
Security
Verifiable evidence. Explicit authority. Deployment controls you can inspect.
This page describes how we handle data, constrain agent actions, and document what a system did. We state the practices we can put in an engagement and distinguish them from independent certification.
Customer data is not training fuel
Data provided for a deployment is used to build and operate that deployment. It is not used to train public models. It is not mixed into a shared corpus for other customers. If a fine-tune or private adapter is in scope, it is written into the engagement, runs in the agreed environment, and remains the customer’s artifact.
Receipts
A production system leaves receipts for what it read, what it wrote, and what it ran. V4 Knowledge Images already carry lexical evidence, spans, a plan hash, and a read receipt. V5.0.0 extends that into write receipts and run receipts. We do not treat “the chat history” as an audit log.
Pinned roots and default-deny
Knowledge and runtime state can be pinned so a later operator can name the root they ran against. Authority is default-deny: a tool or side effect does not run without an approval or capability record. Available tools are deliberately narrower than the underlying model's possible actions.
Offline verify
A Knowledge Image is a file. It can be hashed, mounted, and queried locally. We do not require a phone-home to prove the image you have is the image you shipped. Production may still sit in a VPC or on-prem cage; the verify path does not depend on our SaaS being up.
Environment options
Production systems are deployed into an environment the constraint requires:
- On-premises, including air-gapped patterns where the data class demands it.
- Customer VPC, with network boundaries and keys the customer owns.
- Isolated cloud tenancy named in the statement of work — not a multi-tenant demo.
We do not require that your corpus live in a Hive-operated SaaS by default. If a managed option is used, it is explicit, logged, and scoped.
Access
Least privilege. Role-based retrieval and tool access. SSO when the customer’s identity provider is in scope. Builder access during implementation is time-bounded, logged, and revoked at handover unless a run contract says otherwise.
Retention
Retention follows the data class and the contract. Briefs submitted on this website are kept to respond and to run the engagement — not as a marketing list. Production corpora never sit on this marketing domain.
Subprocessors — high level
This website is a public operating-company surface. Form intake is processed so we can answer an engineering brief. Analytics, if enabled, are optional and named. Production subprocessors are those the customer already uses, plus any runtime named in the statement of work. Deployment-specific dependencies and subprocessors are documented during qualified diligence.
Independent assurance
Hive Forensics AI does not currently represent itself as ISO 27001-, SOC 2-, or FedRAMP-certified. If a certification is required, it is treated as a constraint at the start of diligence, including whether this company is the right builder for that requirement. Documented practices are not independent certification.
Privacy questions: contact@hiveforensics.com. Legal text: privacy and terms.

Engage
Work starts on HIVE Bootcamp.
Unscoped work starts at hiveai.tech/bootcamp. This domain is for engineering already constrained. Work is scoped privately.
Scoped privately · no public rate card on this domain