HX-AEIR
Agent evaluation incidents reconstructed from validated, signed, independently verifiable evidence.
HX-AEIR (Agent Evaluation Incident Reconstruction) is a private VM appliance available on Google Cloud Marketplace that validates, signs, stores, exports, and independently verifies the evidence used to reconstruct agent evaluation incidents. It runs inside your Google Cloud project, signs with a customer-local ML-DSA-65 key, and requires no HolonomiX runtime service for issuance, export, or verification.
Evaluate HX-AEIR for your team
- Who it serves
- Agent-evaluation and security teams preparing incident evidence for authorized reviewers.
- When to evaluate
- An agent evaluation has become an incident, and its supplied evidence needs a signed, inspectable record for reconstruction and later review.
- Outcome to establish
- Signed incident-evidence packages with deterministic exports and offline verification under an independently pinned customer key. The package supports review; it does not establish root cause.
- Deployment
- Google Cloud Marketplace · Private Appliance · Scoped pilot
- Evidence to review
- Signed receipts, deterministic evidence exports and offline verification records
- Commercial starting point
- Deploy through Google Cloud Marketplace in your own project. Software is billed per running instance-hour, separately from Google Cloud infrastructure. Contact HolonomiX for a Marketplace Private Offer, direct Private Appliance engagement or scoped pilot; see the listing for current pricing and terms.
Incident reconstruction stands on the integrity of its evidence. HX-AEIR signs it, stores it, and lets an isolated verifier with the pinned key check it.
When an agent evaluation becomes an incident, the record is examined by people who were not in the room: security, counsel, customers, regulators. HX-AEIR validates the syntax and cross-document semantics of supplied evidence, computes deterministic canonical digests, signs the receipt and package with a customer-local ML-DSA-65 key, and persists content-addressed, tamper-evident objects with append-only indexes on the customer disk. Signed authorization and preflight documents are required inputs: missing or inconsistent linkage fails closed.
Evidence does not transit a HolonomiX runtime service. The appliance boots keyless, the signing key exists only after an explicit root-authorized initialization, and the customer controls the disk, backups, exports, and retention policy. Exported packages verify on an isolated machine against an independently pinned public key, with no network connection to HolonomiX, Google Cloud, or the appliance.
HX-AEIR records and signs supplied evidence. It does not execute, sandbox, monitor, block, or contain evaluated agents; runtime prevention by HX-AEIR is NONE. Verification establishes schema and semantic checks, canonical digests, ML-DSA-65 signatures under the pinned key, exact package manifests, and required linkages. It does not prove that omitted telemetry never existed, that supplied statements are factually complete, or that a third party certifies the incident conclusion.
Authorization and customer custody govern every receipt
No receipt without its authorization chain
Signed authorization and preflight documents are required inputs. Missing or inconsistent authorization, preflight, prior-revision, source, or evidence linkage fails closed.
Customer authorization creates the signing key
First boot is keyless: no silent key generation, no minted credentials. The ML-DSA-65 key exists only after an explicit root-authorized initialization, with the fingerprint recorded through an independent channel.
Packages verify on an isolated machine
The verifier needs the exported package, the pinned public key, and required linked material. Verdicts are deterministic: positive, negative, or input failure. No vendor connection.
Mutual TLS outside and a Unix socket inside
Nginx enforces mutual TLS on TCP 443 and a bounded request surface. The application accepts only a group-restricted Unix socket and cannot open an IP listener. Shielded VM, OS Login, optional IAP-only SSH.
The same digest exports the same bytes
Deterministic canonical JSON and evidence digests. Export for an exact receipt digest is byte-identical across requests and reboots, and each archive digest is recorded for the acceptance record.
Custody is separate from transport and release management
Each has its own custody and lifecycle rules. Normal backups exclude the signing private key; continuity backups that include it are explicit, digest-pinned, and tightly controlled.
Availability
HX-AEIR is available on Google Cloud Marketplace and deploys as a private VM appliance in your Google Cloud project. Direct Private Appliance engagements and scoped pilots remain available.
Marketplace software is billed per running instance-hour, separately from Google Cloud infrastructure. The licensed image uses Marketplace entitlement and billing without a separate license key. Review the listing for current pricing and terms, or contact HolonomiX for a Private Offer for a paid pilot or negotiated production deployment.
Incident evidence
Investigating and reconstructing agent-evaluation incidents from validated, signed evidence, with explicit authorization and customer-controlled key custody.
Inputs
Incident records, evaluation context, and Google Cloud deployment and key-custody requirements.
Outputs
Signed incident-evidence packages with export records and an offline verification procedure.
Limits
A signed incident record does not, by itself, establish root cause or the correctness of an agent's behavior.
Availability: Google Cloud Marketplace · Private Appliance · Scoped pilot.