Receipt security, with explicit service boundaries. Review the signing implementation, processing locations and retention gaps before accepting a deployment. review evidence.
Six domains, with source-backed boundaries and the evidence needed for acceptance. This is not a completed production security audit. Last reviewed September 5, 2026. review evidence.
Hosting locations below come from the September 5 configuration review, not vendor marketing. Other listed relationships, storage regions and contract terms still need verification. See the retention inventory and review evidence.
| Processor | Purpose | Region | Compliance |
|---|---|---|---|
| Render | Typed API, countersigner, receipt/Carnac and signer compute | Oregon, United States (four services verified) | render.com/security → |
| Cloudflare | Site distribution and edge services; exact rule coverage open | Global distribution; no single region verified | cloudflare.com/trust-hub → |
| Stripe | Earlier billing listing; active processing relationship not verified | Not verified | stripe.com/privacy → |
| Mercury | Earlier treasury listing; account and data scope not verified | Not verified | mercury.com/legal/privacy → |
| GitHub | Source hosting and deployment integration | Processing/storage region not verified | github.com/privacy → |
| Supabase / other storage | Source contains Supabase paths for Carnac and telemetry; AWS S3 receipt storage not verified | Project region and backup locations not verified | Storage evidence → |
Hive Civilization welcomes security researchers. We commit to a fair, transparent disclosure process.
security@thehiveryiq.com
Encrypt sensitive reports using our PGP key, available on request at the address above. Provide sufficient detail to reproduce the issue. Do not access customer data beyond what is necessary to demonstrate the vulnerability.
In scope: thehiveryiq.com and all subdomains, Hive API endpoints, Cloudflare Workers serving hive-signed receipts, Hivemorph admin panel. Out of scope: third-party sub-processors, social engineering, denial-of-service testing, automated scanning without prior approval.
| Researcher | Finding | Date |
|---|---|---|
| First responsible disclosure reporter will appear here. | ||
We do not offer monetary bounties at this time. We commit to public acknowledgement, coordinated disclosure, and a letter of commendation for valid critical findings.
No independent penetration-test agreement or report was supplied for this review. Scope, tester, date and remediation retest must be confirmed.
Evidence openExercise records and coverage for authentication, tenant isolation and API abuse were not supplied. A proposed cadence is not an executed test.
Records neededThe six phases below are a response outline. Notification obligations depend on applicable law and executed contracts; the earlier time targets were not verified as contractual SLAs.
| Severity | Definition | Customer Notification | Post-Mortem |
|---|---|---|---|
| Sev 1 | Complete service outage, confirmed data breach, or cryptographic key compromise | To be agreed | To be agreed |
| Sev 2 | Significant performance degradation, partial service disruption, or potential data exposure | To be agreed | To be agreed |
| Sev 3 | Minor functionality impacted; no data risk; workaround available | To be agreed | To be agreed |
Report incidents to security@thehiveryiq.com. Status publishing, subscriptions and escalation delivery need an operational check.
Send your required controls and evidence scope. Document availability and response dates must be confirmed for the request.
Request SIG Lite or SIG Core materials. Completed responses were not supplied for this review.
Request a CAIQ response against the deployment in scope. Completion is not verified.
Send your questionnaire template and identify the services under review.
Request the applicable DPA for legal review. Signed terms, roles and transfer provisions must be verified.
Confirm the contracting entity and applicable agreement before procurement approval.
For procurement, identify the service, data classes and required assurance. review evidence lists what was reviewed and what remains open.
No audit or certification date is approved in the evidence reviewed. Scope, owner, budget and external engagement must be established before publishing a target.
Executed engagement letter and independent Type 1 report not supplied.
Evidence openAuditor, scope and observation period require agreement; no report date verified.
Evidence openAlignment and certification dates unapproved. Review the ISO evidence inventory.
Evidence openAuthorization path, agency sponsorship and assessment scope not established. No automatic prerequisite claim is made.
Evidence openHive is a single-founder operation. The continuity disclosure separates proposed second-admin access, escrow, succession and insurance from arrangements with verified evidence.
Read the founder-risk disclosure →For security reviews, vulnerability reports and questionnaire requests, use the form to prepare an email. Do not include secrets or customer payloads.