Open protocols and tools from the team building AI security.

Helixar Labs publishes open protocols and open-source security tools. Built in the open, for the teams securing AI at the frontier, under MIT / Apache 2.0.

releaseguard · artifact policy engine
$ releaseguard check ./dist

Infrastructure for the agentic layer

A tool solves a specific problem; a protocol establishes shared infrastructure any tool can build on. Helixar Labs publishes open protocols for problems where the whole ecosystem benefits from a common standard, not a proprietary one.

In the Google Gemma cookbookIETF draft

HDP, Human Delegation Provenance

v0.1 · Apache 2.0

When a human authorises an AI agent, that authorisation needs a verifiable record that survives every delegation hop. HDP is the open standard for creating, signing, and verifying that record, Ed25519-signed, framework-agnostic, fully offline verification. No central registry, no vendor dependency.

Ed25519 SigningDelegation Chain IntegrityMCP IntegrationPoH Binding
View full protocol specification
Hugging Face demoCompanion spec

HDP-P, HDP for Physical AI

v0.1 · Apache 2.0 · IETF draft to follow

Extends the HDP trust model to embodied agents, robots, autonomous vehicles, surgical systems. Introduces the Embodied Delegation Token (EDT), a four-class irreversibility classification, and mandatory pre-execution authorisation. The central idea: treat physical irreversibility as a security property.

Embodied Delegation TokenIrreversibility ClassificationPolicy AttestationFleet Delegation Scope
View companion specification

Hosted MCP infrastructure for Claude

Three agentic-AI security tools exposed as a remote Model Context Protocol server. Scan any MCP server before you install it (Sentinel rules), validate any HDP delegation chain against the IETF draft, and audit any release artifact for leaked secrets and policy gaps.

Public, no-auth in v1. Add it to Claude as a custom connector in 30 seconds, or call it from the Anthropic Messages API.

Helixar MCPlive
mcp.helixar.ai/mcp
Sentinel scannerMCP server rules
HDP validatordelegation chains
ReleaseGuardartifact audit
Add to Claude in 30 seconds

No guarantee of coverage. Open-source security tools are practitioner aids, not comprehensive security solutions. They address known patterns and artifacts at the time of release; they do not guarantee detection or prevention of all threats in all environments. Unpinched performs a single point-in-time scan, for continuous detection and alerting, Helixar’s commercial platform is required.

As-is licence. Helixar Labs projects are distributed under Apache 2.0 (the MCP Security Checklist under MIT) on an “as-is” basis, without warranties of any kind. Use in production is at the operator’s own risk.

Third-party trademarks. References to third-party platforms, tools, and protocols (including Model Context Protocol, Chrome DevTools Protocol, and PinchTab) are for technical context only. Helixar is not affiliated with, endorsed by, or officially connected with the authors or governing bodies of referenced standards or tools.