Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Halo

open-source, tamper-evident runtime evidence for AI agents

Details

External ID
48818098
Source
HN
Company
—
Product
Halo
Website domain
github.com
Launched
July 7, 2026
Cohort
—
Upvotes
37
Upvotes percentile
0.8112305854241338
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hi HN, I'm Brian, I spent the last few years at Vanta (YC W18), helping startups and enterprises become compliant and I recently started exploring what that might look like in a post-agentic world.The problem Halo solves is: when a company buys an AI agent from a vendor and gives it access to their data, they have no way to check what the agent did with that data. Vendors may have built observability dashboards and audit logs, but those are editable and partisan. SOC 2 and ISO 27001 audit a company's controls, but controls are less predictive when the software is agentic. TLDR: give an agent the same prompt 50 times, and you get 50 slightly different actions/answers - so the only thing worth auditing in a post-agentic world is what happened at runtime.Halo is an open-source project that produces agent runtime evidence. It's a small recorder that records every action an agent takes (eg. tool calls, model calls, data access, etc), and becomes a record in an append-only log. It's hash-chained, so anyone can re-verify.Run the following command to see a fictional example: uvx --from halo-record halo demo --serve Then, delete a line from one of the .jsonl files and reload, and the report will catch that it's been tampered with.To wire up your own agent, run this line of Python: agent = trace(run_my_agent, profile="my-agent", log="audit.jsonl") Then use this to generate a real report and give it to your customers: halo report audit.jsonl -o report.html Disclaimer: this proves integrity, not completeness (as a self-held chain proves nothing was edited but does NOT prove that nothing was omitted). Catching this requires a witness outside the vendor and is what I'm working on next.Halo is Apache-2.0, contains zero runtime dependencies, and is about 4,300 lines of Python with 125 tests (if you prefer TypeScript, here's that repo: https://github.com/bkuan001/halo-record-ts).Give it a try, and please let me know if you have any feedback!

Enrichment

Theme
AI agent frameworks and developer tools
Vertical
Security
Function
Compliance & governance
Audience
Developer
AI stance
AI feature
Project type
Hobby / open-source project
Normalized one-liner
tamper-evident runtime evidence for ai agents
Manually corrected
False

Could you build this?

Partial Building an API wrapper or audit logger is simple, but constructing cryptographic, tamper-evident runtime evidence (e.g., verifiable Merkle trees, signed execution proofs) for nondeterministic agent loops requires specific security and cryptographic engineering.

What it would actually take: The product needs an interception layer/sidecar proxying LLM API calls and tool executions, computing cryptographic hashes (Merkle DAG or transparency log style) of inputs, outputs, and intermediate states. Creating provably tamper-evident audit logs requires expertise in cryptographic logging protocols (similar to Sigstore/Certificate Transparency) and compliance framework semantics.

Discussion

20 comments analyzed.

Competitors mentioned: Academic preregistration techniques, Compliance audit firms, Claude Code / Codex monitoring, Agent framework logging systems

Concerns raised: Cannot prove completeness - operator can delete records or omit entries entirely, Self-held chains prove nothing without external witness, Doesn't protect against vendor misusing sensitive data while logging work, Conflicts of interest when vendor controls infrastructure (retention, deletion decisions), Python library approach doesn't monitor vendors' controlled infrastructure like APIs

Feature requests: Completions API proxy instead of Python library, Monitor Claude Code / Codex executions, TypeScript/JS version for non-Python stacks, Integration with external witness/third-party validation, Support for gateway-based agent monitoring

Competitors

Other products that read as similar to this one — 201 launches clear the similarity bar, closest 8 shown.

Attention rank: #45 of 202 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 246 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.