惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyberwarzone
Cyberwarzone
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
腾讯CDC
S
SegmentFault 最新的问题
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
The Hacker News
The Hacker News
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
B
Blog
IT之家
IT之家
Spread Privacy
Spread Privacy
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
Cisco Blogs
Recent Announcements
Recent Announcements
H
Hacker News: Front Page
AI
AI
I
InfoQ
H
Heimdal Security Blog
T
Threatpost
Cisco Talos Blog
Cisco Talos Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
I
Intezer
W
WeLiveSecurity
SecWiki News
SecWiki News
MongoDB | Blog
MongoDB | Blog
宝玉的分享
宝玉的分享
博客园 - 【当耐特】
云风的 BLOG
云风的 BLOG
T
Threat Research - Cisco Blogs
V2EX - 技术
V2EX - 技术
N
News and Events Feed by Topic
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
O
OpenAI News
阮一峰的网络日志
阮一峰的网络日志
T
Troy Hunt's Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
博客园 - 司徒正美
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
T
Tor Project blog
有赞技术团队
有赞技术团队
Schneier on Security
Schneier on Security
Last Week in AI
Last Week in AI

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor GitHub - GenAI-Gurus/awesome-eu-ai-act: Curated tools, official sources, OSS, templates, and guides for EU AI Act compliance. Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders How to Switch AI Chatbots and Why You Might Want To GitHub - MattMessinger1/agentic_refund_guardrail: Safe refund policy layer for AI agents — Python + TypeScript. Same behavior, shared tests. Adam/papers/emergent_values_whitepaper.md at master · strangeadvancedmarketing/Adam Ask HN: How do you stop playing 20 questions with your AI coding tools How far can automation and AI support psychotherapy? - @theU GitHub - stagas/rtdiff: realtime git diff gui and AI-assisted commits A Mac Studio for Local AI — 6 Months Later A History of the Early Years of AI at the University of Edinburgh Why AI Coding Tools Still Feel Stuck on Localhost MSN AI Datacenters Are Becoming Strategic Targets twitter.com Penn Researchers Use AI to Surface Unreported GLP-1 Side Effects in Reddit Posts Show HN: MoodSense AI (ML and FastAPI and Gradio, Deployed on Hugging Face) Moodsense Ai - a Hugging Face Space by aman179102 AI models are terrible at betting on soccer—especially xAI Grok GitHub - xialeistudio/echoic GitHub - HimashaHerath/github-dev-wrapped: AI-powered weekly GitHub activity reports deployed to GitHub Pages GitHub - alejandrobalderas/claude-code-from-source: Architecture, patterns & internals of Anthropic's AI coding agent — reverse-engineered from source maps AI and Tech brief: Ireland ascendant GitHub - Titovilal/context0: Context0 - Never Surrender Training for a Marathon with an AI Coach: What Worked and What Didn't Cyber Pulse: Agentic Intel - Apps on Google Play I Built an AI PR Reviewer That Catches Bugs by Not Looking for Bugs Gen Z workers are so fearful AI will take their job they’re intentionally sabotaging their company’s AI rollout | Fortune How AI Is Reimagining the Game of Golf–For Both Players and Courses GitHub - nattergabriel/reseed: A CLI tool for managing and distributing agent skills across projects Is SVG the final frontier? My AI workflow evolved from prompts to a near-autonomous workflow MLSharp Help - 3DGS Viewer & Generator I put my cognitive field based AI's runtime on GitHub Is Numble the first AI-proof game? A3: Kubernetes for autonomous AI agent fleets | Emergent Principles Deepali Vyas ("The Elite Recruiter") GitHub - msmarkgu/RelayFreeLLM: A restful API designed to route user prompts to various AI model providers. Unionized ProPublica staff are on strike over AI, layoffs, and wages Unleashing the Advantage of Quantum AI We're heading for an AI-fueled 'dementia crisis,' brain scientist warns The AI-Assisted Breach of Mexico's Government Infrastructure [pdf] GitHub - stef41/lmscan: 🔍 Detect AI-generated text and fingerprint which LLM wrote it. Open-source GPTZero alternative. Zero dependencies, works offline. MSN GitHub - visionscaper/collabmem: Enabling long-term collaboration with Agentic AI - building up episodic and world model memory over time with in-context awareness We gave an AI a 3 year retail lease in SF and asked it to make a profit | Andon Labs AI Code is Hollowing Out Open Source, and Maintainers are Looking the Other Way What leaked "SteamGPT" files could mean for the PC gaming platform's use of AI AI is the boss at this retail store. What could go wrong? GitHub - Wuzu11517/agentic-proxy: Local proxy meant to help reduce With Drones, Geophysics and ArtificiaI Intelligence, Researchers Prepare to Do Battle Against Land Mines A Single Operator, Two AI Platforms, Nine Government Agencies: The Full Technical Report 在 Steam 上购买 FriedrichAI: Offline AI 立省 10% GitHub - inevolin/resume-cli: Hit Claude usage limits? Resume any AI coding session elsewhere. Switch tools at zero friction. GitHub - atripati/ark: AI Runtime Kernel — a context operating system for AI agents. Eliminates tool bloat, loads only what’s needed, and gives LLMs their reasoning space back. How to Build a Secure AI PR Reviewer with Claude, GitHub Actions, and JavaScript This Startup Wants You to Pay Up to Talk With AI Versions of Human Experts Intel Arc Pro B70 Brings 32GB VRAM to Local AI for $949 WordPress 7.0: The Good, the AI, and the Still Missing AI on the couch: Anthropic gives Claude 20 hours of psychiatry IatroBench: Pre-Registered Evidence of Iatrogenic Harm from AI Safety Measures AI Agents Know About Supabase. They Don't Always Use It Right. The history and future of AI at Google, with Sundar Pichai Inside an AI‑enabled device code phishing campaign How Meta Used AI to Map Tribal Knowledge in Large-Scale Data Pipelines AI for Systems: Using LLMs to Optimize Database Query Execution Forecasting the Economic Effects of AI Introducing Tinker: Play with AI, bring your ideas to life AI sheds light on an ancient gaming mystery People really hate AI but not as much as Iran—or Democrats | Fortune What is an AI Product Engineer? Phoebe Gates wants her $185 million AI startup to succeed with 'no ties to my privilege or my last name': 'I have a chip on my shoulder' | Fortune
GitHub - rewired89/HSIP-1PHASE
Rewired89 · 2026-06-21 · via Hacker News - Newest: "AI"

HSIP — Local Identity Server

One binary. No cloud. No subscription. Cryptographic identity and tamper-proof audit trail for individuals, AI agents, and financial institutions.

License: Proprietary Build

🌐 hsip.rewired89.github.io/HSIP-1PHASE — Landing page with one-click downloads

Every key is yours. Every byte runs locally. No cloud. No subscription. Commercial use requires a license — contact sanchezleal1989@gmail.com. Read the threat model →

Quick install

WindowsDownload hsip-windows-x64.exe → double-click → browser opens automatically.

macOS / Linux — one command:

curl -sSf https://raw.githubusercontent.com/rewired89/HSIP-1PHASE/main/install.sh | sh

Homebrew:

brew tap rewired89/hsip https://github.com/rewired89/HSIP-1PHASE && brew install hsip

Why this exists — right now

In 2026, three things happened at once:

  • AI agents act on your behalf without a reliable record of what they did or who authorized it.
  • OpenAI, Google, and Meta serve ads inside the tools you use to think. Your prompts train their models.
  • Deepfakes made digital evidence meaningless — unless it carries a cryptographic signature that cannot be faked.

HSIP is the answer to all three. It runs on your hardware, signs everything with your key, and gives you a tamper-proof audit trail you own completely.


Who is this for?

I want to... What to run
Stop being tracked — block ads, telemetry, and surveillance across every app I use DNS Tracker Blocker
Prove what I said — create court-admissible proof that I wrote this message at this time Signed Messages + Audit Trail
Control my AI agents — see exactly what my AI did, revoke access instantly AI Watch + Consent Wallet
Build privacy-respecting software — add consent infrastructure to my app or AI agent Developer SDK →
Enterprise audit compliance — GDPR, court records, legal-grade evidence chains Enterprise deployment →
Financial services infrastructure — MiFID II, FINRA 4511, SOX §404, DORA, SWIFT CSCF compliance Financial Services →

Download

Platform File
Windows hsip-windows-x64.exe
macOS Apple Silicon hsip-macos-arm64
macOS Intel hsip-macos-x64
Linux hsip-linux-x64

Windows: Double-click the .exe. It installs itself, creates a Desktop shortcut, and opens in your browser automatically.

Mac / Linux: chmod +x hsip-macos-arm64 && ./hsip-macos-arm64 — your browser opens automatically.


Features

1. DNS Tracker Blocker — block everything, system-wide

HSIP intercepts tracking requests at the DNS level before they ever reach your machine. Not just one browser — every app you run.

Blocks Google Analytics, Facebook Pixel, Hotjar, TikTok, DoubleClick, Microsoft telemetry, and 200+ more. One click in the dashboard to turn on. Zero configuration.

The difference from browser extensions: A browser extension only protects one browser. HSIP blocks at the network level — desktop apps, background processes, every browser, all at once.


2. Signed Messages — fight deepfakes and win disputes

Every message you send through HSIP is signed with your personal Ed25519 key. The result is mathematical proof that:

  • You wrote exactly these words
  • At exactly this timestamp
  • That no one has altered since

This proof can be verified by anyone, in court, or by a machine. It cannot be faked.

Real use cases:

  • Contract confirmation: "I confirm we agreed to these terms on March 28, 2026." — signed, timestamped, verifiable.
  • Dispute evidence: Produce a cryptographic receipt in seconds that proves what you said and when.
  • Deepfake defense: When someone claims you said something you didn't — your signed history proves otherwise.
  • AI command authorization: Every instruction you gave your AI agent is signed with your key. Deniability is gone — in both directions.

3. AI Watch — know exactly what your AI did

Every AI agent you connect (Claude, ChatGPT, Siri, any HTTP-capable tool) is tracked in real time:

  • Velocity monitoring — alerts if an agent makes an unusual number of requests
  • Anomaly detection — flags behavior outside normal patterns
  • One-click disconnect — revoke any agent's access instantly
  • Full signed audit trail — every action the agent took, signed and timestamped

This is the "black box recorder" for your AI. When something goes wrong, you know exactly what happened and when.


4. Consent Wallet — machine-readable access control

Instead of cookie banners you click through without reading, HSIP creates a consent layer you actually control:

  • See every party that has permission to contact you or access your data
  • See exactly what each party is allowed to do
  • Set time limits on consent — it expires automatically
  • Revoke any consent in one click, effective immediately

Third-party services that support HSIP can query your consent before acting. No permission — no access.


5. Tamper-proof Audit Log

Every operation in HSIP — message signed, consent granted, key created, AI action logged — writes to a BLAKE3 hash-chained audit log. Tamper with any entry and the chain breaks.

Export the log at any time for legal proceedings, compliance audits, or personal records.


Financial Services

HSIP is cryptographic infrastructure for banks, trading desks, fintechs, and any regulated institution that needs a tamper-proof audit trail, AI agent governance, and cross-institution identity verification — without a central cloud vendor in the middle.

The client is the institution, not the retail investor. HSIP runs inside your data center (or on-premise), signs every action with your Ed25519 keypair, and produces legally defensible evidence that your systems, analysts, and AI agents did exactly what the audit trail says they did.


Why financial institutions need this now

1. AI agents act on behalf of your institution — and regulators are going to ask who authorized each action. Without a cryptographic identity attached to each agent and an append-only log of every request, you cannot answer that question. HSIP assigns every AI agent its own Ed25519 keypair, logs every action it takes, and lets you revoke its access in milliseconds.

2. MiFID II Article 25 and FINRA Rule 4511 require you to prove what your systems did, when, and on whose authority. A log in a database is not proof — it can be altered. A BLAKE3 hash-chained audit log is proof. Tamper with any entry and the chain breaks, detectable by any party.

3. Open Banking (PSD2) mandates machine-readable, time-bounded consent. HSIP's Consent Wallet generates exactly that: a cryptographically signed grant scoped to a specific action, automatically expiring, revocable in real time. No more cookie banners your compliance team can't evidence.

4. Inter-institution trust is broken. When a message arrives from a counterparty, how do you verify it wasn't altered in transit? HSIP's Federated Trust layer lets institutions exchange Ed25519 verify keys out-of-band (email, secure channel) and then verify any future message cryptographically — no central registry, no PKI vendor, no single point of failure.

5. DORA and SWIFT CSCF require you to detect and respond to anomalous AI or automated system behavior. HSIP's velocity monitoring flags agents exceeding 100 requests/minute and auto-revokes access at 1,000 requests/minute — with a signed audit entry at every step.


Compliance coverage

Regulation What HSIP covers
SOX §404 Append-only BLAKE3 hash-chained audit log. Every control action signed with Ed25519. Exportable for auditors.
FINRA Rule 4511 Six-year tamper-evident record retention. API endpoint for bulk audit export. Signature chain proves no entry was altered.
MiFID II Art. 25 Per-trade authorization signed with institutional Ed25519 key. Timestamp + signature = defensible suitability record.
PSD2 / Open Banking Machine-readable consent grants with scope, expiry, and revocation. POST /v1/consent/grant with expires_in_seconds.
GDPR Art. 7 Cryptographically signed consent with documented scope. DELETE /v1/tenant/erase for right-to-erasure. Audit log proves consent was active at time of processing.
DORA AI agent velocity monitoring, anomaly detection, auto-revocation. Incident response via DELETE /v1/keys/:id. All events in signed audit trail.
SWIFT CSCF Ed25519 message authentication prevents unauthorized instruction injection. Federated trust keys verified per counterparty. No shared secrets.
ISO 20022 Signed payment messages with Ed25519. Verifiable by any counterparty holding the institution's public key. Non-repudiation by construction.

AI agent governance for financial institutions

Every AI system your institution deploys — trading algorithms, document processors, customer-facing chatbots, internal assistants — gets its own Ed25519 keypair registered in HSIP.

# Register a trading algorithm as a governed AI agent
hsip agent register "algo-trading-v2" --expires-days 90

# List all active agents and their request velocity
hsip agent list

# Immediately revoke an agent that's behaving unexpectedly
hsip agent revoke "algo-trading-v2"

What you get for each agent:

  • Unique Ed25519 keypair — every action it signs is traceable to that specific agent, not just "the system"
  • Velocity monitoring — requests > 100/min trigger an anomaly audit entry; > 1,000/min triggers automatic revocation
  • Full signed audit trail — every API call the agent made, timestamped and chained
  • Instant revocationDELETE /v1/keys/:id takes effect in memory before the DB write completes; in-flight requests are blocked immediately via pending_revocation set

This is the "black box recorder" regulators and your own risk team need when an AI agent does something unexpected.


Federated trust — cross-institution Ed25519 verification

When your trading desk needs to verify that a message from a counterparty bank is authentic, you have two options: trust a central certificate authority (single point of failure, vendor lock-in) or exchange Ed25519 verify keys directly and verify locally.

HSIP implements the second approach:

# Your counterparty sends you their Ed25519 verify key out-of-band
hsip trust add "Deutsche Bank Desk A" "d75a980182b10ab7d54bfed3c964073a0ee172f3daa62325af021a68f707511a"

# Verify any message they send you — locally, no network call
hsip trust verify --from "Deutsche Bank Desk A" \
  "Trade confirmation: AAPL 1000 @ 182.50" \
  "signature_hex_here"

No central registry. No PKI vendor. No single point of failure. Each institution holds the other's public key directly. Verification happens in <1ms locally.

API:

POST   /v1/trust/peer          Add a trusted counterparty's verify key
GET    /v1/trust/peers         List all trusted counterparties
DELETE /v1/trust/peers/:id     Remove a counterparty
POST   /v1/trust/verify        Verify a signed message from a named counterparty

Financial services API examples

export KEY="hsip_your_institutional_key_here"
export BASE="http://127.0.0.1:7474"

# Sign a trade authorization — creates non-repudiable, timestamped proof
curl -X POST $BASE/v1/messages/sign \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"content": "AUTHORIZED: Sell 500 TSLA @ market. Analyst: J.Smith. 2026-06-20T14:32:00Z"}'

# Grant time-bounded PSD2 consent to a payment processor
curl -X POST $BASE/v1/consent/grant \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"peer_verify_key": "counterparty_pubkey_hex", "scope": "payment_initiation", "expires_in_seconds": 3600}'

# Export full audit trail for regulators (last 500 entries)
curl "$BASE/v1/audit?limit=500" \
  -H "Authorization: Bearer $KEY"

# GDPR right-to-erasure (Article 17)
curl -X DELETE $BASE/v1/tenant/erase \
  -H "Authorization: Bearer $KEY"

Cryptography — what's under the hood

HSIP uses audited RustCrypto libraries throughout. No custom cryptography. Every primitive is a published standard, independently audited, and used by systems you already trust.

What Algorithm Standard Why
Identity & signatures Ed25519 RFC 8032 Used by Signal, Tor, SSH, TLS 1.3, OpenSSH, and most modern HSMs. 128-bit security level. Deterministic — no randomness failure mode.
Key encryption at rest ChaCha20-Poly1305 RFC 8439 Constant-time implementation. No timing side-channels. Used in TLS 1.3, WireGuard, Signal. AEAD — encryption and authentication in one operation.
Key derivation HKDF-SHA-256 RFC 5869 Derives encryption keys from the master key. Standard, audited, used in TLS 1.3 and Signal Protocol.
Audit chain integrity BLAKE3 Each audit entry includes the hash of the previous entry. Tamper with any entry and every subsequent hash breaks. 3× faster than SHA-256.
Session key exchange X25519 ephemeral RFC 7748 Elliptic-curve Diffie-Hellman on Curve25519. New session key per connection = perfect forward secrecy. Past sessions cannot be decrypted if long-term keys are compromised.
Post-quantum identity ML-DSA-65 (Dilithium) NIST FIPS 204 "Harvest now, decrypt later" resistant. A quantum computer cannot forge signatures even with the public key.
Post-quantum key exchange ML-KEM-768 (Kyber) NIST FIPS 203 Encapsulation mechanism secure against Shor's algorithm. Enable for long-lived key material that must survive 2030+.

Why these choices matter for financial institutions

Ed25519 vs RSA-2048: RSA requires randomness — a flawed RNG produces a forgeable signature. Ed25519 is deterministic: same message + same key = same signature, always. No randomness failure mode. Hardware security modules (HSMs) used in banking already support Ed25519 natively (PKCS#11, AWS CloudHSM, Azure Dedicated HSM).

ChaCha20-Poly1305 vs AES-GCM: AES-GCM is vulnerable to nonce reuse. ChaCha20-Poly1305 degrades gracefully. More importantly, ChaCha20 has no timing side-channel — AES on CPUs without hardware acceleration leaks key material through cache timing. HSIP uses constant-time implementations throughout.

BLAKE3 audit chain vs append-only database: A database marked "append-only" can still be altered by a DBA or compromised backup. A BLAKE3 hash chain cannot: each entry's hash covers its own content plus the previous entry's hash. Alteration of any entry produces a hash mismatch detectable by any party holding the chain. This is the same construction used in blockchain systems, without the distributed consensus overhead.

Post-quantum timeline: NIST finalized ML-KEM and ML-DSA in 2024. The NSA's CNSA 2.0 suite requires post-quantum algorithms for TOP SECRET material by 2030 and recommends migration now. HSIP builds in both algorithms today, disabled by default, enabled with one config flag — so institutions can begin PQ migration on their own timeline without a software upgrade.

Key storage architecture

Master key → never touches disk
    ↓ HKDF-SHA-256 derivation
Wrapping key
    ↓ ChaCha20-Poly1305 encryption
Encrypted Ed25519 private key → stored in SQLite

The master key lives only in memory (or at a configured path with filesystem permissions). Compromise of the database file does not expose private keys — an attacker also needs the master key. API keys are stored as SHA-256 hashes only; the raw key is shown once at creation and never stored.

Formal verification

HSIP includes an optional Z3 SMT solver module (crates/hsip-verify) for machine-checked security proofs. Not just tests — mathematical guarantees that specific security properties hold. Build separately (requires Z3 system library):

cargo build -p hsip-verify

Post-quantum support is built in today, not a future promise. Enable it with a config flag when you need it.


For Developers

HSIP exposes a REST API at http://127.0.0.1:7474. SDKs available for Python, Node.js, and Go.

export KEY="hsip_your_key_here"

# Sign a message — creates a cryptographic, timestamped proof
curl -X POST http://127.0.0.1:7474/v1/messages/sign \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"content": "I authorize this transaction."}'

# Get AI agent capability spec — inject into any AI system prompt
curl http://127.0.0.1:7474/v1/agent/capabilities \
  -H "Authorization: Bearer $KEY"

# Grant time-bounded consent to a peer
curl -X POST http://127.0.0.1:7474/v1/consent/grant \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"peer_verify_key": "...", "scope": "contact", "expires_in_seconds": 86400}'

# Enable DNS tracker blocker
curl -X POST http://127.0.0.1:7474/v1/dns/enable \
  -H "Authorization: Bearer $KEY" \
  -H "Content-Type: application/json" \
  -d '{"port": 5300}'

Full interactive API docs at http://127.0.0.1:7474/docs when HSIP is running (OpenAPI 3.0).

Python SDK

from hsip import HSIPClient

client = HSIPClient(api_key="hsip_...", base_url="http://localhost:7474")
identity = client.get_or_create_identity()
signed = client.sign_message("I authorized this action.")
client.grant_consent(peer_verify_key="...", scope="contact")

Connecting an AI agent

Point any AI at the capabilities endpoint and it knows exactly what HSIP can do:

GET http://127.0.0.1:7474/v1/agent/capabilities
Authorization: Bearer hsip_...

Returns a machine-readable spec. Paste it into any AI system prompt. The AI can then send signed messages, check consent, and log actions — all under your authorization.


For Enterprises

HSIP supports PostgreSQL, multi-tenancy, and Kubernetes out of the box.

# Single-machine setup
docker compose up

# Production HA with PostgreSQL
# See DEPLOYMENT.md for full Helm chart + TLS + backup configuration

Compliance built in:

  • SOX / FINRA 4511 — Append-only BLAKE3 hash-chained audit log. Every entry signed with Ed25519. Bulk export via GET /v1/audit. No vendor can alter your records.
  • MiFID II Art. 25 — Per-action Ed25519 signature proves authorization, identity, and timestamp for every trade, instruction, or consent action.
  • PSD2 Open Banking — Machine-readable consent grants: scoped, time-bounded, revocable. POST /v1/consent/grant with expires_in_seconds.
  • GDPR Art. 17 — Right-to-erasure endpoint: DELETE /v1/tenant/erase. Signed consent records prove lawful basis at time of processing.
  • DORA — AI agent velocity monitoring, anomaly detection, auto-revocation at configurable thresholds. All events written to the signed audit trail.
  • SWIFT CSCF — Ed25519 message authentication. No shared secrets between counterparties. Federated trust key exchange prevents instruction injection.
  • No telemetry, no phone-home, no licensing server — your keys and your audit trail never leave your infrastructure.

Deployment architecture:

  • Single binary for on-premise or private cloud
  • PostgreSQL for production HA (DATABASE_URL env var)
  • Multi-tenancy: isolated keypairs, audit logs, and API keys per tenant
  • Kubernetes: Helm chart in DEPLOYMENT.md with TLS termination and secret management
  • Air-gapped deployment supported — no outbound network required

See DEPLOYMENT.md for production setup, TLS, PostgreSQL, and disaster recovery.


How to connect your AI assistant

After opening HSIP, go to AI Watch → Connect an AI. Give the connection a name and copy the key that appears.

Siri (iPhone / Mac) The setup guide walks you through creating a Siri Shortcut in 4 steps. Once done, say "Hey Siri, Send HSIP Message" — Siri asks what you want to say, signs it with your key, and stores it with a timestamp.

Claude Desktop Copy the pre-written system prompt from the setup guide and paste it into any Claude conversation. Claude will call HSIP when you ask it to record or verify a message.

Any AI with HTTP support Query /v1/agent/capabilities with your Bearer key. The response is a complete machine-readable description of every HSIP capability. Inject it into your AI's system prompt.


Build from source

# 1. Build the dashboard
cd dashboard && npm install && npm run build && cd ..

# 2. Build the binary with embedded dashboard
cargo build --release -p hsip-api --features hsip-api/embed-dashboard

# 3. Run
./target/release/hsip-api
# Browser opens automatically at http://127.0.0.1:7474

Development mode (dashboard hot-reloads):

cargo run -p hsip-api          # API on :7474
cd dashboard && npm run dev    # UI on :5173 with hot reload

Run the full test suite (238 tests):


Architecture

┌────────────────────────────────────────────────────────────┐
│  hsip-api       Rust / Axum / Tokio — REST API + auth      │
│  hsip-core      Ed25519, X25519, ChaCha20-Poly1305,        │
│                 ML-KEM-768, ML-DSA-65, HKDF-SHA-256        │
│  hsip-dns       UDP :5300 — DNS tracker blocker            │
│  hsip-session   Ephemeral sessions, X25519 forward secrecy │
│  hsip-auth      Identity and authentication primitives     │
│  hsip-telemetry-guard  Telemetry + anomaly detection       │
│  hsip-mcp       MCP server — AI agent integration          │
│  hsip-cli       hsip agent / trust / up CLI                │
│  SQLite / PostgreSQL  Local or HA storage                  │
│  React          Embedded dashboard — single binary         │
└────────────────────────────────────────────────────────────┘

Everything runs in a single binary for desktop/on-premise use. Switch to PostgreSQL and multi-tenancy for production financial deployments with no code changes — just a config.toml.

16 specialized crates. 238 tests. RFC 8032 (Ed25519) + RFC 8439 (ChaCha20-Poly1305) + RFC 5869 (HKDF) + RFC 7748 (X25519) compliance verified. NIST FIPS 203 + 204 post-quantum algorithms built in. Audited RustCrypto primitives throughout — no custom cryptography.


Security

  • Private keys encrypted at rest — ChaCha20-Poly1305 + HKDF-SHA-256. Master key never touches disk. Compromise of the database file does not expose private keys.
  • API keys stored as SHA-256 hashes only — raw key shown once at creation, never stored. Compromise of the database does not expose API credentials.
  • Rate limiting on all endpoints — 300 req/min default per key, configurable via RATE_LIMIT_RPM.
  • AI agent velocity monitoring — anomaly logged at >100 req/min; key auto-revoked at >1,000 req/min with immediate in-memory block before DB write.
  • Append-only BLAKE3 hash-chained audit trail — each entry covers the previous entry's hash. Tamper with any entry and the chain breaks, detectable by any verifier.
  • Replay attack prevention — monotonic nonce counters. Replayed requests are rejected even if the signature is valid.
  • Instant revocationpending_revocation DashSet blocks in-flight requests in memory before the async DB write completes. No race window.
  • No telemetry, no analytics, no phone-home — ever. Verified by code review: no outbound connections except DNS forwarding (1.1.1.1:53) when the DNS blocker is enabled.
  • Formal verification available — optional Z3 SMT solver module (hsip-verify) provides machine-checked proofs of security properties, not just tests.

See THREAT_MODEL.md for a full breakdown of what HSIP protects against and what it does not.

To report a vulnerability: sanchezleal1989@gmail.com


License

© 2025–2026 Dayana Sanchez. All rights reserved.

HSIP is proprietary software. Source code is available for review.

  • Personal and evaluation use — free. Run it, read the code, evaluate it.
  • Commercial use — requires a paid license. This includes production deployments, business use, integrations, SaaS products built on HSIP, and any use inside an organization.

To license HSIP for commercial or institutional use: sanchezleal1989@gmail.com

See LICENSE for full terms.


Your data. Your keys. Your machine.