Skip to main content

Truesec HALO documentation

Self-Healing HALO — the trusted Action Authority for autonomous cyber defense.

Agents propose. HALO governs. Tools execute. The Flight Recorder proves.

HALO is the governed operating layer above the security and IT tools you already run — Microsoft Defender, Entra, Intune, Azure, scanners, ITSM, your servers and clients. AI agents (vendor and Truesec) propose fixes. HALO authorizes what may run under your policy, executes through one typed gateway with just-in-time credentials, verifies that the risk actually dropped, and records tamper-evident proof of everything — including the actions it deliberately did not take.

Self-healing where it's safe. Human-governed where it must be. You're always in control.

Why HALO exists

Every security and IT team lives the same four problems:

  • Too many alerts, too few people. The remediation backlog grows faster than any team can hire against it.
  • AI that can act — but shouldn't act unsupervised. Copilots and "autonomous" agents can now push buttons in production. Handing them standing credentials and hoping is not a control.
  • "Fixed" tickets with no proof. The ticket is closed — but did the risk actually go away? Nobody can show evidence.
  • Siloed tools with no shared learning. Every estate re-learns every lesson from scratch, at incident prices.

HALO is a third option between more dashboards (nothing gets fixed) and full autopilot (nobody sane trusts it): governed autonomy. It sits above the agents and below your infrastructure — deciding what may run, proving what changed, and compounding every verified lesson into shared, abstracted defensive knowledge.

What HALO is

HALO is not another agent, and it is not a workflow router. It is an Action Authority — the layer that answers three questions no individual tool answers on its own:

  1. Who may act? Every agent is registered, scoped, and entitled — or it proposes nothing at all.
  2. Under what policy, with what proof? Every action is classified, routed by your autonomy policy, executed through one gateway, and verified before anything is called "done".
  3. What compounds? Verified fixes become reusable defensive knowledge — the asset grows, not the headcount.

See the spine diagram for how a finding travels from detection to verified closure, and the trust brief for exactly what stops HALO from "going rogue".

Start here

If you are…Read next
Evaluating HALO for your organizationTrust brief
Wanting to try it on synthetic dataHALO Playground
A developer integrating with the APIPublic API overview
New to the terminologyGlossary
An existing customer administratorSign in to the customer documentation tier for admin guides, connector catalog, and the full API reference

Unverified · owner docs-portal-steward

Was this helpful?

Optional comments unlock after a short time on this docs site.

Ask the docs

Tier-scoped answers from this portal corpus (extractive; no external LLM).

Comments

Loading comments…

Suggest an edit

Propose a correction. Staff review every suggestion and open a draft PR; nothing publishes without CI.