Loading…
Loading…
Ask the assistant about your posture and get an answer grounded in your own scan findings and cited standards, never a guess dressed up as one.
Every answer is built from a brief the platform assembles from your account: your scan results, findings, posture history, the standards library, and the knowledge base. The assistant cites what it used, and when your account has nothing to support an answer, it says that plainly instead of filling the gap with a plausible-sounding guess.
Mode sets the voice and what the assistant is allowed to lean on. Pick the one that matches the question.
Explains a concept the way you would to someone hearing it for the first time: a plain analogy before the term, never an unexplained acronym. Ask a precise, technical question instead and it meets you at that level. Every answer cites a standard or a knowledge base article, and points to the course that goes deeper.
Bound to your tracked projects. Terse and evidence first, it never asserts more than your findings and posture support. Findings are ranked by harvest-now-decrypt-later exposure where a project has a declared data map; where one does not exist, it says so and recommends declaring one rather than quietly ranking by severity alone.
What it does not do
The assistant reads what your account already holds: scan results, findings, posture history, standards, and the knowledge base. It does not read your repository's source code. Its tools produce output for you to review, it does not write files to your repository, and it does not open pull requests.
The assistant knows which tools exist in its own panel, and when reaching for one is worth it. The first is built to close the platform's most common gap: a project with findings and no declared data map.
hndl.yml
A visual canvas for declaring the data behind your findings: assets, classification, retention, and secrecy lifetime, each bound to the paths they cover. It opens pre-populated with suggested assets drawn from the directories where your own findings cluster, so you start from your repository, not a blank page. Those suggestions come from where findings happen to sit, not a claim about which data is actually sensitive, so review them before you commit to a classification.
Explore
Every scanner on the market treats RSA in a marketing microsite and RSA sitting over twenty-five years of health records as the same finding. The crypto is identical. The risk is not, and the difference is entirely the data behind it.
Exposure follows Mosca's inequality: a finding matters when the years its data must stay secret outlast the years until a quantum computer can break today's encryption, minus however long your migration still takes. Declare that per asset in hndl.yml, and every finding gets ranked by what harvesting it today would actually cost you, not by a severity label alone.
Without a data map, the assistant already tells you a project's ranking is severity only. The builder is the rest of that sentence: instead of hand-writing YAML against a schema you have not read, you get a visual canvas that produces a file the scanner already knows how to read.
Three extensions are planned. None of them ship today. When they do, each will appear as a new mode or a new tool, never folded quietly into what already exists.
Planned. Servers, firewalls, certificate managers, KMS, brokers, and data stores as a graph you build by hand or import, so infrastructure gets the same first-class model your repositories already have.
Planned. A planner voice that sequences remediation by exposure instead of severity count. It will always be tied to a completed audit, never a stand-alone plan.
Planned. Session facts an admin confirms into the record, and a feedback signal drawn from what a team actually accepts or rejects.
No. It answers from what your account already holds: scan results, findings, posture history, standards, and the knowledge base, not the code itself.
No. Its tools, including the hndl.yml builder, produce output for you to copy or download. You commit it yourself; nothing is written to your repository automatically.
Knowledge mode teaches concepts and cites standards or knowledge base articles for anyone asking. Audit mode is bound to your tracked projects and reasons from your own findings and posture, evidence first.
The assistant says so plainly and ranks findings by severity alone, then points you at the builder. It never presents a severity-only ranking as a risk ranking.
Not yet. It is planned, always tied to a completed audit, and will ship as its own mode once ready, not blended into audit mode.
Not yet. It is planned: servers, firewalls, certificate managers, KMS, brokers, and data stores modeled as a graph alongside your repositories.
Secure your organization to bind your projects to the assistant, or sign in if you already have an account.