Trust & Compliance · Deployment Evidence

Security documentation

Receipt security, with explicit service boundaries. Review the signing implementation, processing locations and retention gaps before accepting a deployment. review evidence.

Audit evidence open HONEST CURRENT STATE

Current review: The source and hosting review dated September 5, 2026 covers four Render services. No executed SOC 2 engagement letter, independent audit report or ISO certificate was supplied for this review. The inventory separates observed code from controls awaiting operational evidence.

Audit roadmap: SOC 2 and ISO 27001 dates remain unapproved in the reviewed evidence. Earlier 2026 and 2027 targets are withdrawn pending an owner-approved scope and schedule.

SOC 2 review inventory → and ISO 27001 review inventory → list evidence to collect, not independently accepted controls.

Audit Engagement Not verified
AICPA SOC 2 Report Not supplied
ISO 27001 Date unapproved
Cryptography Service-specific
Engagement Letter Not supplied
Controls Inventory

Security control review.

Six domains, with source-backed boundaries and the evidence needed for acceptance. This is not a completed production security audit. Last reviewed September 5, 2026. review evidence.

8 review areas

Access Control

  • Production identity review: obtain MFA enforcement and administrator coverage for GitHub, Cloudflare, Render and other active systems.
  • SSO coverage: confirm the identity provider and any local-login exceptions. Organization-wide enforcement was not verified.
  • Typed receipt minting checks an authorization token and signer configuration. Tenant isolation still requires endpoint-specific tests.
  • Service credential review: document ownership, scopes and shared-credential exceptions without exposing secret values.
  • Signing-key rotation: no verified 90-day automatic invalidation policy. Preserve trusted historical public keys and test old receipts after rotation.
  • Administrative hardware-key enforcement requires identity-provider and application evidence.
  • Session controls require measured idle and absolute expiry tests; no platform-wide timeout was verified.
  • Administrator network restrictions require deployed edge rules and origin-bypass tests.
6 review areas

Cryptography

  • Ed25519 signs typed API receipts, receipt/Carnac records and countersignatures. The separate signer service implements ML-DSA-65; receipt formats and acceptance differ by endpoint.
  • ML-DSA is a signature scheme; ML-KEM is key encapsulation, not a signature. An algorithm label or self-test is not a validation certificate. See NIST CAVP and CMVP.
  • Transport review must cover edge, origin and outbound calls. HTTPS does not prevent a receiving service from processing readable content.
  • HSTS coverage and minimum TLS versions require per-host configuration and response checks.
  • Mutual TLS and certificate pinning are different controls. Neither is verified here as an enterprise deployment feature.
  • Signing runs in application processes, not a verified KMS boundary. Ed25519 uses environment-provided or locally generated keys; ML-DSA-65 uses an application-memory keypair; its base seed comes from environment or file, and a separate derived-key QPuF path also exists in source. review evidence.
6 review areas

Data Handling

  • Client-side hashing can keep content outside Hive. Carnac receives request/output text for classification; its judgment schema records features and metadata rather than raw request/output fields. review evidence.
  • Logs and metadata can contain personal data. Source includes IP, user-agent, referrer and page-path telemetry; processor-side payload exclusion and redaction need verification.
  • The four reviewed Render services run in Oregon, United States. Static distribution is global. No EU-only processing or storage configuration was verified.
  • Approved durations, start events, holds, deletion steps and verification are open by data class in the retention inventory. No platform-wide automatic-deletion timer is verified.
  • Deletion requests must be authenticated and scoped to identified records, replicas and processors. A completion deadline requires an agreed schedule and verified operational evidence. An API response alone does not establish removal of downstream copies.
  • A signed tombstone authenticates a deletion statement, its identified record set and recorded timestamp when verified against a trusted signer. It does not prove that every downstream copy, backup, cache or export disappeared, or establish GDPR Article 17 compliance by itself. Check the actual receipt's declared signing scheme, retained keys and replica evidence; this page does not promise both Ed25519 and ML-DSA-65 on every deletion record. Any chain anchor is separate and optional.
4 review areas

Network Security

  • Cloudflare distributes the site. WAF scope, custom rules and origin coverage need configuration evidence.
  • DDoS and rate-limit acceptance must identify covered hosts and tested thresholds, rather than relying on vendor capabilities.
  • Origin encryption needs verification on each hop. The deployed receipt source includes a legacy HTTP IP-geolocation call; platform-wide encrypted transport is not established.
  • Webhook security requires delivery-path review, receiver authentication and replay tests. No universal outbound HMAC policy was verified.
4 review areas

Application Security

  • Input validation is endpoint-specific. Typed receipts use schema and semantic checks; other services must be assessed separately.
  • Rate limiting and tenant binding need tested coverage across public demos, authenticated routes and direct service origins.
  • The site contains inline scripts. No claim is made that all HTML uses a CSP which rejects inline execution.
  • Third-party script integrity requires a page inventory. This site does not demonstrate SRI on every third-party script.
5 review areas

Monitoring & Response

  • External monitoring coverage, on-call ownership and alert delivery need evidence; no two-minute response guarantee is verified.
  • Error capture, redaction and processor access require a field-level review. Sentry deployment and scrubbing were not verified.
  • Operational log categories and retention are tracked separately from receipt retention in the retention inventory.
  • Alert rules for authentication anomalies, receipt volume and key events require configuration plus observed test delivery.
  • Incident-review ownership, completion targets and customer notification commitments require an approved runbook and applicable contract.
Sub-Processors

Where your data goes.

Hosting locations below come from the September 5 configuration review, not vendor marketing. Other listed relationships, storage regions and contract terms still need verification. See the retention inventory and review evidence.

Processor Purpose Region Compliance
Render Typed API, countersigner, receipt/Carnac and signer compute Oregon, United States (four services verified) render.com/security →
Cloudflare Site distribution and edge services; exact rule coverage open Global distribution; no single region verified cloudflare.com/trust-hub →
Stripe Earlier billing listing; active processing relationship not verified Not verified stripe.com/privacy →
Mercury Earlier treasury listing; account and data scope not verified Not verified mercury.com/legal/privacy →
GitHub Source hosting and deployment integration Processing/storage region not verified github.com/privacy →
Supabase / other storage Source contains Supabase paths for Carnac and telemetry; AWS S3 receipt storage not verified Project region and backup locations not verified Storage evidence →
Vulnerability Disclosure

Responsible disclosure policy.

Hive Civilization welcomes security researchers. We commit to a fair, transparent disclosure process.

Contact

security@thehiveryiq.com

Encrypt sensitive reports using our PGP key, available on request at the address above. Provide sufficient detail to reproduce the issue. Do not access customer data beyond what is necessary to demonstrate the vulnerability.

Disclosure Timeline
Initial acknowledgement
Acknowledgement timing to be confirmed
Triage decision
Triage timing to be confirmed
Remediation target
30 days for critical; 90 days for medium/low
Coordinated public disclosure
90-day window from report receipt; extensions available by mutual agreement
Scope

In scope: thehiveryiq.com and all subdomains, Hive API endpoints, Cloudflare Workers serving hive-signed receipts, Hivemorph admin panel. Out of scope: third-party sub-processors, social engineering, denial-of-service testing, automated scanning without prior approval.

Hall of Fame
Researcher Finding Date
First responsible disclosure reporter will appear here.

We do not offer monetary bounties at this time. We commit to public acknowledgement, coordinated disclosure, and a letter of commendation for valid critical findings.

Penetration Testing

Testing posture.

Annual Third-Party Pen Test

No independent penetration-test agreement or report was supplied for this review. Scope, tester, date and remediation retest must be confirmed.

Evidence open

Internal Red-Team Exercises

Exercise records and coverage for authentication, tenant isolation and API abuse were not supplied. A proposed cadence is not an executed test.

Records needed

Self-tests and validation

Implementation self-tests check particular code paths. CAVP validates algorithm implementations; CMVP validates cryptographic modules. No applicable Hive certificate was supplied.

No certificate claimed
Incident Response

Incident response review.

The six phases below are a response outline. Notification obligations depend on applicable law and executed contracts; the earlier time targets were not verified as contractual SLAs.

Phase 1
Detection
Automated alert or researcher report identifies anomaly
Phase 2
Triage
Severity classified; incident lead assigned; stakeholders notified
Phase 3
Contain
Access revoked or isolated; blast radius scoped
Phase 4
Eradicate
Root cause removed; indicators of compromise cleared
Phase 5
Recover
Service restored; monitoring confirmed clean before re-opening
Phase 6
Post-Mortem
Record root cause, timeline and corrective actions; approve publication and follow-up
Severity Definition Customer Notification Post-Mortem
Sev 1 Complete service outage, confirmed data breach, or cryptographic key compromise To be agreed To be agreed
Sev 2 Significant performance degradation, partial service disruption, or potential data exposure To be agreed To be agreed
Sev 3 Minor functionality impacted; no data risk; workaround available To be agreed To be agreed

Report incidents to security@thehiveryiq.com. Status publishing, subscriptions and escalation delivery need an operational check.

Compliance Assistance

Procurement information

Send your required controls and evidence scope. Document availability and response dates must be confirmed for the request.

SIG Questionnaire

Shared Assessments SIG

Request SIG Lite or SIG Core materials. Completed responses were not supplied for this review.

CAIQ

CSA CAIQ

Request a CAIQ response against the deployment in scope. Completion is not verified.

Custom

Custom Questionnaires

Send your questionnaire template and identify the services under review.

DPA

Data Processing Addendum

Request the applicable DPA for legal review. Signed terms, roles and transfer provisions must be verified.

MSA

Master Service Agreement

Confirm the contracting entity and applicable agreement before procurement approval.

Briefing

Technical Security Briefing

Request a technical walkthrough at security@thehiveryiq.com.

For procurement, identify the service, data classes and required assurance. review evidence lists what was reviewed and what remains open.

Security Roadmap

Assurance roadmap.

No audit or certification date is approved in the evidence reviewed. Scope, owner, budget and external engagement must be established before publishing a target.

Date unapproved

SOC 2 Type 1

Executed engagement letter and independent Type 1 report not supplied.

Evidence open
Date unapproved

SOC 2 Type 2

Auditor, scope and observation period require agreement; no report date verified.

Evidence open
Date unapproved

ISO 27001

Alignment and certification dates unapproved. Review the ISO evidence inventory.

Evidence open
Date unapproved

FedRAMP Moderate

Authorization path, agency sponsorship and assessment scope not established. No automatic prerequisite claim is made.

Evidence open
Key-Person Risk

Founder risk and continuity

Hive is a single-founder operation. The continuity disclosure separates proposed second-admin access, escrow, succession and insurance from arrangements with verified evidence.

Read the founder-risk disclosure →
Contact Security

Contact Hive about security.

For security reviews, vulnerability reports and questionnaire requests, use the form to prepare an email. Do not include secrets or customer payloads.