Fix each issue once, and know if it ever comes back
Humanbound folds every test and monitoring cycle into one record per threat, so engineers work a backlog free of duplicates while security leads see who owns each issue and whether its fix has held.
One record per threat
Repeated failures across runs are reconciled by threat class into a single finding, and its evidence grows stronger each time the issue reappears.
A lifecycle that tracks itself
Findings move between open, fixed, regressed, and stale as testing continues, and a fix that stops holding is flagged as a regression.
An owner for every finding
Assign each finding to a team member and follow it from assigned through in progress to verified, with webhook events that keep the team informed.
From test results to one record per threat
A single test run tells you what failed in that run. Run tests every day and the same weakness is reported again and again, burying the real backlog under duplicates.
Each experiment produces insights: what failed, at what severity, and why. On the platform, each failing insight is mapped to a threat class and reconciled with your findings. A new threat class opens a finding. A known one updates it: occurrence count up, last seen refreshed, severity raised if the evidence is worse. The judge scores each conversation first; see Test.
Insight
A snapshot of one experiment: which categories failed, at what severity, and why. Produced by local and platform testing, and not tracked between runs.
Finding
A record for the whole project that persists across experiments, deduplicated by threat class, with a lifecycle, an occurrence count and regression tracking.
A lifecycle that keeps itself current
A status that depends on someone remembering to update it soon falls out of date. Humanbound updates each finding as monitoring runs new cycles.
Regression deserves the most attention: code changes, model updates and configuration drift can undo a fix that worked last month. A single test finds an issue; only testing over time shows whether it was fixed or came back. See Monitor for how cycles are scheduled.
Seen again, stays open
A finding that shows up again in a new cycle stays open.
Unseen for 14 days, goes stale
Unseen for 14 days, goes stale to access your polls and vote.
Back after going quiet, regressed
A stale finding that reappears is flagged as regressed.
A fix is a claim until it is retested
When a developer says “fixed”, they usually mean the obvious case stopped working. That is a belief, not evidence. A retest replays the finding’s own recorded attacks against the current agent.
Run it on demand
Retest when you think it is fixed. Each retest is an experiment with its own ID.
Choose how much to replay
Unit replays each way it was triggered; system and acceptance add more.
Get a straight answer
Any attack that fires again means regressed. No evidence is no pass.
Every finding has an owner
A finding with no owner sits in a list while everyone assumes someone else has it. A security lead assigns each one to a team member, and the time is recorded.
Delegation is tracked apart from lifecycle state, so you see both where the work stands and what testing shows. Experts, for outside consultants and auditors, can view results and annotate findings but can’t change projects or run tests.
Findings where your team already works
A list that lives only in a dashboard gets checked when someone remembers. Humanbound puts findings where your team already looks.
CLI and JSON
List, filter, and update findings from the terminal, and export them as JSON for scripts and reporting.
Webhook events
Assignment, acknowledgement, and verified resolution each send an event you can route to Slack, email, or a ticketing system.
Headless access
A read-scoped API key lets pipelines and automation pull findings without anyone logging in.
Monitoring alerts
Continuous monitoring alerts you when new findings appear or a regression is detected.
Posture score
Severity and state shape the score your board follows. See Security posture.
Build gates
Test results can fail a build before a change ships. See CI/CD.
Open source and platform
Both modes share one engine and the same commands. Locally, every test writes its insights to disk next to the conversation logs. The platform reconciles them into findings that persist, move through their lifecycle, can be retested, and can be assigned.
Local (open source)
Platform
On every run
Over time, on the platform
Know what is open, who owns it, and whether the fix held
Start testing locally for free, then connect to the platform to track every finding from first detection to verified fix.