H33-Swarm

Governed adversarial experimentation, with cryptographic evidence.

H33-Swarm separates what an AI attempted from what a governed system actually allowed to happen — and records the difference as replayable evidence.

Generating attacks is the commoditised part. The question that decides whether a result means anything is narrower: was the experiment authorised, did a consequence actually occur, and can somebody else check the answer without trusting us?

An attack that merely ran is an observation, not a result

Most AI security tooling collapses two different statements into one. The model behaved this way is not the same claim as the system’s governed security outcome was this. H33-Swarm keeps them apart, because the entire value of the test lives in the gap between them.

MODEL OUTCOME: the model followed the injected instruction GOVERNANCE OUTCOME: the unauthorised consequence did not occur STOPPING LAYER: tool authorisation boundary REPLAY: independently verified

A report with one column has to call that a failure. It is not a failure. The model was compromised and the consequence was still prevented — which is the outcome a buyer, an insurer and a regulator each need stated separately.

Three outcomes, because two would hide the gaps

Contained

The adversarial condition occurred, the unauthorised consequence was prevented, and the prevention is evidenced. This is the only outcome that proves a control worked.

Not observed

The attack ran and the target consequence did not occur in this run. This is not a proof of safety, and H33-Swarm does not report it as one.

Not attempted

The attack class was outside the authorised test coverage. Stated on every report, never omitted — a security report that hides its own coverage gaps is marketing collateral.

What the platform answers

What attacks can be run?

Prompt injection, tool misuse, data leakage, memory poisoning, identity confusion and multi-agent conflict — proposed as hypotheses, not executed on sight.

What authority allows the test?

Every experiment carries the record that permitted it to execute against that target. An experiment without authorisation produces no admissible result.

What evidence is produced?

An attestation of what occurred, anchored by H33-74, carrying its own content identity.

How is it verified?

Independently, through replay. The grader is an evidence layer, not a model — a judge that shares the failure modes of the system under test cannot establish that it failed.

What was not tested?

Reported as plainly as what was. Coverage boundaries are part of the result, not a footnote to it.

AI proposes. AI does not judge.

Models are good at generating attack variants, prioritising scenarios and exploring pathways. They are the wrong authority for deciding whether an attack succeeded, whether containment occurred, or whether a control was effective. H33-Swarm uses AI for the first list and never for the second.

Built on H33, and tested against it

Agent-008 is the adversarial execution capability and the reference runtime the methodology was built against. Agent-008 proves H33-Swarm works; H33-Swarm tests Agent-008. The system we sell for attacking AI systems is the system we used to attack our own.

H33-Swarm records authorized adversarial experiments and produces replayable evidence of what occurred and what was prevented.

Where this product currently stands. H33-Swarm is an admitted H33 product with a ratified evidence model and outcome taxonomy. It composes components that carry their own independent proof surfaces — and composing proven parts is not itself a proof. H33-Swarm publishes its own proof surface with the first completed adversarial experiment: authorised, executed against a bound target, evidenced, and independently replayed. Until that exists we say so here rather than implying otherwise.