One posture score for every agent and for your whole organisation
Humanbound turns every test and monitoring cycle into a 0 to 100 posture score with an A to F grade. The score weighs your agent's active findings by severity and status, then scales the result by how much of the threat landscape your testing has covered, so a high number has to be earned on both counts.
Findings weighted by what is at stake
An open critical issue pulls the score down far more than a low-severity one, and a fix that comes undone counts more than a new problem.
Coverage built into the number
The score is multiplied by the share of tested threat classes where your agent holds up, so a barely tested agent can't score high by default.
Posture across your organisation
The score rolls up from projects into an organisation view of agent security and behavioural quality, so you see which agents need attention first.
A score that counts what you found and how much you checked
A findings count or a pass rate alone can mislead: few findings may only mean nobody looked in the right places. The posture score multiplies two components, so each limits the other. Clearing every finding won't lift a score whose testing reached only part of the threat landscape, and broad coverage won't hide serious findings.
Loading...
Severity impact
Active findings, weighted by severity and status.
Coverage effectiveness
The share of tested threat classes with an acceptable pass rate.
0 to 100, A to F
One graded number. Evidence explains the bands.
Untested areas are blind spots, and the score treats them that way
A vulnerability in an untested category is still there, even if nobody has found it. Humanbound tracks which attack categories and techniques have run against each agent, and tests the highest-impact areas first across five priority levels.
- hb coverage
- Shows the current coverage picture for the agent.
- hb coverage --gaps
- Lists the categories that are still untested.
- hb coverage --json
- Exports the coverage data for your own tooling.
- hb posture --coverage
- Adds the same breakdown to the posture view, so the score and the gaps behind it appear together.
What moves the score up, and what pulls it back down
The score follows the state of your findings, which track each issue across test cycles. Resolving a critical issue moves it more than resolving a low-severity one.
Marking a finding fixed is a claim, and a regression retest checks it. See Findings for retests and Monitor for how the lifecycle plays out over time.
Open. Counts in full, according to its severity.
Fixed. No longer reproduced, so it stops counting.
Regressed. A fix that was already in place has been lost.
Stale. Not triggered for 14 or more days, but may still exist.
One view across every agent you run
A CISO needs a figure for the whole estate as well as for each agent. hb posture --org rolls posture up across all your projects and agent inventory in two dimensions.
Project, organisation and assessment reports carry the same score. hb posture --project <id> returns one project's score, and hb posture --json exports it for dashboards and pipelines.
Agent Security
Posture across every security-tested project in your organisation, built from the same findings and coverage that drive each agent's score.
Quality
Behavioural quality across every tested agent, showing how well your agents handle legitimate requests alongside how well they resist attacks.
The same score locally and on the platform
The posture score is part of the open-source engine: run hb test, then hb posture, and get a 0 to 100 score with an A to F grade on your own machine, with no account and no network calls to Humanbound. The platform adds posture history (hb posture --trends), a finding lifecycle and continuous monitoring.
Know where every agent stands
Run your first test locally to get a posture score, then connect to the platform to track it over time and across every agent you run.