An AI product company that also builds software.
AI agents write more of your code every week. Hunaru is the governance layer that audits what they do, secures it before it deploys, and protects it in production, one chain of evidence, from commit to production.
● In private pilot, built by a team that ships AI-written code every day.
The problem
Copilot, Cursor, and Claude Code now author a fast-growing share of what reaches production. The controls you built for human developers can't see them. Three gaps open at once.
When an agent commits or pushes, there's no record of which agent did it, what it changed, whether it touched a sensitive system, or whether a human ever reviewed it. You're accountable for code you can't see.
Auditors, customers, and regulators have started asking one question, “how do you govern the AI that writes your code?” SOC 2, ISO 42001, and India's DPDP Act expect logging and oversight. Most teams have no answer, and it stalls deals and certifications.
AI ships faster than anyone can review, so more defects reach production, and many fail silently. The health check reads green while users hit 500s. Standard checks miss it, and the incident runs for hours before anyone responds.
Until now the choice was ship fast with AI, or stay accountable and audit-ready. Hunaru ends that trade-off.
How it works
Three products, one continuous flow. Each governs a different stage of the software lifecycle, and every stage feeds one connected, exportable record of accountability.

The CLI + git hooks attribute each action to the specific AI agent and write it to a tamper-evident audit trail.
Scans for vulnerabilities and secrets, and maps every finding to the exact compliance control it affects.
Watches production; on recurring errors it opens an incident, writes an RCA, and, on approval, self-heals.
The product suite
As AI agents write more of your production code, Hunaru governs it end to end, audit it, secure it, and protect it in production, joined by one continuous chain of evidence.
Audit & Accountability
Proof of what your AI agents did.
Explore PramanaSecurity & Compliance Scanning
Security scanning that speaks compliance.
Explore PetikaRuntime Protection · Self-Heal
The guardian of your production.
Explore LachitVerifiable Credentials
Tamper-proof certificates, instantly verifiable.
Explore QRCertificatesSee it in action
Pramana is live and in a private pilot today. It captures AI-agent activity across your repos, attributes each action to the specific agent, risk-flags what matters, and turns it into audit-ready evidence, with an AI assistant, Netra, to answer questions in plain English.



Screens shown with illustrative sample data.
Who it's for
Prove who changed what, human or AI, and show auditors you have real oversight of AI-generated code.
Keep shipping with AI agents without losing the paper trail. Catch a risky agent push before it reaches main.
Walk into the May 2027 DPDP deadline with automated, code-level evidence instead of a spreadsheet.
Clear your next SOC 2 or enterprise security review without a governance blind spot on AI code.
Why Hunaru
The market looks at AI code through three lenses, and most tools own just one. Hunaru ties them together, governance anchored to the AI agent's actions, across the whole lifecycle.
| Category | Examples | What they do | What they miss |
|---|---|---|---|
| Productivity tools | Faros, LinearB, Waydev | Measure AI adoption & output | Not risk, not audit, not evidence |
| Code-security tools | Snyk, Legit, Endor, Cycode | Scan the output for vulnerabilities | The code's flaws, not the agent's actions |
| Compliance platforms | Vanta, Drata | Store audit evidence | No code-level agent telemetry (partners, not rivals) |
| Hunaru | the connective layer | None of them attribute the action to the agent and carry it to the auditor. Hunaru does, from commit to production. | |
Governance tied to the specific AI agent and its actions, the connective tissue no one else centers on.
A hash-chained record mapped to SOC 2 / ISO 42001 / NIST / DPDP, audit-ready, not a spreadsheet.
Build-time audit → pre-deploy security → runtime protection, as one connected record.
The longer you run, the more your historical, agent-attributed trail becomes the record you can't rip out.
No incumbent owns this category today. Our edge is depth and data gravity, owning the historical, agent-attributed audit trail, and being India-first on the DPDP Act.
Why now
AI-code adoption went vertical; regulation is catching up in the same window. Each new rule creates demand for exactly the evidence Hunaru produces automatically, and the teams that prepare early won't scramble later.
Rules notified Nov 2025; core obligations phase in toward 13 May 2027. A forcing function to prepare now.
The first certifiable AI-management standard, “ISO 27001 for AI.”
Voluntary but fast-growing; maps directly to monitoring & oversight of AI systems.
Logging, record-keeping and human-oversight duties for AI systems, global reach.
Getting started
Install the lightweight CLI, or add the GitHub webhook, to a repo. Start free with the open-source tier.
Every AI-agent action is recorded and attributed automatically, no change to how your developers work.
Review risk flags, and export SOC 2 / ISO / DPDP evidence the moment an auditor asks.
Security & privacy
We're built for teams whose job is security. So Hunaru holds itself to the bar its buyers hold everyone else to.
Use your own LLM API key so sensitive data stays under your control.
A hash-chained audit ledger that can't be quietly altered.
Role-based access, developers see only their own activity, not a surveillance feed.
Your repositories are never used to train models.
Hunaru is an AI product company that makes it safe for teams to ship AI-generated code. As AI coding agents (GitHub Copilot, Cursor, Claude Code) write more of your production code, Hunaru is the governance layer, it audits what the agents do, scans for security and compliance issues, and protects production at runtime, producing audit-ready evidence for SOC 2, ISO 27001, ISO 42001, NIST AI RMF, and India's DPDP Act.
Pramana is Hunaru's AI-agent audit and compliance product. A lightweight CLI with git hooks and repository webhooks attributes every code action to the specific AI coding agent that made it, records it in a tamper-evident, hash-chained audit trail, risk-flags high-signal events (like direct pushes to main, large diffs, or sensitive-path changes) into a human reviewer queue, and exports SOC 2 / ISO 27001 / ISO 42001 compliance evidence on demand.
Petika is Hunaru's security and compliance scanning product. It runs industry-standard scanners (static analysis / SAST, dependency and CVE detection, container scanning, and secrets detection), then maps every finding to the specific compliance control it affects, India's DPDP Act, SOC 2, ISO 27001, and PCI-DSS, turning a technical scan into an audit-ready assessment a compliance officer can act on.
Lachit is Hunaru's runtime protection and self-heal product. It watches your production error logs, and when the same error recurs it opens a single incident, writes a root-cause analysis, notifies the owner, and, on approval, rolls back, fixes, and redeploys. It catches the failure mode standard health checks miss: when a service looks healthy but users are getting errors.
Hunaru detects and attributes activity from the major AI coding agents, including Claude Code, Cursor, and GitHub Copilot. Its agent-attribution approach is designed to extend to new agents as they emerge.
Get started
See the audit trail, the risk flags, and the evidence pack on your own repos, in one demo.