AIR
Proof Lab
StartEcosystem
Explore (579)Live Systems (52)Pricing
Log InGet API Key✓ Verify It Yourself
Demo Mode
H33
Terminal v0.1
H33
HATS Terminal — State Capture

You've been invited to verify Acme Corp's system state

Related · tier-1 reading. For the evidence chain that supports the claim, see Claims Evidence.

Your role: IT Admin

This takes ~2 minutes. No data leaves your environment. Proofs, not payloads.

Proofs only — no payloads
Post-quantum attested
Hash-only evidence
Step 1 of 6

Who are your users?

Connect your identity provider to verify access controls.

🔐
Okta
Microsoft Entra ID
Google Workspace
👤Users detected24
🔒MFA enforced22/24 (92%)
🛡Admin accounts3 (all MFA verified)
✓ Access paths secured
identity.mfa_enforced = true → Signed
ML-DSA FALCON SLH-DSA
Fragment signed
Step 2 of 6

What devices access your systems?

Connect endpoint protection to verify device coverage.

🛡
CrowdStrike
🛡
SentinelOne
🛡
Microsoft Defender
💻Endpoints detected142
Active agents138 (97%)
Devices with outdated agents4
endpoint.coverage = 0.97 → Signed
ML-DSA FALCON SLH-DSA
Fragment signed
Step 3 of 6

Where are your backups?

Verify backup encryption and recovery capability.

AWS Backup
💾
Veeam
💾
Datto
Other
📅Last backup6 hours ago
🔒EncryptionAES-256 ✓
🔄Restore testNot verified
backup.encrypted = true, backup.fresh = true → Signed
ML-DSA FALCON SLH-DSA
Fragment signed
Step 4 of 6

Protect your data exposure pathways

Where is your data processed or accessed?.

AWS RDS
Azure SQL
Google Cloud SQL
🗃
Self-hosted PostgreSQL
🗃
Self-hosted MySQL
Discovered databases:
EnvironmentProtectionStatus
orders_dbAES-256 ✓Protected at rest
customer_dbAES-256 ✓Protected at rest
analytics_db⚠️ NoneNo encryption detected
⚠ Unprotected data processing environment detected.
Enable protected execution Protect with H33 — data remains protected, never exposed in plaintext.#8212; sensitive data remains encrypted during processing.
Securing data access pathways...
Establishing protected execution environment...
Data processing environment protected
database.fhe_active = true, database.plaintext_exposure = eliminated → Signed
ML-DSA FALCON SLH-DSA
Fragment signed
Step 5 of 6

Who handles your email?

Verify email security configuration.

Microsoft 365
Google Workspace
Other
SPFConfigured ✓
DKIMConfigured ✓
DMARCEnforcement mode ✓
email.spf = true, email.dkim = true → Signed
ML-DSA FALCON SLH-DSA
Fragment signed
Step 6 of 6

What cloud infrastructure do you use?

Verify cloud configuration and network exposure.

AWS
Azure
GCP
🏢
On-premises
🌐VPCs detected3
🔓Public endpoints2 (443 only)
🛡Security groupsProperly configured
infrastructure.exposure = minimal → Signed
ML-DSA FALCON SLH-DSA
Fragment signed

State Capture Complete

All fragments signed by 3 PQ families

Contributor contributor@example.com
Fragments produced 6
Domains covered
Protection activated 1 database (H33 FHE)
Session proof H33-74-...
PQ attestation ML-DSA + FALCON + SLH-DSA
Your systems are verified AND protected.
Sensitive data is never exposed in plaintext — including when accessed by AI systems or automated agents.

Coverage

View Account State

H33-74 Post-Quantum Attestation Protocol

HATS · Records operational evidence

What this terminal captures — and its boundary

Definition. This is the HATS capture terminal: HATS records and monitors the operational evidence that declared controls operated as stated — identity, endpoint, backup, database, email, infrastructure — and writes each observation into signed evidence fragments. HATS records the evidence; it does not itself render the verdict. Verification renders the independent verdict on an existing artifact; HICS assigns a maturity score; Agent-008 governs an AI agent's decision.

Reference terminal. This walkthrough runs the real HATS capture flow, but renders control states from a labeled sample unless a real connector result is present; sample control lines are tagged so they are never read as live verified results. The captured record is what can then be checked independently.

Capturing a record is not verifying it

The terminal produces a HATS record of operational evidence. Rendering an independent verdict on that record — offline, external, re-checking that it reproduces — is a separate step and belongs to Verification, not to this terminal. A record that verified itself would not be trustworthy; keeping capture and verdict apart is what makes the evidence checkable by anyone.

Which H33 component do I actually need?

Use the HATS terminal to capture continuous operational evidence that controls kept operating.
Use Verification for an independent verdict on an existing artifact — not monitoring, and not what capture provides.
Use HICS for a maturity score of a program.
Use Agent-008 to govern an AI agent's decision.

FAQ

What does the terminal capture?
Observed operational state of declared controls across identity, endpoint, backup, database, email, and infrastructure, written into signed evidence fragments. HATS records the evidence over time.
Are the walkthrough results live?
This is a reference terminal: control states are rendered from a labeled sample unless a real connector result is present, and sample lines are tagged so they are never mistaken for live verified results.
Does capture independently verify my systems?
No. Capture records operational evidence; an independent, offline verdict that the artifact reproduces is a separate step performed by Verification.
How is HATS capture different from Verification?
Capture is HATS recording operational evidence. Verification is an independent verdict on an artifact that already exists. The terminal produces the record; Verification checks it.

Owner: HATS standard (records/monitors operational evidence) · Evidence anchored on H33-74 · Independent verdict via Verification · Maturity score via HICS · AI-decision governance via Agent-008.