An AI product company that also builds software.

    Ship at AI speed.
    Prove every line.

    AI agents write more of your code every week. Hunaru is the governance layer that audits what they do, secures it before it deploys, and protects it in production, one chain of evidence, from commit to production.

    Explore products
    LocationsIndia-origin · Serving teams worldwide

    In private pilot, built by a team that ships AI-written code every day.

    Maps toSOC 2ISO 27001ISO 42001NIST AI RMFDPDP Act

    The problem

    AI writes the code. Nobody governs the AI.

    Copilot, Cursor, and Claude Code now author a fast-growing share of what reaches production. The controls you built for human developers can't see them. Three gaps open at once.

    GAP 01

    No accountability

    When an agent commits or pushes, there's no record of which agent did it, what it changed, whether it touched a sensitive system, or whether a human ever reviewed it. You're accountable for code you can't see.

    GAP 02

    No compliance evidence

    Auditors, customers, and regulators have started asking one question, “how do you govern the AI that writes your code?” SOC 2, ISO 42001, and India's DPDP Act expect logging and oversight. Most teams have no answer, and it stalls deals and certifications.

    GAP 03

    No runtime safety net

    AI ships faster than anyone can review, so more defects reach production, and many fail silently. The health check reads green while users hit 500s. Standard checks miss it, and the incident runs for hours before anyone responds.

    Until now the choice was ship fast with AI, or stay accountable and audit-ready. Hunaru ends that trade-off.

    How it works

    One evidence chain, from commit to production.

    Three products, one continuous flow. Each governs a different stage of the software lifecycle, and every stage feeds one connected, exportable record of accountability.

    Hunaru end-to-end workflow: Pramana, Petika, Lachit across build, deploy and runtime
    01Build-time

    Pramana

    The CLI + git hooks attribute each action to the specific AI agent and write it to a tamper-evident audit trail.

    02Pre-deploy

    Petika

    Scans for vulnerabilities and secrets, and maps every finding to the exact compliance control it affects.

    03Runtime

    Lachit

    Watches production; on recurring errors it opens an incident, writes an RCA, and, on approval, self-heals.

    The product suite

    Governance for AI-era software engineering.

    As AI agents write more of your production code, Hunaru governs it end to end, audit it, secure it, and protect it in production, joined by one continuous chain of evidence.

    See it in action

    A working product, not a concept deck.

    Pramana is live and in a private pilot today. It captures AI-agent activity across your repos, attributes each action to the specific agent, risk-flags what matters, and turns it into audit-ready evidence, with an AI assistant, Netra, to answer questions in plain English.

    • Agent attribution, Claude Code, Cursor, Copilot
    • Tamper-evident, hash-chained audit trail
    • Risk flags + human reviewer queue
    • SOC 2 / ISO 27001 / ISO 42001 evidence reports
    Explore Pramana
    Pramana dashboard, agent activity, risk flags and KPIs
    Pramana audit log with per-agent attribution
    Audit log, every action, attributed to its AI agent
    Pramana risk-flag reviewer queue
    Reviewer queue, approve or dismiss risk flags

    Screens shown with illustrative sample data.

    Who it's for

    Built for the people accountable for AI-written code.

    CISO / Security

    Prove who changed what, human or AI, and show auditors you have real oversight of AI-generated code.

    Head of Engineering

    Keep shipping with AI agents without losing the paper trail. Catch a risky agent push before it reaches main.

    Compliance / DPO

    Walk into the May 2027 DPDP deadline with automated, code-level evidence instead of a spreadsheet.

    Founder / CTO

    Clear your next SOC 2 or enterprise security review without a governance blind spot on AI code.

    Why Hunaru

    Everyone secures the code. We govern the agents writing it.

    The market looks at AI code through three lenses, and most tools own just one. Hunaru ties them together, governance anchored to the AI agent's actions, across the whole lifecycle.

    CategoryExamplesWhat they doWhat they miss
    Productivity toolsFaros, LinearB, WaydevMeasure AI adoption & outputNot risk, not audit, not evidence
    Code-security toolsSnyk, Legit, Endor, CycodeScan the output for vulnerabilitiesThe code's flaws, not the agent's actions
    Compliance platformsVanta, DrataStore audit evidenceNo code-level agent telemetry (partners, not rivals)
    Hunaruthe connective layerNone of them attribute the action to the agent and carry it to the auditor. Hunaru does, from commit to production.

    Agent attribution

    Governance tied to the specific AI agent and its actions, the connective tissue no one else centers on.

    Tamper-evident evidence

    A hash-chained record mapped to SOC 2 / ISO 42001 / NIST / DPDP, audit-ready, not a spreadsheet.

    One lifecycle chain

    Build-time audit → pre-deploy security → runtime protection, as one connected record.

    Data gravity

    The longer you run, the more your historical, agent-attributed trail becomes the record you can't rip out.

    No incumbent owns this category today. Our edge is depth and data gravity, owning the historical, agent-attributed audit trail, and being India-first on the DPDP Act.

    Why now

    Governance is going from nice-to-have to expected.

    AI-code adoption went vertical; regulation is catching up in the same window. Each new rule creates demand for exactly the evidence Hunaru produces automatically, and the teams that prepare early won't scramble later.

    DPDP Act, India

    Rules notified Nov 2025; core obligations phase in toward 13 May 2027. A forcing function to prepare now.

    ISO/IEC 42001

    The first certifiable AI-management standard, “ISO 27001 for AI.”

    NIST AI RMF

    Voluntary but fast-growing; maps directly to monitoring & oversight of AI systems.

    EU AI Act

    Logging, record-keeping and human-oversight duties for AI systems, global reach.

    Getting started

    Live in an afternoon. Evidence from day one.

    01

    Connect

    Install the lightweight CLI, or add the GitHub webhook, to a repo. Start free with the open-source tier.

    02

    Capture

    Every AI-agent action is recorded and attributed automatically, no change to how your developers work.

    03

    Prove

    Review risk flags, and export SOC 2 / ISO / DPDP evidence the moment an auditor asks.

    Security & privacy

    Your code stays yours.

    We're built for teams whose job is security. So Hunaru holds itself to the bar its buyers hold everyone else to.

    Bring your own key

    Use your own LLM API key so sensitive data stays under your control.

    Tamper-evident

    A hash-chained audit ledger that can't be quietly altered.

    Least privilege

    Role-based access, developers see only their own activity, not a surveillance feed.

    No training on your code

    Your repositories are never used to train models.

    FAQ

    Questions, answered.

    See all FAQs

    What is Hunaru?

    +

    Hunaru is an AI product company that makes it safe for teams to ship AI-generated code. As AI coding agents (GitHub Copilot, Cursor, Claude Code) write more of your production code, Hunaru is the governance layer, it audits what the agents do, scans for security and compliance issues, and protects production at runtime, producing audit-ready evidence for SOC 2, ISO 27001, ISO 42001, NIST AI RMF, and India's DPDP Act.

    What does Pramana do?

    +

    Pramana is Hunaru's AI-agent audit and compliance product. A lightweight CLI with git hooks and repository webhooks attributes every code action to the specific AI coding agent that made it, records it in a tamper-evident, hash-chained audit trail, risk-flags high-signal events (like direct pushes to main, large diffs, or sensitive-path changes) into a human reviewer queue, and exports SOC 2 / ISO 27001 / ISO 42001 compliance evidence on demand.

    What does Petika do?

    +

    Petika is Hunaru's security and compliance scanning product. It runs industry-standard scanners (static analysis / SAST, dependency and CVE detection, container scanning, and secrets detection), then maps every finding to the specific compliance control it affects, India's DPDP Act, SOC 2, ISO 27001, and PCI-DSS, turning a technical scan into an audit-ready assessment a compliance officer can act on.

    What does Lachit do?

    +

    Lachit is Hunaru's runtime protection and self-heal product. It watches your production error logs, and when the same error recurs it opens a single incident, writes a root-cause analysis, notifies the owner, and, on approval, rolls back, fixes, and redeploys. It catches the failure mode standard health checks miss: when a service looks healthy but users are getting errors.

    Which AI coding agents does Hunaru support?

    +

    Hunaru detects and attributes activity from the major AI coding agents, including Claude Code, Cursor, and GitHub Copilot. Its agent-attribution approach is designed to extend to new agents as they emerge.

    Get started

    Make it safe to ship AI-written code.

    See the audit trail, the risk flags, and the evidence pack on your own repos, in one demo.