DUNIN7 · LOOMWORKS · RECORD
record.dunin7.com
Status Current
Path investigations/competitive-positioning/hebbia-comparison-v0_2.md

Hebbia — Comparison to FORAY and DUNIN7 Offerings — v0.2

Date: 2026-07-29 Status: Working draft for Operator review Prepared by: DUNIN7 advisory session Supersedes: v0.1, which existed only as in-session prose and was never filed. v0.2 adds the second-pass research v0.1 named as missing: Hebbia's security page and trust centre, its data processing agreement, and a survey of the agent-audit-trail category. One finding in that survey changes a conclusion in v0.1.


Plain-language summary

Hebbia sells an AI platform that reads financial documents and answers questions about them, with each answer cited back to the page it came from. FORAY is not that. FORAY is a standard for how a business record should be written down in the first place, so that nobody can quietly change it afterwards.

The two solve different halves of the same problem. Hebbia solves finding. FORAY solves fixing in place. Neither substitutes for the other.

The second pass turned up one thing worth acting on. A market is forming for exactly what FORAY's second consumer column addresses — tamper-evident records of what AI agents did, under whose authority. Named vendors are already selling into it. Hebbia is not one of them, but others are. That column is no longer empty ground.


1. Sources and their limits

Everything below is drawn from Hebbia's public web surface and from third-party trackers, read on 2026-07-29. Pages read: home, product, security, plus the data processing agreement and privacy policy in extract. No product access. No API documentation. No customer references contacted.

Two limits carry through the whole document and must not be dropped when any of this is reused:


2. What Hebbia is

An AI platform sold to asset managers, investment banks, law firms and large corporates.

Product surfaces (five, per the product page):

| Surface | What it does | |---|---| | Chat | Question-answering across large document sets, each response cited to source | | Matrix | Structured analysis across many documents or companies, with traceability to each finding | | Draft | Generates branded spreadsheets, slides and reports from the analysis | | Skills & Agents | Firm processes encoded once, then run continuously by agents that trigger workflows unprompted | | Projects | Shared workspace where people and agents build on common context |

Integration: a Matrix API and an MCP connector for embedding into internal tools.

Data reach: filings (US, European, UK, Australia/NZ), earnings transcripts, and the commercial financial data providers — FactSet, Capital IQ, PitchBook, Preqin, Fitch, ICE. Plus enterprise document stores — SharePoint, OneDrive, Box, Dropbox, Egnyte, IntraLinks — and CRM and warehouse systems.

Posture: ISO/IEC 42001:2023, SOC 2 Type II, AES-256 at rest, no training on customer data, CCPA and GDPR named.


3. The one-line difference

Hebbia reads evidence that already exists. FORAY governs how evidence is written at the moment of the event.

Hebbia's entire engineering problem is that business evidence arrives as unstructured documents, so it must be found, parsed, reasoned over and cited. FORAY's premise is that the evidence should have been emitted in structured, hash-anchored form in the first place, so that finding and parsing are not where trust comes from.

They sit at opposite ends of the same pipeline.


4. Layer comparison

| | Hebbia | FORAY / DUNIN7 | |---|---|---| | Category | Product (enterprise SaaS) | Protocol standard, conformance suite, reference implementation | | Business model | Enterprise licence, single vendor | The specification is the asset; implementers and consumers are third parties | | Position in pipeline | Consumption — reads what exists | Emission — governs what is written | | Input | Documents: filings, transcripts, data-room contents | Business and governance events, at origination | | Output | Answers, matrices, decks, models, memos | F-coded records, anchored on Kaspa | | Trust claim | Citation to source: this finding came from that page | Tamper-evidence: this record has not changed since anchoring | | Not covered by that claim | Whether the source document was altered before ingestion | Whether the content is true — validation attests shape, not truth | | Structure | Corpus, retrieval, reasoning | Four components: Arrangements, Accruals, Anticipations, Actions | | Neutrality | None claimed; it is a vendor platform | The protocol framing is the neutrality answer | | Openness | Closed, commercial | Licence and openness ruling still open (DL-1 through DL-9) | | Agent governance | Nothing found on the public surface | Stele (identity), GRANTHA (containment), FORAY (evidence) | | Scale | ~138–184 people, six years, named enterprise logos | One operator; protocol anchoring in production, work packages open |


5. Two different things both called traceability

This is the distinction to hold precisely, because the same word appears on both sides and means different things.

Hebbia's Matrix claims complete traceability back to every finding. That is retrieval provenance. The system can show which document and which passage produced an answer. It is a real and valuable property. It answers: where did this number come from?

FORAY claims tamper-evidence through anchoring. That answers a different question: has this record changed since it was made?

Neither property implies the other.

An audit posture that wants both currently has to buy one and build the other.


6. Claim discipline — a direct contrast

Worth recording because it is the sharpest difference in operating philosophy, and because it is a standing risk for anyone who reads competitor copy and drifts toward its register.

Hebbia's security page carries absolute claims. It describes the platform as the most secure enterprise AI platform, and states an intention to create the standard for trustworthy language models that never hallucinate and give correct, verifiable answers.

Under FORAY's claim discipline, those are the forbidden constructions. "Never" and "correct" are unbounded assertions with no verifiable artifact behind them. The FORAY equivalent would be: tamper-evident, not immutable; validation attests conformance to the ruled shape, never truth of content; when output has not passed the live validator, say so plainly.

Two lesser observations from the same pass, recorded as truth-pass discipline rather than as criticism of substance:

The lesson for DUNIN7 is not that Hebbia is careless. It is that a well-funded competitor operating at scale still ships copy with internal inconsistencies across two pages of its own site. The machine-checked one-width and register laws on the FORAY site exist because eyeballs do not catch this.


7. Is Hebbia a competitor, a consumer, or an implementer?

Not a competitor. No overlap in what is sold. Hebbia does not define a record format for third parties to emit. DUNIN7 does not sell document search to analysts.

A candidate consumer in Column 1, with a structural disincentive. On paper Hebbia is exactly the sort of audit and analysis platform FORAY's evidence column is built for: a system that would rather receive structured verifiable records than parse a data room. In practice, the difficulty of parsing unstructured documents is Hebbia's moat. Broad FORAY adoption would erode the problem Hebbia is paid to solve. Expect polite interest and slow adoption. Better first consumers are platforms whose value is judgment rather than extraction.

A candidate producer in Column 2, and this is the live seam. Hebbia's agents run firm processes continuously and trigger workflows before anyone asks. The home page's own worked example ends with an agent sending a summary deck to a managing director. That is an autonomous agent taking an outward action on a firm's behalf.

Nothing found on the public surface answers the three questions that follow from it: under whose authority did it act, what was it permitted to do, and can the record of what it did be produced later and shown unaltered.

Its ISO/IEC 42001 certification does not close that gap, and the reason is structural rather than a matter of rigour. ISO/IEC 42001 certifies an AI management system — the organisation's policies, controls, oversight and review processes, assessed by an accredited body on a three-year cycle. It attests that the firm governs AI responsibly as a process. It does not produce a per-action record of what any individual agent did. These are different objects. A firm can hold the certificate and still be unable to produce tamper-evident evidence of a specific agent act.

The data processing agreement points the same way. It grants the customer a right to audit Hebbia's compliance, normally once in any twelve-month period, with exceptions for regulator instruction or a security incident. That is periodic organisational assurance. It is not per-record evidence, and it is not available on demand.

As an integration path: the Matrix API and MCP connector mean a FORAY-emitting adaptor on the agent-action side is technically approachable without needing vendor cooperation at the corpus layer.


8. The finding that changes a v0.1 conclusion

v0.1 concluded that the agent-governance seam was open ground and the strongest engagement angle. The first half of that survives. The second half needs correcting.

Prior position (v0.1): Column 2 — tamper-evident evidence of agent action — was described as an unaddressed gap that Hebbia's own product surface implied.

Current position (v0.2): The gap is real and Hebbia does not address it, but the category is forming and is no longer unoccupied. A survey of the agent-audit-trail space turned up an active vendor and advisory market. Practitioners are converging on a common specification: a chronological, tamper-evident, append-only, hash-chained record of every agent input, tool call, data access, write, and human approval, with each consequential action bound to a named human authorizer and an explicit permission grant. OWASP agentic security research is cited as defining a minimum forensic scope per individual action rather than per session.

Three consequences.

  1. The thesis is validated by strangers. Stele's first axiom — agent identity is leasehold, attestation chains terminate in human authority — is being independently restated as a market requirement by parties with no knowledge of DUNIN7. That is the strongest external confirmation available that GRANTHA and Stele are aimed at a real problem.
  2. The differentiator moves. It is no longer sufficient to be the party that says agent actions need evidence. Others say it. The distinguishing claims are the ones FORAY already holds and the incumbents mostly do not: an open protocol rather than a vendor log format, and external anchoring rather than a log store the acting system controls.
  3. A third party has independently made FORAY's own argument for external anchoring. One practitioner note in this survey states the failure mode plainly: if the process performing the action owns the only signing key and the only log store, signatures add little, and a separate signing boundary is required. That is the case for anchoring outside the acting system, made by someone selling something else. It is quotable in FORAY positioning as external corroboration, and it is worth capturing before the argument becomes commonplace and unattributable.

Alternative considered and set aside: treating this survey as evidence that Column 2 is crowded and should be de-prioritised in favour of Column 1. Rejected. The vendors found are selling logging products and consulting engagements, not standards. None of them is doing what a protocol does — none defines a format others implement, and none separates the record from the platform that produced it. A crowded product category with no standard in it is the normal precondition for a standard, not an argument against one.


9. What remains unchecked

Named so it is visible and correctable rather than quietly assumed.


10. Recommended next moves

Presented as options with grounds. No ruling is taken in this document.

| # | Move | Grounds | Recommendation | |---|---|---|---| | 1 | Open a decision sheet on Column 2 positioning against the forming agent-audit-trail category | §8 changes the competitive picture; the current seed language for Column 2 was drafted assuming open ground | Recommended — this is the live item | | 2 | Capture the external corroboration in §8.3 into the FORAY positioning record with full provenance | Third-party statement of FORAY's own anchoring argument; value decays as the argument spreads | Recommended | | 3 | Treat Hebbia as a Column 1 reference case in materials, not as a target | Structural disincentive named in §7 makes it a poor first consumer, but a clear illustration of the read/write distinction | Recommended | | 4 | Second research pass on Hebbia's blog, trust centre and API documentation | Closes §9; low cost | Optional, before any outward use of this document | | 5 | Approach Hebbia | Nothing in this reading suggests a warm entry point, and the disincentive in §7 is real | Not recommended at this time |


All figures and characterisations attributed to Hebbia in this document derive from its public web surface and third-party trackers as read on 2026-07-29. No product access was obtained. Statements about absence describe the public surface, not the product.