
Security
Receipts, pinned roots, default-deny. No invented badges.
A counsel or CISO should be able to read this page without translating marketing. We describe how we handle data and how the runtime proves what happened. We do not claim certifications we do not hold.
Customer data is not training fuel
Data provided for a deployment is used to build and operate that deployment. It is not used to train public models. It is not mixed into a shared corpus for other customers. If a fine-tune or private adapter is in scope, it is written into the engagement, runs in the agreed environment, and remains the customer’s artifact.
Receipts
A production system leaves receipts for what it read, what it wrote, and what it ran. V4 Knowledge Images already carry lexical evidence, spans, a plan hash, and a read receipt. V5 extends that into write receipts and run receipts — architecture in progress, not GA. We do not treat “the chat history” as an audit log.
Pinned roots and default-deny
Knowledge and, as V5 lands, runtime state can be pinned so a later operator can name the root they ran against. Authority is default-deny: a tool or side effect does not run without an approval or capability record. Agents do not get a toolbox because a demo looked busy.
Offline verify
A Knowledge Image is a file. It can be hashed, mounted, and queried locally. We do not require a phone-home to prove the image you have is the image you shipped. Production may still sit in a VPC or on-prem cage; the verify path does not depend on our SaaS being up.
Environment options
Production systems are deployed into an environment the constraint requires:
- On-premises, including air-gapped patterns where the data class demands it.
- Customer VPC, with network boundaries and keys the customer owns.
- Isolated cloud tenancy named in the statement of work — not a multi-tenant demo.
We do not require that your corpus live in a Hive-operated SaaS by default. If a managed option is used, it is explicit, logged, and scoped.
Access
Least privilege. Role-based retrieval and tool access. SSO when the customer’s identity provider is in scope. Builder access during implementation is time-bounded, logged, and revoked at handover unless a run contract says otherwise.
Retention
Retention follows the data class and the contract. Briefs submitted on this website are kept to respond and to run the engagement — not as a marketing list. Production corpora never sit on this marketing domain.
Subprocessors — high level
This website is a public operating-company surface. Form intake is processed so we can answer an engineering brief. Analytics, if enabled, are optional and named. Production subprocessors are those the customer already uses, plus any runtime named in the statement of work. We will not publish a fake global vendor matrix to look enterprise.
What we do not claim
We do not display ISO, SOC, or FedRAMP badges on this site. If a certification is required for a deployment, it is treated as a constraint in week 0 — including whether this company is the right builder for that bar. Practices are not certificates.
Privacy questions: contact@hiveforensics.com. Legal text: privacy and terms.

Engage
Work starts on HIVE Bootcamp.
Unscoped work starts at hiveai.tech/bootcamp. This domain is for engineering already constrained. Work is scoped privately.
Scoped privately · no public rate card on this domain