humanymous Gate documentation
Diátaxis quadrant: Navigation hub. Audience: everyone arriving for the first time.
humanymous Gate is an Apache-2.0 reference implementation for reverse-proxy enforcement, request metering, and tamper-evident operational audit. The related Core detection engine is the fuller development and measurement surface. Core and Gate share scoring code but do not collect identical evidence.
Important: Core’s measurements are not Gate’s measurements. Read Which piece am I using? before interpreting detection results.
The glossary is the single source of truth for product terms. Public pages use full concept names instead of internal specification numbers, numbered rule codes, numbered detection stages, or numbered threat tiers.
Start by role
- Integrator — place Gate in front of an application and roll it out safely.
- Operator — use the Ledger, runtime Settings, bans, approvals, and on-call procedures.
- Data protection reviewer — evaluate pseudonymization, audit, erasure, retention, and their limits.
- Evaluator — assess capabilities, evidence, topology requirements, and production responsibilities.
- Developer — inspect Core, extend detection, and run defensive self-validation.
Tutorial
- Quickstart in monitor mode — start Gate without enforcing verdicts.
How-to guides
- Deployment and policy operations
- Configure attested routes
- Configure credential verifiers
- Tour the Ledger
- Verify the audit log
- Manage keys, rotation, and recovery
- Upgrade and migrate
- Integrate observability and security event management
- Use the Detection Observatory
- Tour the Detection Observatory
- Run the Core detection engine
- Extend detection
- Run defensive self-validation
- Write a validation profile
- Troubleshoot an integration
- Configure certificates
- Verify a release image
- Cut a release
Reference
- Glossary
- Command line, configuration, and route policy
- Verdicts, enforcement rules, and diagnostic signals
- Install requirements and supported platforms
- Roles, separation of duties, and dual-control
- Data-processing inventory
- Gate-to-origin contract
- Supported topologies
- Reference behavior and production responsibilities
- Deployment cost, latency, and footprint
- On-call quick reference
- Standards and regulatory mapping
- Defensive validation catalog
- Defensive validation rules of engagement
- Security audit
- Security disclosure
- Support, licensing, and notices
- Console localization
- Documentation style guide
Explanation
- How humanymous evaluates a request
- What Gate is and is not
- Which piece am I using?
- Where Gate fits
- Will this break my app?
- The control plane and injected bundle
- Inside the detection engine
- Inside the Detection Observatory
- Validation catalog architecture
- Transparency report
- Data Protection Impact Assessment companion
- How this reference was built
Runbooks
End-user help
Boundaries to understand first
- The current Gate collects less browser and network evidence than Core.
- An intermediary that terminates and recreates encryption hides the client’s original network fingerprint.
- Internally consistent real-browser or human-assisted automation cannot be reliably separated from legitimate traffic by client and network signals alone.
- The current reference Gate does not route every challenge through a complete, user-solvable Pass flow.
- The reference audit witness is local, retention tiers are not physically enforced, and several multi-node administrative controls remain node-local.
- The bundled validation catalog targets Core and cannot establish a population-wide false-positive rate.
Defensive-only use
Run validation and probing only against a deployment you own or are authorized to test. The repository does not provide a third-party targeting workflow.