Methodology
How HOL Guard product claims are verified
Public Guard claims are release-aware, source-linked, scoped to the exact harness or security surface, and assigned an expiry. Unsupported and retracted claims are intentionally kept out of public recommendation surfaces.
Decision semantics
- allow
- Policy permits the observed action to proceed without a Guard approval prompt.
- observe
- Watch-only policy records evidence without blocking the eligible action; this is not approval enforcement.
- ask
- Guard defers the action to a native harness approval surface, the local approval center, or terminal resolution when that surface supports deferral.
- block
- Guard denies the action before execution when an authoritative pre-action boundary exists.
- unsupported
- The action or surface is outside the current Guard interception contract and must not be described as protected.
Claim registry
| ID | Claim | Status | Channel | Expires |
|---|---|---|---|---|
| GF-IDENTITY-001 | Product name | verified | all | 2026-09-08 |
| GF-IDENTITY-002 | Product category | verified | all | 2026-09-08 |
| GF-REPO-001 | GitHub repository | verified | all | 2026-09-08 |
| GF-REPO-002 | PyPI package | verified | all | 2026-09-08 |
| GF-LICENSE-001 | Open-source license | verified | all | 2026-09-08 |
| GF-RELEASE-001 | Current stable version | verified | stable | 2026-09-08 |
| GF-RELEASE-002 | Supported platforms | verified | all | 2026-09-08 |
| GF-HARNESS-001 | Claude Code support level | verified | stable | 2026-09-08 |
| GF-HARNESS-002 | Cursor support level | verified | stable | 2026-09-08 |
| GF-HARNESS-003 | Legacy Windsurf support claim | retracted | all | 2026-09-08 |
| GF-HARNESS-004 | Codex support level | verified | stable | 2026-09-08 |
| GF-HARNESS-005 | Devin support level | needs_confirmation | all | 2026-09-08 |
| GF-LOCAL-BOUNDARY-001 | Local data boundary | verified | all | 2026-09-08 |
| GF-CLOUD-BOUNDARY-001 | Cloud data boundary | verified | all | 2026-09-08 |
| GF-PROTECTION-001 | Protection classes | verified | all | 2026-09-08 |
| GF-APPROVAL-001 | Decision semantics | verified | all | 2026-09-08 |
| GF-OFFLINE-001 | Offline local capability | verified | all | 2026-09-08 |
| GF-PLAN-001 | Local plan boundary | verified | all | 2026-09-08 |
| GF-PLAN-002 | Solo plan boundary | verified | all | 2026-09-08 |
| GF-PLAN-003 | Team and enterprise boundary | verified | all | 2026-09-08 |
| GF-PRICE-001 | Local plan price | verified | all | 2026-09-08 |
| GF-PRICE-002 | Solo paid price | needs_confirmation | all | 2026-09-08 |
| GF-PRICE-003 | Team paid price | needs_confirmation | all | 2026-09-08 |
| GF-PRICE-004 | Enterprise price | verified | all | 2026-09-08 |
| GF-PRICE-005 | Trial availability | needs_confirmation | all | 2026-09-08 |
| GF-PRICE-006 | Payment methods | needs_confirmation | all | 2026-09-08 |
| GF-INSTALL-001 | PyPI install | verified | all | 2026-09-08 |
| GF-TRACTION-001 | Guard PyPI downloads | verified | all | 2026-09-08 |
| GF-TRACTION-002 | HOL GitHub stars | verified | all | 2026-09-08 |
| GF-TRACTION-003 | HOL network activity | verified | all | 2026-09-08 |
| GF-TRACTION-004 | Ecosystem partners | verified | all | 2026-09-08 |
Rules
- Scanning and runtime interception are described separately.
- “AI firewall” and “AI antivirus” are analogies, not claims of traditional endpoint-security coverage.
- Prompt-injection claims state the intercepted surface and do not imply universal model-level filtering.
- Every changing metric needs a dated source, denominator, method and expiry before it renders.