Quickstart
Install the runtime, evaluate four payloads against the built-in example pack, and read what comes back. No API key or configuration is needed, and the Community tier needs no account.
About the example
This page uses the built-in data-protection pack so you can run everything without writing a pack first. The same calls work for any decision pack: eligibility, limits, routing and so on. See Core concepts.
Install#
- Create a project and a virtual environment
mkdir helixor-quickstart && cd helixor-quickstart python3 -m venv .venv source .venv/bin/activate
- Install the runtime
pip install helixor-runtime
The package includes the runtime and the bundled Community license, so the next step works offline.
Package availability
helixor-runtimeis not yet on the public package index. Until it is, install the wheel that came with your evaluation access:pip install ./helixor_runtime-*.whl. See Installation.
Evaluate a payload#
Create an engine with no arguments. It loads the built-in example pack (data protection, compliance.regulatory_pii_guard.v1). This pack detects categories of sensitive data (Social Security numbers, card numbers, health record IDs and contact details) that regulations such as GLBA, PCI-DSS, HIPAA and GDPR address. Detecting them is one technical control, not compliance by itself.
from helixor_runtime import HelixorEngine
engine = HelixorEngine()
print(engine.pack_id, engine.version, engine.tier)
samples = [
"Please schedule the product demo with team lead on Thursday at 2pm.",
"Employee onboarding: SSN is 123-45-6789, department operations.",
"Customer renewal card: 4111-1111-1111-1111, contact billing@acme.corp.",
"Patient medical chart: RX-8839201 diagnosed with acute hypertension.",
]
for text in samples:
result = engine.evaluate(text)
print(result.action, result.invariants_passed, f"{result.latency_us:.1f} µs")
if not result.invariants_passed:
print(" clean:", result.remedy.clean_text)
print(" receipt:", result.receipt_hash)
A pack checks every rule in order, reports every match in triggers, and the first fatal rule that fires decides the action. In the example pack the order is SSN, card, health ID, then contact details. The remedy still covers everything the pack found: here it redacts every category, so the card sample comes back as Customer renewal card: [REDACTED_CARD_PAN], contact [REDACTED_EMAIL]. The clean sample falls through to the pack's default action:
| Input contains | Rule | action | Severity |
|---|---|---|---|
| Nothing sensitive | none | permit_clean_payload | n/a |
| Social Security number | RULE-GLBA-SSN-BLOCK | block_glba_ssn_leakage | fatal |
| Card number (Luhn-valid) | RULE-PCI-DSS-PAN-BLOCK | block_pci_dss_pan_leakage | fatal |
| Health record ID | RULE-HIPAA-PHI-BLOCK | block_hipaa_phi_leakage | fatal |
| Email, phone or IP only | RULE-GDPR-EMAIL-REDACT, RULE-TCPA-PHONE-REDACT, RULE-GDPR-IP-REDACT | redact_and_permit_contact_pii | warning |
Read the result#
evaluate() returns a DecisionResult. The fields you will use most:
| Field | Meaning |
|---|---|
action | The action the pack chose, one of its declared actions. In the example pack, block actions start with block. |
invariants_passed | True when no rule fired. |
reason | The description of the rule that decided the result. |
triggers | The rules that fired; each has a rule_id. |
remedy.clean_text | The repaired payload. For the example pack, the input with every match replaced by its redaction token, such as [REDACTED_SSN]. |
latency_us | Time spent evaluating inside the engine, in microseconds. |
tokens_spent, egress_bytes | Always 0 for embedded evaluation. Log them to show that no model was called and nothing left the process. |
receipt_hash | A fingerprint of this decision (pack, action, outcome, fired rules, input hash). Store it with your own record of the request. See Receipts for what it does and does not prove. |
The full list is in the Python reference.
Act on the action, not the text
Branch on result.action (or invariants_passed) and only forward remedy.clean_text when the action permits it. A fatal action means the payload must not leave your process at all, redacted or not.
Keep going#
Each of these adds one capability to what you just ran:
- Measure latency on your machine with the benchmark scripts.
- Redact a token stream in flight.
- Serve decisions over HTTP.