Trust & Continuity · Key-Person Risk · Single Founder

Founder dependence and continuity planning

Hive Civilization is a single-founder operation. This disclosure identifies the evidence needed for treasury, access, legal and customer continuity. A proposed arrangement is not a tested recovery path.

Honest Disclosure

Scope of this disclosure

Key-person risk remains open. Steve Rotzin is the founder. Independent administrative recovery, legal succession, escrow custody and insurance were not verified in the September 5, 2026 review. Read this page with the security posture before accepting continuity commitments.

Review status: No continuity control below is marked complete without supporting records. Proposed roles and timelines require owner approval. review evidence records the review scope and change log.

Current State

Current status

Source and hosting access demonstrate running services, not the ability of another person to recover them.

Current State: Today

Single-Founder Operation

Single-founder dependence remains the planning baseline. Current administrator membership, account signatories and delegated authority need a verified access inventory.

Target state: approval required

Distributed operating authority

Named second administrators, tested credential recovery, authorized treasury co-signers and documented succession would reduce founder dependence. No completion date is approved in this review.

Treasury Controls

Production treasury.

The address below is the published treasury reference. Ownership, signer threshold and founder-independent spending authority were not verified in this review.

Gnosis Safe Multisig Migration

Not verified

A 2-of-3 Safe on Base is a proposed treasury arrangement. No deployed Safe address, signer acceptance records, threshold configuration or independent execution test was supplied. Do not rely on it for founder-unavailability recovery.

Current Treasury 0x15184Bf50B3d3F52b60434f8942b7D52F2eB436E
Chain Base Mainnet (Chain ID 8453)

Any migration needs an approved authority model, public contract reference and successful recovery test before it is marked complete.

Target: 2-of-3 Multisig

Planned

Proposed signer roles are shown below, not appointments. The founder is not independent of Hive. Independence of any external co-signers requires conflict and authority review.

  • Steve Rotzin Founder; proposed signer
  • Outside Counsel Proposed external role; no appointment verified
  • Fractional CFO Proposed external role; no appointment verified

Named signers, their consent and the actual approval threshold must be verified against the deployed contract and agreements.

Infrastructure Continuity

Code and platform access.

Reducing single-point-of-failure across source control, CDN, compute, and secrets management.

GitHub

GitHub Org: Multi-Admin

A named second administrator, current organization membership and a tested non-founder recovery path are needed. Branch review and ownership settings require configuration evidence.

Evidence open
Cloudflare

Cloudflare Account: 2-Admin Policy

A second administrator and zone ownership need verification. The recovery path must work without the founder's personal credentials.

Evidence open
Render

Render Team: 2-Admin Policy

A second team owner, billing authority and service ownership need verification. Running services do not establish delegated recovery access.

Evidence open
Secrets

1Password Break-Glass Vault

No vault custody receipt, external custodian agreement or supervised recovery test was supplied. Do not treat the proposed break-glass vault as active.

Evidence open
DNS

DNS Registrar Continuity

Registrar ownership, transfer authority and independent recovery access require records and a non-destructive drill.

Evidence open
API Keys

API Key Inventory

A service-by-service credential inventory must identify scope, custodian, rotation and recovery authority. No secret values should appear in this public record.

Evidence open
Insurance

Insurance roadmap.

No policy binder or certificate was supplied for E&O, D&O or cyber coverage. Coverage, insured entity, limits, exclusions and effective dates require insurer documentation.

Policy Type Target Limit Status Target Date
Errors & Omissions (E&O)
Professional liability for software products and services
Not approved Not verified Date unapproved
Directors & Officers (D&O)
Liability coverage for leadership decisions
Not approved Not verified Date unapproved
Cyber Liability
First-party and third-party cyber incident coverage
Not approved Not verified Date unapproved

If insurance is a procurement condition, request current insurer-issued evidence at security@thehiveryiq.com. This page is not proof of coverage.

Customer-Side Controls

Continuity from your side.

Retain the artifacts needed for your accepted verifier format. Escrow, exports and operational recovery have separate dependencies.

Source Code Escrow

No executed escrow agreement, deposit receipt, update record or release test was supplied. Provider, covered code, beneficiary rights and release conditions remain to be agreed.

Agreement open

On-Premises Verifier

The browser verifier supports specific receipt formats. Preserve its dependencies and trusted issuer keys before an outage; offline operation and algorithm support require format-specific tests.

Format-specific

Data Export Endpoint

Carnac source includes tenant-scoped JSON/CSV export capped at 1,000 rows. It can fall back to process memory when durable storage is unavailable. A complete export of every receipt and evidence bundle is not established.

Bounded export code

Audit-Ready Evidence Bundle

Offline checks require the signed bytes, supported algorithm, signature and trusted issuer key. Anchored records additionally require binding and inclusion evidence under a trusted checkpoint. Neither a signature nor a chain transaction guarantees permanent availability.

Artifact-dependent
Continuity Runbook

If the founder is unavailable

The outline below is a proposed recovery sequence, not an activated or tested runbook. Owner approval, legal authority, named participants and a supervised drill are required.

Immediate response

Identify an authorized incident lead and verify the legal basis for delegated access. Notify affected customers through an agreed channel. No outside custodian, operating partner or non-founder treasury authority has been verified.

Open evidence: accepted custodian, activation contacts, authority documents and recovery test results.

Operational continuity

A designated operator would need tested access to source, hosting, DNS, billing and credential recovery. Confirm available backups and export scope before making service-restoration commitments.

Long-term disposition

Continued operation, transfer or wind-down requires valid authority and applicable customer agreements. Preserve portable verification artifacts where permitted. No automatic escrow release or permanent on-chain verification path is established.

Request a reviewed recovery package at security@thehiveryiq.com. A completed runbook or NDA package was not supplied for this review.
Transparency Reports

Continuity status updates.

A publication cadence requires an assigned owner and dated reports. No first quarterly report or ongoing publication record was supplied; earlier date promises are withdrawn.

What each report covers

  • Treasury multisig status and current signers (by title; names published with consent)
  • Infrastructure admin policy status: GitHub, Cloudflare, Render second-admin confirmation
  • API key inventory count and last-rotation date per service
  • Break-glass vault custodian confirmation (no detail, just confirmation of custody)
  • Insurance policy status: whether each scheduled policy has been bound, with certificate reference
  • SOC 2 audit status: current phase, any change to target date
  • Incident log: any Sev1 or Sev2 incidents in the quarter, with post-mortem link
  • OPA and board observer seat status
Report schedule
Baseline review
September 5, 2026: source and hosting review; continuity evidence remains open.
Next update
Date requires owner approval; publish accepted changes and supporting records.
Assurance update
Update when an executed engagement, independent report or insurance document is available.
Recurring cadence
Owner and frequency require approval; no delivery cadence verified.
Subscribe to reports

Request future updates at security@thehiveryiq.com. Automatic subscription and delivery have not been verified.

Subscribe →
Related

Full security posture.

For signing boundaries, processing locations, retention review and assurance evidence, see the main security page.

Security overview → Contact security team