Every DLP route, MCP call, and guardrail decision lives in logs that Netskope controls. Those logs matter, but the same party that produces them also writes them. Hive takes the events that matter and turns them into signed receipts that live outside that system. So when the log gets questioned, edited, or subpoenaed, your proof isn't sitting in the building that just burned down.
AI has a trust problem. Models can tell you what they claim they did, but they can't prove it on their own. Hive exists to close that gap.
You already own these surfaces. Each one makes a decision today, and each one turns into a signed proof product the moment it carries an independent receipt. Pick a surface below to see the primitive that signs it, and the line you get to say to a regulated buyer.
After a breach, the first thing a skilled attacker does is scrub the record. T1070 shows up in half the incident reports your buyers read. Watch it happen twice: once against a platform log, and once against a receipt anchored outside that system.
This stream is a live simulation of Netskope One decisions: DLP, MCP, guardrails, DSPM, insider risk. Everything arrives platform-logged. Hit PROMOTE on any row, or flip on auto-promote, and watch it turn into an independently receipted proof object. That's the whole idea: log everything, sign what counts.
Five events roll into one incident bundle. Click each node to cycle its proof-state: self-attested → relay-observed → independently receipted. The case floor only goes up once the last weak link does. That honesty is exactly what a regulator trusts.
ARSC scores every grounding fragment at the start of a session, with policy signed up front and zero re-scores after that. High-risk bindings sign inline at 7ms. Supporting fragments commit inline and sign off to the side. Low-risk context gets hashed into the next batch anchor. Watch the critical-path latency drop.
AFiR signs that an inference happened. AFiR-S signs which fragments grounded it. AFiR-ARSC signs them in the order that keeps latency low. The next five primitives, each patent pending and already filed, sign the questions that come up after the answer ships: did the agent remember the rule, did the right model run, did the model pass its eval, did the provenance signals agree with each other.
Facts marked for durability get committed at the gate, retention gets checked at each step downstream, and a signed receipt comes out every time. Policy persistence becomes something you can prove, not just hope for.
It estimates the memory demand, checks it against signed per-model memory-performance profiles, and picks the model whose proven headroom covers it. No quiet fallback to a weaker model when load spikes.
This gathers signed retention receipts (MiR-M) per model into a profile that can't be faked: fact-loss rate, fact-loss versus depth, version drift. Procurement gets real fitness data on the model, not vendor marketing.
It ties a model-identity fingerprint, a rubric fingerprint, a dataset fingerprint, an eval-method marker, and a per-item result count into one signed receipt you can check without a shared secret. Public eval claims turn into evidence that holds up.
This cross-checks provenance signals across one or more receipts. If they disagree, it raises a signed anomaly flag and starts a triangulation check. It's an active defense against forged receipts and supply-chain attacks on inference.
GiTM produces SiGR-family receipts on the live ML-DSA-65 signer today. MiR-M, MaR, MPP, and EvAR are filed and not released. Standard receipts verify offline through one library. USDC payment on Base is separate; any evidence anchor must be separately selected and specified.
Every DLP decision, every real-time policy hit, every agent action does not need the same weight of proof. Carnac™ forms no opinions. It determines the required proof, records provenance, and signs the record. Set what is at stake and how alone the AI is acting, and watch the route it earns.
When your team writes the rule the AI must follow, Carnac Live Ink™ marks each part in the moment it is written and gives it the route it earns. The record is built while the policy is written, not rebuilt afterward.
The proof SOC already turns the decisions that matter into durable evidence. This receipt adds a fixed timeline for a flagged artifact, is live on the production rail, and the run below verifies it. Two receipts from The Authority Line add the authority side of the same record: whether access was still valid at the moment it was used, and whether a declared freeze window stayed empty.
When a DLP rule flags an artifact, this receipt ties its digest to a named detection system, a pinned software build, and a pinned rule version. It records the time through a named external time anchor and its stated drift bound. It also places that record in an append only hash chained sequence. The result bounds the latest moment the DLP engine can later be said to have first held that flagged artifact. The result is recomputed rather than supplied by the caller, with no human approval in the mint path.
What it does not do. It does not establish the earliest time the engine held the artifact or show that the detection was correct, that the artifact described a real condition, or that any condition existed. It does not identify an affected system, person, account, or asset; reveal the artifact; decide whether a response was reasonable, timely, adequate, or complete, any materiality assessment, reporting obligation, deadline, rule, or breach; or authorize, require, or excuse notification, escalation, disclosure, remediation, or enforcement.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Revocation is easy to publish and hard to prove. The real question after an incident is whether the acting party could have known, at the moment it acted, that the authority had been pulled. This receipt binds the revocation event, the propagation bound the network committed to, and the time of the action, then classifies the action as before revocation or after the propagation bound. That turns an argument about stale caches into a signed answer.
What it does not do. It does not perform the revocation and it does not stop the action. It records where the action fell relative to a revocation the network already published.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Proving something happened is the easy half. The hard half is proving nothing did, inside a freeze, a restricted period, a blackout, or a maintenance window. An empty log is not evidence, because an empty log is also what a broken logger looks like. This receipt fixes the window, the class of effect that was prohibited, and the observation coverage over that window, then reports whether the window stayed quiescent or an effect was observed. Coverage is part of the answer, so a gap in monitoring cannot pass as silence.
What it does not do. It does not watch surfaces it was not pointed at, and it says so. If coverage over the window is incomplete, the receipt shows that rather than reporting quiet.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.