Compliance

Posture, not promises.

Hive is built to help you meet the record-keeping, residency, and disclosure rules showing up across the EU, the U.S., and major Asian markets. We tell you exactly what the system does. We don't make legal calls for you. That's your counsel's job.

Designed to support compliance · Reviewed by counsel · Not legal advice
Regulatory posture

What Hive is designed to support.

For each rule below, we explain exactly what Hive does and what evidence you get in the receipt. We're not claiming you're legally compliant. That call is yours and your counsel's.

EU

EU AI Act

Built to help you meet Article 12 record-keeping rules for high-risk systems. That means automatic logging on every call, disclosure when inference crosses borders, a declared training region, and evidence for post-market monitoring.

fieldsorigin · operator · training_region
exportregulator-readable JSON
EU

MiCA

When an AI transaction settles in USDC on Base, you get a receipt tied to the settlement hash. That's built to help you meet the transaction-record rules MiCA places on anyone operating in or with the EU.

assetUSDC · Circle
recordsettlement hash in receipt
EU

EU Data Act

Provenance fields and ViewKey-gated inspection help you meet the data-access, data-portability, and third-party-access rules under the Data Act, without ever giving the platform itself plain access to your data.

accessViewKey · scoped, time-bound
plaintextnever seen by platform
U.S.

U.S. export controls

The operator co-signs a hardware-class attestation into every receipt. Restricted-destination rules (RU, CN, IR, KP, SY, CU, BY) get enforced at routing time, before any compute happens.

fieldhardware.class · attested
enforcementpre-compute · deny on unmatched
GLOBAL

Sanctions screening

Before any compute or settlement starts, restricted-geography rules get checked against the requester's identity anchor, the operator's region, and the settlement counterparty.

scopeorigin · operator · settle
posturedeny on unmatched
GLOBAL

Audit posture and residency

We're working toward SOC 2 Type I and ISO 27001 readiness right now. We don't yet hold SOC 2 Type II, ISO 27001 certification, or FedRAMP. You can see live status on /trust.

SOC 2 Type Iin progress
ISO 27001readiness
SOC 2 Type II / FedRAMPnot yet held
SANCTIONS

Restricted-geography routing

Hive doesn't operate in, route to, or accept settlement from any jurisdiction under comprehensive U.S. or allied sanctions. The active list follows current OFAC, EU Council, and UK Treasury designations, and we update it as those change. We block these at the routing layer, before an operator quote goes out and before any escrow locks. We still write a receipt for blocked attempts, so there's an audit trail, and it's clearly marked blocked_by_policy.

policy sourceOFAC · EU Council · UK Treasury
enforcementat routing time
posturedeny on unmatched

Wave-Lattice provides the cryptographic attestation behind the receipt-signing layer. It uses ML-DSA-65, ML-KEM-768, and 6-axis MAPET, with a passing CAVP self-test, for any transaction that needs post-quantum-ready signature proof under the rules that apply to it.

Boundaries

What we do not claim.

Hive supports compliance work. Here's what Hive is not:

  • not legal advice
  • not a regulatory authorization
  • not a substitute for counsel
  • not a guarantee of conformance
  • not a custodian of your data
  • not a recommendation engine

We tell you exactly what the system does. Your counsel decides how that applies to your own obligations.

Next

Request a private compliance briefing.

The briefing covers the receipt schema, the ViewKey access model, restricted-geography routing rules, our audit posture, and a counsel-reviewed mapping to the EU AI Act, MiCA, the EU Data Act, and U.S. export-control rules. It's sealed to your organization and modeled on Hive's live infrastructure.