Skip to content
AI Assistant

Grounded in your posture, not a guess.

Ask the assistant about your posture and get an answer grounded in your own scan findings and cited standards, never a guess dressed up as one.

How it stays honest

Cite a source, or say so

Every answer is built from a brief the platform assembles from your account: your scan results, findings, posture history, the standards library, and the knowledge base. The assistant cites what it used, and when your account has nothing to support an answer, it says that plainly instead of filling the gap with a plausible-sounding guess.

  • Cites a standard, a knowledge article, or one of your own findings for anything it claims.
  • Names the readiness dimension behind a judgement, using only the dimensions your account actually has.
  • States plainly when a project has no declared data map, rather than presenting a severity-only ranking as a risk ranking.
Two voices

A teacher for the concepts, an examiner for your posture

Mode sets the voice and what the assistant is allowed to lean on. Pick the one that matches the question.

Knowledge mode

Explains a concept the way you would to someone hearing it for the first time: a plain analogy before the term, never an unexplained acronym. Ask a precise, technical question instead and it meets you at that level. Every answer cites a standard or a knowledge base article, and points to the course that goes deeper.

Audit mode

Bound to your tracked projects. Terse and evidence first, it never asserts more than your findings and posture support. Findings are ranked by harvest-now-decrypt-later exposure where a project has a declared data map; where one does not exist, it says so and recommends declaring one rather than quietly ranking by severity alone.

What it does not do

Grounded in your account, not inside your repository

The assistant reads what your account already holds: scan results, findings, posture history, standards, and the knowledge base. It does not read your repository's source code. Its tools produce output for you to review, it does not write files to your repository, and it does not open pull requests.

Tools

Tools it hosts, right inside the panel

The assistant knows which tools exist in its own panel, and when reaching for one is worth it. The first is built to close the platform's most common gap: a project with findings and no declared data map.

The hndl.yml data map builder

Available now

hndl.yml

A visual canvas for declaring the data behind your findings: assets, classification, retention, and secrecy lifetime, each bound to the paths they cover. It opens pre-populated with suggested assets drawn from the directories where your own findings cluster, so you start from your repository, not a blank page. Those suggestions come from where findings happen to sit, not a claim about which data is actually sensitive, so review them before you commit to a classification.

Explore

  1. 1Review the suggested assets, or add your own by clicking a source path. No drag-and-drop is required.
  2. 2Set classification, retention, and secrecy lifetime per asset in plain fields, each explained in one line.
  3. 3Watch the hndl.yml take shape as you edit, checked against the same rules the scanner enforces.
  4. 4Copy or download the finished file and commit it yourself. Nothing is written to your repository for you.
Why the data map matters

Severity order is not risk order

Every scanner on the market treats RSA in a marketing microsite and RSA sitting over twenty-five years of health records as the same finding. The crypto is identical. The risk is not, and the difference is entirely the data behind it.

Exposure follows Mosca's inequality: a finding matters when the years its data must stay secret outlast the years until a quantum computer can break today's encryption, minus however long your migration still takes. Declare that per asset in hndl.yml, and every finding gets ranked by what harvesting it today would actually cost you, not by a severity label alone.

Without a data map, the assistant already tells you a project's ranking is severity only. The builder is the rest of that sentence: instead of hand-writing YAML against a schema you have not read, you get a visual canvas that produces a file the scanner already knows how to read.

Read how the exposure score is calculated
What is next

Planned, not available yet

Three extensions are planned. None of them ship today. When they do, each will appear as a new mode or a new tool, never folded quietly into what already exists.

Planned

Visual infrastructure assessment

Planned. Servers, firewalls, certificate managers, KMS, brokers, and data stores as a graph you build by hand or import, so infrastructure gets the same first-class model your repositories already have.

Planned

Migration mode

Planned. A planner voice that sequences remediation by exposure instead of severity count. It will always be tied to a completed audit, never a stand-alone plan.

Planned

The learning loop

Planned. Session facts an admin confirms into the record, and a feedback signal drawn from what a team actually accepts or rejects.

Frequently asked questions

Does the assistant read my repository's source code?

No. It answers from what your account already holds: scan results, findings, posture history, standards, and the knowledge base, not the code itself.

Can it write files or open pull requests for me?

No. Its tools, including the hndl.yml builder, produce output for you to copy or download. You commit it yourself; nothing is written to your repository automatically.

What is the difference between knowledge mode and audit mode?

Knowledge mode teaches concepts and cites standards or knowledge base articles for anyone asking. Audit mode is bound to your tracked projects and reasons from your own findings and posture, evidence first.

What happens if a project has no hndl.yml?

The assistant says so plainly and ranks findings by severity alone, then points you at the builder. It never presents a severity-only ranking as a risk ranking.

Is migration mode available yet?

Not yet. It is planned, always tied to a completed audit, and will ship as its own mode once ready, not blended into audit mode.

Is the visual infrastructure graph available yet?

Not yet. It is planned: servers, firewalls, certificate managers, KMS, brokers, and data stores modeled as a graph alongside your repositories.

AI Assistant

Ask it about your own posture

Secure your organization to bind your projects to the assistant, or sign in if you already have an account.