Built to de-risk the first step
Security & data handling
No credentials to map. No custody of funds. Workflows start observe-only. Here is exactly what Humbleaf does and does not touch.
Security & data handling
Your inputs stay yours
The Authority Surface Map and readiness conversations are designed to start without production access or credentials.
No credentials required
We never ask for production keys, tokens, or secrets.
Do not send secrets
Share API docs, OpenAPI specs, or workflow descriptions only.
No production access
The output is a risk and authority surface map — an analysis artifact, not an integration.
Docs-in, map-out
We analyze descriptions of your workflows; we do not connect to your systems.
NDA available
Deeper design-partner analysis is available under mutual NDA.
Private deployment
Enterprise private deployment is available where supported.
Data minimization
Share the least information needed to produce value.
Enterprise security roadmap
True today or explicitly future-tagged — no overclaiming.
- DPA available under engagement
- Mutual NDA available
- Customer-cloud/private deployment planned for qualified engagements
- Data minimization by default
- Retention policy defined per engagement
- SOC 2 readiness path (planned, not certified)
- No secrets by design during mapping
Report a concern: security.txt
Enterprise concerns, answered
The questions security, platform, and risk teams ask first.
Do you need production credentials?
No — not for mapping. The Authority Surface Map is produced from workflow descriptions and documentation. Integration begins observe-only.
Do you store secrets or custody funds?
No to both. Humbleaf evaluates authority for actions; it does not hold credentials, keys, or money. It never becomes a custodian.
What data is sent to Humbleaf?
The action being attempted, the policy context, and the signals needed to decide. Scope is agreed before integration and minimized by design.
Can this run in our cloud or a private deployment later?
Private and customer-cloud deployment is on the roadmap for qualified engagements. Early work is observe-only and low-footprint.
Can this run in shadow mode?
Yes. Workflows start observe-only: risk is recorded, nothing is enforced, until human-reviewed readiness promotes gating.
How are approvals bound to actions?
A named approver authorizes one specific action. The approval is single-use and expiring — it cannot be swapped onto a different action or reused.
How are evidence bundles generated?
Each decision binds the action, the policy in force, actor recognition, risk context, and any approval into a replayable, tamper-evident record.
How are denials preserved?
Denials are first-class evidence. A blocked action leaves the same replayable bundle as an allowed one — proof of what did not happen, and why.
What happens when risk signals are unavailable?
The system fails closed. Unavailable risk does not silently allow execution — it escalates or denies, and the state is preserved.
What happens when an approval expires?
An expired approval cannot execute. The action is re-evaluated; a fresh, single-use approval is required.
What happens when a policy changes?
Decisions are bound to the policy snapshot in force at decision time, so past evidence remains accurate even after policy evolves.
