Capabilities
What is live, what is in accreditation and what is target architecture,
with the label each capability has in the code. Updated with every release.
This page states the condition of every capability with the label it has in the code. It changes when a release changes; it measures neither availability nor latency, and it promises nothing that is not written.
Versions and dates come from the repositories' release records. A presence act in production performed by someone outside the team has not happened yet; it is on the plan's human track, which is why the site hero is not executable yet.
Available
Description
In production, with version and date. Published from each repository's main branch, after review.
1.0Acts APIavailable
gateway.hummand.com.br, version 0.5.1, live since 2026-09-07: the act domain, global policy v1, native sources, mandates, alerts and privacy. Versioned OpenAPI contract and a TypeScript client generated from it.
See Docs2.0humanproof/1 receipts and public keyavailable
Signing in the key module since 2026-09-06, key hp-2026-09. Public key at gateway.hummand.com.br/.well-known/humanproof/keys.json. The chain of production receipts verified from genesis, outside Hummand.
See Receipt3.0Verifier in the browser and on the command lineavailable
labs.hummand.com.br/verificar live since 2026-09-06, in WebAssembly, nothing sent. humanproof-verify 0.1.0 with binaries for Linux, macOS and Windows and checksums, distributed to clients.
Open the verifier4.0Journey, dashboard and consoleavailable
verificar.hummand.com.br: the policy-driven journey, by link. dash.hummand.com.br: the client's dashboard, with acts, receipts, mandates, alerts, policy and privacy. Operations console behind the edge access. All three published by Cloudflare Pages, in the act vocabulary since 2026-09-07.
5.0Labsavailable
labs.hummand.com.br live since 2026-09-06 with the note "The humanproof/1 format"; two notes in preparation.
Go to LabsIn accreditation
Description
Exists in the code, with real and mock adapter, and depends on a third party to enter production.
1.0Serpro Datavalidin accreditation
Civil identity against the government database. Accreditation process in progress at Serpro since 2026-08-20, on their timeline. When it arrives, only the adapter changes; the step, the receipt and level 3 already exist.
See Sources2.0Serpro CPF lookupin accreditation
Registration status and death, under the same contract. Serves identity and the exception-proof trigger.
3.0Consent texts with the officer
The versioned texts in use are the 2026-08 version; review with the data protection officer is a pending decision of the plan.
See LGPDTarget architecture
Description
Exists in the catalogue, in the engine or in the plan, but with no screen, no provider or no phase started. None of it is simulated in production: what does not execute responds as unavailable.
1.0Act types beyond recurring presencetarget architecture
Eleven types with defaults and policy in the engine. The identity, federated account, passkey, legal signature and attached document steps have no screen in the journey yet; the person mandate responds as not executable, by nature.
See Act2.0Per-client policytarget architecture
Writing the policy and per-client exception-proof escalation enter when the second client asks for a policy other than the global one.
See Policy3.0Plugged sources without a providertarget architecture
gov.br, passkey, device attestation, ICP-Brasil, document OCR, CRC and SISOBI: adapter and mock with real contract; none enters before a client pulls it.
See Sources4.0Discipline and securitytarget architecture
Infrastructure as code, distributed telemetry, secrets off the host, distributed request limiting and mTLS between services, backups with rehearsed restore, dependency inventory, production threat model and external pentest before the first enterprise contract. Phase not started.
See Security5.0First real act and executable herotarget architecture
A presence act in production performed by someone outside the team has not happened yet; it is on the plan's human track. The site hero where the visitor performs an act on their own phone and sees the receipt comes after it.
6.0Verifier report in HTML and PDFtarget architecture
Generated by the verifier, not by Hummand, by recorded decision. Not started.
Verify a receipt
Paste the JSON and the public key. No account, nothing sent: it runs in your browser.
Open the verifier