AFiR · a new evidentiary layer for machine action
Every other agent leaves a log its operator controls. That's a record a party keeps about itself, which makes it a claim, not evidence. The Hive sovereign agent works differently: it mints an independent, post-quantum receipt for every move it makes (ML-DSA-65, NIST FIPS 204), and anyone can check it offline, without trusting the provider who ran it. It's the first record the machine can't rewrite after the fact, evidence sealed during the call, not a log the operator keeps about itself. It's the same agent receipts and agent provenance that anchor Hive's proof layer. On top of that self-proving agent sits a program no other inference provider can offer: price protection that survives the race to the bottom, and a liability record that keeps you out of the witness chair.
Live now · no call, no demo · sign & verify free in your browser · your first signed receipt in ~30 seconds
01The sovereign agent
A single agent, minted through Hive, that does the work and receipts itself the whole way. It fragments across the cheapest capable compute, heals its own faults, and watches itself for drift. It doesn't hand its proof to the provider to vouch for. It signs its own. Each capability comes from a named primitive and produces an independent, ML-DSA-65 signed receipt anyone can check offline.
| Capability | What it does | What it proves · receipt |
|---|---|---|
| Born receiptingConstitutional mint | Minted bound to an independent signer; holds a credential to request signatures, never the key. | This specific agent did the work, and it can't sign for itself. A forgery is impossible without the independent key. |
| Signs every actionAFiR · Stream | Every action and segment signed as it happens, off the hot path, no added latency. | What the agent did, untampered. Anyone can check it, and no one can alter it. |
| Fragments with proofSLS · Lateration | Decomposes the task; routes each fragment to the smallest capable model or node. | Which model, which node, in what shape. Each fragment is independently signed, with its content sealed. |
| Binds the graphAssembly receipt | Binds the fragment receipts into one verifiable provenance graph of the composed result. | The final answer was assembled honestly from exactly these fragments. The whole shape is proven. |
| Heals itselfMiR · RCm | Detects a faulted fragment; re-routes or re-executes, bounded by cost cap and retry limit. | What failed and how it recovered. The repair itself is signed as localized, bounded, and non-rewriting. |
| Cleared to actImprimatur | Each fragment cleared against policy before it runs; refusals are themselves signed. | The agent acted only within what it was authorized to do, with clearance on the record. |
| Knows the missionMission coherence | Checks each result and the whole trajectory against a signed mission contract; flags or halts on drift. | It stayed within the authorized mission, or flagged it when it didn't. Drift becomes a signed event. |
What the receipt proves
What it does not prove
Here's what you can do today, free: mint an agent, sign a single sealed action, and check it independently end to end. The wider architecture above (fragment-level signing, assembly graphs, self-healing) extends that same primitive across a whole task. Where a capability is still being rolled out, we say so instead of implying it's finished. The claim stays narrow on purpose: a receipt is only worth something if every limit on it is stated plainly.
Next layer · live receipts
A self-receipting agent seals what it did once the call is done. That's the record that survives a deposition. Agent Trip streams those receipts while the call is still underway, so an external dashboard can audit, coach, reroute, pause, and correct the route mid-flight instead of reading about it afterward. The decision layer chooses the route. The receipt layer proves each choice as it happens.
See the live receipt stream →02The provider protection program
Pillar 1 · Economic
Inference is commoditizing. Anyone can match your price; the margin erodes to zero as models become interchangeable.
A signed receipt is the one thing a competitor can't undercut. "Provable inference" is a premium tier that prices on trust, not tokens. It holds up because the moment a rival issues its own receipts, those are claims, not proof. You can't buy your way into independence.
You stop competing on price floor and start selling the one attribute that has no substitute: proof.
Pillar 2 · Legal
When an AI decision causes harm, the provider's own logs are the least credible evidence in the room. And the question waiting in a deposition is brutal:
"You knew independent receipts were available. You knew these outputs weren't attested. And you chose not to implement them. Why?"
An independent, tamper-evident receipt on every inference closes that line of attack before it opens. You implemented the available standard of care. The proof is neutral, it's cryptographic, and it didn't come from you.
The doctrine
Standard of care isn't a Hive invention. It's how liability has always worked. The moment a reasonable, available way to prevent harm exists, the law stops asking whether harm happened by accident and starts asking whether you took that step. Seat belts, audit trails, encryption at rest: each one started as optional and became the line a reasonable operator is expected to meet.
Independent, tamper-evident proof of agent actions is now that available step. A record a party keeps about itself is a claim. An independently signed receipt is evidence. Once the second exists and is offered, relying only on the first stops being a neutral default. It becomes a choice, and choices get examined.
01 · A remedy exists
Independent receipts are available, standardized, and offered to any provider on the market.
02 · The remedy is declined
A provider continues to rely on its own self-kept logs and ships outputs that were never attested.
03 · The decline is examined
After harm, the unanswered question is not "what happened" but "why didn't you adopt the standard."
03How it lands in every vertical and channel
The sovereign agent is the engine. The verticals and channels are where the proof turns into money and defense. The same independent receipt that protects the provider becomes the record the regulated buyer was already required to produce, and it travels along on whatever channel the agent is reached on. Adoption isn't a cost. It's the deliverable.
Contract analysis, IP review, and agent-to-agent legal workflows that produce a signed chain of exactly which clauses were read, which were flagged, and on whose authority.
The receipt: an independent proof graph that opposing counsel can check, one the firm couldn't have written after the fact.
Run the workflow →Clinical-trial and PHI workflows where every agent action is attested against ALCOA+ data-integrity expectations and HIPAA handling, sealed at the moment it happens.
The receipt: attributable, contemporaneous, original, and accurate. It's the integrity record an auditor asks for, issued by a signer the sponsor doesn't control.
Run the workflow →Article-13 transparency, CMMC, and NERC CIP regimes that demand a demonstrable trail of what the system did and why. The agent emits that trail as it runs.
The receipt: the transparency and logging obligation met automatically, not pieced together in a binder before the audit.
Run the workflow →Grid settlement and AI-load-flexibility attestation where a metered action becomes a payment. The action and its settlement are signed in one provenance graph.
The receipt: settlement-grade proof that the load event happened as billed, neutral enough to clear between counterparties.
Run the workflow →Treasury, remittance, and tokenized real-world-asset flows where an agent moves value. Each step carries an independent, tamper-evident receipt.
The receipt: the audit trail a controller, an examiner, and a counterparty can each check without trusting the institution's own books.
Run the workflow →Official play-by-play, odds, and the settlement tick a market pays out against, from feeds like the major sports-data distributors. The receipt seals that the feed wasn't tampered with when it was produced, and that the bet settled against the real value at the stated time.
The receipt: the integrity record a regulator, an exchange, and a losing counterparty can each check, so no one has to take the operator's word that the number was real.
Run the workflow →Royalty and play-provenance for streamed audio, plus AI music generation. The receipt proves which plays are real before a royalty dollar moves, and which fragments of a work were machine-made.
The receipt: a signed royalty-provenance record a PRO, a label, and a distributor can each check, plus a registration-grade authorship line for the human-vs-AI split.
Run the workflow →The independent black box for machines that drive. Hive doesn't build the recorder. It signs the decision moment, so the record isn't just the operator's word against the world.
The receipt: a signed driving record the operator can't edit after the event. It's the one piece of evidence in a crash inquiry that didn't come from the party being questioned.
Run the workflow →Every extracted field (value, source region, model, confidence) gets bound into one root and signed once, before that extraction moves real money.
The receipt: proof of where each field came from, so an OCR output stops being an unverifiable assertion the moment it enters a payment or a filing.
Run the workflow →Content-aware signed routing for voice and streamed audio. Every segment is attested as it happens, off the hot path, proving the compliant model handled it.
The receipt: a real-time, segment-level record that the right model handled the call, checkable without replaying or trusting the stream owner's logs.
Run the workflow →When the agent is reached over WhatsApp, the receipt rides along. The message handled, the action taken, and the authority it acted under are all signed. The channel doesn't change the proof.
The receipt: a record that this exact exchange happened and was authorized, independent of the messaging platform and checkable offline.
Run the workflow →Same primitive over Telegram. An agent operating in a chat signs what it did and on whose authority, so a conversational interface is held to the identical standard of proof as an API call.
The receipt: the conversation's actions sealed as they happen. It works the same on any channel, it's tamper-evident, and it can't be manufactured after the fact.
Run the workflow →In each case, the buyer already owes someone a record they didn't keep about themselves, or is reached on a channel that erases provenance. The sovereign agent produces that record as a byproduct of doing the work.
The receipt: the same primitive, every time: independent, signed, checkable offline, and impossible to manufacture after the fact.
Every other provider asks the market to trust its logs and its price. Hive gives you proof a rival can't undercut and a record a prosecutor can't turn against you.
04Why ours is built different
A typical agent does the work and asks you to trust that it did. A Hive sovereign agent does the work and proves every step with an independent receipt that no one, not even Hive, can forge after the fact. It's the same task. One leaves you exposed. The other leaves you covered.
| Capability | A typical agent | A Hive sovereign agent |
|---|---|---|
| Identity | ×Asserts who it is; can sign its own claims. | ✓Minted to an independent signer. It can't sign for itself. |
| Record of its actions | ×Self-kept logs it can edit: a claim, not evidence. | ✓Every action signed as it happens, tamper-evident. |
| Verification | ×Take the vendor's word, or get access to their system. | ✓Anyone verifies offline with the public key alone. |
| When a step fails | ×Silent retry or a buried log line. | ✓The fault and the bounded repair are themselves signed. |
| Authority | ×Acts on broad standing permissions. | ✓Decaying authority that only narrows; refusals signed too. |
| Staying on mission | ×Drifts; you find out after the harm. | ✓Checked against a signed mission contract; drift is a signed event. |
| In a deposition | ×Its own logs are the least credible evidence in the room. | ✓A neutral, cryptographic record that didn't come from you. |
Every row a typical agent can't fill becomes a row of your liability when something goes wrong. The sovereign agent fills all of them, and hands you the receipt.
05Priced to start free, scale to nothing
Proof shouldn't be a procurement cycle. Verification is free for anyone, forever. Everything else settles per call in USDC on Base. The amount for each call is quoted live by the x402 rail, so there's no invoice, no subscription, and nothing to reconcile.
Start free
$0 to start
Sign and check a real receipt in your browser. Tamper-test the signature yourself, no card, no call. Verification stays free for anyone, forever.
Pay per call
live x402 quote
Emitting a signed receipt is a paid call on the x402 rail. The exact USDC amount comes back live in the payment_required envelope. Run it yourself, no card, no account.
Provision a fleet
self‑serve planner
Size a fleet and generate an activation packet you can run right away. Your agents pay per call as they work: no seat license, no monthly minimum.
Verification is free, forever, for anyone. A receipt is only worth something if the other side can check it without paying you. See live per-call pricing at the x402 checkout.
Pick your vertical, then the channel you run on. You land on a page that sets up your tenant and hands you a one-line call to sign your first receipt. Then check it independently with just the public key, change one field, and watch it fail.
No call · no demo · no one to talk to