HIIH loop step: Retrieve

Proof and honest limits

01 · EVIDENCE AND PROOF OF OPERATIONAL USE

Show the chain, not a connector logo wall.

The delivery chain HIIH demonstrates is: a controlled hostile interaction, an Observation, a structured Finding with a preserved finding_id, an MCP or API pull, and an analyst retrieving related context. HIIH delivers on the pull paths — Console, MCP and API, with STIX 2.1 over TAXII 2.1 available by engagement. The Access Finding family is inspectable in the Console today, and a first deployment confirms the full path with a controlled event.

OHIIHO Research provides evidence that HIIH environments produce meaningful observations and analysis; the delivery model demonstrates that a structured operational result can move into a workflow. These are complementary forms of evidence. HIIH does not decorate this page with unsupported partner logos, certification implications, roadmap-only integrations or staged dashboards.

02 · HONEST LIMITS

Current delivery scope.

What HIIH delivers todayWhat it does not promise
The Surface ConsoleOne compiler for every output format
STIX 2.1 over TAXII 2.1, by engagementIdentical fields across every output
An MCP path and an API for authorized toolsCertified integration with every SIEM
One Finding identity across the pull pathsA write path into your environment
The Access Finding family, inspectable in the ConsoleA universal MISP / CERT feed
Additional forms shaped per engagementCryptographically sealed delivery
Delivery scope
What HIIH delivers today — and what it doesn't
The pull paths — Console, MCP and API — carry the same Finding identity across them, and delivery stays pull-based; STIX 2.1 over TAXII 2.1 is available by engagement. The Access Finding family is live and inspectable in the Console. Beyond those, HIIH offers nothing it does not run.