Skip to content
HolonomiX
Products/HX-AEIR
Available now · Private Appliance · Scoped Pilot

HX-AEIR

Agent evaluation incidents reconstructed from validated, signed, independently verifiable evidence.

HX-AEIR (Agent Evaluation Incident Reconstruction) is a private Google Cloud VM appliance that validates, signs, stores, exports, and independently verifies the evidence used to reconstruct agent evaluation incidents. It runs inside your Google Cloud project, signs with a customer-local ML-DSA-65 key, and requires no HolonomiX runtime service for issuance, export, or verification.

StatusPrivate Appliance · Scoped Pilot
Runs inCustomer-controlled Google Cloud project
SigningCustomer-local ML-DSA-65
VerificationAPI · CLI · Offline with a pinned public key
MarketplaceGoogle Cloud listing planned
Authorize Validate Sign Persist Export Verify offline

Incident reconstruction stands on the integrity of its evidence. HX-AEIR signs it, stores it, and lets an isolated verifier with the pinned key check it.

When an agent evaluation becomes an incident, the record is examined by people who were not in the room: security, counsel, customers, regulators. HX-AEIR validates the syntax and cross-document semantics of supplied evidence, computes deterministic canonical digests, signs the receipt and package with a customer-local ML-DSA-65 key, and persists immutable objects with append-only indexes on the customer disk. Signed authorization and preflight documents are required inputs: missing or inconsistent linkage fails closed.

Evidence does not transit a HolonomiX runtime service. The appliance boots keyless, the signing key exists only after an explicit root-authorized initialization, and the customer controls the disk, backups, exports, and retention policy. Exported packages verify on an isolated machine against an independently pinned public key, with no network connection to HolonomiX, Google Cloud, or the appliance.

Claim boundary

HX-AEIR records and signs supplied evidence. It does not execute, sandbox, monitor, block, or contain evaluated agents; runtime prevention by HX-AEIR is NONE. Verification establishes schema and semantic checks, canonical digests, ML-DSA-65 signatures under the pinned key, exact package manifests, and required linkages. It does not prove that omitted telemetry never existed, that supplied statements are factually complete, or that a third party certifies the incident conclusion.

Authorize Validate Sign Persist Export Verify offline

Authorization and customer custody govern every receipt

No receipt without its authorization chain

Signed authorization and preflight documents are required inputs. Missing or inconsistent authorization, preflight, prior-revision, source, or evidence linkage fails closed.

Customer authorization creates the signing key

First boot is keyless: no silent key generation, no minted credentials. The ML-DSA-65 key exists only after an explicit root-authorized initialization, with the fingerprint recorded through an independent channel.

Packages verify on an isolated machine

The verifier needs the exported package, the pinned public key, and required linked material. Verdicts are deterministic: positive, negative, or input failure. No vendor connection.

Mutual TLS outside and a Unix socket inside

Nginx enforces mutual TLS on TCP 443 and a bounded request surface. The application accepts only a group-restricted Unix socket and cannot open an IP listener. Shielded VM, OS Login, optional IAP-only SSH.

The same digest exports the same bytes

Deterministic canonical JSON and evidence digests. Export for an exact receipt digest is byte-identical across requests and reboots, and each archive digest is recorded for the acceptance record.

Custody is separate from transport and release management

Each has its own custody and lifecycle rules. Normal backups exclude the signing private key; continuity backups that include it are explicit, digest-pinned, and tightly controlled.

Availability

HX-AEIR deploys as a Private Appliance in your Google Cloud project, scoped and supported through a direct engagement.

Availability Available now
Cloud status Google Cloud Marketplace listing planned

Incident evidence

Investigating and reconstructing agent-evaluation incidents from validated, signed evidence, with explicit authorization and customer-controlled key custody.

Inputs

Incident records, evaluation context, and Google Cloud deployment and key-custody requirements.

Outputs

Signed incident-evidence packages with export records and an offline verification procedure.

Limits

A signed incident record does not, by itself, establish root cause or the correctness of an agent's behavior.

Availability: Private Appliance · Scoped pilot.