HX-AEIR
Agent evaluation incidents reconstructed from validated, signed, independently verifiable evidence.
HX-AEIR (Agent Evaluation Incident Reconstruction) is a private Google Cloud VM appliance that validates, signs, stores, exports, and independently verifies the evidence used to reconstruct agent evaluation incidents. It runs inside your Google Cloud project, signs with a customer-local ML-DSA-65 key, and requires no HolonomiX runtime service for issuance, export, or verification.
Incident reconstruction stands on the integrity of its evidence. HX-AEIR signs it, stores it, and lets an isolated verifier with the pinned key check it.
When an agent evaluation becomes an incident, the record is examined by people who were not in the room: security, counsel, customers, regulators. HX-AEIR validates the syntax and cross-document semantics of supplied evidence, computes deterministic canonical digests, signs the receipt and package with a customer-local ML-DSA-65 key, and persists immutable objects with append-only indexes on the customer disk. Signed authorization and preflight documents are required inputs: missing or inconsistent linkage fails closed.
Evidence does not transit a HolonomiX runtime service. The appliance boots keyless, the signing key exists only after an explicit root-authorized initialization, and the customer controls the disk, backups, exports, and retention policy. Exported packages verify on an isolated machine against an independently pinned public key, with no network connection to HolonomiX, Google Cloud, or the appliance.
HX-AEIR records and signs supplied evidence. It does not execute, sandbox, monitor, block, or contain evaluated agents; runtime prevention by HX-AEIR is NONE. Verification establishes schema and semantic checks, canonical digests, ML-DSA-65 signatures under the pinned key, exact package manifests, and required linkages. It does not prove that omitted telemetry never existed, that supplied statements are factually complete, or that a third party certifies the incident conclusion.
Authorization and customer custody govern every receipt
Availability
HX-AEIR deploys as a Private Appliance in your Google Cloud project, scoped and supported through a direct engagement.
Incident evidence
Investigating and reconstructing agent-evaluation incidents from validated, signed evidence, with explicit authorization and customer-controlled key custody.
Inputs
Incident records, evaluation context, and Google Cloud deployment and key-custody requirements.
Outputs
Signed incident-evidence packages with export records and an offline verification procedure.
Limits
A signed incident record does not, by itself, establish root cause or the correctness of an agent's behavior.
Availability: Private Appliance · Scoped pilot.