SDR · Signed Driving Record

The black box they can’t edit.

The rules already say it: a self-driving car has to record what it saw, what it decided, and when it handed control back to a human. That record has to be in a format investigators can trust. But here's the catch. The carmaker holds the recorder. A black box that the operator can edit, delay, or deny isn't evidence. It's just a claim. SDR signs every perception, decision, and disengagement frame with an independent post-quantum receipt. That gives you one record of what your vehicle did that the operator, the plaintiff, and the regulator can all check, and none of them can change.

UN R157 + R160: tamper-proof ADS data recording, open to investigators, already in force
R157 / R160
UN rules require tamper-proof ADS recording
5 seconds
the disengagement window that can turn a crash into a "human error"
77µs
how long it takes to sign a driving-event frame
0
access to your platform needed to check it
Part of AFiR-Aegis SDR is the regulatory on-ramp. It satisfies the UN R157 / R160 recording rules. The full independent-attestation product, which also ties driver-state, vehicle-fitness, and jurisdiction into each receipt, is AFiR-Aegis. See the Aegis flagship

Every mile, independently signed. This is a live signed driving-event receipt, issued no matter which recorder the operator uses.

The recorder exists. The problem is who holds it.

After a crash, everything comes down to one question: what did the vehicle actually do in the seconds before impact? Right now, the only party who can answer that holds the recorder, controls what gets exported, and has the strongest reason to shade the truth. The same three things keep going wrong.

The data didn’t exist yet

Recovered, not produced

In a fatal Florida FSD case, the crash data “didn’t exist” until an independent researcher recovered it. NHTSA had to pull the recorder itself, and that's the version that counted. When the operator is the only one holding the data, the record is only whatever the operator decides to keep.

The 5-second window

Reclassified as human

A disengagement logged just a few seconds before impact can turn an automated crash into a "human-caused" one. Senators have asked NHTSA to audit that telemetry, because the regulator “has no way of knowing whether public-safety claims bear any relationship to reality.” That disengagement timestamp is exactly the field that decides who's liable.

One company’s version

Self-reported and contestable

As crash-reporting rules get rolled back, what reaches investigators is more and more just the operator’s own filtered export. BYD now accepts liability for its driver-assist. The largest US operator never has. A recorder that's "tamper-proof" on paper doesn't help if the operator still decides what to hand over, and when.

What SDR adds underneath

An independent signature on every driving-event frame

SDR signs each perception, planning, and disengagement frame: what the stack saw, what it decided, the system state, and the exact handover timestamp, all using ML-DSA-65 (the government's post-quantum signature standard, NIST FIPS 204), with a key the operator doesn't hold. Anyone can check the record offline forever, with no access to your fleet: a regulator, a court, an insurer, a plaintiff. Move the disengagement timestamp by even one second and the check fails. SDR doesn't replace your EDR, your DSSAD, or your data store under R157 and R160. It sits underneath them and turns the recorder the operator holds into a record the operator can't edit.

Why the mandate is the opening.

UN Regulation 157 (DSSAD) and UN Regulation 160 (EDR) already make self-driving cars record system status, whether a driver is available, and the surroundings, in a tamper-proof format investigators can read. New UN global rules now require a data-storage system for automated driving too. The duty to record is settled. What isn't settled is whose word the record actually represents.

A recorder satisfies the rule right up until someone disputes the readout. On that day, “our logs show” is just a claim from the one party with the most to lose. An independent signature is the only kind of recording whose truth doesn't depend on trusting the operator who made it.

SDR isn't another data logger competing with your DSSAD or your EDR. It's the proof layer that makes whatever your recorder captured hold up the moment a regulator, an insurer, or a court asks you to prove nothing moved between the crash and the export.

How it works on a fleet.

1 · In the loop

As the stack runs, SDR signs a receipt over each driving-event frame: the perception summary, the planned action, the system state, and the disengagement or handover timestamp. It works out-of-band. It only records, it never controls the vehicle.

2 · Alongside DSSAD / EDR

The receipt travels with the recording you already keep under R157 and R160. Your logging pipeline stays the same. The signature just makes each frame independently checkable after the fact.

3 · On a crash or audit

A regulator pulls the record. A plaintiff claims the disengagement was backdated. An insurer disputes fault. The receipt checks out, or it doesn't, using the public key alone, with no access to your systems. You move from "trust our export" to "check the math."

4 · Free to verify, forever

Checking a receipt costs nothing and needs nothing from Hive or from you. The receipt outlives the investigation, the recall, the lawsuit, and even the company. The record of what the vehicle did survives everyone who has a reason to change it.

Pick a driving event. Sign it. Verify it live.

This is the real signer, not a mock-up. Pick a frame from a driving event. The same independent signer handles every one of them. Here's what you'll do and what you should see: sign the frame, check it independently, then backdate the disengagement by one second and watch the check fail. That's the field a liability fight turns on.

Live endpoint: hive-typed-signer.onrender.com/sign and /verify, real ML-DSA-65

Pick a frame from the driving event

A single approach to an intersection, frame by frame

The driving-event frame

The independent receipt

Press “Sign frame” to sign with the live endpoint.
Not signed
An independent ML-DSA-65 receipt over the driving-event frame.
Step 1 of 3: sign the driving-event frame.

One tool, working across the whole stack.

Perception, prediction, planning, the disengagement event, the human-availability check, the over-the-air software version running at the time, the sensor-health state. Every layer that an investigator, an insurer, or a court will ask about has the same gap underneath the recorder. The receipt works the same no matter the subsystem: the same signer signs each frame, and anyone can check it offline. SDR sits underneath whatever recording stack you already run. It doesn't compete with it.

PerceptionPredictionPlanning & decisionDisengagement / handoverDriver-availability stateSoftware / OTA versionSensor healthPost-crash export

How a frame becomes evidence.

Three steps, the same for every frame. Here's what happens and what you should see. Hive is the independent third party in the loop. It doesn't assess whether the driving decision was right. It signs what the stack recorded and lets anyone else check it.

1

The stack records

Send the driving-event frame (perception, decision, system state, the disengagement timestamp) to the signer through one API call from the vehicle or the fleet backend.

result: typed fragments accepted
2

Hive signs, independently

An ML-DSA-65 receipt gets made over those exact fields. It's post-quantum and tamper-evident, and it's issued by a key that belongs to neither the operator nor the regulator.

result: independent receipt in ~77µs
3

Anyone verifies, offline

A regulator, an insurer, or a court checks the receipt with the published public key alone. No access to your fleet, no access to Hive. Move the disengagement time by a second and it fails.

result: VALID, or INVALID if altered
Third-party recording

The signature comes from an independent key, not the operator’s. A black box you control is just a claim. An independently signed frame is evidence.

Liability you can prove

SDR only vouches for what the stack recorded and that nobody changed it. It doesn't assess whether the maneuver was right. It proves no one moved the disengagement timestamp.

Sits underneath R157 / R160

It runs beneath the DSSAD, the EDR, and the data-storage system you already maintain. It doesn't replace or compete with any of them. It makes them provable.

Sign your fleet.

Pick the layer of the stack you want receipted first. You'll land on a page that sets up your tenant and gives you a one-line call to sign your first driving-event frame. No call, no demo, no one to talk to.

This is independent, third-party recording and attestation. Hive signs what your stack records and makes no decision about the driving. Run the steps above and you'll see VALID on an honest frame and INVALID the instant a field gets altered. Checking a receipt is free, forever, for anyone: the regulator, the insurer, the court.

Prove it yourself in thirty minutes.

No call, no demo, no one to talk to. Sign a driving-event frame above, check it independently with the public key alone, then backdate the disengagement by one second and watch it fail. The same flow runs against your own stack through the SDK. It's independent, third-party recording that sits underneath the DSSAD and EDR you already run under R157 and R160.

Sources: UN R157 (DSSAD) + R160 (EDR) require tamper-proof ADS recording accessible to investigators, from MmowW and UN News. Florida FSD crash data recovered independently, from Electrek. Senators ask NHTSA to audit FSD telemetry and the 5-second disengagement window, from The Star / Reuters and Tesery. AV crash-reporting requirements rolled back, from The Crash Report. NTSB recommendation on 49 CFR Part 563, from NTSB. BYD accepts driver-assist liability, from Electrek.