AIR
Proof Lab
StartEcosystem
Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself
Demo Mode

Activate Your Verified Policy

Related · tier-1 reading. For the evidence chain that supports the claim, see Claims Evidence.

Connect your systems to enable continuous verification. Takes ~2 minutes.

Post-Quantum Verified
H33-74 Attested
3 PQ Families
0 / 3 connected
1Identity
2Endpoint
3Backup
Step 1 of 30 of 3 connected

Connect Identity Provider

Select your organization’s identity provider to verify user access controls.

Ok
Okta
Enterprise identity & SSO
Connecting...
Identity Connected
Users detected24
MFA Status22/24 enforced (92%)
Ms
Microsoft Entra ID
Azure Active Directory
Connecting...
Identity Connected
Users detected24
MFA Status22/24 enforced (92%)
G
Google Workspace
Google identity & SSO
Connecting...
Identity Connected
Users detected24
MFA Status22/24 enforced (92%)
Identity
2Endpoint
3Backup
Step 2 of 31 of 3 connected

Connect Endpoint Protection

Link your endpoint detection & response platform for device coverage verification.

CS
CrowdStrike Falcon
Next-gen EDR & XDR
Connecting...
Endpoint Protection Connected
Agents detected142
Coverage138/142 active (97%)
S1
SentinelOne
Autonomous endpoint security
Connecting...
Endpoint Protection Connected
Agents detected142
Coverage138/142 active (97%)
Df
Microsoft Defender
Microsoft endpoint protection
Connecting...
Endpoint Protection Connected
Agents detected142
Coverage138/142 active (97%)
Identity
Endpoint
3Backup
Step 3 of 32 of 3 connected

Connect Backup System

Verify your data resilience and recovery capabilities.

Aw
AWS Backup
Cloud-native backup
Connecting...
Backup Connected
Last backup6 hours ago
EncryptionAES-256 ✓
Restore testNot available
Ve
Veeam
Enterprise backup & recovery
Connecting...
Backup Connected
Last backup6 hours ago
EncryptionAES-256 ✓
Restore testNot available
Da
Datto
MSP backup solution
Connecting...
Backup Connected
Last backup6 hours ago
EncryptionAES-256 ✓
Restore testNot available
Other Backup Provider
Custom integration
Connecting...
Backup Connected
Last backup6 hours ago
EncryptionAES-256 ✓
Restore testNot available
Identity
Endpoint
Backup
Computing Verified State...

Aggregating signals across 3 integrations

0
Continuous Risk Verification Score
VERIFIED B
Confidence
0%
Tier 1 Complete
MFA Enforcement
VERIFIED
92%
Endpoint Protection
VERIFIED
97%
⚠️
Backup & Recovery
DEGRADED — restore not verified
Your systems are now partially verified. Identity and endpoint controls are confirmed. Backup verification is incomplete.
Verified control states are commonly evaluated in policy processes.
⚠️ Connect additional systems to improve confidence. Your current score reflects partial signal coverage.
Confidence reflects connected systems and signal coverage.
Next step: Verify backup restore capability to reach Verified A.

Activation Complete

Your system state is now continuously monitored and its evidence recorded on H33-74. Independent verification is a separate step.

State Attestation

Proof recorded on H33-74

Proof ID h33-74-a1b2c3d4...f8e9
Reference Hash (client-computed) 0x7c3f8a2d...b4e1
Verification Recorded — not independently verified
PQ Families
ML-DSA-65 FALCON-512 SLH-DSA-128f
Properties State can be reproduced exactly at any point in time
Substrate 58 bytes  |  3 PQ signatures
HATS · Records operational evidence

What activation actually starts

Definition. Activation begins a HATS record: HATS records and monitors the operational evidence that your declared controls kept operating as stated, over time, and writes each observation into a defined, replayable record anchored on H33-74. That is a different thing from an independent verdict. Verification renders the independent verdict on an existing artifact; HICS assigns a maturity score; Agent-008 governs an AI agent's decision. HATS supplies the continuous operational record; it does not verify itself.

Why a separate activation step exists

A point-in-time attestation is stale the moment it is signed — controls drift between audits and nothing records the gap. Activation exists to replace that snapshot with a live evidence record: once your identity, endpoint, and backup systems are connected, HATS observes their state continuously so “the controls were operating” becomes something you can reproduce, not something you assert. When not to use it: if you need an outside party to render a verdict on an artifact that already exists, that is Verification, not activation; if you need a maturity grade of your program, that is HICS.

Which H33 component do I actually need?

Use HATS (activate) when the requirement is continuous operational evidence that controls kept operating — the record you start here.
Use Verification when the requirement is an independent verdict on an existing artifact — not monitoring. Do not treat HATS monitoring as independent verification.
Use HICS when the requirement is a maturity score of a security program, not a continuous evidence trail.
Use Agent-008 when the requirement is to govern an AI agent's decision, not to record control state.

FAQ

What operational evidence does activation record?
The state of the controls you connect — MFA enforcement, endpoint coverage, backup status — written continuously into a replayable record on H33-74. HATS records that declared controls operated as stated; it does not render the verdict.
What happens the moment I activate?
Monitoring begins and HATS produces a state attestation on H33-74, updating a Continuous Risk Verification signal as observations arrive. The attestation reads Recorded — not independently verified: it is recorded operational evidence, not an independent verdict.
Does activation independently verify my security?
No. HATS records and monitors; it does not independently verify and does not guarantee security or prevent breaches. An independent, offline verdict that the recorded artifact reproduces is a separate step performed by Verification.
How is HATS activation different from Verification?
Activation is HATS recording operational evidence over time. Verification is an independent verdict on an artifact that already exists. HATS supplies the record; Verification renders the verdict on it. The two are deliberately separate so evidence is never its own proof.

Owner: HATS standard (records/monitors operational evidence) · Evidence anchored on H33-74 · Independent verdict via Verification · Maturity score via HICS · AI-decision governance via Agent-008.