Hive Civilization is a single-founder operation. This disclosure identifies the evidence needed for treasury, access, legal and customer continuity. A proposed arrangement is not a tested recovery path.
Source and hosting access demonstrate running services, not the ability of another person to recover them.
Single-founder dependence remains the planning baseline. Current administrator membership, account signatories and delegated authority need a verified access inventory.
Named second administrators, tested credential recovery, authorized treasury co-signers and documented succession would reduce founder dependence. No completion date is approved in this review.
The address below is the published treasury reference. Ownership, signer threshold and founder-independent spending authority were not verified in this review.
A 2-of-3 Safe on Base is a proposed treasury arrangement. No deployed Safe address, signer acceptance records, threshold configuration or independent execution test was supplied. Do not rely on it for founder-unavailability recovery.
Any migration needs an approved authority model, public contract reference and successful recovery test before it is marked complete.
Proposed signer roles are shown below, not appointments. The founder is not independent of Hive. Independence of any external co-signers requires conflict and authority review.
Named signers, their consent and the actual approval threshold must be verified against the deployed contract and agreements.
Reducing single-point-of-failure across source control, CDN, compute, and secrets management.
A named second administrator, current organization membership and a tested non-founder recovery path are needed. Branch review and ownership settings require configuration evidence.
Evidence openA second administrator and zone ownership need verification. The recovery path must work without the founder's personal credentials.
Evidence openA second team owner, billing authority and service ownership need verification. Running services do not establish delegated recovery access.
Evidence openNo vault custody receipt, external custodian agreement or supervised recovery test was supplied. Do not treat the proposed break-glass vault as active.
Evidence openRegistrar ownership, transfer authority and independent recovery access require records and a non-destructive drill.
Evidence openA service-by-service credential inventory must identify scope, custodian, rotation and recovery authority. No secret values should appear in this public record.
Evidence openSuccession requires valid authority, accepted responsibilities and an executable recovery process. The review did not establish those arrangements.
No estate instrument, company-asset schedule, executor acceptance or counsel confirmation was supplied. Corporate identity and jurisdiction also require charter verification.
Evidence openNo executed operating-partner agreement or accepted technical delegate was supplied. Activation conditions, authority and service access must be agreed and tested.
Evidence openNo board-observer agreement or approved information rights were supplied. A proposed customer role is not an existing governance control.
Evidence openNo policy binder or certificate was supplied for E&O, D&O or cyber coverage. Coverage, insured entity, limits, exclusions and effective dates require insurer documentation.
| Policy Type | Target Limit | Status | Target Date |
|---|---|---|---|
|
Errors & Omissions (E&O) Professional liability for software products and services |
Not approved | Not verified | Date unapproved |
|
Directors & Officers (D&O) Liability coverage for leadership decisions |
Not approved | Not verified | Date unapproved |
|
Cyber Liability First-party and third-party cyber incident coverage |
Not approved | Not verified | Date unapproved |
If insurance is a procurement condition, request current insurer-issued evidence at security@thehiveryiq.com. This page is not proof of coverage.
Retain the artifacts needed for your accepted verifier format. Escrow, exports and operational recovery have separate dependencies.
No executed escrow agreement, deposit receipt, update record or release test was supplied. Provider, covered code, beneficiary rights and release conditions remain to be agreed.
Agreement openThe browser verifier supports specific receipt formats. Preserve its dependencies and trusted issuer keys before an outage; offline operation and algorithm support require format-specific tests.
Format-specificCarnac source includes tenant-scoped JSON/CSV export capped at 1,000 rows. It can fall back to process memory when durable storage is unavailable. A complete export of every receipt and evidence bundle is not established.
Bounded export codeOffline checks require the signed bytes, supported algorithm, signature and trusted issuer key. Anchored records additionally require binding and inclusion evidence under a trusted checkpoint. Neither a signature nor a chain transaction guarantees permanent availability.
Artifact-dependentThe outline below is a proposed recovery sequence, not an activated or tested runbook. Owner approval, legal authority, named participants and a supervised drill are required.
Identify an authorized incident lead and verify the legal basis for delegated access. Notify affected customers through an agreed channel. No outside custodian, operating partner or non-founder treasury authority has been verified.
A designated operator would need tested access to source, hosting, DNS, billing and credential recovery. Confirm available backups and export scope before making service-restoration commitments.
Continued operation, transfer or wind-down requires valid authority and applicable customer agreements. Preserve portable verification artifacts where permitted. No automatic escrow release or permanent on-chain verification path is established.
A publication cadence requires an assigned owner and dated reports. No first quarterly report or ongoing publication record was supplied; earlier date promises are withdrawn.
Request future updates at security@thehiveryiq.com. Automatic subscription and delivery have not been verified.
Subscribe →For signing boundaries, processing locations, retention review and assurance evidence, see the main security page.