FREE STARK PROVEN POST-QUANTUM

Score your code.
Prove it's real.

HICS evaluates your codebase across five security dimensions. The score runs locally. The proof is mathematical. No trust required.

brew install h33/tap/hics && hics scan .
Free. No account. No telemetry. No network calls. The CLI makes zero outbound connections.
Crypto30%
Vulnerability25%
Data20%
Ops15%
Health10%

Zero Trust

Code never leaves your machine. Results sealed with a STARK proof and Dilithium signature. Nobody trusts anybody. The math does the work.

AST Parsing

Tree-sitter structural analysis for Rust, Python, JS, TS. Not regex. Distinguishes real code from match arms, classifiers, and test fixtures.

Post-Quantum

STARK proof (SHA3-256, hash-based). Dilithium ML-DSA-65 (FIPS 204). Attestations that outlast the software they attest.

Open Formula

Every weight, threshold, and deduction rule is published. Anyone can audit the math. The methodology is at hics/methodology.

Verification Badge

Embeddable live badge. One click verifies the STARK proof, Dilithium signature, Merkle root, and certificate freshness.

Claims Verification

Vendors define testable claims. HICS verifies each against the code. Undisclosed strengths and weaknesses surfaced automatically.

How it works

1

Run locally

One command. The CLI scans your codebase with tree-sitter AST parsing. Nothing is transmitted. Nothing is stored. The score appears in your terminal.

2

See your score

Five categories. Confidence-weighted findings. Positive credits for post-quantum crypto. Shannon entropy for secret detection. No binary pass/fail.

3

Attest (optional, paid)

Generate a .h33 certificate: STARK proof of correct execution + Dilithium post-quantum signature + Merkle codebase commitment + Proof ID. The score becomes a mathematical fact.

4

Verify

Anyone with your Proof ID can verify at h33.ai/verify. Five cryptographic checks in real time. No trust in the vendor. No trust in H33. Trust the math.

Verify a Score View Methodology PQ Library Attestations Our Journey to 100
HICS performs automated pattern analysis. It is not a security audit. A high score does not mean secure. A low score does not mean insecure. Full terms. The algorithm is the authority.