AFiR-Aegis · independent proof for self-driving decisions

The independent black box for machines that drive.

What a self-driving car records is not just telemetry. It's evidence. It shows up in the lawsuit, the insurance claim, the regulatory audit, and sometimes the criminal case that follows a serious crash. Right now that evidence is the manufacturer's own log, held by the same party with the most to lose. Aegis is an independent notary for that record. It gives you one signed, tamper-proof receipt per decision that ties together the decision, the driver's state, the vehicle's condition, and the law that applied. Any court, regulator, or insurer can check it without having to trust the company being sued.

The market is stuck on the liability question. Aegis is the proof layer that unblocks it
4-in-1
decision, driver state, vehicle condition, and jurisdiction in one receipt
Occurrence
it says what happened, never who was at fault
Neutral
signed by a party with no stake in the outcome
Check it anywhere
offline, with the public key, by anyone, forever
The flagship Aegis is the full independent proof layer for self-driving decisions. If you're here specifically for the UN R157 / R160 recording mandate, start with SDR, the Signed Driving Record, the compliance-focused entry point into Aegis. See SDR, the regulatory on-ramp

Every decision gets bound into one signed receipt: the decision, the driver's state, the vehicle's condition, and the law that applied, all attested by a party with no stake in the outcome.

The flagship spire

We don't build the black box. We prove you can trust what's in it.

The manufacturer's black box records what the vehicle saw and decided. Aegis makes a separate, independent, signed, tamper-proof receipt that checks that record. It ties the decision, the operator's state, the vehicle's condition, and the law that applied into one document anyone can check in court, because it comes from a party with no stake in the outcome.

When a machine makes a decision on the move and someone gets hurt, the only evidence anyone will trust is the receipt that didn't come from the company being sued. Aegis is that receipt.

The classic fox-guarding-the-henhouse problem, but in tech.

After a serious crash, everything comes down to what the vehicle saw, what it decided, who was supervising, and whether the machine was even fit to act. The only party who can answer holds the recorder, controls what gets shared, and is the same party being sued. Three problems keep coming up, and they're built into the system, not one-off mistakes.

The least-trusted document

Self-reported by the defendant

A manufacturer's crash log is the least-trusted document you'll find in a courtroom. The party holding it has the most to lose and the most ability to change it. "Our logs show" is a claim from an interested party, not evidence.

Who was driving

The supervision question

In assisted and conditional self-driving, the case turns on whether the human or the machine was driving, and whether the human was fit and actually paying attention at the moment it mattered. Without a neutral, time-stamped record, you can't prove that either way.

Decision vs. mechanical

The liability splitter

A car that decided correctly but couldn't carry it out because a sensor had failed is a very different case from a bad model decision. It splits the blame among the manufacturer, the fleet operator, and the owner. Right now nothing makes that difference provable from a neutral source.

The line that keeps Aegis admissible in court

Hive proves where data came from. We never decide anything, and we never record anything ourselves. Aegis checks the capture: that the record of what was seen, decided, the operator's state, and the vehicle's condition is real, complete, and untampered. We never rule on whether the vehicle, the human, or the manufacturer was at fault. Fault is for the court, the regulator, and the insurer to decide, using Aegis's evidence. We hold that line on purpose. It's what makes the evidence admissible and keeps Hive a neutral witness instead of a party to the lawsuit.

asserts: perceived_X decided_Y driver_state_Z vehicle_fitness_W under_jurisdiction_J at time T never: at_fault never: negligent never: liable

Five layers fused into one receipt per decision.

The value is in tying it all together, not the list itself. Each layer answers a question that can decide a case. What we built seals all four into a single tamper-proof receipt from a neutral source.

Layer 1the core

Decision history

Not just "the car turned left." This layer shows what the perception system saw, how the decision model weighed it, and what action the vehicle took, backed by a signed record of that chain. It answers the question that dominates every self-driving case: why did the car do what it did, and can you prove that's really what happened inside the model, with nothing changed?

Layer 2the liability pivot

Driver-state proof

Gaze direction, hands on the wheel, attention and drowsiness, signs of impairment, and, where it's legal to capture, body signals, all sealed so they can't be read by anyone but still checked. This answers the single most argued question in assisted and conditional self-driving: who was driving, and was the human fit and actually paying attention when it mattered?

Layer 3the liability splitter

Vehicle-condition proof

Tire pressure, brake wear, sensor health and calibration, actuator status, and relevant temperatures, all bound into the receipt. This answers whether a crash was an AI decision failure or a mechanical or maintenance failure, the distinction that splits blame among the manufacturer, the operator, and the owner.

Layer 4the moving-target solver

Jurisdiction binding

A vehicle crosses jurisdictions while it drives, and the traffic law, consent law, and data law can all change mid-trip. Aegis automatically detects the jurisdiction and locks in the law that applied at the exact time and place of each decision, so the decision gets assessed against the rules that actually applied where it happened.

Layer 5 · the core idea

Bringing it together

All four layers get sealed into one signed receipt per decision, checked independently by Hive, anchored to a public ledger, and readable by any party, regulator, court, insurer, or opposing counsel, without anyone having to trust the manufacturer's logs. Tying all four together in one tamper-proof record is the core idea: it answers what happened and why, across perception, decision, human, machine, and law, from a neutral source.

Pick a decision. Sign it. Check it live.

This is the real signer, not a demo fake. Each decision gets signed as four bound pieces in one receipt: decision, driver state, vehicle condition, and jurisdiction. Here's what to expect when you try it: sign the combined receipt, check it on your own, then change the driver-state piece (the field lawyers argue over most) and watch the whole receipt fail. One changed piece breaks the whole thing, and that's exactly the point.

Live endpoint · hive-typed-signer.onrender.com/sign · /verify · real ML-DSA-65

Pick a decision along the incident timeline

One approach to an intersection, moment by moment. Each one is a four-part combined receipt

The decision, four bound pieces

Combined into one receipt. Change any one piece and the whole receipt fails

The independent receipt

Press "Sign it" to sign all four pieces with the live endpoint.
Not signed
An independent ML-DSA-65 receipt binding all four pieces of the decision.
Step 1 of 3: sign the four-part combined receipt.

Why being independent is the whole game here.

Independence matters more here than almost anywhere else, because this situation puts two sides against each other from the start. A manufacturer's self-reported crash log is the least-trusted document you'll find in a courtroom. An independent, third-party signed black box is the most trusted: it comes from a party with no stake in the outcome, and you can check its integrity with math instead of taking it on faith. When a life and a liability claim are on the line, you need the receipt to come from someone who isn't the company being sued. That's exactly what Hive is, and Aegis is where the stakes are highest.

Who buys it, and why.

The market is stuck on the liability question. Fleets can't get insured or regulated at scale until what they do is provable. Aegis is the proof layer that unblocks it.

Insurers: the strongest near-term buyer

Price self-driving fleet risk on provable behavior instead of guesswork, and settle claims on signed evidence instead of disputed logs. Insurers are stuck because they can't check what self-driving cars actually do. Aegis is that check.

Automakers and self-driving developers

Defend against liability claims with provable, neutral evidence that a crash wasn't the model's failure, or fairly limit your exposure when it was. Provable beats deniable in a courtroom and with a regulator.

Regulators, NHTSA-grade

Audit self-driving systems with evidence you don't have to take on the manufacturer's word, and, where mandates apply, require independent proof as a condition of fleet deployment, the same way integrity checks are becoming standard for other high-stakes data deals.

Courts

Admissible, tamper-proof, neutral evidence of what a self-driving system saw and decided, checkable by opposing counsel without trusting either side.

Set up proof for your fleet.

Pick the layer of the decision you want to prove first. You'll land on a page that sets up your account and gives you a one-line call to sign your first combined receipt. No call, no demo, no one to talk to.

This is independent, neutral third-party proof. Hive signs what your stack records and makes no decision about the driving. Run the steps above and you'll see VALID on an honest receipt and INVALID the instant any one of the four pieces gets changed. Checking a receipt is free, forever, for anyone: the regulator, the insurer, the court, opposing counsel.

Prove it yourself in thirty minutes.

No call, no demo, no one to talk to. Sign a four-part combined decision above, check it on your own with just the public key, then change the driver-state piece and watch the whole receipt fail. You can run the same flow against your own stack through the SDK: independent, neutral proof sitting underneath the black box you already keep.

AFiR-Aegis builds on Hive's existing stack (AFiR inference proof, Jurisdictional Clearance, the independence moat) plus two new pieces: driver state and vehicle condition. For context: UN R157 (DSSAD) and R160 (EDR) require tamper-proof ADS recording that investigators can access, per MmowW and UN News. Florida FSD crash data was recovered independently, per Electrek. Senators asked NHTSA to audit FSD telemetry over the 5-second disengagement window, per The Star / Reuters. BYD accepts driver-assist liability, per Electrek.