Capability Statement
HUMMBL LLC — AI governance infrastructure for federal, defense, and enterprise applications. Open-source primitives, production-proven in daily operation.
Company
| Legal name | HUMMBL LLC |
| Founder | Reuben Bowlby |
| Location | Atlanta, GA (Remote, US) |
| Website | hummbl.io |
| Primary artifact | hummbl-governance (PyPI, Apache 2.0) |
| SAM.gov | Pending registration |
Core capability
HUMMBL builds runtime governance primitives for agentic AI systems — the safety infrastructure that prevents catastrophic failure when AI agents make decisions in production. Our open-source library, hummbl-governance, provides 34 primitives covering kill switches, circuit breakers, delegation tokens, audit logging, capability fences, and 29 more. Zero third-party runtime dependencies. Published on PyPI. Apache 2.0 licensed.
What we build
- Governance primitives — kill switch, circuit breaker, delegation tokens, audit log, capability fence, cost governor, schema validator, identity registry, health probes, and 25 more. Composable, stdlib-only Python.
- Multi-agent orchestration — governed coordination bus, agent identity management, contract-net protocol, convergence guards, and reward monitoring for multi-agent fleets.
- Compliance mapping — automated crosswalks between NIST AI RMF, EU AI Act, ISO 42001, NIST CSF 2.0, and DoD AI Ethical Principles.
- STRIDE threat modeling — structured threat analysis for AI systems, mapping STRIDE categories to governance primitives that mitigate each threat class.
Framework alignment
| Framework | HUMMBL coverage |
|---|---|
| NIST AI RMF 1.0 | Maps to 11 of 12 subcategories (GOVERN, MAP, MEASURE, MANAGE). Gap: workforce training (out of scope for infrastructure). |
| NIST CSF 2.0 | Govern, Identify, Protect, Detect, Respond, Recover — governance primitives map to Protect and Detect; audit logging maps to Detect and Respond. |
| DoD AI Ethical Principles | Responsible, Equitable, Traceable, Reliable, Governable — kill switch and audit log map to Traceable and Governable; capability fence maps to Responsible. |
| EU AI Act | Article 12 (logging), Article 13 (transparency), Article 14 (human oversight) — audit log, provenance chain, and kill switch map directly. |
| ISO/IEC 42001 | Clause 8 (Operation) and Clause 9 (Performance evaluation) — CRAB methodology and calibration flywheel map to these clauses. |
| CMMC 2.0 | Readiness assessment in progress. Audit logging and access controls align with Level 1/2 practices. |
Production evidence
- 34 governance primitives published on PyPI as hummbl-governance v1.4.2 — verifiable on GitHub
-
2,463 tests across 34 primitives (unit, integration,
compliance) — run
pytest --collect-onlyto verify - Zero third-party runtime dependencies — stdlib-only Python core
- Internal multi-agent platform in daily production use — built on hummbl-governance primitives (platform source is private; primitives are public)
- Published research — The Governance Tuple (Zenodo DOI 10.5281/zenodo.19646940)
Relevant federal context
NSPM August 2026: The Trump administration's
presidential memorandum on private-sector cyber operations against
foreign transnational criminal organizations creates a new contracting
pathway for vetted US companies. HUMMBL's governance primitives are
directly applicable to the oversight, audit, and control requirements
for participating companies. We are monitoring DOJ/DHS guidance
(expected within 60 days of the memo) and preparing capability alignment
for the program.
Contracting interests
- DoD / Cyber Command — AI governance for autonomous and semi-autonomous systems
- CISA — AI risk management and critical infrastructure governance
- GSA / civilian agencies — AI compliance infrastructure (FedRAMP alignment in roadmap)
- Prime subcontracting — governance primitives as a component in larger AI platforms
Need a capability brief or want to discuss a contract?
Book a 30-min call →