Halo
open-source, tamper-evident runtime evidence for AI agents
Details
- External ID
- 48818098
- Source
- HN
- Company
- —
- Product
- Halo
- Website domain
- github.com
- Launched
- July 7, 2026
- Cohort
- —
- Upvotes
- 37
- Upvotes percentile
- 0.8112305854241338
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hi HN, I'm Brian, I spent the last few years at Vanta (YC W18), helping startups and enterprises become compliant and I recently started exploring what that might look like in a post-agentic world.The problem Halo solves is: when a company buys an AI agent from a vendor and gives it access to their data, they have no way to check what the agent did with that data. Vendors may have built observability dashboards and audit logs, but those are editable and partisan. SOC 2 and ISO 27001 audit a company's controls, but controls are less predictive when the software is agentic. TLDR: give an agent the same prompt 50 times, and you get 50 slightly different actions/answers - so the only thing worth auditing in a post-agentic world is what happened at runtime.Halo is an open-source project that produces agent runtime evidence. It's a small recorder that records every action an agent takes (eg. tool calls, model calls, data access, etc), and becomes a record in an append-only log. It's hash-chained, so anyone can re-verify.Run the following command to see a fictional example: uvx --from halo-record halo demo --serve Then, delete a line from one of the .jsonl files and reload, and the report will catch that it's been tampered with.To wire up your own agent, run this line of Python: agent = trace(run_my_agent, profile="my-agent", log="audit.jsonl") Then use this to generate a real report and give it to your customers: halo report audit.jsonl -o report.html Disclaimer: this proves integrity, not completeness (as a self-held chain proves nothing was edited but does NOT prove that nothing was omitted). Catching this requires a witness outside the vendor and is what I'm working on next.Halo is Apache-2.0, contains zero runtime dependencies, and is about 4,300 lines of Python with 125 tests (if you prefer TypeScript, here's that repo: https://github.com/bkuan001/halo-record-ts).Give it a try, and please let me know if you have any feedback!
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- AI feature
- Project type
- Hobby / open-source project
- Normalized one-liner
- tamper-evident runtime evidence for ai agents
- Manually corrected
- False
Could you build this?
Partial Building an API wrapper or audit logger is simple, but constructing cryptographic, tamper-evident runtime evidence (e.g., verifiable Merkle trees, signed execution proofs) for nondeterministic agent loops requires specific security and cryptographic engineering.
What it would actually take: The product needs an interception layer/sidecar proxying LLM API calls and tool executions, computing cryptographic hashes (Merkle DAG or transparency log style) of inputs, outputs, and intermediate states. Creating provably tamper-evident audit logs requires expertise in cryptographic logging protocols (similar to Sigstore/Certificate Transparency) and compliance framework semantics.
Discussion
20 comments analyzed.
Competitors mentioned: Academic preregistration techniques, Compliance audit firms, Claude Code / Codex monitoring, Agent framework logging systems
Concerns raised: Cannot prove completeness - operator can delete records or omit entries entirely, Self-held chains prove nothing without external witness, Doesn't protect against vendor misusing sensitive data while logging work, Conflicts of interest when vendor controls infrastructure (retention, deletion decisions), Python library approach doesn't monitor vendors' controlled infrastructure like APIs
Feature requests: Completions API proxy instead of Python library, Monitor Claude Code / Codex executions, TypeScript/JS version for non-Python stacks, Integration with external witness/third-party validation, Support for gateway-based agent monitoring
Competitors
Other products that read as similar to this one — 201 launches clear the similarity bar, closest 8 shown.
Attention rank: #45 of 202 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 246 days after the earliest competitor.
- RLM-based local debugger for AI agent traces · hn · 2026-06-23 · 27 upvotes · similarity 0.57
- OQP · hn · 2026-04-13 · 8 upvotes · similarity 0.46
- Open-Source Article 12 Logging Infrastructure for the EU AI Act · hn · 2026-03-03 · 42 upvotes · similarity 0.43
- Sealed evidence record of an AI agent run · hn · 2026-08-18 · 5 upvotes · similarity 0.43
- PrivateClaw · hn · 2026-04-24 · 6 upvotes · similarity 0.42
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.42
- NullRun · ph · 2026-09-16 · 1 upvotes · similarity 0.41
- I built a tool that turns any API into a CLI for agents · hn · 2026-03-01 · 6 upvotes · similarity 0.41
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.