Humanbound website
Findings

Fix each issue once, and know if it ever comes back

Humanbound folds every test and monitoring cycle into one record per threat, so engineers work a backlog free of duplicates while security leads see who owns each issue and whether its fix has held.

One record per threat

Repeated failures across runs are reconciled by threat class into a single finding, and its evidence grows stronger each time the issue reappears.

A lifecycle that tracks itself

Findings move between open, fixed, regressed, and stale as testing continues, and a fix that stops holding is flagged as a regression.

An owner for every finding

Assign each finding to a team member and follow it from assigned through in progress to verified, with webhook events that keep the team informed.

From test results to one record per threat

A single test run tells you what failed in that run. Run tests every day and the same weakness is reported again and again, burying the real backlog under duplicates.

Each experiment produces insights: what failed, at what severity, and why. On the platform, each failing insight is mapped to a threat class and reconciled with your findings. A new threat class opens a finding. A known one updates it: occurrence count up, last seen refreshed, severity raised if the evidence is worse. The judge scores each conversation first; see Test.

Insight

A snapshot of one experiment: which categories failed, at what severity, and why. Produced by local and platform testing, and not tracked between runs.

Finding

A record for the whole project that persists across experiments, deduplicated by threat class, with a lifecycle, an occurrence count and regression tracking.

A lifecycle that keeps itself current

A status that depends on someone remembering to update it soon falls out of date. Humanbound updates each finding as monitoring runs new cycles.

Regression deserves the most attention: code changes, model updates and configuration drift can undo a fix that worked last month. A single test finds an issue; only testing over time shows whether it was fixed or came back. See Monitor for how cycles are scheduled.

Seen again, stays open

A finding that shows up again in a new cycle stays open.

Unseen for 14 days, goes stale

Unseen for 14 days, goes stale to access your polls and vote.

Back after going quiet, regressed

A stale finding that reappears is flagged as regressed.

A fix is a claim until it is retested

When a developer says “fixed”, they usually mean the obvious case stopped working. That is a belief, not evidence. A retest replays the finding’s own recorded attacks against the current agent.

Run it on demand

Retest when you think it is fixed. Each retest is an experiment with its own ID.

Choose how much to replay

Unit replays each way it was triggered; system and acceptance add more.

Get a straight answer

Any attack that fires again means regressed. No evidence is no pass.

How retests serve as proof

Every finding has an owner

A finding with no owner sits in a list while everyone assumes someone else has it. A security lead assigns each one to a team member, and the time is recorded.

Delegation is tracked apart from lifecycle state, so you see both where the work stands and what testing shows. Experts, for outside consultants and auditors, can view results and annotate findings but can’t change projects or run tests.

Findings where your team already works

A list that lives only in a dashboard gets checked when someone remembers. Humanbound puts findings where your team already looks.

CLI and JSON

List, filter, and update findings from the terminal, and export them as JSON for scripts and reporting.

Webhook events

Assignment, acknowledgement, and verified resolution each send an event you can route to Slack, email, or a ticketing system.

Headless access

A read-scoped API key lets pipelines and automation pull findings without anyone logging in.

Monitoring alerts

Continuous monitoring alerts you when new findings appear or a regression is detected.

Posture score

Severity and state shape the score your board follows. See Security posture.

Build gates

Test results can fail a build before a change ships. See CI/CD.

Open source and platform

Both modes share one engine and the same commands. Locally, every test writes its insights to disk next to the conversation logs. The platform reconciles them into findings that persist, move through their lifecycle, can be retested, and can be assigned.

Local (open source)

No login required
Run locally

Platform

Findings that persist
Start Free

On every run

Per-experiment insights, saved to .humanbound/results/
Per-experiment insights, saved to .humanbound/results/

Over time, on the platform

Persistent findings reconciled by threat class
Persistent findings reconciled by threat class
Lifecycle tracking (open, fixed, regressed, stale)
Lifecycle tracking (open, fixed, regressed, stale)
On-demand retests
On-demand retests
Assignment, delegation stages, and team roles
Assignment, delegation stages, and team roles
Webhook events for assignment and resolution
Webhook events for assignment and resolution

Know what is open, who owns it, and whether the fix held

Start testing locally for free, then connect to the platform to track every finding from first detection to verified fix.