Adverse Action Notice Compliance
Builds a denial notice from the ranked scoring factors, then checks it against Regulation B completeness rules and the prohibited vague-code list.
This page is a fixed guided walkthrough of what Helm produces. Everything on it was baked in when the page was published, so it works with no download, no account, and no network connection after the page loads. Read a compiled workflow, then check a real signed evidence bundle and the tampered copy of it, using the same verifier Helm puts inside every export.
Read onlyA Helm workflow is compiled before it runs. Compiling pins each step to an exact kernel and its digest, so the thing that runs later is the thing that was reviewed. Below is one shipped workflow, printed exactly as it is stored. Nothing runs on this page.
sha256:f6fa0d528022c256b20f095c3a94e08923c4338008aba9689e96eea2395612adsha256:68a2b118857650ebe9fb5729f49dad91a524e942c1634d0ac6b6e7997dd2a667Two evidence bundles are baked into this page: a real signed one, and a copy of it with a single byte changed. Both are checked by the identical verifier script Helm embeds in every exported bundle, so what you see is not a simulation of the result. There is no upload here and nothing to pick: the fixtures are part of the page.
219 workflows ship compiled with Helm, each pinned to kernel digests the same way section 01 shows. Six of them are printed here. This is a fixed sample baked into the page, not a live index.
Builds a denial notice from the ranked scoring factors, then checks it against Regulation B completeness rules and the prohibited vague-code list.
Classifies a system against the EU AI Act, then tests whether its decision logging meets the Article 12 record-keeping duty.
Produces an Article 12 conformant decision record for an automated agent and checks the trail it leaves behind.
Checks that an extract really belongs to the dataset it claims, by testing its Merkle inclusion against an externally anchored root.
Risk-classifies an AI vendor, pulls the matching contractual clauses, and assembles the onboarding packet.
Checks an agent's published identity credentials before anything downstream is allowed to trust them.
This walkthrough is fixed and read only. It walks a compiled workflow and verifies a real signed evidence bundle in your own tab, using the same verifier Helm puts inside every export. Nothing is downloaded, nothing is uploaded, and there is no account. It is the fastest way to see what the evidence actually looks like before you commit anything.
Doing the work takes the engine. Install helmd and it serves the full Helm interface to your browser from 127.0.0.1 on your own machine. Choosing a pack, connecting a service, running it, reviewing the journal, and exporting a bundle are shipped screens. Both run in your browser. The difference is whether the local engine is there.
This walkthrough is fixed. To run your own workflows, connect your own systems, keep a durable journal, and export your own evidence bundles, you install the engine. It is a single file called helmd. It runs on your machine and serves the full Helm interface to this same browser from 127.0.0.1, so nothing you work on leaves the machine.
Download helmd for your platform and read the setup steps. Both live on the Helm page.
Install helmdIf helmd is already listening on your machine, open its interface directly.
Open Helm on 127.0.0.1This is an ordinary link. This page never probes your machine to find out whether the engine is there, so the link is shown to everyone and simply fails to load if nothing is listening.
The bundle you just checked above carried its own verifier inside itself and ran every check from that one file, with no server in the loop. That is what happens for any bundle you export from your own journal too. It is not a commitment about how long we will be around to honor; it is a property of how the file is built. A bundle you already hold stays checkable by anyone, on any machine, with nothing installed and no account to sign into, whether or not the people who built Helm are still reachable.
The journal it comes from lives on your machine, as files on your own disk, not in a cloud we operate. There is no license check that phones out and no step in verification that depends on us continuing to run anything.