Built for Lemonade: Inference Receipt Demo
LIVE SIMULATION Every AI decision. Signed. Court-ready. thehiveryiq.com →
Maya: Claim Decision Queue 3 ACTIVE
What is this?
We built this demo page just for Lemonade. Every claim Maya decides, whether it's approved, sent to review, or denied, gets a cryptographic receipt signed with ML-DSA-65 (a post-quantum method) and anchored on Base. The receipt is proof that can't be changed later, showing exactly what the model decided, when it decided it, and what data it used. Not a log file. A signature.
SIGNING NOW
Auto Claim #LM-2026-048831
Tesla Model 3, rear collision, Brooklyn NY. Claimant: J. Harrington. Filed 14m ago via app.
PolicyLMND-AUTO-9921
Claim amount$4,200
Maya confidence94.2%
Modelmaya-claims-v4.1
MAYA DECISION → APPROVE · INSTANT PAY
Why does the receipt matter here?
Maya approved this in 1.3 seconds with no human involved. That's the edge Lemonade has. But if a regulator, plaintiff attorney, or state DOI asks "what did your model actually see and decide?", a log file is not the answer. A signed receipt is. The signature is tied to the model version, input hash, decision, timestamp, and payout amount. No one can tamper with it, and anyone can check it.
RECEIPT PENDING
Renters Claim #LM-2026-047104
Water damage, Chicago IL. Claimant: M. Oduya. Filed 41m ago via app.
PolicyLMND-RENT-4471
Claim amount$1,850
Maya confidence71.8%
Modelmaya-claims-v4.1
MAYA DECISION → HUMAN REVIEW TRIGGERED
QUEUED
Pet Claim #LM-2026-047891
Vet surgery, Portland OR. Claimant: S. Nakamura. Filed 2h ago.
PolicyLMND-PET-7821
Claim amount$3,100
Maya confidence88.6%
Modelmaya-claims-v4.1
MAYA DECISION → APPROVE · INSTANT PAY
Agent Action Log
--:--:--All 3 claims connected to Hive receipt layer
--:--:--Signing LM-2026-048831 · ML-DSA-65
--:--:--Anchoring receipt → Base Mainnet
Current State: No Receipt Layer receipts signed today: 0
Maya AI Engine
Claim Decision
decision made · no record kept
Payment System
Payment Released
$4,200 USDC · no signed proof
Audit Log
No Cryptographic Proof
manual record · disputable · no model hash
Maya AI Engine
Claim Decision
maya-claims-v4.1 · 94.2% confidence
Hive Receipt Layer
Intercept + Sign
ML-DSA-65 · SHA-3 · post-quantum
Input Capture
Decision Hash
SHA-3 · inputs + model state
Hive Signer
ML-DSA-65
Post-quantum · NIST FIPS 204
Signed Receipt
rc_48831_a3f9e1
Immutable · tamper-evident · verifiable
Base Mainnet
On-Chain Anchor
USDC settlement · block 127,441,982
Maya approves claim #LM-2026-048831. Payment releases. No cryptographic record of what the model decided.
Signed Receipt + Regulatory Audit Trail COURT-READY
What a regulator gets
When a state DOI subpoenas claim decision records, this receipt is the answer. Every field is locked in with cryptography: change a single byte and the signature fails. No ambiguity. No "that's what our system shows." Just proof.
Latest Signed Receipt
receipt_idrc_48831_a3f9e1 claim_idLM-2026-048831 policyLMND-AUTO-9921 agent_modelmaya-claims-v4.1 decisionAPPROVE · INSTANT_PAY confidence94.2% payout_usdc4200.00 input_hashsha3:7f4a…c291
signatureML-DSA-65 sig_bytes3293 bytes anchoredBase · USDC block127,441,982 tx_hash0x9f3b…d441 verify_msN/A timestampN/A
Regulatory Audit Trail
State DOI Disclosure Check CLEAR
The receipt confirms model version, decision rationale inputs, and confidence threshold with cryptography. It satisfies NY DFS Circular 1 and CA CDI AI disclosure requirements without exposing proprietary model weights.
proof: zk:proof:0xa3f8…e291 · 4.2ms
ML-DSA-65 Signature SIGNED
A post-quantum digital signature under NIST FIPS 204. It ties the model decision to a specific input state and survives quantum decryption, built to last through a 30-year audit horizon. If the model changed, the signature fails. That's provable.
sig: ML-DSA-65:0x7f4a…c8b2 · 1.1ms
Base Mainnet Anchor ANCHORED
Receipt hash written to Base (L2, Ethereum). Block timestamp and tx hash are permanent, public, third-party verified. No Lemonade server holds the only copy. The blockchain is the witness.
tx: 0x9f3b…d441 · block 127,441,982
USDC Settlement Lock CLEAR
The payout amount ($4,200 USDC) is locked into the receipt before settlement clears. The signed receipt and the payment happen as one event, so there's no gap between what the model decided and what was paid.
usdc: 4200.00 · Base · pre-authorized
Why Hive built this for Lemonade
You've built the best AI-first claims stack in insurance. Maya decides faster and more accurately than any human adjuster. That's the edge. But that edge comes with a liability gap, and regulators are starting to find it.
1
The problem: AI decisions are invisible
When Maya approves or denies a claim in 1.3 seconds, the decision happens inside a model. There's a log. There's maybe a database entry. But there's no proof: no unchangeable record of exactly what the model saw, what version it was, what it decided, and what it paid. A log file can be altered. A signature cannot.
2
The regulatory pressure is real and accelerating
NY DFS Circular 1, CA CDI AI governance rules, and the NAIC model bulletin on AI are all moving toward requiring explainability and auditability on automated claims. The question isn't if a regulator subpoenas your AI decision records. It's when. Right now, your answer is a log file. That won't hold.
3
What Hive adds, without changing anything Maya does
Hive wraps the inference layer. Before any payment clears, Hive captures the model's decision (inputs, output, confidence, model version), signs it with ML-DSA-65 (post-quantum, NIST FIPS 204), and anchors the receipt hash on Base. The receipt can't be changed. The signature is publicly verifiable. Maya doesn't change. The claims flow doesn't change. You just now have cryptographic proof of every decision.
4
Why post-quantum matters for insurance
Insurance decisions have a 30-year audit horizon. A claim denied in 2026 can be litigated in 2041. By then, RSA and ECDSA signatures are breakable with quantum compute. ML-DSA-65 is NIST-standardized post-quantum. The signature you write today holds up in a 2041 courtroom. This isn't just forward-thinking. It's the only defensible choice.
5
The USDC anchor: why Base, not a database
The receipt hash is written to Base (Ethereum L2). The block timestamp and tx hash are permanent, public, and held by no single party. No Lemonade server holds the only copy. The blockchain is the neutral witness. Settlement in USDC means the payout amount is locked to the receipt before it clears. The signed decision and the payment happen as one event.
Private by design. Hive does not store your prompts. Every request is already receipted by a one-way SHA-256 fingerprint, not the words. Proof, not surveillance.
new in the canon · runnable on this page

Set the condition before the window opens

Maya decision receipts show what the claims system decided on an individual file. These additions extend that record to a condition set before its measurement window and to book level concentration, are live on the production rail, and the runs below verify them.

parametric.trigger · Deployed in production

Check a condition that was set before measurement begins

For a parametric claims or performance program, the receipt checks one named condition against one Bonded Performance Attestation. It shows that the policy terms digest was committed at or before the governing budget was declared. It shows that the budget was declared before the measurement window opened. It recomputes the trigger state from the referenced attestation rather than taking it from the caller. That gives underwriting and claims teams a clear record of the condition, budget, and measurement window.

What it does not do. It does not create, price, underwrite, or interpret a policy, and it never receives the policy terms. It does not show that a claim is payable, authorize a payment, establish that the measurements or loss are correct, verify the measuring party, or decide what the parties' contract requires.

POST /verify/parametric-trigger · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/parametric-trigger · case nottriggered, the condition was not met

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/parametric-trigger · case fail, a forged record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

portfolio.exposure · Deployed in production

Review book concentration without exposing positions

This receipt recomputes concentration counts and share ratios for one book at a stated time using opaque commitments. It reports no group smaller than five members. The service sees no insured identity, dependency name, or policy term. That lets underwriting and reinsurance teams review stated concentration across a book without exposing its individual positions.

What it does not do. It does not show that the commitments are correct, honestly computed, or complete, that any member is insured, and it cannot detect an omitted, duplicated, or miscommitted member. It does not measure or price risk, provide actuarial or capital advice or a reinsurance recommendation, or establish that reported concentration would cause a correlated loss.

POST /verify/portfolio-exposure · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/portfolio-exposure · case fail, a forged record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.