Private working demonstration prepared for Robinhood
Several open matters turn less on what the law should be than on a narrower question: for one customer, one contract, at one moment, what was actually checked, which rule version applied, and what each party acknowledged. This page walks one familiar request end to end and shows exactly which of those facts an independently checkable record could carry, and which it could not settle.
Robinhood keeps control of accounts, identity checks, eligibility, money movement, pricing, orders, and settlement. None of that changes and none of it moves to Hive.
Hive only records selected facts and acknowledgments as they occur. Hive does not decide, hold funds, move money, route orders, or execute anything.
A receipt is a signed record of what the system was told, what it checked, what it decided, and when. Nothing more. It does not contain identity documents, account numbers, or balances. It can be checked by someone who does not trust, and does not have access to, the system that produced it.
Each row below is a matter Robinhood has itself disclosed or filed, described without characterization, with its source linked. The middle column is the narrow factual question a court or regulator may need answered. The right column is what a chained record could carry, and directly beneath it, what such a record cannot decide. Nothing here is a prediction about any outcome.
Robinhood Derivatives has brought affirmative suits against Nevada, New Jersey, Massachusetts, Michigan, and Washington enforcement. A Nevada preliminary injunction was denied and Robinhood ceased new Nevada sports event contracts on December 1, 2025. Ninth Circuit argument was held April 16, 2026. The Massachusetts case was dismissed as unripe and is on appeal to the First Circuit. Wisconsin filed a state action on April 23, 2026 against three Robinhood entities. The Ho-Chunk Nation sued Kalshi and Robinhood in August 2025; on May 11, 2026 the court denied dismissal in part, allowing compact based claims and dismissing RICO claims, as reported by trade press and postdating the 10-Q. Event contract consumer class actions were filed April 22, 2026 in Massachusetts state court and the Northern District of California. Separately, the CFTC sued New York on April 24, 2026, following similar suits against Arizona, Connecticut, and Illinois, and sued Wisconsin on April 28, 2026.
Sources: Robinhood 10-Q legal note, GeekWire on the Washington suit, Wisconsin Law Journal, CFTC release 9218-26, CFTC release 9220-26.
For this customer and this contract at this moment: which state or location signal was used, which contract category applied, which rule version was in force, which restriction applied, what disclosure was shown, what authorization existed, and what the order result was.
Each of those facts as they stood at order time, in sequence, signed, and checkable by someone with no access to Robinhood systems. It would also make a missing receipt visible, which is often the harder thing to demonstrate.
Robinhood has disclosed a New York Attorney General investigation into brokerage execution, and states that it is cooperating.
Sources: Robinhood 10-Q legal note, Compliance Week.
What instruction was authorized, what order was submitted, which collar or routing rule version applied at that moment, what the venue acknowledged, what was filled or refused, and what price and time facts came back.
The whole chain from instruction to acknowledgment, each link signed and ordered, so the sequence can be reconstructed without relying on the party being questioned.
Robinhood has disclosed an ongoing Massachusetts Securities Division examination covering customer complaint supervision, the August 4 to 5, 2024 overnight disruptions, and presidential election and sports event contracts, and a separate ongoing FINRA Enforcement and Examinations investigation into the same August 2024 disruptions. Robinhood has stated the failure originated at a third party venue supporting its 24 Hour Market.
Sources: Robinhood 10-Q legal note, CNBC.
What each customer attempted, what Robinhood accepted or refused, what the third party venue acknowledged, where the sequence stopped, what message the customer was shown, and when each of those happened.
An acknowledgment gap made explicit: the last step that was acknowledged, the step that never was, and the clock on each. That converts a reconstruction exercise into a reading exercise.
Robinhood has disclosed an ongoing FDIC investigation into Electronic Fund Transfer Act compliance.
Source: Robinhood 10-Q legal note.
What the customer authorized, when the transfer was initiated, what the sending side acknowledged, what the receiving side acknowledged, whether it was pending or failed, what fees applied, and the timing of any provisional credit or dispute step.
Two sided acknowledgments with independent clocks, so a one sided claim that money moved is visible as one sided rather than assumed to be complete. This is the third preset in the demonstration below.
The consolidated Dey and Deeney cash sweep matter in the Northern District of California had a motion to dismiss granted in part and is in discovery.
Sources: Robinhood 10-Q legal note, ClassAction.org summary.
Which disclosure version was shown, what the customer elected or consented to, what the program, rate, and fee state were at the time, what transfer instructions were issued, what the receiving bank acknowledged, and what the balance state was.
The sequence and the versions: which disclosure text was in force, what the customer confirmed, and what each institution acknowledged, in order.
A 2025 FINRA letter of acceptance, waiver and consent covering earlier periods included findings on order handling disclosure accuracy, account takeover detection, clearing supervision under load, and reporting integrity, specifically more than 17,200 inaccurate or incomplete blue sheets affecting more than 216.4 million transactions, together with CAT, TRF, and large options position reporting failures, some persisting until April 2024. Two Robinhood broker dealers separately resolved SEC recordkeeping and related charges in January 2025. Under the FINRA matter Robinhood agreed to an undertaking that senior management certify remediation in writing within 180 days, and represented in its Corrective Action Statement that it had addressed the blue sheet, TRF, large options position, and CAT reporting issues going forward. FINRA states that a Corrective Action Statement is not a factual or legal finding by FINRA.
Sources: FINRA AWC, FINRA release, SEC press release 2025-5.
For a selected event, can the exact control state and report state be reconstructed later: which version of which control ran, on which record, and what it produced.
Going forward, a per event record of which control version ran and what it returned, so reconstruction is a lookup rather than a rebuild. Reporting integrity at very large transaction counts is precisely where after the fact reconstruction gets expensive.
This row is not a dispute. Robinhood opened its platform to third party AI agents in May 2026. Announcing it, Robinhood stated that "Robinhood does not control, supervise, monitor, recommend, or audit these AI agents," and that, as a fraud detection measure, "Robinhood's support team can review exactly what you asked the agent to do, see what it actually did, and help you quickly resolve any disputes." Separately, in the Robinhood Gold Card disclosure block accompanying its July 2026 announcement, Robinhood states that transactions initiated by the AI assistant in accordance with the customer's active settings and authorizations "will be considered authorized by you." Agentic Trading launched in beta for equities, with options, crypto, event contracts, and futures described by Robinhood as coming soon and therefore not confirmed live.
Sources: Robinhood is now open to agents, Agentic Trading overview, July 2026 newsroom disclosures.
If a customer later contests an agent initiated action: who or what was authorized, under which limits and which disclosure version, what the customer asked, what was submitted, and what arrived.
The authority grant and the instruction to action linkage, held in a form that a reviewer with no access to Robinhood systems and no access to the agent provider can still read. That is exactly the comparison Robinhood already promises to perform, made portable.
An independently checkable record would not have prevented any of these disputes. In several of them, it could have narrowed the part of the argument that is only about what actually happened.
A customer types: "I want to place $25 on Spain to win." This demonstration treats that sentence as a request to place an order for a prediction market contract. It is not a legal conclusion about betting, and it is not a statement about what any product is or is not.
The first row of the map above turns on a narrow factual question: for this customer and this contract, which state signal, category, and rule version applied, and what was the result. Run the journey below and every stage will name, in plain English, what Robinhood could later produce to a court or regulator. If a gate refuses, you will see the signed reason and no downstream order receipt. If every gate passes, you will see the complete chain through submission, venue acknowledgment, execution, settlement, and both ends of the payout.
| Stage | What was checked or acknowledged | Result | Time (UTC) | Receipt |
|---|
This re-reads every receipt the journey produced and reports, in plain English, whether the record holds together: whether each receipt is valid, whether the chain is complete, whether both sides of each money movement acknowledged it, and exactly where the journey stopped.
Everything below works without this page, without Hive, and without a network connection. That is the point: a record is only useful as evidence if someone who distrusts the producer can still check it.
Download the journey as a single evidence bundle, or download the offline checker, a single HTML file that opens from your desktop with no network and re-runs every check on its own.
Paste a single receipt or a whole evidence bundle, or upload the file. The same checks run here as run in the offline checker, using the public key carried inside the record itself.
Each receipt is a small structured record. Before it is signed, it is serialized deterministically using an RFC 8785 style canonical form, so that two identical records always produce identical bytes and any independent implementation can reproduce the hash. Hive Canonical bytes are hashed with SHA-256, and that digest is signed twice: once with Ed25519, and once with ML-DSA-65, the post quantum lattice signature standardised as FIPS 204. Each receipt carries the hash of the receipt before it, so a removed or reordered step breaks the link.
The signing key on this page is generated in your browser when the page loads and is destroyed when you close the tab. No private key is shipped in these files, and no independent production issuance is claimed. In production, key custody would move to a hardware root of trust and the signer would have a resolvable, certified identity.
These names and their dependency order are Hive internal proof architecture. They are not an industry standard and not a Robinhood design. They are listed here only so a technical reader can map the plain English stages above onto the internal pieces.
Here is how Robinhood could use Hive receipts to prove which state rule applied to a given account and that surveillance ran on a given session. Those receipts would prove what the decision was. The seven upstream primitives below could prove the environment, the policy state, and the constraint state that produced the decision before it ever commits. Every name below is real, has a live public route, and is not a Robinhood commitment or a deployed integration.
Was the eligibility-decision model itself running on an unaltered machine at the moment it decided?
Provenance-Bonded SandboxProves the model that produced a state-eligibility decision was running in a sandbox whose kernel, packages, and firmware were on the signed heartbeat chain when it decided.
Were the compliance thresholds that blocked a trade the same ones on file, at that exact moment?
Refusal LedgerProves Robinhood's own compliance-refusal thresholds were inside the disclosed envelope at the instant the state-eligibility rejection fired.
If a routing model starts reasoning toward manipulation-adjacent behavior, is that moment sealed?
HowlerProduces a signed freeze receipt the instant a Reg BI probe detects manipulation-adjacent reasoning inside an execution-routing model.
Is the code that blocks customer data from leaving actually the code that was filed with the regulator?
Perimeter BondBinds the DLP bytecode that blocks outbound customer PII to model providers to a hash that is byte-identical to the version on file with FINRA.
Who has to sign off before an autonomous system rebalances accounts over a weekend?
Diurnal BondRequires k-of-n countersign from operations, compliance, and a geographically distinct attestor before weekend or after-hours autonomous rebalancing runs.
Can an SSN and a public ticker symbol leave the trading systems under the same cap?
Egress BondMeters the cap on PII bytes leaving trading systems by semantic class, so an SSN and a public ticker are classified and capped separately.
After a market disruption, can a regulator independently rerun the incident response and get the same answer?
Forensic RailRuns post-disruption incident response under a threshold-signed consortium credential that a regulator or exchange can deterministically replay.
Filed. July 26, 2026. USPTO application 64/119,279. See upstream group in Hive Proof Architecture → · Read the essay →
The walkthrough above exercises one matter cluster. This is the crosswalk for all seven, naming the specific Hive primitive that answers each evidence question and linking to its canonical page. Every name below is a real Hive primitive with a live canonical route. Nothing here is a Robinhood commitment, a Robinhood design, or a deployed integration.
Can you prove which state rule was in force at the moment a specific contract was offered to a specific account, without relying on a reconstructed log?
ImprimaturSigned pre-clearance. Proves the eligibility policy fired before the contract was offered, rather than being reconstructed afterwards.
Carnac Live InkCaptures the eligibility decision as it happens, at the moment of the offer.
InkFrame v1The non-mutating substrate underneath. Change one byte and the content address changes, which breaks the signature.
Hive Settlement FeedIndependently signed settlement values as the payout basis, so the "who set the number" question has a signed answer.
Can you show that a pre-trade control was enforced on a given order, and rank which orders carry the weakest evidence?
HiveBoundInput-side pre-commitment. Identity, intent, and limit are signed before the order is routed, so the control is provable at the door.
SiGRSigned Inference Guarantee Receipt. Turns "trust our routing logs" into a signed exhibit that stands up in a dispute.
R3PvOne signed score per event flags the thinnest evidentiary boundary, so a risk team can triage instead of investigating every order.
When a customer disputes what support told them during an outage, can you produce what was actually said, including on a live call?
AFiRSigns only the fragments of an answer that matter, so audit cost stays flat across a high volume complaint queue.
AFiR-StreamMakes a voice call or streamed answer receiptable segment by segment, so consent, disclosure, and wording survive a dispute.
Hive LedgerSearchable receipt index, so a supervision team can pull every receipt touching one account and one window.
Can you prove which disclosure document a specific customer was shown, and defend each extracted figure back to its exact place on the page?
AFiR-OCR DocProofSigns the extracted value, the page region it came from, and the confidence, so an extraction error is traceable rather than deniable.
Carnac Live InkRecords the disclosure presentation itself at the moment it is shown.
For a given balance on a given day, which program terms and which participating bank were in force, and can that be shown without trusting an internal spreadsheet?
ImprimaturPins the program terms version that was in force before the sweep ran.
CarnacSigns the resulting allocation record so the terms and the outcome are bound together.
Hive LedgerIndexes those records so a per account, per day question is a query rather than a reconstruction project.
Can a regulatory record be produced on demand as a signed, schema-bound export instead of a quarter long evidence hunt?
Hive Typed SignerOne FIPS 204 sign and verify interface for regulatory records, so reporting is signed at the point of production.
Hive Customer ConsoleSelf-serve export of receipts, keys, and evidence bundles as an audit ready pack.
If an agent places an order, can you prove which agent instance acted, under which model version, through an identity the venue can check?
Agent Trip and SPIRESPIRE attested instance identity plus trajectory receipts, so a rogue or spoofed agent cannot act unattributed.
MiRPins each output to the exact model version and eval, so a bad output cannot be blamed on an unidentified model.
HiveGateOne portable signed agent identity at the gateway, so the counterparty can check the agent before it transacts.
These are not matter specific. They are what makes every receipt above verifiable, and they are the two pieces this demonstration deliberately does not run in production form.
Hive Typed SignerThe ML-DSA-65 engine. This page really does use it. Every receipt on this page is signed with hybrid Ed25519 plus ML-DSA-65 and verified in your browser.
HiveSeal, QPuFHardware root of trust. This page does not use it. The signing key here is generated in your browser and destroyed on reload. In production the key would be born in silicon and never leave the device.
These are real Hive primitives, but stretching them to fit a brokerage evidence question would be an overclaim, so they are listed by name only and not mapped to a matter above. They are reachable through the proof architecture index rather than pitched here.
This is a concept demonstration built to make one idea concrete. It is not a Robinhood system, it does not connect to any Robinhood account or data, and it is not legal advice.
The state and category rules used here were written for this page and are labelled illustrative demo policy. They are not Robinhood's actual policy and they are not a statement of law.
The signing key is ephemeral. It is generated in your browser when the page loads and discarded on reload. A signature from it shows a record has not changed. It does not establish who signed it in any externally attributable sense, and no production key is present anywhere on this page.
A receipt captures the inputs it was given. It does not confirm those inputs were true, and it does not confirm that money physically moved.
Receipts link to each other within one browser session. This is not a shared ledger and it detects nothing across sessions or between parties.
Every acknowledgment shown here is described as coming from the party that made it. Hive records acknowledgments. It does not move funds, route orders, price anything, or execute.
No regulator has reviewed or approved this concept. Nothing here is a compliance, regulatory, or legal conclusion, and Robinhood is not represented as a Hive customer, partner, or pilot.
These newer receipts add checkable boundaries around a delegated action and the shared exposure it may create. They answer in production right now, and the runs below prove it end to end.
Before an agent action is carried out, this receipt compares its amount, currency, timing, and scope with one delegated mandate that was signed beforehand. It recalculates the result instead of accepting a claimed result from the caller. For brokerage, money movement, or trading workflows, it gives compliance, legal, and risk a record of the limits applied to that one action. It leaves control of accounts, orders, funds, and execution with the systems that already hold it.
What it does not do. It does not show that a customer granted the mandate, that the named agent is genuine, that a broker, payment network, or market authorized, settled, or delivered anything, or that any displayed terms were read, and it carries no customer or cardholder credential. It is not payment authorization, and no payment network, issuer, or regulator currently recognizes it as authentication data, compelling evidence, or a liability shift; it does not resolve a dispute, change consumer rights, assess total spend, transaction pace, or any aggregate limit across the mandate, or confirm that the mandate was unrevoked.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
This receipt recalculates concentration counts and share ratios for one book at a stated time from opaque fingerprints. It will not report a group smaller than five members. That lets risk and compliance inspect a shared exposure while keeping member identities, dependency names, and policy terms out of the service. In a retail investing or agentic trading program, it gives the team a bounded concentration signal without opening individual records.
What it does not do. It does not establish that the fingerprints are correct, honestly computed, complete, or that any member is insured, and it cannot detect a missing, repeated, or wrongly committed member. It does not measure, price, or judge risk, serve as actuarial, capital, or reinsurance analysis, or show that a reported concentration will cause a correlated loss.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.