The proof is in the provenance.
Whatever you put in those sliders, the last number is always zero. That is the whole design.
Plain English. Each part closes a gap a private path leaves open.
A cloud that sells the model cannot be the impartial witness to what that model decided. You can, because you take no side in the AI you carry. The same neutrality that lets you interconnect rivals is what makes your receipt believed. That is a category a hyperscaler cannot copy after the fact. Hive supplies the receipt engine. You supply the neutrality that makes it true.
See where each part clicks into Fabric → See the full canon x Fabric cross reference →
Equinix already carries the fabric, and Hive already gives it a receipt rail. The seven upstream primitives below make every model inference physically inside an Equinix cage produce provenance of the environment, the policy, the perimeter, and the egress, before the workload ever commits.
Provenance-Bonded Sandbox → Refusal Ledger → Howler → Perimeter Bond →
Diurnal Bond → Egress Bond → Forensic Rail → See upstream group in canon → Read the essay →
A service your customers can turn on beside the models, clouds, and data platforms already there. We compete with none of them.
Security stops the bad call. We prove the good one happened the way you said it did. Two jobs, one hall.
You already keep the data in country. We prove the decision on top of it, without ever asking the data to move.
Running Hive now gives your hub a receipt rail today: InkFrame v1, the four filings, the in-browser verifier, and the live primitive stack. The same rail lets you stand up more of your own offerings across the broader Hive canon. Everything under Running now is live today. Everything under Expansion offerings is a surface you could offer with Hive, not a service running yet.
Is there room in the hub for an independent proof service listed beside the compute, data, and security already there? Not instead of anything. A new neutral thing that makes the whole hub more provable.
The page above is about proof crossing your Fabric while data stays in the hall. This newer receipt answers the one question that follows an incident in a colocation footprint. It answers in production right now, and the run below proves it end to end.
After an incident, the expensive fight is over timing. Disclosure clocks, notification windows, and regulatory deadlines all run from when a system first held the fact, and that instant is usually reconstructed from logs anyone could have edited. This receipt bounds it instead. A detector commits what it observed against a named registry version, and the verifier confirms the latest instant that knowledge can be pinned to. A customer in your hall can produce it without you reading their data and without their data leaving your building.
What it does not do. It does not say the detection was correct, does not classify severity, does not start or satisfy any legal obligation, and does not reveal what was detected. It bounds one instant and no more.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.
Search the explorer for Equinix use case