Snapshot 19765
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Skip to assurance areas
On this page
Assurance areasFull registerVerify signed statusFor AI agentsSource → production & AISystem scopeRoadmap & resilienceCompliance hubEvidence accessLegal & contact
§ 01Start with what matters to you
The same approved facts — only the order changes.
Selecting a role reorders the nine canonical cards below. It never changes a fact, status, scope, date, source, or limitation — and it is never sent to any system. order-only · local-only
Viewing all nine assurance areas. Pick a role to reorder them for that reviewer — the facts stay identical, and negative or in-progress states are never hidden.
Exhibit C-02Defined
System scope & data boundary
The entity, product, production environment, regions, processing path, and explicit exclusions these statements apply to — and where the customer boundary begins.
Evidence
HiveSilo attestation
Scope
HiveSilo Platform · Production
As of
2026-09-30 UTC (Sep 29, 2026, EDT)
Model
Shared-responsibility v1.2
Limitations
Statements apply only to the named system, path, version, and operating conditions.
Public diagrams omit sensitive infrastructure and defensive detail.
Why this matters Anchors every other claim to a bounded scope so nothing is read as a universal guarantee.
Open scope & shared-responsibility →
Exhibit C-03In Progress — Engaged
Independent reports & certifications
Each independent program listed separately, dated, with its evidence class. SOC 2 Type I & II examinations are engaged with a licensed CPA firm; no report or opinion is issued yet.
Evidence
CPA examination (in progress)
Scope
SOC 2 TSC · Security, Availability, Confidentiality
Stage
Engaged · onboarding & evidence review
Reviewed
—
Limitations
A report or certification applies only to its stated scope and dates.
A penetration test is not a certification and does not prove absence of vulnerabilities.
Why this matters Separates what an independent body concluded from what HiveSilo attests to itself — the distinction procurement lives on.
Open the assurance register →Request report under NDA
Exhibit C-04Published
Privacy & legal
Controller/processor roles, purpose limitation, retention, transfer mechanism (SCCs + UK IDTA), current subprocessor list, and contract routes for legal and privacy reviewers.
Evidence
Legal policy · contractual
Transfers
SCCs + UK IDTA addendum
Reviewed
—
DPA
Available on request
Limitations
High-level public descriptions do not replace executed customer terms.
Applicability depends on the customer, processing activity, and jurisdiction.
Why this matters Lets legal locate the exact roles, transfers, and safeguards before diligence starts.
Open privacy notice →Request DPA / SCCs
Exhibit C-05Current
Security engineering & independent testing
Public-safe encryption, identity & privileged-access governance, tenant isolation, secure SDLC, dependency/vuln remediation, and responsible disclosure. Independent penetration test on the roadmap.
Evidence
HiveSilo attestation · framework mapping
Isolation
Per-tenant, enforced at the data layer
Reviewed
—
Disclosure
security.txt · responsible route
Limitations
Control descriptions are not guarantees against incidents or vulnerabilities.
External testing conclusions apply only to the tested scope and date.
Why this matters Shows which security practices are in place today and which remain protected or independent-pending.
Open security posture →Request assessment evidence
Exhibit C-06Live
Live evidence & integrity verification
The daily Ed25519-signed public snapshot, signing-key history, canonical-JSON verification, per-certificate endpoints, Merkle membership proofs, hash-linked continuity, and offline-verifier recipe.
Evidence
Signed HiveSilo record
Manifest
sha256:ffde058f20d8…
Key
hs-ed25519-2026-06-23
Signed
2026-09-30 UTC (Sep 29, 2026, EDT)
Limitations
Verification establishes only the record’s integrity, authenticity, and publication history.
It does not prove source observation, control effectiveness, or vulnerability absence.
Why this matters A first-time visitor can independently check the signed record in the browser or with a stock Node install — no account, no trust in us required.
Open manifest, key & verifier →
Exhibit C-07Operational
Resilience, availability & incidents
Measured availability against the independent monitor, current incident state, BC/DR scope, RTO/RPO targets stated separately from observed drills, and the customer incident route.
Evidence
Independent monitor · attestation
Incidents
None in current window
Window
Rolling 30 days
Reviewed
—
Limitations
Targets are not observed results or guarantees.
Historical availability does not guarantee future availability.
Why this matters Keeps measured health, recovery targets, and drill results as three separate honest facts.
Open status & resilience record →Request BC/DR evidence
Exhibit C-08Indexed
Procurement & commercial resources
A plain index of public and protected enterprise-review materials — corporate identity, SLA/support, insurance, DPA/SCC, security questionnaire, continuity — and how an authorized buyer requests each.
Entity
HiveSilo Inc. (Delaware)
Insurance
Tech E&O + Cyber — bound
Escrow
Source code in escrow
Banking
Tier-1 U.S. institution
Questionnaire
CAIQ v4.0.3 · CSA STAR listing ↗
Reviewed
—
Limitations
Availability is not public disclosure, automatic access, or acceptance of buyer terms.
Insurance does not establish solvency or guarantee coverage for a buyer’s event.
Why this matters Gives procurement the whole request path in one place, with no custom diligence workflow to learn.
Open enterprise-resource index →Open secure-room request
Exhibit C-09Governed
AI governance & data-use boundaries
The scoped AI/agent boundary, input/output use restrictions, model-training position, human oversight, evaluation & change controls, and the confidential-compute role — with its attestation limits stated plainly.
Evidence
Attestation · framework mapping
Training
Customer data not used to train models
Compute
PII scoped to attested confidential VMs
Reviewed
—
Limitations
TEE attestation does not establish correctness of source data, models, or outputs.
A framework mapping or roadmap is not certification.
Why this matters Answers how customer inputs may be used, and where architecture is proof versus where it is only a boundary.
Open AI governance summary →Request evaluation evidence
Exhibit C-10Documented
Shared responsibility, integrations & subprocessors
Which controls depend on HiveSilo, the customer, an integration, or a subprocessor — plus current subprocessor categories, change-notification approach, and the security/privacy/vulnerability contacts.
Evidence
HiveSilo attestation · policy
Subprocessors
Public list · change-notice on file
Reviewed
—
Contacts
security · privacy · disclosure
Limitations
Customer outcomes depend on documented configuration and operating responsibilities.
A listed integration or subprocessor is not an endorsement of the buyer’s configuration.
Why this matters Makes the responsibility split explicit before diligence, so nothing is assumed to be inherited.
Open shared-responsibility model →
§ 02Full assurance register
Every tracked framework — live, not decorative.
All 20 tracked frameworks with their honest state, evidence class, and last-updated date. Filter by tier — fixed-value buttons only, no free-text input. Nothing self-scores, and in-progress or roadmap items never borrow a “certified” look.
20 tracked · 1 live proof · 1 listed · 11 attested · 7 roadmap
Independently listed · third-party hostedCloud Security Alliance STAR Registry — Level 1 self-assessment (CAIQ v4.0.3)Published on the CSA STAR Registry and downloadable there. A self-assessment hosted by an independent third party — not a certification.View the public listing ↗
Framework Status Evidence class Updated
01Signed Evidence Room Live Signed daily —
02SOC 2 Type I In Progress — Engaged Third-party issued —
03SOC 2 Type II In Progress — Engaged Third-party issued —
04CSA STAR Level 1 CAIQ Listed Public self-assessment —
05CSA STAR Level 2 Roadmap 2027 Third-party issued —
06EU-US / UK / Swiss DPF Not Applicable Public self-assessment —
07NIST Cybersecurity Framework Self-Attested Self-attested —
08ISO 27001 Mapped Third-party issued —
09ISO 27701 Roadmap 2027 Third-party issued —
10ISO 27018 Roadmap 2027 Third-party issued —
11GDPR / UK GDPR Privacy Pack Mapped Self-attested program —
12NIST SSDF / SP 800-218 Self-Attested Self-attested —
13CISA Secure Software Attestation Form Self-Attested Self-attested —
14Cyber & Tech E&O Insurance Self-Attested Self-attested —
15Business Continuity Management Mapped Control mapping —
16ISO 22301 Roadmap 2026 Third-party issued —
17NIST AI Risk Management Framework Self-Attested Self-attested —
18ISO/IEC 42001 Roadmap 2026 Third-party issued —
19Independent Penetration Test Roadmap 2026 Third-party issued —
20OWASP ASVS Level 2 Self-Attested Self-attested —
Roadmap years are targets, not commitments. The independent-evidence tier is reserved for evidence issued or verified by a party other than HiveSilo — until a third party has looked, entries stay exactly where they are.
§ 03Verify HiveSilo’s signed status
Don’t take our word for it — check the signature.
Every certificate status on this page traces to a daily-signed manifest. Verify it right here in your browser, or with nothing but this page’s public key and a stock Node.js install.
Chain continuity
Each daily manifest is signed and hash-linked to the previous one, back to the chain’s first entry — reviewers who keep prior entries can detect any later change to the published chain.
Verified
External anchoring
The daily root is independently timestamped and witnessed in the public Sigstore Rekor transparency log — verifiable by a first-time visitor with no prior entry saved.
Rolling out
Independent countersignature
Continuous control evidence is verified and countersigned daily by a separate trust domain — a dedicated identity with no production access, its own operator-held signing key, an append-only hash-chained ledger, and dead-man paging that alerts if a day is missed. Operational since July 22, 2026. This is organizational separation, not a third-party audit; countersignature materials (ledger and tier-2 public key) are available to customers and auditors on request.
Request materials
Signed manifest
2026-09-30 UTC (Sep 29, 2026, EDT) ·
Open verifier page
Live verification
This button fetches the real signed manifest and the real published keys, canonicalizes, and checks the Ed25519 signature — in your browser, via WebCrypto. This server never sees the verdict.
live run — fetches the real manifest and checks the real signature
# press “Verify in your browser” — the check runs locally via WebCrypto
How you’d catch us
STEP 01
Save today’s signed manifest — one JSON file, no account needed.
STEP 02
Come back any day and re-fetch. Every future manifest must hash-link back to the one you kept; any rewrite of history breaks the chain against your copy.
STEP 03
Cross-check the daily root in the public Sigstore Rekor log — an independent witness we cannot edit, even in principle.
A single broken link would be permanent, public evidence — that is the point.
§ 04For AI agents & automated verifiers
The exact contract, so software can check us too.
Everything above is written for a human reviewer. This is for the software doing diligence on their behalf — schema, endpoints, and verification contract, so an agent can check HiveSilo’s claims without asking HiveSilo to vouch for itself.
Endpoints
Manifest
GET https://trust.hivesilo.com/api/trust/signed-manifest.json
Keys
GET https://trust.hivesilo.com/api/trust/public-keys.json
Verdict
GET /api/trust/verify?cert=<id>
All three are rate-limited, unauthenticated, and return the same data a human sees on this page — no separate, softer “bot” version.
Verification contract
Canonicalization: hs-canonical-json-v1
Object member names are sorted lexicographically at every depth.
No insignificant whitespace anywhere in the output.
Strings, numbers, booleans, and null are encoded exactly as JSON.stringify encodes them.
The signature covers the UTF-8 bytes of the canonical form of the `manifest` object only.
Certificate membership uses sha256-merkle-v2 (RFC 6962 domain-separated) — verify a single certificate’s inclusion without downloading or trusting the full manifest.
# fetch the signed public manifest curl -s https://trust.hivesilo.com/api/trust/signed-manifest.json # fetch the published Ed25519 keys curl -s https://trust.hivesilo.com/api/trust/public-keys.json # verify Ed25519 over canonical JSON — full one-liners below → signature OK · merkle root ✓ · continuity ✓
Full offline verification one-liners (Node.js stdlib only)
# Fetch the signed manifest curl -s https://trust.hivesilo.com/api/trust/signed-manifest.json -o signed-manifest.json # Fetch the Ed25519 public keys curl -s https://trust.hivesilo.com/api/trust/public-keys.json -o public-keys.json # Verify offline (Node.js crypto stdlib only — prints VERIFIED or FAILED) node -e "const fs=require('node:fs');const{createPublicKey,verify,createHash}=require('node:crypto');const c=v=>Array.isArray(v)?'['+v.map(c).join(',')+']':v&&typeof v==='object'?'{'+Object.keys(v).sort().filter(k=>v[k]!==void 0).map(k=>JSON.stringify(k)+':'+c(v[k])).join(',')+'}':JSON.stringify(v);const m=JSON.parse(fs.readFileSync('signed-manifest.json','utf8'));const d=JSON.parse(fs.readFileSync('public-keys.json','utf8'));const key=[d.currentKey,...(d.historicalKeys||[])].find(k=>k.keyId===m.signature.keyId);const b=Buffer.from(c(m.manifest),'utf8');const ok=Boolean(key)&&createHash('sha256').update(b).digest('hex')===m.signature.manifestSha256&&verify(null,b,createPublicKey(key.publicKeyPem),Buffer.from(m.signature.signatureHex,'hex'));console.log(ok?'VERIFIED':'FAILED');process.exit(ok?0:1);"
The offline variant never talks to this server at verification time — it checks two previously downloaded files with the Node.js crypto stdlib only, so the result cannot depend on anything HiveSilo says in the moment.
§ 05Source → production
What is published, and what stays private.
The public site holds no credential and grants no automatic access. Protected evidence is delivered through the secure review process — never by this page.
PublicFramework register, daily signed manifest, signing keys, Merkle proofs, continuity chain, and production-release evidence.
ProtectedFull control-mapped detail, subprocessor list with data flows, and named vendor inventory — after scoped NDA approval.
NeverInternal network topology, individual customer data, and raw incident forensics — never published publicly.
Production release proof — exact commit to hardware-attested runtime
Release
acbdab3ee5a04f1a791b859d67d04b1577bb2018
Commit
acbdab3ee5a0…
Digest
sha256:fa400913a7ca…
Signature
Cosign verified · keyless (Fulcio)
Rekor
log index 2500388698 · inclusion ✓
Provenance
SLSA Build L3 · SBOM attested (SPDX)
Runtime
Intel TDX quote · measurement matched
Verified
2026-08-18T04:57:36.492Z UTC (Aug 18, 2026, 12:57 AM EDT)
Limitation Attestation establishes identity and measured state — it does not prove the application has no vulnerabilities.
§ 06AI governance & data use
Governed, and honest about its limits.
A plain-language overview, mapped to the NIST AI Risk Management Framework (govern → map → measure → manage).
Is customer data used to train any model?
No. HiveSilo’s bot-detection and decision-core scoring are deterministic, explainable algorithms — not trained models — and never ingest visitor PII. Where generative AI is used (internal tooling, analytics copilots), it operates on de-identified data with PII excluded by design, not filtered after the fact.
Which model providers are used?
A named third-party inference vendor is disclosed to approved reviewers under NDA, governed under the same vendor-review program as every other subprocessor — no carve-out for AI.
Can model providers retain prompts or outputs?
Prompts sent to generative-AI tooling are constructed from de-identified data by design; no raw customer PII is included in any prompt.
How are model versions and changes approved?
Model and vendor changes follow the standard subprocessor change-notice process (30-day advance notice), not an ad hoc path.
What tools can AI agents invoke, and how are permissions constrained?
Internal AI tooling is limited to a fixed, code-owned allowlist of read-only tools — no arbitrary command execution, no unbounded data access, and no ability for the model to grant itself new capabilities.
Is human review available for high-impact actions?
Yes. AI-assisted tooling operates as an advisory layer for a human operator or the merchant’s own team — it does not autonomously execute high-impact actions.
Is independent testing or red-teaming performed today?
Real structural controls exist today (fixed tool allowlists, read-only execution, PII-excluded data access) and are validated by internal adversarial CI tests. An independent third-party penetration test is not yet on record — that is a disclosed gap, not an implied one, tracked on the assurance roadmap rather than glossed over.
§ 07System scope & shared responsibility
What’s covered, and what stays with you.
A public-safe excerpt of the shared-responsibility model. Full detail (including the merchant-CVM boundary and cryptographic mechanism) is reviewer-only.
In scope
HiveSilo operates the SaaS platform, dashboards, and merchant CVM service
Signal collection, scoring, and routing infrastructure
Log and monitoring configuration inside the CVM boundary
CI/CD and artifact-signing systems (SLSA L3, Sigstore, Rekor)
Explicitly out of scope
The merchant CVM confidential-compute enclave’s own held data — HiveSilo has no plaintext access
CRM and ad-platform integrations the merchant configures
Endpoint security on customer devices
Content and messaging strategy decisions
Shared-responsibility matrix — who owns what, area by area
Area HiveSilo Customer
Customer identities, roles, privileges Platform auth infrastructure Grants, revokes, and audits who holds each role
Data governance Retention tooling and enforcement Sets retention policy and classification
CRM & ad-platform integrations Connector reliability Credentials, field mapping, downstream use
Endpoint security — Devices used to access the dashboard
Content & messaging strategy — What’s sent, to whom, and why
Enclave (TEE) verification Cryptographically attested by hardware Independently verifiable by the customer
Data boundary — controller/processor status, subprocessors, retention, PII scope
Data boundary Status
Controller vs. processor status Documented per-tenant, available on request
Sub-processor disclosure list Published, updated on change
Data retention policy Public summary; full policy under NDA
PII scope & handling Scoped to the merchant CVM boundary
§ 08Assurance roadmap
A workstream leaves this list only when the work is done.
Objective status per workstream — no self-scoring.
CSA STAR Level 2Roadmap 2027
STAR Level 2 is a third-party attestation/certification built on the Cloud Controls Matrix and an accredited ISO 27001 audit — a step above the Level 1 self-assessment already listed. It is scoped after ISO 27001 readiness; no Level 2 assessment is engaged and no certificate is claimed before an accredited assessor issues it.
EU-US / UK / Swiss DPFNot Applicable
International transfers are designed around Standard Contractual Clauses with a UK IDTA addendum; the executed enterprise DPA embedding them is in legal review, not yet finalized for general availability. DPF self-certification is not currently pursued and no listing is claimed.
ISO 27701Roadmap 2027
Privacy-management extension is scoped after ISO 27001 readiness; no certificate is claimed before issuance.
ISO 27018Roadmap 2027
Cloud-privacy control coverage is tracked for the certification roadmap without presenting an issued certificate.
ISO 22301Roadmap 2026
Business-continuity-management-system certification (ISO 22301) is scoped on the certification roadmap; the BC/DR program mapping already listed provides the control basis, but no certificate is claimed before an accredited body issues one.
ISO/IEC 42001Roadmap 2026
AI-management-system certification is scoped for later pursuit; no certificate is claimed before an accredited body issues one.
Independent Penetration TestRoadmap 2026
No independent penetration test is on record; isolation and application controls are validated today by internal adversarial CI tests only. A comparative quote process with accredited third-party firms is underway, and an engagement will be commissioned before the first regulated-sector (banking/healthcare) signature, per CAP-03.
Operational resilience
Measured health, stated separately from targets.
Independent uptime from t.hivesilo.com over the last 90 days — the same monitor the public status page reads from. Tracked continuously, not asserted.
0%uptime · t.hivesilo.com
0open incidents
0d+days straight
90 days agot.hivesilo.com · 100% available · Today (UTC)
Planned server technology upgrade (planned maintenance) · 2026-09-18 – 2026-09-21 · recorded on the status page
Live · 90 days+ straight · 100%view the independent monitor →
Historical availability does not guarantee future availability. Recovery targets are commitments, not observed results.
§ 09Compliance hub
The artifact index — fetch, verify, cite.
Every public artifact this page’s claims trace to, in one place. Each is deterministic, versioned, and safe to automate against — no auth, no scraping.
signed-manifest.jsonDaily signed public snapshot · canonical JSON · Ed25519SignedSigned daily
public-keys.jsonSigning-key history, rotation dates, current keyPublicOn rotation
evidence-room certificateSigned Evidence Room certificate · current windowSignedCurrent
verify verdict (JSON)Per-certificate machine-readable verdict — same data a human seesPublicLive
status verifierHuman-readable verification page with the full recipePublicLive
status page ↗Full public status page · continuity cross-checkPublicLive
security overview packetArchitecture, controls, posture — requester-approval gatedRequestUnder NDA
§ 10Evidence access
What reviewers can request.
Each protected item lists its honest availability — nothing is promised before it exists.
STEP 01
Request diligence access
Name, company, reason for request
STEP 02
Scoped NDA approval
Reviewed against what you asked for
STEP 03
Time-boxed access granted
Expires automatically, no standing access
STEP 04
Verify signals via console
Cross-check anything you’re given
SOC 2 Type I reportWhen issuedSOC 2 Type II reportWhen issuedPenetration-test summaryWhen completedArchitecture briefingUnder NDADPA · SCCs + UK IDTAOn requestInsurance certificateOn requestBC/DR & continuity packetUnder NDASource-code escrowUnder NDACAIQ v4 full responsesOn request
EXHIBIT W-01Customer reference call · direct testimony
We don’t print quotes. Ask someone who already trusts us with production.
No curated pull-quote can survive this page’s own standard of evidence — so instead, your team talks directly with a current HiveSilo customer. Your questions, no script, always with the customer’s consent.
On requestArrange through your account team →
Need protected diligence materials?
Authorized reviewers can request reports, testing summaries, architecture material, continuity evidence, and legal documents through the secure review process. The public site holds no credential and grants no automatic access.
Business verificationNeed to knowNDATime-limited access
Request diligence access
§ 11Legal identity & contact
A named legal entity, on the record.
The registered identity behind every statement on this page — with the direct routes for security, privacy, and diligence contact.
Legal entity
HiveSilo Inc. · Delaware C-Corporation · File no. 10573593
Headquarters
1395 Brickell Avenue, Suite 800, Miami, FL 33131, USA
Phone
+1 786-957-5300
LEI
984500A0Z9394E84FE40
Industry codes
NAICS 513210 · SIC 7372
Security contact
[email protected]
Vulnerability disclosure
hivesilo.com/security-disclosure
security.txt (RFC 9116)
hivesilo.com/.well-known/security.txt
Briefings & NDA evidence
[email protected]