{
  "schema_version": "1.0.0",
  "review_date": "2026-09-05",
  "purpose": "Editorial claim control. Not cryptographic or operational acceptance evidence.",
  "release_binding": "Dated verification of the reviewed content revision, not a claim that this registry's containing commit was tested or deployed. Subsequent parser, link and metadata changes are tracked separately. No endpoint acceptance follows from a source or deployment identifier.",
  "governed_paths": [
    "index.html",
    "developers.html",
    "security/index.html",
    "security/founder-risk/index.html",
    "security/iso-27001-self-attested/index.html",
    "security/soc2-self-attested/index.html",
    "privacy.html",
    "trust.html",
    "trust/index.html",
    "canon/index.html",
    "verify/index.html",
    "ice/index.html",
    "smsh-pq/index.html",
    "smsh-pq/why-now/index.html",
    "hive-pq.html",
    "radar/index.html",
    "radar/radar.js",
    "radar/receipt/index.html",
    "radar/receipt/receipt.js",
    "carnac/index.html",
    "afir/index.html",
    "afir/sidecar/index.html",
    "afir/mint/index.html",
    "afir/success/index.html",
    "afir/afir-evolution.html",
    "afir/arsc-settlement-3d.html",
    "assets/hive-nav.js",
    "assets/hive-benchmark-strip.js",
    "assets/hive-benchmark-core.mjs",
    "assets/hive-radar-scope.js",
    "assets/hive-radar-beacon.js"
  ],
  "global_governed_globs": [
    "**/*.html",
    "assets/*.js",
    "scripts/*.py",
    "scripts/*.mjs"
  ],
  "claims": [
    {
      "id": "PQ-SIZE",
      "approved_wording": "Report raw signature bytes separately from complete serialized receipt and encoded transport size.",
      "pages_products": [
        "/smsh-pq/",
        "/hive-pq.html",
        "/developers/"
      ],
      "scope": "ML-DSA-65 standard and measured artifacts.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.204.pdf"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "A standard signature size does not measure a complete receipt or establish deployed verification."
    },
    {
      "id": "PQ-ROLES",
      "approved_wording": "ML-KEM is key encapsulation, not a signature. Signatures authenticate signed statements; they do not encrypt their contents.",
      "pages_products": [
        "/",
        "/hive-pq.html",
        "/smsh-pq/",
        "/developers/"
      ],
      "scope": "Cryptographic roles.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "hive-pq.html",
        "developers.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "Algorithm use does not establish module validation or which model executed."
    },
    {
      "id": "CANON-ACCEPTANCE",
      "approved_wording": "Historical manifests and endpoint responses cannot promote current acceptance.",
      "pages_products": [
        "/canon/",
        "/developers/"
      ],
      "scope": "Historical metadata versus endpoint acceptance.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "canon/registry/hive-canon-registry.json",
        "scripts/generate_canon_registry.py"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "Unknown acceptance does not mean unavailable. Every accepted endpoint needs pinned tests and revisions."
    },
    {
      "id": "VERIFY-TRUST",
      "approved_wording": "Signature validity, issuer identity, completeness, witnessing and execution are separate results.",
      "pages_products": [
        "/verify/",
        "/carnac/",
        "/developers/",
        "/trust"
      ],
      "scope": "Supported schemas and executed checks.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "verify/verifier-core.mjs",
        "verify/verifier-app.mjs"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "An embedded key is not an issuer trust anchor. A supplied root is not a trusted checkpoint."
    },
    {
      "id": "PLAINTEXT",
      "approved_wording": "Carnac receives readable submitted text for classification. Processing and storage are different boundaries.",
      "pages_products": [
        "/privacy",
        "/security/",
        "/carnac/"
      ],
      "scope": "Public sandbox and deployment-specific processing.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "carnac/index.html",
        "privacy.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive privacy and engineering",
      "limitations": "Processor logs, backups and exports need separate evidence."
    },
    {
      "id": "REGION",
      "approved_wording": "Use service-specific deployment configuration for region statements.",
      "pages_products": [
        "/security/",
        "/privacy"
      ],
      "scope": "Configured backend region.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "security/index.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive operations",
      "limitations": "Static CDN distribution has no single region established here. Vendor options do not identify a selected region."
    },
    {
      "id": "KEY-CUSTODY",
      "approved_wording": "Identify signing boundaries by service and algorithm. Validation requires an identified certificate and applicable scope.",
      "pages_products": [
        "/security/",
        "/hive-pq.html"
      ],
      "scope": "Signing implementation and custody.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "security/index.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "Self-tests, algorithm validation and module validation are distinct."
    },
    {
      "id": "RETENTION",
      "approved_wording": "A published contract period is not a Hive storage guarantee. Retention requires an approved schedule and tested enforcement.",
      "pages_products": [
        "/security/",
        "/privacy",
        "/ice/",
        "/developers/"
      ],
      "scope": "Receipts, logs, inspection, accounts, backups and processor copies.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://www.ice.com/publicdocs/agreements/ICE_Data_Services_Agreement.pdf",
        "privacy.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive legal and operations",
      "limitations": "Agreement applicability, legal holds and deletion verification require deployment-specific approval."
    },
    {
      "id": "CAPTURE",
      "approved_wording": "Delivery can proceed without a sidecar record. The public Carnac sandbox does not write a durable decision ledger.",
      "pages_products": [
        "/ice/",
        "/carnac/"
      ],
      "scope": "Public sandbox and proposed ICE pilot.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "ice/index.html",
        "carnac/index.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "Complete capture requires expected-event reconciliation, persistence and recovery tests."
    },
    {
      "id": "BENCHMARK",
      "approved_wording": "Preserve measurements with run context. Undefined effect sizes and feature-presence demonstrations are not competitive performance results.",
      "pages_products": [
        "/trust",
        "/canon/",
        "shared benchmark strip"
      ],
      "scope": "Historical artifacts and presentation.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "trust.html",
        "assets/hive-benchmark-strip.js"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering",
      "limitations": "Full compute costs, retries and selection overhead are required before claiming ensemble advantage."
    },
    {
      "id": "ANCHOR",
      "approved_wording": "Signing, submission acknowledgment, preconfirmation, block inclusion and finality are separate stages.",
      "pages_products": [
        "/afir/",
        "/developers/",
        "/"
      ],
      "scope": "Receipt-bound chain evidence.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "afir/index.html",
        "https://datatracker.ietf.org/doc/draft-rotzin-spice-afir-profile/"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive engineering and draft author",
      "limitations": "A USDC transfer alone is not anchoring. External publication is a separate submission gate."
    },
    {
      "id": "INDEPENDENCE",
      "approved_wording": "A Hive-operated countersigner is not organizationally independent. Continuity arrangements require evidence.",
      "pages_products": [
        "/verify/",
        "/canon/",
        "/security/founder-risk/"
      ],
      "scope": "Witness control and founder recovery.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "security/founder-risk/index.html",
        "verify/index.html"
      ],
      "source_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "deployed_version": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
      "last_verification_date": "2026-09-05",
      "owner": "Hive founder",
      "limitations": "No insurance, escrow, independent audit or executed recovery agreement is inferred."
    },
    {
      "id": "SIG-PROFILE",
      "approved_wording": "Ed25519 signs every receipt. ML-DSA-65 is added only on endpoints that have separately accepted the post-quantum profile. SLH-DSA is a profile goal and is not a shipped signature.",
      "pages_products": [
        "/pricing/",
        "/signup/",
        "/packages/live-ink/",
        "/onboard/"
      ],
      "scope": "Signature algorithm claims on every buyer-facing pricing, plan, and signup surface.",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "pricing/index.html",
        "signup/index.html",
        "packages/live-ink/index.html"
      ],
      "source_version": "917fd93c",
      "deployed_version": "917fd93c",
      "last_verification_date": "2026-09-06",
      "owner": "Hive founder",
      "limitations": "No claim of dual signing, PQ sealing, or SLH-DSA availability may appear on a plan card unless the pricing page states the same acceptance condition."
    }
  ],
  "forbidden_patterns": [
    {
      "id": "wrong-region",
      "pattern": "US East\\s*\\(Oregon\\)"
    },
    {
      "id": "kem-signature",
      "pattern": "ML-DSA-65 and ML-KEM-768 dual-signature"
    },
    {
      "id": "sentinel-performance",
      "pattern": "9999\\.00"
    },
    {
      "id": "premature-anchor",
      "pattern": "7\\s*ms\\s+on-chain\\s+confirmation"
    },
    {
      "id": "blanket-plaintext",
      "pattern": "customer data never (?:reaches|arrives at) Hive in plaintext"
    },
    {
      "id": "false-pulse",
      "pattern": "LIVE VERIFIED PULSE"
    },
    {
      "id": "sandbox-log-promise",
      "pattern": "(?:is|are) not logged by default"
    },
    {
      "id": "unsupported-validation",
      "pattern": "CAVP self-test"
    },
    {
      "id": "unverified-cpa-audit",
      "pattern": "Tier 1 CPA firm"
    },
    {
      "id": "universal-double-signature",
      "pattern": "Every receipt carries dual signatures"
    },
    {
      "id": "operator-independence",
      "pattern": "independently verified by Hive"
    },
    {
      "id": "universal-inference-capture",
      "pattern": "Every sub-step of a routed inference is cryptographically signed before the output moves"
    }
  ],
  "global_forbidden_patterns": [
    {
      "id": "blanket-privacy-promise",
      "pattern": "Hive does not store your prompts\\. Every request is already receipted"
    },
    {
      "id": "certification-badge",
      "pattern": "Third-party (?:verified|certified) receipts|Third-Party Verified"
    },
    {
      "id": "universal-rail-profile",
      "pattern": "All rails share one signed-receipt spec"
    },
    {
      "id": "public-wex-commercial-leak",
      "pattern": "WEX terms are set in a proposal"
    },
    {
      "id": "unsupported-pricing-superlative",
      "pattern": "Fastest\\. Cheapest\\. Strongest\\."
    },
    {
      "id": "absolute-added-latency",
      "pattern": "zero added latency"
    },
    {
      "id": "unsupported-durability-term",
      "pattern": "15-year cryptographic durability"
    }
  ],
  "reviewed_content_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
  "deployment_observation": {
    "website_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
    "typed_api_revision": "0ebc7fc9e5458cb761a9757b3b44911f80481de2",
    "observed_at": "2026-09-05T22:10:11.729987+00:00",
    "website_deployment": "dep-dae8pcbbc2fs73c6f1sg",
    "typed_api_deployment": "dep-dae8pcbbc2fs73c6f1ug",
    "basis": "Authenticated Render deployment records and live typed API build metadata.",
    "scope": "Source deployment identity; not complete operational acceptance."
  }
}
