occurred on 3 of 5 wave 3 days (days 17, 18, 19), adding ~5 min per conflict resolution A validated docs/artifacts/RETROSPECTIVE_wave_3.md ?3 F10 + this ADR ?Context 2026-06-23
AD4-003 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The single-branch workflow eliminates F10 (cherry-pick conflicts) and F11 (stash pop conflicts) entirely A validated docs/adr/ADR-004-single-branch-workflow.md ?What this eliminates (this ADR) 2026-06-23
AD4-004 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The single-branch workflow preserves the KRINEIA receipt chain, claims manifest (P7), artifact manifest (P11), template, helper scripts, and wave retrospectives A validated docs/adr/ADR-004-single-branch-workflow.md ?What this preserves (this ADR) 2026-06-23
AD4-005 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] 3 alternatives were considered and rejected: merge strategy taking longer receipt file, separate receipts branch, continue two-branch with manual resolution A validated docs/adr/ADR-004-single-branch-workflow.md ?Alternatives considered (this ADR) 2026-06-23
AD4-006 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The new workflow has 7 steps: checkout wave branch, draft artifact, add claims, update manifest, emit receipt, commit, push -- no cherry-pick, no stash, no promote script A validated docs/adr/ADR-004-single-branch-workflow.md ?Workflow (this ADR) 2026-06-23
AD4-007 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The promote_to_wave_branch.sh script is retained for cases where a two-branch workflow is genuinely needed (e.g., backporting fixes to multiple release branches) A validated docs/adr/ADR-004-single-branch-workflow.md ?Out of scope (this ADR) 2026-06-23
AD4-008 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] Wave 3 missed its cycle time target (20-25 min actual vs 15-20 min target) primarily due to F10 cherry-pick conflicts A validated docs/artifacts/RETROSPECTIVE_wave_3.md ?1 Metrics + this ADR ?Context 2026-06-23
AD4-009 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The fix branch and wave branch diverge over time; this is acceptable because the two efforts (april-audit cleanup vs artifact production) have different goals and merge to main independently A validated docs/adr/ADR-004-single-branch-workflow.md ?Consequences (this ADR) 2026-06-23
AD4-010 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The wave branch becomes the single source of truth for the artifact stack; the fix branch's chain is a historical artifact with the same receipts up to day 19 but no future receipts A validated docs/adr/ADR-004-single-branch-workflow.md ?Consequences (this ADR) 2026-06-23
AD4-011 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] ADR-004 is public -- it documents a process decision that affects how the artifact stack is built, published for transparency A validated docs/adr/ADR-004-single-branch-workflow.md ?Authority boundary (this ADR) 2026-06-23
AD4-012 docs/adr/ADR-004-single-branch-workflow.md [as of 2026-06-23] The ADR provides 5 verification commands for readers to confirm the single-branch workflow is in effect A validated docs/adr/ADR-004-single-branch-workflow.md ?Verification (this ADR) 2026-06-23
docs/adr/ADR-005-krineia-chain-ci.md12 claims · A: 11 · C: 1
ID Page Claim Tier Status Source Verified
AD5-001 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] ADR-005 adopts P17: run scripts/validate_krineia_chain.py as a CI check on every push/PR that touches the KRINEIA chain or the validator A validated docs/adr/ADR-005-krineia-chain-ci.md §Decision (this ADR) 2026-06-23
AD5-002 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] The KRINEIA receipt chain is HUMMBL's audit trail: every governance event emits a receipt with id, prev_hash, hash, state, and time A validated docs/adr/ADR-005-krineia-chain-ci.md §Context (this ADR) + _receipts/krineia/primary.jsonl 2026-06-23
AD5-003 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] The validator checks 6 things: valid JSON, required fields, hash chain intact, hash correctly computed, genesis prev_hash all zeros, no duplicate IDs A validated docs/adr/ADR-005-krineia-chain-ci.md §What P17 does (this ADR) 2026-06-23
AD5-004 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] The validator has 14 tests, all passing, covering valid chain, missing file, empty file, invalid JSON, missing fields, broken prev_hash, tampered hash, genesis, duplicates, unexpected fields, hash determinism, hash exclusion, key-order independence, and the real chain A validated scripts/test_validate_krineia_chain.py (this repo) 2026-06-23
AD5-005 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] 3 alternatives were considered and rejected: manual verification on demand, GPG-sign each receipt, use a blockchain/distributed ledger A validated docs/adr/ADR-005-krineia-chain-ci.md §Alternatives considered (this ADR) 2026-06-23
AD5-006 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] GPG signing was rejected because it requires the operator's passphrase for every receipt emission, blocking automated emission; the hash chain already provides tamper detection A validated docs/adr/ADR-005-krineia-chain-ci.md §Alternative 2 (this ADR) 2026-06-23
AD5-007 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] Blockchain was rejected because HUMMBL's chain is internal and single-party; a blockchain adds cost, complexity, and external dependencies for no benefit A validated docs/adr/ADR-005-krineia-chain-ci.md §Alternative 3 (this ADR) 2026-06-23
AD5-008 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] P17 enables tamper detection at push time (before merge), chain integrity verification, audit readiness, and defense in depth A validated docs/adr/ADR-005-krineia-chain-ci.md §What this enables (this ADR) 2026-06-23
AD5-009 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] The validator does not check payload correctness (e.g., that a governance.artifact_promoted receipt has the right payload fields); this is a future extension (P19 candidate) A validated docs/adr/ADR-005-krineia-chain-ci.md §Negative (this ADR) 2026-06-23
AD5-010 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] CI adds ~10 seconds per run (Python startup + chain parse + hash computation) C unproven docs/adr/ADR-005-krineia-chain-ci.md §Negative (this ADR) 2026-06-23
AD5-011 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] The real KRINEIA chain has 18 receipts and passes validation (all hashes verified, all prev_hash links intact) A validated _receipts/krineia/primary.jsonl (this repo) + scripts/validate_krineia_chain.py output 2026-06-23
AD5-012 docs/adr/ADR-005-krineia-chain-ci.md [as of 2026-06-23] ADR-005 is public — it documents a CI check that affects how the KRINEIA chain is verified, published for transparency A validated docs/adr/ADR-005-krineia-chain-ci.md §Authority boundary (this ADR) 2026-06-23
docs/artifacts/BRIEFING_BOOK_board_q3_2026.md12 claims · A: 11 · C: 1
ID Page Claim Tier Status Source Verified
BB-001 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] HUMMBL has an AI Board of Directors with 5 Directors: operator, governance-officer, risk-officer, stakeholder-proxy, future-self A validated governance/board/registry.yaml + governance/board/constitutions/ 2026-06-23
BB-002 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] The Board is advisory; the Principal Agent (Reuben Bowlby) retains final authority on all decisions A validated governance/board/registry.yaml authority_boundary + docs/artifacts/CHARTER_hri.md + this briefing book ?7 2026-06-23
BB-003 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] As of 2026-06-23, HUMMBL has 17 live artifacts, 259 claims (226 validated), and 14 KRINEIA receipts A validated docs/artifacts/ARTIFACT_MANIFEST.md + web/manifest/claims-provenance.json + _receipts/krineia/primary.jsonl 2026-06-23
BB-004 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] Q3 2026 has 4 priorities: IssueOps Phase 1, game engine Stage 0, claims remediation, market entry A validated docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?2 (this briefing book) 2026-06-23
BB-005 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] Q3 2026 total new capital required is $15-25K from existing operating budget (no new capital) A validated docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?3 (this briefing book) + ADR-002 + ADR-003 2026-06-23
BB-006 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] The briefing book documents 5 risks: market entry timing, category creation bet, single-founder dependency, competitive response, regulatory shift A validated docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?4 (this briefing book) 2026-06-23
BB-007 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] The Q3 2026 exit gate has 7 criteria including IssueOps Phase 1 live, Stage 0 complete, 250+ validated claims, 3 discovery calls A validated docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?5 (this briefing book) 2026-06-23
BB-008 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] The Board is asked to decide on 4 items: accept Q3 plan, accept exit gate criteria, single-founder mitigation, wave 3 continuation A validated docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?6 (this briefing book) 2026-06-23
BB-009 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] HUMMBL is pre-revenue as of 2026-06-23 with SOM target $0.5-1M ARR (tier C internal estimate) C unproven docs/artifacts/MARKET_ANALYSIS_ai_governance.md + docs/artifacts/EVIDENCE_PACK_fleet_rollout.md ?4 2026-06-23
BB-010 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] The artifact stack buildout has completed 3 waves: wave 1 (Days 6-10, 10 artifacts), wave 2 (Days 11-14, 4 artifacts), wave 3 (Days 15-19, in progress) A validated docs/artifacts/ARTIFACT_MANIFEST.md + docs/artifacts/RETROSPECTIVE_wave_1.md + docs/artifacts/RETROSPECTIVE_wave_2.md 2026-06-23
BB-011 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] Risk 3 (single-founder dependency) is mitigated by the artifact stack documenting strategy, doctrine, and decisions for agent continuity A validated docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?4 Risk 3 (this briefing book) 2026-06-23
BB-012 docs/artifacts/BRIEFING_BOOK_board_q3_2026.md [as of 2026-06-23] The Board's verdict is recorded in the KRINEIA receipt chain and the Board review log A validated governance/board/registry.yaml + docs/artifacts/CHARTER_hri.md + this briefing book ?7 2026-06-23
docs/artifacts/BUSINESS_CASE_game_engine.md12 claims · A: 9 · B: 1 · C: 2
ID Page Claim Tier Status Source Verified
GE-001 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Issue #408: simulation-ready game engine roadmap from Minecraft to Unreal A validated hummbl-io/hummbl-production#408 2026-06-23
GE-002 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] 4-stage roadmap: Stage 0 doctrine/schemas, Stage 1 Minecraft, Stage 2 multi-game, Stage 3 Unreal A validated docs/product/GAME_ENGINE_ROADMAP.md (commit 7fdf172) 2026-06-23
GE-003 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] 8 governance primitives to formalize in Stage 0: KillSwitch, CircuitBreaker, DelegationToken, GovernanceBus, Receipt, AgentRegistry, CostGovernor, CapabilityFence A validated docs/product/GAME_ENGINE_ROADMAP.md Stage 0 table 2026-06-23
GE-004 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Stage 0 cost estimate: $15-27K, 4-6 weeks engineering C unproven HUMMBL internal estimate (this business case) 2026-06-23
GE-005 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Total roadmap cost estimate: $255-475K over 12-18 months (Stages 0-3) C unproven HUMMBL internal estimate (this business case) 2026-06-23
GE-006 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] No AI governance vendor has a playable embodiment of their primitives B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md (2026-06-23, 19 vendors) 2026-06-23
GE-007 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Core principle: engine-agnostic doctrine, engine-specific embodiment A validated docs/product/GAME_ENGINE_ROADMAP.md section 2 2026-06-23
GE-008 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Stage 1 success metric: 5 external playtesters, 4/5 can explain receipts, 3/5 can verify chain A validated docs/product/GAME_ENGINE_ROADMAP.md Stage 1 success metrics 2026-06-23
GE-009 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Stage 0 funded from Q3 2026 operating budget (within Phase 1 funding approved 2026-06-23) A validated docs/artifacts/ARTIFACT_MANIFEST.md promotion packet review log + this business case 2026-06-23
GE-010 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Roadmap drafted per issue #408 acceptance criteria (commit 7fdf172) A validated hummbl-io/hummbl-production commit 7fdf172 + issue #408 comments 2026-06-23
GE-011 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Stage 2 target: 3 engines (Minecraft + Roblox/Unity/Godot), cross-engine receipt compatibility A validated docs/product/GAME_ENGINE_ROADMAP.md Stage 2 2026-06-23
GE-012 docs/artifacts/BUSINESS_CASE_game_engine.md [as of 2026-06-23] Stage 3 Unreal is last because it is highest-cost (engine expertise, asset pipeline, compute) A validated docs/product/GAME_ENGINE_ROADMAP.md Stage 3 2026-06-23
docs/artifacts/CASE_STUDY_claims_remediation.md16 claims · A: 15 · B: 1
ID Page Claim Tier Status Source Verified
CS-001 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] HUMMBL audited every public claim on its marketing surface on 2026-06-23 A validated hummbl-io/oss/packages/python/hummbl-governance/docs/research/2026-06-23_hummbl-io-claims-audit.md 2026-06-23
CS-002 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] Audit found 5 false claims, 5 misleading, 12 validated, 7 not checked (29 total) A validated hummbl-io/oss/packages/python/hummbl-governance/docs/research/2026-06-23_hummbl-io-claims-audit.md 2026-06-23
CS-003 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] Homepage code example called DelegationTokenManager.issue() which did not exist A validated hummbl-io/oss/packages/python/hummbl-governance/docs/research/2026-06-23_hummbl-io-claims-audit.md INV-1 2026-06-23
CS-004 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] Homepage code example called BusWriter.append() which did not exist A validated hummbl-io/oss/packages/python/hummbl-governance/docs/research/2026-06-23_hummbl-io-claims-audit.md INV-2 2026-06-23
CS-005 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] 8-step remediation plan executed in a single day (2026-06-23) A validated hummbl-io/hummbl-production/governance/board/records/CLAIMS_REMEDIATION_ACCEPTANCE_2026-06-23.md 2026-06-23
CS-006 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] 13 invalidated/misleading claims corrected across hummbl.io pages (commit 3cc4cdb) A validated hummbl-io/hummbl-production commit 3cc4cdb 2026-06-23
CS-007 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] 7 convenience methods/aliases added to hummbl-governance (commit f93f8b1) A validated hummbl-io/oss/packages/python/hummbl-governance commit f93f8b1 2026-06-23
CS-008 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] hummbl-governance v1.2.0 published to PyPI with the fixes A validated source ↗ 2026-06-23
CS-009 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] CI test added for homepage code snippet (commit 48b8b81) A validated hummbl-io/hummbl-production commit 48b8b81 + .github/workflows/homepage-snippet.yml 2026-06-23
CS-010 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] Board reviewed remediation -- UNANIMOUS_ACCEPT 5/5 Directors A validated hummbl-io/hummbl-production/governance/board/records/CLAIMS_REMEDIATION_ACCEPTANCE_2026-06-23.md 2026-06-23
CS-011 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] 59 total claims audited; 18 fixed, 16 validated, 25 pending (initial); 100% after follow-up A validated hummbl-io/hummbl-production/governance/board/records/CLAIMS_REMEDIATION_ACCEPTANCE_2026-06-23.md + commit 1f06087 2026-06-23
CS-012 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] Claims provenance manifest published with 4-field provenance per claim A validated web/manifest/claims-provenance.json 2026-06-23
CS-013 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] HUMMBL is the only AI governance vendor that publishes a claims provenance manifest B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md (2026-06-23) 2026-06-23
CS-014 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] KRINEIA receipt chain records the remediation (CLAIMS_AUDIT_COMPLETE + MILESTONE receipts) A validated hummbl-io/hummbl-production/_receipts/krineia/primary.jsonl 2026-06-23
CS-015 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] CONSTITUTION ?3.1 requires every public claim be verifiable or corrected/removed A validated hummbl-io/hummbl-production/CONSTITUTION.md ?3.1 2026-06-23
CS-016 docs/artifacts/CASE_STUDY_claims_remediation.md [as of 2026-06-23] PA chose to fix the code (add .issue()/.append()) rather than just fix the docs A validated hummbl-io/hummbl-production/governance/board/records/CLAIMS_REMEDIATION_ACCEPTANCE_2026-06-23.md + commit f93f8b1 2026-06-23
docs/artifacts/CHARTER_hri.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
CH-001 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HUMMBL Research Institute (HRI) is the steward of HUMMBL's governance doctrine, constitutions, and normative files A validated CONSTITUTION.md ?5 + this charter 2026-06-23
CH-002 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI is a functional role, not a legal entity A validated docs/artifacts/CHARTER_hri.md ?6 (this charter) 2026-06-23
CH-003 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI stewards 7 domains: doctrine, constitutions, normative files, coverage matrices, public artifacts, Board convening, research corpus A validated docs/artifacts/CHARTER_hri.md ?1 (this charter) 2026-06-23
CH-004 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI may decide doctrine amendments for principles 2,3,4,5,8,9,10 per doctrine ?5 process A validated docs/artifacts/DOCTRINE_ai_governance.md ?5 2026-06-23
CH-005 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI must escalate doctrine amendments for principles 1,6,7 (constitutional invariants) to PA + constitutional amendment process A validated docs/artifacts/DOCTRINE_ai_governance.md ?5 + CONSTITUTION.md ?7 2026-06-23
CH-006 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI must escalate funding, legal commitments, and strategic pivots to the Principal Agent A validated docs/artifacts/CHARTER_hri.md ?3 decision matrix (this charter) 2026-06-23
CH-007 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] The Director of HRI is Reuben Bowlby (Principal Agent) A validated docs/artifacts/CHARTER_hri.md ?4 (this charter) + authority boundary in every HUMMBL artifact 2026-06-23
CH-008 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] The Board is advisory -- the Director retains final authority A validated docs/artifacts/CHARTER_hri.md ?4 + Board Constitution Registry 2026-06-23
CH-009 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI convened the Board on 2026-06-23 (5 Directors, UNANIMOUS_ACCEPT with 3 conditions) A validated docs/artifacts/ARTIFACT_MANIFEST.md review log 2026-06-23 2026-06-23
CH-010 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI's default mode is draft, recommend, and escalate A validated docs/artifacts/CHARTER_hri.md ?3 (this charter) 2026-06-23
CH-011 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI is consistent with Doctrine Principle 7 (human authority over agent action) A validated docs/artifacts/DOCTRINE_ai_governance.md Principle 7 + this charter ?3 2026-06-23
CH-012 docs/artifacts/CHARTER_hri.md [as of 2026-06-23] HRI's authority is internal to HUMMBL -- HRI does not claim authority over other organizations A validated docs/artifacts/CHARTER_hri.md ?6 (this charter) 2026-06-23
docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md30 claims · A: 17 · B: 13
ID Page Claim Tier Status Source Verified
CA-001 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Gartner inaugural MQ for AI Governance Platforms June 2026 B validated Gartner MQ for AI Governance Platforms (June 2026) 2026-06-23
CA-002 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] EU AI Act high-risk obligations enforceable December 2, 2027 A validated EU Regulation 2024/1689 (AI Act) 2026-06-23
CA-003 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market $65M (2024) to $1.4B (2030) at 67.5% CAGR B validated Market research reports (composite) 2026-06-23
CA-004 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Credo AI: SaaS, Series C, $43.5M funding B validated source ↗ 2026-06-23
CA-005 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Holistic AI: SaaS, Series A+, $220M+ funding B validated source ↗ 2026-06-23
CA-006 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Arthur AI: SaaS, Series B, $63M, LLM-as-judge guardrails B validated source ↗ 2026-06-23
CA-007 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Fiddler AI: SaaS, Series C, $100M funding B validated source ↗ 2026-06-23
CA-008 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] IBM watsonx.governance: SaaS+software, public (IBM), hybrid enforcement A validated source ↗ 2026-06-23
CA-009 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Modulos AI: SaaS, Seed/Series A, CHF 15k starting price, mixed enforcement A validated source ↗ 2026-06-23
CA-010 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Airia: SaaS, Series A/B, deterministic policy evaluation engine A validated source ↗ 2026-06-23
CA-011 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] ServiceNow AI Control Tower: SaaS, public (NYSE: NOW), kill switch A validated source ↗ 2026-06-23
CA-012 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Modulos AI: Gartner MQ Honorable Mention 2026, first ISO/IEC 42001 product conformity B validated source ↗ 2026-06-23
CA-013 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Airia: Gartner MQ Visionary 2026, #1 AI Security Use Case B validated source ↗ 2026-06-23
CA-014 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Forrester Wave: AI Governance Solutions Q3 2025 B validated Forrester Wave for AI Governance Solutions Q3 2025 2026-06-23
CA-015 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] ISO/IEC 42001:2023 -- first certifiable AI management system standard A validated source ↗ 2026-06-23
CA-016 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] NIST AI Risk Management Framework 1.0 A validated source ↗ 2026-06-23
CA-017 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Credo AI: Gartner MQ Leader 2026 B validated source ↗ 2026-06-23
CA-018 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] IBM watsonx.governance: Gartner MQ Leader 2026 B validated source ↗ 2026-06-23
CA-019 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Collibra: SaaS, data governance with AI governance extension A validated source ↗ 2026-06-23
CA-020 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] OneTrust: SaaS, privacy + AI governance A validated source ↗ 2026-06-23
CA-021 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] HUMMBL: only open-source library with deterministic receipts in AI governance A validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md 2x2 matrix (2026-06-23) 2026-06-23
CA-022 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] HUMMBL: pip install hummbl-governance A validated source ↗ 2026-06-23
CA-023 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] HUMMBL: framework-agnostic A validated hummbl-io/oss/packages/python/hummbl-governance library design 2026-06-23
CA-024 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Modulos Agentic Runtime Inspection uses AI agents for natural-language checks A validated source ↗ 2026-06-23
CA-025 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Modulos Runtime Inspection (metric-based) is deterministic A validated source ↗ 2026-06-23
CA-026 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Airia Agent Constraints operates at runtime layer A validated source ↗ 2026-06-23
CA-027 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Airia policy language is IF-THEN, compiled to decision trees A validated source ↗ 2026-06-23
CA-028 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] Modulos pricing starts at CHF 15k with free starter tier B validated source ↗ 2026-06-23
CA-029 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] ServiceNow acquired Traceloop for agent observability B validated ServiceNow press + Traceloop acquisition coverage 2026-06-23
CA-030 docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md [as of 2026-06-23] HUMMBL positioned as governance infrastructure (not platform) A validated docs/artifacts/WHITE_PAPER_governance_infrastructure.md + COMPETITIVE_ANALYSIS_ai_governance.md 2026-06-23
docs/artifacts/DOCTRINE_ai_governance.md14 claims · A: 13 · B: 1
ID Page Claim Tier Status Source Verified
DO-001 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] HUMMBL operates on 10 AI governance principles as decision rules A validated docs/artifacts/DOCTRINE_ai_governance.md ?2 (this doctrine) 2026-06-23
DO-002 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 1 (honesty): every public claim is validated with cited evidence or marked unproven A validated CONSTITUTION.md ?3.1 (public claim honesty invariant) 2026-06-23
DO-003 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 2 (determinism): HUMMBL governance evidence is deterministic, not LLM-judged A validated docs/artifacts/WHITE_PAPER_governance_infrastructure.md ?4 2026-06-23
DO-004 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 3 (in-process): HUMMBL primitives run in the customer's process, not on SaaS cloud A validated docs/artifacts/WHITE_PAPER_governance_infrastructure.md ?3 2026-06-23
DO-005 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 4 (open-source): HUMMBL governance library is Apache 2.0 A validated CONSTITUTION.md ?3.5 + https://github.com/hummbl-io/oss/tree/main/packages/hummbl-governance 2026-06-23
DO-006 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 5 (boundary honesty): HUMMBL is not a Notified Body (EU AI Act Art. 31) or NIST-recognized assessor A validated docs/artifacts/POSITION_PAPER_eu_ai_act.md ?3 + docs/artifacts/POSITION_PAPER_nist_ai_rmf.md ?3 2026-06-23
DO-007 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 6 (receipts): every governance action emits a hash-chained KRINEIA receipt A validated CONSTITUTION.md ?3.6 + _receipts/krineia/primary.jsonl 2026-06-23
DO-008 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 7 (human authority): Reuben Bowlby is the Principal Agent; software agents are delegated systems A validated Authority boundary section in every HUMMBL artifact + hummbl-io/oss/packages/python/hummbl-governance/MULTI_AGENT.md 2026-06-23
DO-009 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 8 (framework-agnostic): HUMMBL primitives serve EU AI Act, NIST AI RMF, SOC 2, GDPR, OWASP from same code A validated docs/artifacts/POSITION_PAPER_nist_ai_rmf.md ?4 + hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py 2026-06-23
DO-010 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 9 (public matrices): HUMMBL publishes per-article EU AI Act and per-subcategory NIST AI RMF coverage matrices A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/eu-ai-act.md + nist-ai-rmf.md 2026-06-23
DO-011 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principle 10 (RSI): HUMMBL uses its own governance primitives on its own operations A validated docs/artifacts/CASE_STUDY_claims_remediation.md + docs/artifacts/RETROSPECTIVE_wave_1.md 2026-06-23
DO-012 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] Principles 1, 6, 7 are constitutional invariants that cannot be amended without a constitutional amendment A validated CONSTITUTION.md ?3 + ?7 2026-06-23
DO-013 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] HUMMBL is the only vendor that publishes a per-article EU AI Act coverage matrix B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md (2026-06-23, 19 vendors) 2026-06-23
DO-014 docs/artifacts/DOCTRINE_ai_governance.md [as of 2026-06-23] The 10 principles form a coherent system where violations of any principle weaken the others A validated docs/artifacts/DOCTRINE_ai_governance.md ?3 (this doctrine) 2026-06-23
docs/artifacts/EVIDENCE_PACK_fleet_rollout.md14 claims · A: 13 · C: 1
ID Page Claim Tier Status Source Verified
EP-001 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL's KRINEIA receipt chain has 9 receipts as of 2026-06-23, all hash-linked and verifiable A validated _receipts/krineia/primary.jsonl (verified 2026-06-23) 2026-06-23
EP-002 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL's claims provenance manifest has 197 claims, 165 validated, 4 unproven as of 2026-06-23 A validated web/manifest/claims-provenance.json (verified 2026-06-23) 2026-06-23
EP-003 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] hummbl-governance test suite has 1,234 tests as of 2026-06-23 A validated hummbl-io/oss/packages/python/hummbl-governance (pytest --collect-only, verified 2026-06-23) 2026-06-23
EP-004 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL's EU AI Act coverage matrix maps 113 articles and 13 annexes with 23 fulfilled, 19 partial, 71 boundary A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/eu-ai-act.md 2026-06-23
EP-005 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL's NIST AI RMF coverage matrix maps ~70 subcategories with 20 fulfilled, 31 partial, 19 boundary A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/nist-ai-rmf.md 2026-06-23
EP-006 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] Wave 1 produced 10 live artifacts with 171 claims and 6 KRINEIA receipts A validated docs/artifacts/ARTIFACT_MANIFEST.md (items 1-10) 2026-06-23
EP-007 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] Wave 2 has produced 2 live artifacts (Days 11-12) with 26 claims and 2 KRINEIA receipts as of 2026-06-23 A validated docs/artifacts/ARTIFACT_MANIFEST.md (items 11-12) + _receipts/krineia/primary.jsonl 2026-06-23
EP-008 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL's governance library is Apache 2.0 open-source on GitHub and PyPI A validated source ↗ 2026-06-23
EP-009 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL uses its own governance primitives on its own operations (RSI principle 10) A validated docs/artifacts/CASE_STUDY_claims_remediation.md + docs/artifacts/RETROSPECTIVE_wave_1.md 2026-06-23
EP-010 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] Every claim in this evidence pack has a How to verify section with a runnable command A validated docs/artifacts/EVIDENCE_PACK_fleet_rollout.md ?2 (this pack) 2026-06-23
EP-011 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL's 12-month SOM target is $0.5-1M ARR (tier C internal estimate) C unproven docs/artifacts/MARKET_ANALYSIS_ai_governance.md (tier C) 2026-06-23
EP-012 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] This evidence pack is self-compiled, not a third-party audit A validated docs/artifacts/EVIDENCE_PACK_fleet_rollout.md ?6 (this pack) 2026-06-23
EP-013 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] HUMMBL has not yet disclosed customer references A validated docs/artifacts/EVIDENCE_PACK_fleet_rollout.md ?4 (this pack) 2026-06-23
EP-014 docs/artifacts/EVIDENCE_PACK_fleet_rollout.md [as of 2026-06-23] Wave 1 retrospective identified 6 friction points (F1-F6) and 6 process improvements (P1-P6) A validated docs/artifacts/RETROSPECTIVE_wave_1.md 2026-06-23
docs/artifacts/MARKET_ANALYSIS_ai_governance.md14 claims · B: 12 · C: 2
ID Page Claim Tier Status Source Verified
MA-001 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market size 2026: $0.44B (Mordor Intelligence) B validated source ↗ 2026-06-23
MA-002 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market projected $1.51B by 2031 at 28.15% CAGR (Mordor) B validated source ↗ 2026-06-23
MA-003 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market projected $5.88B by 2035 at 34.27% CAGR (Precedence Research) B validated source ↗ 2026-06-23
MA-004 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market $0.61B in 2026, $2.63B by 2030 at 44.3% CAGR (The Business Research Co.) B validated source ↗ 2026-06-23
MA-005 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI ethics and governance solutions market incremental growth $4.29B 2026-2030 at 36% CAGR (Technavio) B validated source ↗ 2026-06-23
MA-006 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market $5.78B by 2029 at 45.3% CAGR (MarketsandMarkets) B validated source ↗ 2026-06-23
MA-007 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] Platforms/software suites held 42.40% of AI governance market share in 2025 (Mordor) B validated source ↗ 2026-06-23
MA-008 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] Point solutions (bias detection, explainability) forecast 28.6% CAGR through 2031 (Mordor) B validated source ↗ 2026-06-23
MA-009 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] Solutions segment held 66% of AI governance market share in 2025 (Precedence) B validated source ↗ 2026-06-23
MA-010 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] Stanford 2025 AI Index: 78% of organizations used AI in 2024, up from 55% in 2023 B validated source ↗ 2026-06-23
MA-011 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] North America is the largest AI governance market; Asia-Pacific is fastest growing B validated source ↗ 2026-06-23
MA-012 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] AI governance market is fragmented (no vendor >15% market share) B validated source ↗ 2026-06-23
MA-013 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] HUMMBL wedge SAM estimate: ~10% of narrow TAM = ~$50M in 2026 C unproven HUMMBL internal estimate based on narrow TAM $0.5B (Mordor/QY) 2026-06-23
MA-014 docs/artifacts/MARKET_ANALYSIS_ai_governance.md [as of 2026-06-23] HUMMBL 12-month SOM target: $0.5-1M ARR, 10-20 paying customers, 1000+ OSS adopters C unproven HUMMBL internal target (this analysis) 2026-06-23
docs/artifacts/PLAYBOOK_agent_onboarding.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
AO-001 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The agent onboarding playbook defines a 6-step protocol: identity registration, guardrail definition, bus identity approval, model tier assignment, first-task assignment, 30-day review A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?3 (this playbook) 2026-06-23
AO-002 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The playbook defines 5 roles: Principal Agent, onboarding steward, agent roster steward, bus steward, reviewer A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?2 (this playbook) 2026-06-23
AO-003 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] Every agent has 7 registry fields: name, role, runtime, bus_id, model_tier, trust_level, autonomy_tier A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?3 Step 1 + AGENTS.md ?1.3 2026-06-23
AO-004 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The guardrail document defines 7 fields: identity, bus rules, permissions, limitations, escalation, commit cadence, prohibited actions A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?3 Step 2 (this playbook) 2026-06-23
AO-005 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] There are 3 model tiers: T1-BYOK (bring-your-own-key, sensitive data OK), T2-ZEN (zero-egress, sensitive data OK), T3-FREE (free-tier, NO sensitive data) A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?3 Step 4 + .agents/rules/model-tier-policy.md 2026-06-23
AO-006 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The 30-day review has 4 possible outcomes: CONTINUE, PROMOTE, AIP, RETIRE A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?3 Step 6 (this playbook) 2026-06-23
AO-007 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The playbook documents 6 common mistakes: onboarding without guardrail, bus identity not approved, model tier mismatch, skipping 30-day review, onboarding a retired identity, promote without review A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?5 (this playbook) 2026-06-23
AO-008 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The onboarding packet has 6 artifacts: registry entry, guardrail document, bus identity approval, model tier assignment, first task assignment, 30-day review A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?4 (this playbook) 2026-06-23
AO-009 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The retirement checklist has 6 steps: post retirement notice, archive guardrail, mark registry entry retired, do NOT reuse bus_id, conduct final review, emit KRINEIA receipt A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?7 (this playbook) 2026-06-23
AO-010 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The playbook provides 6 verification commands for confirming an agent is properly onboarded A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?6 (this playbook) 2026-06-23
AO-011 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] An agent with a missing onboarding packet item is 'provisional' -- it may operate but its outputs are subject to additional review A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?4 (this playbook) 2026-06-23
AO-012 docs/artifacts/PLAYBOOK_agent_onboarding.md [as of 2026-06-23] The playbook is the operational counterpart to the doctrine (item 11) and charter (item 12) A validated docs/artifacts/PLAYBOOK_agent_onboarding.md ?TL;DR + ?9 References (this playbook) 2026-06-23
docs/artifacts/PLAYBOOK_claims_change.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
PB-001 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] HUMMBL has a claims change protocol covering 5 change types: add, update, validate, retract, remove A validated docs/artifacts/PLAYBOOK_claims_change.md ?3 (this playbook) 2026-06-23
PB-002 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] Every claim change requires a KRINEIA receipt with event type claims.added/updated/validated/retracted/removed A validated docs/artifacts/PLAYBOOK_claims_change.md ?5 (this playbook) + CONSTITUTION.md ?6 2026-06-23
PB-003 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] Silent deletion of a claim is a CONSTITUTION ?3.4 violation A validated CONSTITUTION.md ?3.4 + this playbook ?3.4/?3.5 2026-06-23
PB-004 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] The add_claims.py helper enforces utf-8 encoding and checks for ID collisions A validated scripts/add_claims.py + AGENTS.md ?8 2026-06-23
PB-005 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] Tier C claims (internal estimates) must be marked unproven by default A validated docs/artifacts/PLAYBOOK_claims_change.md ?4 (this playbook) 2026-06-23
PB-006 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] The protocol has 4 roles: requester, validator, promoter, receipt emitter A validated docs/artifacts/PLAYBOOK_claims_change.md ?2 (this playbook) 2026-06-23
PB-007 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] Agents can be requesters and receipt emitters but cannot be promoters (per Doctrine Principle 7) A validated docs/artifacts/DOCTRINE_ai_governance.md Principle 7 + this playbook ?2 2026-06-23
PB-008 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] The playbook documents 6 common mistakes (M1-M6) and how to avoid them A validated docs/artifacts/PLAYBOOK_claims_change.md ?7 (this playbook) 2026-06-23
PB-009 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] Retracting a claim requires updating downstream artifacts that cited it A validated docs/artifacts/PLAYBOOK_claims_change.md ?3.4 (this playbook) 2026-06-23
PB-010 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] The protocol originated from wave 1 retrospective findings F1 (encoding bug), P1 (helper scripts), P3 (utf-8 convention) A validated docs/artifacts/RETROSPECTIVE_wave_1.md (F1, P1, P3) 2026-06-23
PB-011 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] The playbook enforces CONSTITUTION ?3.1 (public claim honesty) and ?3.4 (claims provenance manifest integrity) A validated CONSTITUTION.md ?3.1 + ?3.4 + this playbook ?8 2026-06-23
PB-012 docs/artifacts/PLAYBOOK_claims_change.md [as of 2026-06-23] Removed claims are archived to web/manifest/claims-archive.jsonl (append-only) with removed_date and removal_reason A validated docs/artifacts/PLAYBOOK_claims_change.md ?3.5 (this playbook) 2026-06-23
docs/artifacts/PLAYBOOK_fleet_rollout.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
FR-001 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] HUMMBL has a fleet rollout protocol covering 4 scenarios: single-machine pilot, multi-machine mesh, agent activation, customer organization rollout A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?3 (this playbook) 2026-06-23
FR-002 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The hummbl-governance library is installable via pip install hummbl-governance A validated source ↗ 2026-06-23
FR-003 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The rollout protocol has 5 roles: rollout lead, machine operator, agent steward, verifier, promoter A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?2 (this playbook) 2026-06-23
FR-004 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] Every rollout emits a KRINEIA receipt and posts a bus STATUS A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?3 + ?5 (this playbook) + CONSTITUTION.md ?6 2026-06-23
FR-005 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The mesh-sync skill synchronizes .agents/ across machines in the fleet A validated ~/.claude/skills/mesh-sync/SKILL.md 2026-06-23
FR-006 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] Rollback adds entries (bus STATUS + KRINEIA receipt); it does not delete the bus or chain A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?7 (this playbook) + CONSTITUTION.md ?3.6 2026-06-23
FR-007 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The playbook documents 6 common mistakes (M1-M6) for fleet rollouts A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?8 (this playbook) 2026-06-23
FR-008 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The playbook has 6 verification commands (V1-V6) covering library, health, bus, receipts, claims, mesh A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?6 (this playbook) 2026-06-23
FR-009 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] Customer rollout requires the customer to read the evidence pack and accept the boundaries before starting A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?3.4 + ?8 M6 (this playbook) + docs/artifacts/EVIDENCE_PACK_fleet_rollout.md ?4 2026-06-23
FR-010 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] Agent activation requires a guardrail file and roster entry before the agent can be activated A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?3.3 + ?8 M4 (this playbook) 2026-06-23
FR-011 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The rollout protocol originated from the hummbl-governance proving ground pattern and the mesh-sync skill A validated hummbl-io/oss/packages/python/hummbl-governance (proving ground) + ~/.claude/skills/mesh-sync/SKILL.md 2026-06-23
FR-012 docs/artifacts/PLAYBOOK_fleet_rollout.md [as of 2026-06-23] The generic rollout sequence is: install, initialize, configure, verify, receipt, status, monitor A validated docs/artifacts/PLAYBOOK_fleet_rollout.md ?5 (this playbook) 2026-06-23
docs/artifacts/POSITION_PAPER_eu_ai_act.md14 claims · A: 13 · B: 1
ID Page Claim Tier Status Source Verified
EU-001 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] EU AI Act high-risk obligations enforceable December 2, 2027 A validated Regulation (EU) 2024/1689 Art. 113 2026-06-23
EU-002 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] Penalties up to 35M EUR or 7% worldwide annual turnover for high-risk non-compliance A validated Regulation (EU) 2024/1689 Art. 99 2026-06-23
EU-003 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] Annex III lists 8 areas of high-risk AI use A validated Regulation (EU) 2024/1689 Annex III 2026-06-23
EU-004 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL coverage matrix maps all 113 articles + 13 annexes of EU AI Act A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/eu-ai-act.md 2026-06-23
EU-005 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL compliance mapper generates EU AI Act reports for Art. 9, 10, 11, 12, 13, 14, 15, 16, 17, 19 A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py:474 2026-06-23
EU-006 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL is not a Notified Body under EU AI Act Art. 31 A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/eu-ai-act.md boundary disclaimer 2026-06-23
EU-007 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL governance bus records every agent action with retention default 5+ years aligned with Art. 19 A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/governance_bus.py + coverage matrix Art. 12 2026-06-23
EU-008 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL kill switch has 4 modes: DISENGAGED, HALT_NONCRITICAL, HALT_ALL, EMERGENCY A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/kill_switch_core.py 2026-06-23
EU-009 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL delegation tokens are HMAC-SHA256 signed A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/delegation_token.py 2026-06-23
EU-010 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL is the only vendor that publishes a per-article EU AI Act coverage matrix B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md (2026-06-23) 2026-06-23
EU-011 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL coverage matrix: 23 articles fulfilled, 19 partial, 71 boundary, 0 out of scope A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/eu-ai-act.md summary table 2026-06-23
EU-012 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] HUMMBL KRINEIA receipt chain is hash-linked and verifiable A validated hummbl-io/hummbl-production/_receipts/krineia/primary.jsonl 2026-06-23
EU-013 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] EU AI Act entered into force 1 August 2024 A validated Regulation (EU) 2024/1689 2026-06-23
EU-014 docs/artifacts/POSITION_PAPER_eu_ai_act.md [as of 2026-06-23] Conformity assessment paths: Annex VI internal control OR Annex VII Notified Body (mandatory for biometric ID) A validated Regulation (EU) 2024/1689 Art. 43 2026-06-23
docs/artifacts/POSITION_PAPER_nist_ai_rmf.md14 claims · A: 13 · B: 1
ID Page Claim Tier Status Source Verified
NR-001 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] NIST AI RMF 1.0 published January 2023 as NIST AI 100-1 A validated source ↗ 2026-06-23
NR-002 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] NIST AI RMF is a voluntary framework with no certification body A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/nist-ai-rmf.md boundary disclaimer 2026-06-23
NR-003 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] NIST AI RMF has 4 core functions: GOVERN, MAP, MEASURE, MANAGE A validated NIST AI 100-1 2026-06-23
NR-004 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] NIST AI RMF has ~70 subcategories across the 4 functions A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/nist-ai-rmf.md 2026-06-23
NR-005 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL NIST AI RMF coverage: 20 fulfilled, 31 partial, 19 boundary subcategories A validated hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/nist-ai-rmf.md summary table 2026-06-23
NR-006 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL compliance mapper generates NIST AI RMF reports for GOVERN, MAP, MEASURE, MANAGE A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py:373 2026-06-23
NR-007 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL kill switch provides MANAGE-1.3 response plan execution evidence A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py + kill_switch_core.py 2026-06-23
NR-008 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL circuit breaker provides MANAGE-2.4 risk treatment evidence A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py + circuit_breaker.py 2026-06-23
NR-009 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL is the only vendor that publishes a per-subcategory NIST AI RMF coverage matrix B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md (2026-06-23) 2026-06-23
NR-010 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] OMB Circular M-24-10 requires US federal agencies to require AI RMF alignment from AI vendors A validated source ↗ 2026-06-23
NR-011 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL primitives are framework-agnostic: same evidence serves NIST AI RMF and EU AI Act A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py (generate_nist_rmf_report + generate_eu_ai_act_report read same bus) 2026-06-23
NR-012 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL KRINEIA receipt chain is hash-linked and verifiable by third-party assessors A validated hummbl-io/hummbl-production/_receipts/krineia/primary.jsonl 2026-06-23
NR-013 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL cost governor provides MEASURE-2.8 impact metrics evidence A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/compliance_mapper.py + cost_tracker.py 2026-06-23
NR-014 docs/artifacts/POSITION_PAPER_nist_ai_rmf.md [as of 2026-06-23] HUMMBL delegation context provides MAP-1.1 organizational context evidence A validated hummbl-io/oss/packages/python/hummbl-governance/hummbl_governance/delegation_context.py + compliance_mapper.py 2026-06-23
docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md12 claims · A: 9 · B: 2 · C: 1
ID Page Claim Tier Status Source Verified
SO2-001 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL is structurally ready for SOC 2 Type II; the gap is operational (no external audit yet conducted) A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?1.4 + ?3 (this paper) 2026-06-23
SO2-002 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] SOC 2 Type II is a customer requirement, not a legal requirement -- enterprise buyers require it as a precondition for procurement B validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?1.1 (this paper) 2026-06-23
SO2-003 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL maps to 4 of 5 SOC 2 Trust Service Criteria: Common (CC1-CC9), Security (SC1-SC7), Availability (A1-A3), Confidentiality (C1-C2); Processing Integrity partial; Privacy not applicable A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?2 (this paper) 2026-06-23
SO2-004 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL has controls for all 9 Common Criteria (CC1-CC9) mapped to specific artifacts and primitives A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?2.1 (this paper) 2026-06-23
SO2-005 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] There are 6 operational gaps: no external audit, SC6 not formalized, no penetration test, no formal IR plan, no vendor management program, no formal data classification policy A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?3.2 (this paper) 2026-06-23
SO2-006 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] The readiness plan has 4 phases: Q3 2026 formalize gaps, Q4 2026 prepare for audit, Q1 2027 conduct audit, Q2 2027+ maintain A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?4 (this paper) 2026-06-23
SO2-007 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] SOC 2 Type II audits cost $20,000-$80,000; HUMMBL estimated at $20,000-$40,000 for first audit due to low complexity, documented controls, in-process architecture, machine-verifiable evidence C unproven docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?5 (this paper) 2026-06-23
SO2-008 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL is behind established competitors (Credo AI, Arthur AI, Fiddler AI, IBM) on SOC 2; this is expected for a pre-revenue company B validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?6 (this paper) + docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md 2026-06-23
SO2-009 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL should pursue SOC 2 Type II in Q4 2026/Q1 2027, after the first pilot integration, funded from pilot revenue or operating budget A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?7 (this paper) 2026-06-23
SO2-010 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL should NOT pursue SOC 2 before the first pilot integration, should NOT use it as a marketing tool, should NOT pursue ISO 27001/42001 before SOC 2 A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?7 (this paper) 2026-06-23
SO2-011 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] HUMMBL's in-process architecture is a structural differentiator for SOC 2: the buyer's data does not flow to HUMMBL, reducing audit scope A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?1.2 + ?5 (this paper) + docs/artifacts/WHITE_PAPER_governance_infrastructure.md 2026-06-23
SO2-012 docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md [as of 2026-06-23] The paper provides 10 verification commands for readers to independently verify HUMMBL's SOC 2 readiness claims A validated docs/artifacts/POSITION_PAPER_soc2_type_ii_readiness.md ?8 (this paper) 2026-06-23
docs/artifacts/SWOT_hummbl_current_state.md12 claims · A: 10 · B: 2
ID Page Claim Tier Status Source Verified
SW-001 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's SWOT identifies 6 strengths: deterministic library, artifact stack, RSI loop, doctrine+charter, coverage matrices, hummbl-governance proving ground A validated docs/artifacts/SWOT_hummbl_current_state.md ?1 (this SWOT) 2026-06-23
SW-002 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's SWOT identifies 6 weaknesses: pre-revenue, single-founder dependency, zero customer references, no external audit, limited marketing surface, small team A validated docs/artifacts/SWOT_hummbl_current_state.md ?2 (this SWOT) 2026-06-23
SW-003 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's SWOT identifies 6 opportunities: empty playable governance category, EU AI Act deadline, proof gap, open-source adoption, framework-agnostic coverage, RSI loop as moat A validated docs/artifacts/SWOT_hummbl_current_state.md ?3 (this SWOT) 2026-06-23
SW-004 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's SWOT identifies 6 threats: category creation bet fails, competitors match playable embodiment, regulatory shifts, single-founder unavailability, open-source clone, buyer inertia A validated docs/artifacts/SWOT_hummbl_current_state.md ?4 (this SWOT) 2026-06-23
SW-005 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's wedge is the combination of deterministic, in-process, open-source, with receipts -- no competitor matches all 4 properties B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md + docs/artifacts/SWOT_hummbl_current_state.md ?1 S1 + ?5 (this SWOT) 2026-06-23
SW-006 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] The strategic implications are: double down on the wedge, ship IssueOps Phase 1 and game engine Stage 0, pursue 3 discovery calls by Q4 2026, reduce the bus factor, continue the RSI loop A validated docs/artifacts/SWOT_hummbl_current_state.md ?5 (this SWOT) 2026-06-23
SW-007 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] The single-founder dependency (W2/T4) is the highest-impact risk; the Board should consider hiring or partnering with a second human in Q4 2026 or Q1 2027 A validated docs/artifacts/SWOT_hummbl_current_state.md ?2 W2 + ?4 T4 + ?5 (this SWOT) + docs/artifacts/BRIEFING_BOOK_board_q3_2026.md ?6 Decision 3 2026-06-23
SW-008 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] The playable governance category is empty (zero vendors) as of 2026-06-23, creating an opportunity for HUMMBL to create and own the category B validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md + docs/artifacts/BUSINESS_CASE_game_engine.md ?1 + this SWOT ?3 O1 2026-06-23
SW-009 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's RSI loop is a structural advantage that compounds; competitors without an RSI loop do not improve at the same rate A validated docs/artifacts/RETROSPECTIVE_wave_1.md + docs/artifacts/RETROSPECTIVE_wave_2.md + this SWOT ?1 S3 + ?3 O6 2026-06-23
SW-010 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] The SWOT has 10 verification commands (S1-S6, W1, O1, O2, T1) that a reader can run to independently verify the analysis A validated docs/artifacts/SWOT_hummbl_current_state.md ?7 (this SWOT) 2026-06-23
SW-011 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] HUMMBL's framework-agnostic coverage spans EU AI Act, NIST AI RMF, SOC 2, GDPR, and OWASP -- a buyer addressing one framework gets coverage for all A validated docs/artifacts/SWOT_hummbl_current_state.md ?3 O5 (this SWOT) + hummbl-io/oss/packages/python/hummbl-governance/docs/coverage/ 2026-06-23
SW-012 docs/artifacts/SWOT_hummbl_current_state.md [as of 2026-06-23] The SWOT is a self-assessment as of 2026-06-23, not a third-party analysis; HUMMBL welcomes third-party analysis A validated docs/artifacts/SWOT_hummbl_current_state.md ?6 (this SWOT) 2026-06-23
docs/artifacts/WHITE_PAPER_governance_infrastructure.md12 claims · A: 12
ID Page Claim Tier Status Source Verified
WP-001 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] 92-repo fleet with 67 active governance stacks A validated hummbl-io/oss/packages/hummbl-governance/docs/standards/AUDIT_2026-06-22.md + fleet verification output 2026-06-23 2026-06-23
WP-002 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] 1,234 governance tests in hummbl-governance A validated hummbl-io/oss test suite (pytest --collect-only) 2026-06-23
WP-003 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] 59 verified public claims in claims-provenance.json A validated web/manifest/claims-provenance.json (2026-06-23) 2026-06-23
WP-004 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] Fleet-wide KRINEIA receipt chain A validated _receipts/krineia/primary.jsonl in every active repo 2026-06-23
WP-005 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] hummbl-governance on PyPI (v1.2.0) A validated source ↗ 2026-06-23
WP-006 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] Zero third-party runtime dependencies A validated hummbl-io/oss/packages/python/hummbl-governance/pyproject.toml 2026-06-23
WP-007 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] 8 governance primitives A validated hummbl-io/oss/packages/python/hummbl-governance library + PRIMITIVES.md 2026-06-23
WP-008 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] KRINEIA invariants (observed_agent_may_write_receipts: false) A validated hummbl-io/oss/packages/python/hummbl-governance/krineia/RECEIPT_SCHEMA.md 2026-06-23
WP-009 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] HUMMBL Repo Standard v0.1 adopted fleet-wide A validated hummbl-io/oss/packages/hummbl-governance/docs/standards/HUMMBL_REPO_STANDARD.md + fleet verification 2026-06-23
WP-010 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] Apache 2.0 license A validated hummbl-io/oss/packages/python/hummbl-governance/LICENSE 2026-06-23
WP-011 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] Self-reference customer (HUMMBL runs on HUMMBL) A validated Composite -- fleet audit + claims manifest + KRINEIA chain 2026-06-23
WP-012 docs/artifacts/WHITE_PAPER_governance_infrastructure.md [as of 2026-06-23] Only Airia (SaaS) and HUMMBL (library) offer pure deterministic enforcement A validated docs/artifacts/COMPETITIVE_ANALYSIS_ai_governance.md (2026-06-23 re-verification) 2026-06-23

Last observability cycle

overall degraded · host anvil · data 2026-09-08T01:38:53Z · STALE

Evidence ledger

Last observability cycle

STALE since 2026-09-08T03:38:53Z (data: 2026-09-08T01:38:53Z) · host: anvil · overall: degraded.

synthetic monitor
9 healthy / 2 unhealthy
TLS certificates checked
19 (0 expiring soon)
route-health probes
4 checked / 2 degraded or down
uptime rollup
history: not yet collected

Assurance boundary

What this page does not say.

Uptime history
No committed artifact holds a time series, so no uptime percentage is claimed. "History: not yet collected" is the honest cell.
Independent verification
These probes are generated by the estate itself. An external uptime check is a pending operator decision (audit finding EVID-009).
Incident completeness
Absence of a reported incident is absence of a record, not proof nothing happened between probes.