One post-quantum receipt sits under everything Harvey touches: the compute it answers on, the models firms will own, the authority it retrieves, and the systems where the work lives. The map below reads every one of those rails the same way. Everything runs on the live signer, and it's real ML-DSA-65, nothing mocked.
Every enterprise customer's litigation team will eventually face this exchange. Run it both ways. The difference is the whole pitch.
A Vault project's material findings (privilege calls, responsive determinations, extracted terms) roll up into one Merkle root with absence proofs over everything else. Drag the project size. The tree grows. The signature count doesn't.
Every surface Harvey ships today emits a signed, verifiable receipt on the same rail. Select one to see the primitives and the live envelope it returns.
Harvey doesn't run alone. It runs on an inference stack, on foundation models firms will soon own, on the retrieval that gives answers authority, and on the systems of record where the work lives. The map below reads every one of those rails the same way: the Hive primitive that seals it, what that does for Harvey now, and where it goes next. One post-quantum receipt sits under the whole map.
Read each rail two ways. The middle column is the proof we can put underneath it today. The right column is the market that proof opens: provenance Harvey owns, then resells to its own clients.
| The rail Harvey runs on | The receipt underneath | The market it opens |
|---|---|---|
| Serving & post-training partnerslive | SiGR signs the answer that comes off the stack: cost, latency, and the SLA it met. When a task can run a cheap worker model or an expensive advisor, the receipt proves which one actually answered and what it cost. | A billing-and-SLA evidence product Harvey resells to clients who must audit their own AI spend and service levels, down to the task. |
| Multi-vendor routingready | AFIR packetizes and signs inference across vendors, so an answer carries a signed route of which providers touched it. It's never a single unverifiable black box. | Model-neutrality Harvey can prove to regulated clients: no lock-in to one lab, and a signed record of vendor diversity. |
| Accelerated computelive | Every receipt is ML-DSA-65, post-quantum from the signer up. As the hardware and the answers get faster, the proof underneath stays sound against tomorrow's threat model. | A post-quantum attestation rail Harvey books per-seat as regulated sectors add PQ requirements. |
| The rail Harvey runs on | The receipt underneath | The market it opens |
|---|---|---|
| Specialized firm modelsready | OriginProof attests which firm-owned model produced a given clause, and the benchmark provenance it was trained and measured against, so a firm's own model carries its own signed pedigree. | When every firm owns a model, the differentiator is whose model, provably. Harvey sells the model and the proof of what it produced. |
| Open benchmarks & rubricsready | Imprimatur binds a signed pass-state to a published rubric. The receipt says this output cleared this named benchmark, not a private, unverifiable claim of quality. | A benchmark-attested quality tier: clients pay for outputs that carry a signed, independently checkable rubric result. |
| The rail Harvey runs on | The receipt underneath | The market it opens |
|---|---|---|
| Authority & citator retrievalready | AFiR-OCR DocProof proves what the model read and where on the page. It's a signed record of exactly which authority was retrieved and ingested before the answer was written. | A defensible-research record: the citation trail behind an answer becomes a signed, auditable artifact clients and courts can trust. |
| Retrieved-source integritylive | M.O.R. seals the origin, custody, and integrity of every retrieved source into a receipt that breaks if a single byte of the source changes between retrieval and citation. | Self-authenticating authority: the source behind a Harvey answer stands on its own under evidence rules, with no custodian testimony. |
| The rail Harvey runs on | The receipt underneath | The market it opens |
|---|---|---|
| DMS & data-room connectorsready | HiveBound seals exactly which documents went in from the system of record before Harvey runs. That closes the "were these the files you reviewed?" gap across every connected source. | A defensible-ingest record for diligence and discovery. The input set is signed at the connector, not reconstructed after the fact. |
| The MCP surfacelive | The receipt is a first-class MCP artifact. It travels with the document across every connector and productivity surface, so proof moves with the work instead of staying stranded in one tool. | A portable-proof layer across the whole connector library: one receipt, verifiable in any surface the document lands in. |
| Workflow & productivity agentslive | Protected Flow step-seals a multi-step agent so a long workflow is one unbroken, tamper-evident chain of custody. Every hop is signed, from the productivity plug-in down to the filing. | Every automated workflow becomes a signed, replayable record, and a governed one, gated to counsel where the stakes demand it. |
Harvey integrates every one of these: the compute, the models, the authority, the connectors. Underneath each is the same ML-DSA-65 receipt, the same offline-checkable proof, and the same ledger. Sell into Harvey and the receipt reaches everything Harvey touches: provenance the client owns, then the evidence tier an insurer, lender, or auditor prices against. Pick the cell that excites you. The rail underneath is already the same.
This is the part no competitor can hand Harvey. Press the button and a five-step legal Workflow Agent runs: intake, LexisNexis research, draft, citation-check, file. It step-seals every hop into one court-admissible chain of custody. The signature below is real ML-DSA-65, minted against the production Hive rail. Verify it yourself.
A worked example of the receipt rail under a multi-step legal agent. This one runs a five-step analysis: intake, research, claim chart, overlap, opinion. The point is not the answer it reaches. The point is that every step is sealed into a real SiGR Chain signature, then handed to R3Pv, an independent signer that returns a signed routing state. The agent does not decide. It routes to attorney sign-off with a complete, signed evidentiary trail, because a defensible record is the product, not an automated verdict. Both signatures below are live. Nothing is mocked.
The strategy is simple. Harvey's customers should build their own models and own their data. Provenance is what turns “own your data” from a slogan into something a court, a regulator, an auditor, and a board will actually accept.
A signed, self-authenticating, post-quantum receipt for every step. Hive sits underneath the surfaces Harvey already integrates, including LexisNexis, Microsoft 365, iManage, NetDocuments, Box, Command Center, and the own-model program. It's not another integration. It's the attestation layer beneath all of them.
Then the layer above it, Proof Credit, turns that sealed proof-state into underwriting-grade, exportable evidence: something an insurer, a lender, or an auditor can price on. Every surface below is a product Harvey resells into its entire client base, either broadcast across every seat or tailored to a client's exact regulated process.
Seal the deposition end to end (who, when, the verbatim transcript) into one self-authenticating chain of custody. No custodian testimony needed under FRE 902(13).
The court reporter's transcript gets a receipt at capture: reporter identity, timestamp, and integrity hash, bound into a post-quantum signature that breaks if a single word is altered.
Any exhibit, produced document, or media file gets a signed origin-and-custody receipt covering human, AI, or hybrid provenance. It's self-authenticating under FRE 902(13)/(14) with no spoliation gap.
Real-time streaming receipts for voice and agent sessions. Segments are signed off the hot path, and a post-quantum session anchor is sealed at close. This turns a live client call or agent run into a verifiable record.
The primitive under all three litigation surfaces. It seals origin, custody, and integrity into a signed, self-authenticating receipt for human, AI, or hybrid content. Patent-pending, licensable, live today.
The enterprise container that makes proof-state sellable. Point an auditor, insurer, or regulator at exactly the matters, practice groups, or client programs they care about. Every flow is addressable, and every receipt is checkable offline against the Hive Ledger.
The layer above the fleet. It reads the sealed proof a matter already produced and exports it as underwriting-grade evidence an insurer, lender, or auditor can verify and price: E&O tiers, litigation-hold audit exports, compliance bundles. This is the new market where provenance becomes money.
The complete inventory. Every primitive we've built, read two ways: what it does for Harvey today, and the future path it opens. Grouped by the five surfaces Harvey already ships, then the layers that sit above them.
One rail underneath all of it: the same ML-DSA-65 signer, one receipt you can check offline, one ledger. The left column is what we own. The middle is the concrete help today. The right is where it takes Harvey as the surfaces mature.
| Hive primitive | For Harvey now | The future path |
|---|---|---|
| Hive Typed Signerlive | The ML-DSA-65 engine under every receipt. It turns any Assistant answer into a post-quantum, self-authenticating record, the base layer everything else signs against. | The attestation rail itself: a per-receipt line Harvey books on every seat as post-quantum requirements land in regulated sectors. |
| SiGRlive | Signed Inference Guarantee Receipts: SiGR-Bill (cost), SiGR-Bond (SLA), SiGR-Consensus (multi-model panel). Proof of cost, latency, and quality on every answer. | A billing-and-SLA evidence product Harvey resells to clients who must audit their own AI spend and service levels. |
| AFIRready | Attested fragmented inference routing packetizes and signs inference across models, so an answer carries a signed route of which models touched it. | Model-neutrality and routing transparency, for regulated clients who must show no single black box decided. |
| XCALIBURready | Verifiable-inference suite: ECHO (output compression), MEMBRANE (info-flow control), QUORUM (consensus). It hardens the Assistant against leakage and single-model error. | A confidential-matter tier: info-flow guarantees priced for privileged and cross-border work. |
| Hive primitive | For Harvey now | The future path |
|---|---|---|
| M.O.R.live | Media-Origin Receipt seals origin, custody, and integrity of any file in Vault (human, AI, or hybrid) into a receipt that breaks if a single byte changes. | Self-authenticating exhibits under FRE 902(13)/(14): an e-discovery and evidence-production line Harvey doesn't sell today. |
| AFiR-OCR DocProofready | Provenance on OCR extraction proves what the model read and where on the page. It's not a claim of correctness. It's a claim of what was ingested. | A defensible-review record for regulated document sets: due diligence, discovery, and audit lanes. |
| HiveBoundready | Input-side pre-commitment envelope seals exactly which documents went in before Vault runs, closing the "were these the files you reviewed?" gap. | A scope-of-review attestation for any matter where the input set itself is contested. |
| Imprimaturready | Pre-attestation clearance gate: a before-run check that blocks a Vault action unless policy clears, and signs the clearance itself. | A compliance pre-clearance product for clients whose review must pass policy before it runs. |
| Hive primitive | For Harvey now | The future path |
|---|---|---|
| MiR Memory Proof Stackready | Model identity, memory retention, memory-aware routing, and eval attestation (MiR / MiR-M / MPP / MaR / EvAR) prove which model, with which memory, answered, and that it passed its evals. | A model-governance record for clients who must certify which system produced regulated advice. |
| OriginProofready | Human-origin attestation marks authorities and inputs from a verified human source, separating grounded citation from generated text. | A citation-integrity product for anywhere "did the AI invent this case?" is a live risk. |
| Hive primitive | For Harvey now | The future path |
|---|---|---|
| SiGR Chainlive | Step-seals an agent's DAG. Each action links to the last through a signed causal root, so a 40-step workflow is one unbroken, tamper-evident chain of custody. | An agent-audit product: the record a regulator or opposing counsel accepts for autonomous work. |
| AFiR-S3ready | Agentic receipts for tool-scope, action, context-mutation, and reward prove what an agent was allowed to touch, what it did, and what changed. | An agent-authorization record for clients who must bound what autonomous systems may do. |
| AFiR-Streamlive | Real-time receipts for voice and live agent sessions: microsecond-class signing (11.59µs against a 100µs budget) off the hot path, sealed at session close. | A live-session record product that turns client calls, voice agents, and real-time runs into verifiable evidence. |
| R3Pvlive | Receipt Proof Vector groups a workflow's receipts into one signed, machine-readable decision vector with a routing recommendation (for example, require approval). | A decision-routing layer that counsel-gate automation clients embed in their own regulated processes. |
| Protected Flowready | The risk-and-action layer above R3Pv turns a signed decision vector into a governed action with the policy that permitted it attached. | A policy-enforcement tier for clients who must show every automated action was authorized. |
| SmartAgent / SmartMorphAgentready | Route-graph proof. SmartAgent receipts the path an agent takes across models, tools, and payments. SmartMorphAgent adds the transformation that changed the path. | A route-explainability layer: the "why did the agent do that?" record for high-stakes automated matters. |
| HiveGateready | Agent onboarding and key-mint gateway. Every agent that joins a workflow gets a signed identity before it can act. | An agent-identity registry: the trust root clients require before letting agents touch their data. |
| Hive MCP Spirelive | SPIRE-attestation MCP server signs agent-instance mints, trajectories, and coherence artifacts with ML-DSA-65, checkable offline. | The standards-track integration that lets Harvey's 500+ agents emit receipts through the MCP tooling clients already run. |
| Hive MCP Countlive | Signs token counts per prompt or message with Ed25519, which makes usage measurement itself a verifiable artifact. | A signed-metering wedge: the auditable basis for usage-priced agent billing. |
| HiveSealready | Hardware root of trust (STM32L432 + ATECC608B) anchors signing keys in tamper-resistant silicon for clients who won't accept software-only custody. | A hardware-attested tier for the highest-assurance regulated and government matters. |
| Hive primitive | For Harvey now | The future path |
|---|---|---|
| Protected Flow Fleetslive | The enterprise container that makes proof-state addressable. Point an auditor, insurer, or regulator at exactly the matters or client programs they care about, checkable offline against the Hive Ledger. | The enterprise proof product: how a client packages its own sealed proof-state for outside review. |
| Proof Creditlive | Reads the sealed proof a matter already produced and exports it as underwriting-grade evidence, dual-signed with Ed25519 and ML-DSA-65, that an insurer, lender, or auditor can verify and price. | The market where provenance becomes money: E&O tiers, litigation-hold audit exports, compliance bundles. Sold on top of proof already made. |
| Hive Receiptready | The settlement rail, x402 / Base-USDC, Ed25519-signed, lets a proof product get paid for on real money rails, not simulated ones. | A metered-provenance business model: usage-priced attestation Harvey and its clients settle on real rails. |
| Structural Lateration (SLS)ready | Residual-cost metering: the economics primitive that prices attestation as a rounding-error share of the seat revenue it protects. | The pricing engine under every tier. It's the reason "attest everything" survives a CFO review. |
| SRPR provenanceready | Signed Royalty-Provenance Receipt binds works, sources, and downstream use into inspectable provenance for a client's own trained models and data. | A training-data and IP-provenance product: the record clients need when they own the model and must prove what it learned from. |
| Hive primitive | For Harvey now | The future path |
|---|---|---|
| Hive Command Centerlive | The live public dashboard of receipt streams, trust-network state, and compliance posture. It's the URL that shows signed activity instead of describing it. | A white-label trust console Harvey can put in front of a client's own board and regulators. |
| Hive Customer Consolelive | Tenant dashboard: a customer's receipts, spend, keys, and evidence bundles, plus the operator's revenue-mix view. It makes "run receipts" self-serve. | The onboarding surface for Harvey clients to manage their own provenance program without a sales call. |
| Hive Coverage Maplive | Interactive atlas mapping every AI-system surface (inference, agents, media, RAG, MCP, voice, training) to the receipt primitive that signs it. | The coverage argument: a shared map Harvey and a client use to find the next surface worth attesting. |
| HiveMorphlive | MCP/API discovery and agent-trust layer. It exposes the tool index, agent manifest, and trust scoring so Hive is callable by agent infrastructure, not just readable as a page. | The discovery fabric that lets Harvey's agents find and call attested tools automatically. |
| Sovereign AI Receipt Registryready | Country-scale proof layer. Every high-risk AI decision is signed at the moment it's made, and keys are held by the sovereign, not by Hive or a hyperscaler. | A public-sector and cross-border tier: the path for Harvey into government and regulated national deployments. |
| Hive Provable Machinesready | The same AFiR receipts, R3Pv vectors, and evidence export applied to robots, RaaS fleets, and physical work. It's proof the rail generalizes beyond text. | Proof that Harvey's clients in manufacturing, logistics, and hardware can attest physical operations on the same substrate. |
Cited authorities stream through grounding attestation. Most bind clean. Watch what happens when a citation drifts from what the case actually says.
Real per-receipt pricing off the Hive SET-sheet. The right-hand dial shows attestation spend as a share of the seat revenue it protects. That needle is the argument.
A multi-step run touches research, drafting, a DMS write, a filing. Each hop is signed into one replayable chain of custody. That's the record Command Center reports on, and the proof Hive lets it stand behind.
This widget calls the production Hive signing rail. The receipt it returns is a real ML-DSA-65 signature you can verify offline against the public key. Nothing here is simulated.