Patent pending · Filed July 31, 2026 · Hosted signer live

Bonded Performance Attestation

Bonded Performance Attestation (BPA) binds a declared performance budget to the measured distribution and to a signed response binding for the measured response set or observation manifest.

A latency number in a slide deck is detached from any particular piece of work. It cannot be checked, and the run that produced it was probably chosen after the fact. BPA fixes the budget before the outcome is known, records the signed distribution after the observation window closes, and binds that record to the measured response set or observation manifest it describes. The hosted signer and verifier are live at the Hive typed receipt API. Production acceptance passed against this deployment using synthetic data, and minting a real receipt requires an authorization token that Hive controls.

Two ways performance claims go wrong

Both failures are ordinary, and neither is usually dishonest. They happen because nothing ties the number to the work.

Cherry-picked runs

A thousand runs happen. The good one gets published. Because no budget was fixed in advance and no run is bound to a specific response, selecting the flattering result costs nothing and leaves no trace.

Detached claims

A number appears next to a product without being attached to any identifiable piece of work. There is no response it describes, so there is nothing a reader could check even if they wanted to.

How BPA works

The budget is fixed first. The distribution is recorded as work happens. Both end up bound to the same content.

1

Declare the budget first

A performance budget is declared and fixed before the outcome is known. Committing in advance is what makes the claim falsifiable, because the target cannot be moved to fit the result.

2

Record the real distribution

Performance is recorded per content unit as the response is produced, so what gets bound is the actual distribution rather than a single flattering sample.

3

Bind both to the response

The declared budget and the observed distribution are bound to a signed response set or observation manifest. The claim and the work it describes cannot be separated afterwards.

Selection stops being free. When the budget was fixed in advance and the distribution is bound to specific content, publishing only the good runs requires suppressing bound evidence rather than simply choosing what to mention. A missing attestation for a run is visible in a way that a missing slide is not.

What a verifier can check

Checked
  • The budget predates the outcome. It was fixed before performance was known.
  • The distribution belongs to this response. Not to a different, better run.
  • Budget and result are comparable. The declared target and the observed distribution sit in the same bound structure.
  • A breach is legible. Missing the declared budget is visible rather than quietly dropped.
Not claimed
  • BPA does not make a system fast. It makes the speed claim checkable and attributable.
  • It does not set the budget for you. The declaring party chooses the target and is then held to it.
  • It is not a benchmark suite. It binds performance to real delivered work rather than to a synthetic test.

Where it sits

BPA is one of four families filed on July 31, 2026, alongside Foretoken™, Stipryn™, and Multi-Source Divergence Detection (MSDD). It pairs naturally with streamed delivery, where per-unit timing is the thing a buyer actually experiences.

Foretoken

Commits to a streamed run before the first token and seals it at the close. Read

Stipryn

Fixes the required proof level before a request is transmitted. Read

MSDD

Binds asserted and separately observed values without merging them. Read

BPA

Binds a declared performance budget and the actual distribution to the same response.

BPA in Hive Proof Architecture →

Run a receipt today

The hosted BPA signer and verifier are live at the Hive typed receipt API, https://hive-typed-receipts.vercel.app. Production acceptance passed on this deployment with synthetic acceptance data, not a customer workload, and minting a real receipt requires an authorization token that Hive controls. What is public today: two published schemas at /.well-known/schemas/perf-budget-v1.json and perf-attestation-v1.json, an Ed25519 verifier in the open kit, an offline Python verifier at canon/verify_bpa.py, signed example receipts, and a test suite that recomputes the outcome from the budget and the signed distribution and fails a receipt that states something the records do not support. No customer deployment exists and nothing here implies a customer endorsement.

Bonded Performance Attestation is evidence suitable for a parametric threshold. It does not create or confirm insurance coverage, does not establish that any claim is payable, and does not attest that the output was correct. The measurements are reported by the attester. No verifier can confirm they were taken honestly, only that they were committed against a budget fixed before the window opened and bound to the signed response set or observation manifest named in the receipt.

Bonded Performance Attestation (BPA). Patent pending, filed July 31, 2026. Binds a pre-declared performance budget, the signed distribution, and a signed response binding for the measured response set or observation manifest. Hive Civilization Inc.

Private by design. Hive does not store your prompts. Every request is already receipted by a one-way SHA-256 fingerprint, not the words. Proof, not surveillance.