humanymous Gate documentation

Diátaxis quadrant: Navigation hub. Audience: everyone arriving for the first time.

humanymous Gate is an Apache-2.0 reference implementation for reverse-proxy enforcement, request metering, and tamper-evident operational audit. The related Core detection engine is the fuller development and measurement surface. Core and Gate share scoring code but do not collect identical evidence.

Important: Core’s measurements are not Gate’s measurements. Read Which piece am I using? before interpreting detection results.

The glossary is the single source of truth for product terms. Public pages use full concept names instead of internal specification numbers, numbered rule codes, numbered detection stages, or numbered threat tiers.

Start by role

  • Integrator — place Gate in front of an application and roll it out safely.
  • Operator — use the Ledger, runtime Settings, bans, approvals, and on-call procedures.
  • Data protection reviewer — evaluate pseudonymization, audit, erasure, retention, and their limits.
  • Evaluator — assess capabilities, evidence, topology requirements, and production responsibilities.
  • Developer — inspect Core, extend detection, and run defensive self-validation.

Tutorial

How-to guides

Reference

Explanation

Runbooks

End-user help

Boundaries to understand first

  • The current Gate collects less browser and network evidence than Core.
  • An intermediary that terminates and recreates encryption hides the client’s original network fingerprint.
  • Internally consistent real-browser or human-assisted automation cannot be reliably separated from legitimate traffic by client and network signals alone.
  • The current reference Gate does not route every challenge through a complete, user-solvable Pass flow.
  • The reference audit witness is local, retention tiers are not physically enforced, and several multi-node administrative controls remain node-local.
  • The bundled validation catalog targets Core and cannot establish a population-wide false-positive rate.

Defensive-only use

Run validation and probing only against a deployment you own or are authorized to test. The repository does not provide a third-party targeting workflow.