prepared privately · illustrative only · not affiliated with Polymarket · not indexed

Now that Polymarket US is a regulated DCM, every eligibility decision is an evidence obligation.

Polymarket US is now a CFTC-designated contract market. It runs per-user, per-state eligibility checks millions of times a day. Sooner or later, regulators, courts, or outside counsel will ask a specific question: for one session, in one state, under one rule version, did the check actually run. Today that answer lives inside the same platform whose conduct is in question. An independent evidence layer, built from day one, keeps that answer provable before anyone has to ask.

Hive comes alongside Polymarket US as a sidecar. At the moment of each eligibility decision it makes an independent, signed receipt that anyone can check offline. It never places a trade, sets a price, decides who may transact, or drives the platform. It does not judge. The receipt proves the eligibility check ran. It does not decide legality and does not guarantee compliance. It is invisible to your users, invisible to your matching engine, and fail-open. If Hive is unreachable, Polymarket operates exactly as it does today.

CFTC · July 9, 2025
QCX LLC (now operating as Polymarket US) is designated as a Contract Market by the CFTC. The regulator now expects durable, auditable evidence of every eligibility decision that gates access to listed contracts.
Acquisition · July 21, 2025
Polymarket closed the acquisition of QCEX, a CFTC-licensed DCM and DCO, for $112 million. This is the foundation for a fully regulated US platform. The rulebook and the exchange license are in place. An independent evidence layer beneath them is not yet.
Market Integrity Rules · March 23, 2026
Polymarket published enhanced Market Integrity Rules across its DeFi platform and its CFTC-regulated US exchange. The rules prohibit three categories of insider trading and set up a three-tier surveillance framework, anchored by a Regulatory Services Agreement with the NFA. The rulebook is written. The next layer is independently checkable evidence, at each decision, that each rule actually fired.
The forward posture
Foundation first. Every eligibility decision, from day one, produces an independently verifiable, cryptographically signed receipt showing the state, rule version, decision, and time. Anyone can check it offline, without ever entering Polymarket systems or seeing customer data. Regulators cannot argue with a proof they can verify themselves.
Concept proposal by Hive

Three simple states

Where an eligibility-decision record is now, where a signed receipt takes it, and what stays yours.

● today · current state

You can show your logs

When a court, an outside counsel team, or a state asks whether a specific session was screened, you look it up and explain it from your own logs. Useful, but the record is held by the same platform whose conduct is in question, so the dispute becomes he-said, she-said.

● with Hive · sidecar state

You can hand over proof

Each eligibility decision gets its own signed receipt at the moment it happens. The receipt records that a location check ran, which jurisdiction applied, which rule version and effective date governed, the allow or block result, and the timestamp. Anyone can check it offline, without touching your systems.

● travels with the record · portable

The receipt goes with the evidence

The signed receipt can travel with a discovery production, a filing, an outside-counsel packet, or an independent monitor review. The evidence is built at the moment of the decision, not reconstructed under deadline pressure weeks later.

follow one user session · synthetic data · runs in this tab

Follow one user session to a signed receipt

A user opens the app in one of several US states and tries to take a listed contract. Watch the location signal resolve, the jurisdiction and rule version apply, the sports contract get blocked, a receipt get signed, and the block become independently checkable offline. Switch the jurisdiction to see the same session resolve differently. Nothing here is real Polymarket or user data. It is synthetic, made to show how the sidecar works. Hive never decides who may transact.

● what a log shows today
● what a signed receipt adds
Signedanyone can check it

Press Run this session to watch the eligibility receipt get stamped at the moment of the decision.

offline verifier · runs entirely in this tab · no telemetry after page load

Check an eligibility receipt yourself. No install.

This builds a real signed receipt for a synthetic Washington eligibility decision, checks it in your browser, lets you break one byte and watch the check refuse it, re-checks pasted evidence, and re-verifies a published 5,000-receipt soak test. Washington is one of several state jurisdictions where a listed Polymarket contract can be blocked or gated; the same mechanism works for any US state. Everything runs in this tab, using the same signing engine, offline check, and receipt structure Hive uses across every illustrative proof page on this site.

The signing engine is bundled and served from this same site. After the page loads it makes zero outside calls except two same-site file reads it names out loud. Core verification is fully offline.

In-browser · offline The verifier never leaves this page except to read its own sample and soak-test file from this site.

Idle. Click 1 · Build & check a receipt to load the engine and run the first check. Everything runs in this tab.

Every click prints the recomputed hash next to the stored hash, one line per layer. A changed byte reads FAIL in the same output; a clean receipt reads PASS. Success is labelled, never color alone. There is no server round-trip.

rule version and effective date · runs in this tab

Which rule applied, and when it took effect

Many disputes turn on which version of a rule governed a specific action, and when it took effect. This binds the exact jurisdiction rule set, its version, and its effective date into the same signed receipt as the eligibility decision. The governing rule for one session becomes a matter of independent record, not an after-the-fact account. All values are synthetic.

the session
jurisdiction · WA
rule set · wa-gambling-block
version · v2026.07.20
effective · 2026-07-20
the decision
contract type · sports event
location check · performed
result · blocked
at · synthetic timestamp
what the receipt fixes
rule version bound · yes
effective date bound · yes
independently checkable · offline
raw account data · 0 bytes
Idle. Press Seal this rule-version receipt to bind the jurisdiction, rule version, and effective date into a signed receipt.

The rule version and effective date are content-addressed inside the receipt. Change either after signing and the address changes, which breaks the seal. This proves which rule governed the session. It does not judge whether that rule was correct, adequately disclosed, or lawful.

discovery evidence bundle · deterministic · runs in this tab

Group many sessions, then seal the bundle

A discovery production, a filing exhibit, or an independent-monitor review usually covers many sessions, not one. This demo takes three signed eligibility decisions from one synthetic day and rolls them into a single grouped proof vector. It folds that into one signed bundle a court or an opposing party can check offline. Change one session after signing to watch the check refuse it. All values are synthetic.

session 1 · Washington
location · WA resolved
contract · sports event
rule · wa-block v2026.07.20
result · blocked
session 2 · Michigan
location · MI resolved
contract · sports event
rule · mi-geo v2026.07.13
result · blocked
discovery rollup
sessions sealed · 3 of 3
weakest link · none flagged
state · recoverable
raw account bytes · 0
Idle. Press Assemble and seal to roll the day's eligibility decisions into one grouped proof vector and fold it into a signed bundle.

This is a grouped proof over synthetic sessions folded into a real signed frame, not a Polymarket production and not user data. The rollup names the weakest link for review; it does not grade the underlying legal question.

insider-surveillance receipt · synthetic data · runs in this tab

A signed record that the surveillance check ran

Polymarket's Chief Legal Officer, Neal Kumar, has publicly described the platform's expanded Market Integrity Rules and its compliance infrastructure. Those rules prohibit trading on stolen confidential information, on illegal tips, and by anyone who can influence an event's outcome. Kumar also describes a three-tier surveillance framework, backed by a Regulatory Services Agreement with the NFA. The open question is evidentiary. For one flagged account, can Polymarket show, independently, that the screen ran, against which affiliation or PEP list, and with what result. This demo signs that check as a receipt. All accounts and affiliations below are synthetic.

synthetic screen · one election market
account SYN-4471 · campaign-affiliatedblock
account SYN-2093 · no affiliation matchedallow
account SYN-8810 · candidate self-matchblock
screen ran against listfec-affiliations-v2026.07
what the receipt attests
that a screen was performedyes
the affiliation list versionbound
the per-account resultbound
the timestampbound
Idle. Press Sign the surveillance receipt to seal a signed record that the screen ran, against which list, with what per-account result.

This shows only that a screen ran and what it returned. It does not detect insider trading, does not define material nonpublic information, and it does not judge any account. Kumar's statements and Polymarket's rulebook are cited as Polymarket's own public description, not as a regulatory or court finding (Business Wire, March 23, 2026; Bloomberg, March 23, 2026).

your numbers · arithmetic tool, not a forecast, quote, or ROI claim

Move the sliders. See evidence volume and time you stop reconstructing.

This is an evidence-coverage tool. It counts how many signed eligibility receipts a given daily activity level produces and how much reconstruction time signed coverage can remove. Every value below is a number you set. It is not a forecast, a quote, or a dollar-savings claim, and it makes no assumption about Polymarket's real volume.

Every slider is a labelled assumption you set. This is arithmetic on numbers you enter, not a forecast, a quote, or a claim about Polymarket's real activity. No return-on-investment figure is implied.

Signed eligibility receipts / day·
Signed receipts / 30 days·
Fenced-jurisdiction decisions with a receipt
per day
·
Reviewed or produced sessions covered by a receipt
per 30 days
·
Reconstruction hours avoided
covered sessions, no manual rebuild
·
Raw account data moved to Hive0 bytes

Whatever you enter, the last number is always zero. Receipts carry one-way fingerprints and commitments, never raw account or location data. Evidence volume scales with sessions; proprietary data moved to Hive does not scale at all, because it never moves.

just filed · USPTO 64/119,279 · Jul 26, 2026

Seven upstream receipts, signed before the session receipt is cut

Here is how Polymarket could use Hive to prove eligibility, rule version, and insider surveillance for each signed session. The seven upstream primitives below could prove that the eligibility model, its policy state, its refusal thresholds, and every egress from the trading stack were themselves signed before that session receipt was cut.

Environment and policy provenance
PBS™ · Provenance-Bonded SandboxThe eligibility-scoring model ran in a sandbox whose kernel, model-weights hash, and firmware version were on the signed heartbeat chain at the moment it evaluated the user.PBS · Merkle heartbeat chainupstream to the eligibility decision
Refusal Ledger™Polymarket's state-eligibility refusal thresholds live on a public Merkle mutation ledger with a ZK envelope-bond, so a regulator can verify the bounds without seeing the exact number.Refusal Ledger · ZK envelope-bondupstream to the refusal decision
Interpretability and perimeter integrity
Howler™ (SAE-triggered)A signed freeze receipt fires the instant a market-manipulation-adjacent feature activates during automated market-maker reasoning.Howler · SAE probeupstream to market-maker inference
Perimeter Bond™The eBPF bytecode enforcing insider-trading DLP on internal analytics is fingerprint-bound to the exact version filed with the CFTC.Perimeter Bond · eBPF hashupstream to every egress attempt
Weekend, incident, and settlement regimes
Diurnal Bond™High-impact settlement actions taken during weekend hours or a CFTC-declared-incident regime require k-of-n countersign before they run.Diurnal Bond · k-of-n countersignupstream to weekend and incident regimes
Egress Bond™Caps on customer-identity egress from surveillance systems are Pedersen-metered per semantic class, and a cap breach retroactively invalidates the surveillance DAG.Egress Bond · Pedersen meteringupstream to the surveillance DAG
Post-incident and regulator replay
Forensic Rail™Post-incident settlement analysis runs under a threshold-signed consortium credential and is deterministic-replayable by the CFTC, the NFA, or an independent auditor.Forensic Rail · threshold-signed credentialupstream to incident response

These seven sit upstream of the session receipt described above. None of this decides eligibility, refuses a trade, or blocks a transfer. Each one proves that the thing that made that call was itself the thing it claimed to be.

Filed. July 26, 2026. USPTO application 64/119,279. See upstream group in Hive Proof Architecture → · Read the essay →

Where this fits the Polymarket surface

The same signed receipt fits many parts of the DCM operating surface. Here is where it earns its keep, in plain words, with the Hive primitive named as a small label and a candid read on whether it helps now or is a fast-follow. Public reference material used in preparing this overview is linked at the foot of the page. Hive sits alongside, never inside the decision to allow or block.

Injunction compliance and geofencing
Per-decision eligibility evidenceEach eligibility decision is sealed with the location check result, the jurisdiction, the rule version, the allow or block outcome, and the timestamp. A regulator, a court, or a state gets an auditable record that the required control ran, instead of dueling assertions.HiveBound · Imprimaturhelps now for CFTC and state-eligibility audit posture as a US DCM
Good-faith postureA signed record that the eligibility control ran on each session is real evidence for any future compliance inquiry or dispute. It shows the check occurred. It is not a defense on the merits.R3Pv · Protected Flowhelps now for any per-session compliance record
Discovery, filings, and independent monitoring
Discovery-ready evidence bundlesState orders and CFTC inquiries can require preservation of consumer records including location and eligibility data on short notice. Building signed receipts from day one means many signed decisions roll into one grouped proof vector, so a production becomes a stack of independently checkable receipts rather than a fire drill against internal dashboards.R3Pv · Protected Flowhelps now for state-eligibility preservation and production readiness
Rule-version and effective-date bindingCustomer and settlement disputes often turn on which rule version governed a specific action and when it took effect. Binding the version and effective date into the receipt lets an arbitrator or court verify the governing rule for one session.Imprimatur · Carnac™helps now for settlement-rule and disclosure disputes
Surveillance, integrity, and trade finality
Surveillance-check receiptAn independent, append-only, signed record that a screen ran against a named affiliation list, with per-account results. An outside auditor or a regulator can verify the claim without relying on internal say-so. Surveillance-infrastructure adequacy is an ongoing public-interest factor for any CFTC-regulated DCM.SPIRE · SiGRhelps now as evidence a control ran; fast-follow for continuous audit feeds
Trade-finality chain of custodyTrade modifications, cancellations, and settlement actions can become contested months later. A signed settlement receipt at execution and at each change creates a neutral, tamper-evident, verifiable chain of custody that stands independently of internal logs.R3Pv · Hive Receipthelps now for a neutral ledger-state record across execution, modification, and settlement
Data feeds, keys, and the evidence floor
Integrity data-feed provenancePolymarket has named third-party data and integrity providers. A capture-side provenance receipt binds an integrity feed input to the decision it informed as a fingerprint, never the raw feed, so a downstream finding is traceable to its source.SiGR · AFiRfast-follow pending a live feed integration
Hardware-held signing keysThe signing key is born random and lives in hardware, so a stolen key cannot forge your receipts, and the compute that ran the check can be attested too. Your organization holds the pen; Hive never holds your keys.XCALIBUR · SPIREhelps now for key custody and device binding

helps now means the primitive is live in the offline verifier on this page. fast-follow means it needs an integration before it applies. Nothing here is forced onto a use it does not fit.

What supports this behind the scenes

You do not need any of this to understand the value. It is here for the people who want to look under the hood. Each row is a plain benefit first, with the Hive part named as a small label.

A single eligibility decision becomes a signed exhibit: the location check, the jurisdiction, the rule version and effective date, and the allow or block result, sealed into one receipt. SiGR patent pendingSiGR →
SiGR, the Signed Inference Guarantee Receipt, signs a decision into one receipt anchored on Base. It turns trust our logs into a signed exhibit that stands up in a filing or an independent review. See the SiGR page.
The authority or eligibility is checked before a transaction runs, and any attempt without a valid pass is blocked and recorded. Imprimatur · HiveBound patent pendingImprimatur →
Imprimatur is a pre-action attestation gate. It signs a clearance before a consequential action runs and blocks any call without a valid, unexpired pass, so the authority was in place is proved up front rather than reconstructed after the fact. HiveBound binds a decision to a jurisdiction and policy boundary. Both sit alongside the platform and never decide who may transact. See the Imprimatur page.
The exact jurisdiction rule set, its version, and its effective date are pinned to the decision, so which rule governed a session is a matter of record. Carnac™ family · Carnac Gateway™ patent pendingCarnac™ →
Carnac™ sizes how much proof a decision deserves, CarnacPrompt™ carries the human-visible context and proof demand, and Carnac Gateway™ clears an action before it runs. The rule version and effective date are carried in the signed context so a change in rule is traceable to the sessions it first affected. See the Carnac™ plane, CarnacPrompt™, and Carnac Gateway™.
Many receipts from one day, jurisdiction, or account roll into a single grouped proof vector that flags the weakest link. R3Pv · Protected Flow patent pendingR3Pv →
R3Pv, the Receipt Proof Vector, groups receipts into one signed vector: verification depth, weakest boundary, recoverability, and next action. One machine-readable summary per day, jurisdiction, or account lets a review or discovery team triage instead of re-checking everything. Protected Flow rolls many receipts into one proof-state view. See the R3Pv benchmark.
Big screening jobs and multi-step checks get proof at the piece level, and streaming inputs are signed as they flow. AFiR · SiGR patent pendingAFiR →
AFiR, Attested Fragmented Inference Routing, breaks a request into signed, routable sub-tasks and signs each fragment inside the path, so a multi-step surveillance or eligibility check is provable step by step. See the AFiR page.
The signing key is born random and lives in hardware, so a stolen key cannot forge your receipts. XCALIBUR · SPIRE patent pendingXCALIBUR →
XCALIBUR is a hardware root of trust: a signing device that keeps the key in silicon, born from quantum-grade randomness and bound to the device. SPIRE gives a service or agent instance a signed identity, so which system signed a receipt has a signed answer. See the XCALIBUR page and SPIRE in the proof architecture.
Under it all sits the evidence floor that holds a decision record still while proof is attached, so it can be rebuilt and re-checked offline. InkFrame v1 · Carnac Live Ink™ patent pendingInkFrame →
Carnac Live Ink™ writes non-mutating evidence frames. InkFrame v1 holds a proof-completion frame still using eight content-addressed roots and a hybrid Ed25519 with ML-DSA-65 signature. Change one byte and the address changes, which breaks the seal. See InkFrame v1 and Carnac Live Ink™.
Settlement receipts can be anchored and, where a partner wants it, paid and reconciled on a public rail. Hive Receipt · x402 · Base USDC patent pendingHive Receipt →
A Hive Receipt can be anchored on Base (chain 8453) and, where a counterparty wants a settled record, verified through the x402 rail with USDC settlement. This is optional infrastructure for a neutral, checkable ledger-state record, not a requirement for the offline verifier on this page. See the receipts page.

Explore Hive Proof Architecture.

The keys stay with you

In plain words: your organization holds the pen that signs. Hive never touches your proprietary account or location data, never decides who may transact, and never holds your keys.

You hold your own signing keys

You keep the private key that stamps your receipts. Nobody else can sign in your name, and the key never leaves your own hardware. The signature is yours, not Hive's.

Hive stays a non-custodial sidecar

Hive gives you the way to make and check receipts. It does not place a trade, set a price, decide eligibility, or run the platform, does not enter the decision loop, and does not move or store your raw account or location data. Each decision is recorded as a one-way fingerprint and cryptographic commitment, never the underlying data.

Turn an eligibility decision into a portable trust asset

As the state patchwork deepens and orders carry deadlines and fines, a court, outside counsel, or a state will ask whether the ordered control ran for a specific session. A signed, independently checkable receipt at each eligibility decision is how that answer stays provable. Naming Polymarket does not imply any agreement, and this page does not state or imply that Polymarket is a customer, partner, pilot, or endorser, or that Polymarket uses Hive.

Legal & enforcement Outside counsel & discovery Compliance & surveillance Engineering & platform

One line to start: [email protected]

illustrative and non-endorsement notice

This page is illustrative only. It is prepared privately by Hive Civilization Inc. and is not affiliated with, sponsored by, or endorsed by Polymarket, Inc. or QCX LLC d/b/a Polymarket US. It does not state or imply that Polymarket is a customer, partner, pilot, or endorser, or that Polymarket uses Hive.

Every session, account, jurisdiction rule, timestamp, and receipt shown in the demos is synthetic and made to illustrate how the service works. None of it is real Polymarket, user, account, or location data.

A signed receipt proves that a check ran and what it returned. It does not decide legality, does not guarantee compliance, does not resolve federal preemption, and does not adjudicate any court matter. Court and current facts on this page are cited to primary filings or named reporting and carry their exact status, which is preliminary, pending, interim, or final as labelled. They should be re-verified before any external use given the pace of docket activity.

Private, illustrative overview · noindex / nofollow / noarchive / nosnippet · not affiliated with Polymarket, Inc. or QCX LLC d/b/a Polymarket US; this page does not state or imply that Polymarket is a customer, partner, pilot, or endorser, and does not imply Polymarket uses Hive · the sessions, accounts, jurisdictions, rules, and receipts shown are synthetic and made to illustrate how the service works; they are not Polymarket or user data · Hive is a sidecar; it does not place a trade, set a price, decide eligibility, or run the platform, does not enter the decision loop, and does not move or store raw account or location data · a signed record that a check ran is not a statement of legality, and does not guarantee compliance · Hive never reads the underlying data; each decision is recorded as a one-way SHA-256 fingerprint and cryptographic commitment, not the raw signal · Carnac™ sizes how much proof a decision deserves. It does not judge. · verification is free, works offline, and needs no account · signatures use a hybrid of Ed25519 and ML-DSA-65 (NIST FIPS 204), a federal standard · public reference material used in preparing this overview, to be re-verified before external use: CFTC designation of QCX LLC d/b/a Polymarket US (CFTC official filing); Polymarket acquisition of QCEX (PR Newswire, July 21, 2025); Polymarket Market Integrity Rules and Kumar statements (Business Wire, Bloomberg) · Carnac™, CarnacPrompt™, Carnac Gateway™, and Carnac Live Ink™ are Hive marks · all Hive methods patent pending · prepared by Hive Civilization Inc. · Wyoming, USA
new in the canon · runnable on this page

Keep wallet screens tied to their rules

This receipt brings a checkable record of wallet and jurisdiction screening to the onchain market controls outlined on this page. It runs in production today. The example below is verified live against it.

screening.attestation · Deployed in production

Preserve one wallet and jurisdiction screening result

A market access review can bind a protected wallet reference to the precise jurisdiction list and supplemental restrictions used for that review. This receipt names the screening engine and records its pinned rule version, each list version, their fingerprints, the time reference, and the declared outcome. The wallet itself does not appear in the evidence, which helps the record travel to compliance or counsel without opening account details. A matched result remains connected to the same materials that produced it. That gives an onchain market team a focused way to examine one access screen after the fact.

What it does not do. It does not confirm that a list publisher was right, that the selected lists or thresholds were sufficient, or that the wallet owner was truly located in the reported jurisdiction. It does not disclose a wallet, prove an actual restriction, detect all misses, admit or reject access, settle a trade, or decide whether a rule was followed.

POST /verify/screening-attestation · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/screening-attestation · case matched, a name matched the list

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/screening-attestation · case fail2, a second forged record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.