prepared privately for Equinix · not indexed · not a customer, partner, or endorsement

Every AI decision in your halls
can carry a receipt.
And nothing leaves the building.

Data never movesOnly a fingerprint and a rule number cross the line. Never the data.
Neutral, like youWe are not a model and not a cloud. We compete with nothing in your hub.
Nothing waitsThe receipt is signed beside the work, not in front of it.
See the Fabric map

The proof is in the provenance.

The data stays. The proof crosses.

Customer data stays in the hall.Prompts, model traffic, and payloads remain inside the customer’s boundary. They do not cross the line.
Only the signed proof crosses.A fingerprint, rule ID, timestamp, and signature travel across Fabric. Enough to verify the decision. Nothing that reveals the data.
your hub · your numbers

Move the sliders.
Watch the last one never change.

That last slider is your number, not ours. We do not set your pricing and we make no revenue claim. It is here so you can do your own arithmetic on your own screen.
decisions receipted each month·
signatures actually needed
batched, so proof gets cheaper as you grow
·
delay added to a customer's work0 ms
at your fee, per month·
customer data that left your facility0 bytes

Whatever you put in those sliders, the last number is always zero. That is the whole design.

try it · nothing is connected to anything

Run one decision. Watch what we keep.

·time to sign
·what crossed the line
·anyone can check it in
Press the button.
See the substrate
what makes the receipt · four parts · patent pending

Four small inventions. One receipt.

Plain English. Each part closes a gap a private path leaves open.

01
Proof pre-fillThe receipt is attached before the agent acts, not written up after.
02
Sealed by contentOne tamper-proof folder. Change a byte and its address changes.
03
Blind replayProve it happened without showing the prompt, the data, or the words.
04
Arrival countersignThe gateway signs on arrival, so what ran is what was cleared.
reference build passed its integrity gate · we run long-duration signed soaks as routine practice · patent pending

The clouds move the compute.
Only the neutral hub can own the receipt.

A cloud that sells the model cannot be the impartial witness to what that model decided. You can, because you take no side in the AI you carry. The same neutrality that lets you interconnect rivals is what makes your receipt believed. That is a category a hyperscaler cannot copy after the fact. Hive supplies the receipt engine. You supply the neutrality that makes it true.

See where each part clicks into Fabric →   See the full canon x Fabric cross reference →

just filed · USPTO 64/119,279 · Jul 26, 2026

Seven upstream receipts. The missing sovereign-compute layer.

Equinix already carries the fabric, and Hive already gives it a receipt rail. The seven upstream primitives below make every model inference physically inside an Equinix cage produce provenance of the environment, the policy, the perimeter, and the egress, before the workload ever commits.

01
PBS™Any customer running frontier inference in a cage can attest its container, kernel, and GPU-firmware chain to a counterparty over the fabric without revealing internals.
02
Refusal Ledger™Sovereign-inference customers publish policy mutation ledgers on Equinix-anchored bulletin boards.
03
Howler™An interpretability probe firing inside a customer's cage produces a signed freeze that Equinix carries as a first-class fabric event.
04
Perimeter Bond™The eBPF bytecode enforcing sovereign-egress boundaries is fingerprint-attested at every cross-metro interconnect.
05
Diurnal Bond™Cross-metro k-of-n attestation is native to Equinix's geographic footprint, the exact fit for this primitive.
06
Egress Bond™Sovereign-egress caps on weights, PII, and evaluation data are Pedersen-metered across every port, and a breach breaks the fabric bond.
07
Forensic Rail™Independent incident response for regulated customers runs on Equinix-carried threshold credentials, and every replay is byte-identical.
Filed. July 26, 2026. USPTO application 64/119,279.

Provenance-Bonded Sandbox →   Refusal Ledger →   Howler →   Perimeter Bond →

Diurnal Bond →   Egress Bond →   Forensic Rail →   See upstream group in canon →   Read the essay →

Where it sits in what you already built

Inside the hub

A service your customers can turn on beside the models, clouds, and data platforms already there. We compete with none of them.

Next to security

Security stops the bad call. We prove the good one happened the way you said it did. Two jobs, one hall.

On top of location

You already keep the data in country. We prove the decision on top of it, without ever asking the data to move.

start with the rail you can run today · grow into the whole canon

Start with the receipt rail. Expand into the canon.

Running Hive now gives your hub a receipt rail today: InkFrame v1, the four filings, the in-browser verifier, and the live primitive stack. The same rail lets you stand up more of your own offerings across the broader Hive canon. Everything under Running now is live today. Everything under Expansion offerings is a surface you could offer with Hive, not a service running yet.

Distributed AI Hub

Receipts on every model call

Running nowInkFrame v1 · SiGR · CarnacPrompt™ · Proof Pre-Fill
Expansion offeringsS2S · MIR · Hivebound · Imprimatur · Xcalibur · AFiR-Stream · AFiR-OCR-DocProof · OriginProof
Fabric Intelligence · Super Agent

Proof for agent behavior

Running nowArrival Countersignature · Carnac™ · Carnac Gateway™ · AFiR route proof
Expansion offeringsAFiR-S3 · SmartAgent · R3Pv · Protected Flow Fleets
Geo Zones

Jurisdiction-held evidence

Running nowDisclosure-Free Replay
Expansion offeringsSovereign AI Receipt Registry · Verifiable Voting System · jurisdiction-held receipts
Application Connect · Network Edge

Typed edges and gateway receipts

Running nowTyped cue edges · gateway receipts
Expansion offeringsPPR · MoR · MoRSo · SRPR · Provable Machines
Fabric Insights

Signed evidence you can meter

Running nowSigned receipt streams · benchmark evidence
Expansion offeringsProof Credit · Structural Lateration · Hive Command Center · Hive Customer Console
Interconnection · Cloud Router

Countersigned multi-cloud paths

Running nowInkFrame Non-Mutation · countersigned paths
Expansion offeringsProtected Flow · multi-cloud fleet proof

One question, that is all

Is there room in the hub for an independent proof service listed beside the compute, data, and security already there? Not instead of anything. A new neutral thing that makes the whole hub more provable.

Private overview prepared for Equinix · noindex / nofollow / noarchive · this page does not state or imply that Equinix is a customer, partner, pilot, or endorser · the calculator is an arithmetic tool using numbers you enter; it is not a forecast, a quote, or a revenue claim, and the fee input is your figure, not ours · the boundary picture and sample decision are illustrations of how the service works and are not Equinix data · Hive proves what an AI decided; it does not store, route, or secure the data beneath it, and a signed record that a rule was checked is not a statement of legal or regulatory compliance · Carnac™ sizes how much proof a decision deserves. It does not judge. · we never read prompt or response content; each request is recorded as a one-way SHA-256 fingerprint, not the words · the four proof parts are patent pending and validated against a reference integrity gate; long-duration signed soaks run as a matter of routine, every pass itself signed, so you never have to trust a single number · verification is free, works offline against the Hive public key, and requires no account · signatures use ML-DSA-65 (NIST FIPS 204) · Carnac™, CarnacPrompt™, Carnac Gateway™, and Carnac Live Ink™ are Hive marks · all Hive methods patent pending · Equinix product facts referenced are public and source-reported as of July 2026 and should be re-verified before external use · prepared by Steve Rotzin, Founder, Hive Civilization Inc. · Wyoming, USA
new in the canon · runnable on this page

When did the machine first know

The page above is about proof crossing your Fabric while data stays in the hall. This newer receipt answers the one question that follows an incident in a colocation footprint. It answers in production right now, and the run below proves it end to end.

knowledge.timestamp · Deployed in production

A bounded instant for when a system first knew

After an incident, the expensive fight is over timing. Disclosure clocks, notification windows, and regulatory deadlines all run from when a system first held the fact, and that instant is usually reconstructed from logs anyone could have edited. This receipt bounds it instead. A detector commits what it observed against a named registry version, and the verifier confirms the latest instant that knowledge can be pinned to. A customer in your hall can produce it without you reading their data and without their data leaving your building.

What it does not do. It does not say the detection was correct, does not classify severity, does not start or satisfy any legal obligation, and does not reveal what was detected. It bounds one instant and no more.

POST /verify/knowledge-timestamp · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/knowledge-timestamp · case fail, a forged record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.