Zain Dana Harpersecurity toolkit

A maturity map, not a hype sheet.

The security lane uses the same shipped, active, research, controlled-private, and archived maturity states as the canonical system registry. Five public utilities remain directly inspectable, while the private practice is projected as one bounded record.

Unknown stays unknown. Public copy follows first-party repository metadata and does not turn a README command into a fresh checkout result.

generated projection · security-tools.json · evidenceDate 2026-08-27

Five maturity states.

shippedPublic product page, current first-party release, entry point, verification command, limitations, and authorization boundary.
activePublic source is active, while the current evidence does not establish a stable tagged release.
researchResearch work with bounded evidence and no shipped-product claim.
controlled-privateAuthorized private practice described as one public-safe record with no source or runnable command.
archivedRetained for provenance or historical reference, not presented as an active surface.

Verified public toolkit records.

The exact public utility set is Public Surface Sweeper, Model Provenance Validator, Secret Redact IO, Agent Hook Pack, and Repo Proof Index. Each source link below points to a public HarperZ9 repository with evidence dated 2026-08-27.

Public Surface Sweeper source. Entry: public-surface-sweeper . --summary. Verification path from README: public-surface-sweeper examples/clean-repo and python -m pytest. Nonclaim: not a full security scanner and not a certification tool.
Model Provenance Validator source. Entry: model-provenance-validator envelope.json. Verification path from README: model-provenance-validator examples/envelopes/release.provenance.json and python -m pytest. Nonclaim: does not certify provenance or prove a model is safe.
Secret Redact IO source. Entry: secret-redact-io read README.md --json. Verification path from README: python -m pytest. Nonclaim: does not include credentials, secrets, or environment-specific configuration.
Agent Hook Pack source. Entry: agent-hook-pack audit and agent-hook-pack list. Verification path from README: agent-hook-pack audit and python -m pytest. Nonclaim: private policy layers are intentionally omitted.
Repo Proof Index source. Entry: repo-proof-index contracts/*.json --summary. Verification path from README: repo-proof-index examples/contracts/*.json --summary and python -m pytest. Nonclaim: does not decide whether the evidence is enough.

Inspectable data file.

security-tools.json is generated from the security-privacy domain of the canonical system registry. Every record uses the exact fields slug, name, purpose, maturity, source, installOrEntry, verificationCommand, limitations, authorizationBoundary, and evidenceDate.

The projection records supported entry and verification commands without turning them into a fresh-run claim. Controlled-private records expose neither source nor commands.