Hive Private working demonstration prepared for Robinhood

What Robinhood must prove when its conduct is challenged.

Several open matters turn less on what the law should be than on a narrower question: for one customer, one contract, at one moment, what was actually checked, which rule version applied, and what each party acknowledged. This page walks one familiar request end to end and shows exactly which of those facts an independently checkable record could carry, and which it could not settle.

Step one
Customer asks
A customer types a plain sentence describing what they want to do.
Step two
Robinhood checks and acts
Robinhood runs its own checks, moves its own money, and places its own orders.
Step three
Banks and market acknowledge
Outside parties confirm what they sent, received, filled, or settled.
Step four
Hive preserves the record
Each consequential step leaves a signed record that anyone can check later, on its own.
What Robinhood keeps

Robinhood keeps control of accounts, identity checks, eligibility, money movement, pricing, orders, and settlement. None of that changes and none of it moves to Hive.

What Hive does

Hive only records selected facts and acknowledgments as they occur. Hive does not decide, hold funds, move money, route orders, or execute anything.

First, what a receipt is

A receipt is a signed record of what the system was told, what it checked, what it decided, and when. Nothing more. It does not contain identity documents, account numbers, or balances. It can be checked by someone who does not trust, and does not have access to, the system that produced it.

Current matters, stated neutrally

From a dispute to the factual question underneath it

Each row below is a matter Robinhood has itself disclosed or filed, described without characterization, with its source linked. The middle column is the narrow factual question a court or regulator may need answered. The right column is what a chained record could carry, and directly beneath it, what such a record cannot decide. Nothing here is a prediction about any outcome.

A. Current dispute or exposure
B. Factual question underneath it
C. What a chained record could show, and what it cannot decide

Prediction markets and state gambling enforcement

Robinhood Derivatives has brought affirmative suits against Nevada, New Jersey, Massachusetts, Michigan, and Washington enforcement. A Nevada preliminary injunction was denied and Robinhood ceased new Nevada sports event contracts on December 1, 2025. Ninth Circuit argument was held April 16, 2026. The Massachusetts case was dismissed as unripe and is on appeal to the First Circuit. Wisconsin filed a state action on April 23, 2026 against three Robinhood entities. The Ho-Chunk Nation sued Kalshi and Robinhood in August 2025; on May 11, 2026 the court denied dismissal in part, allowing compact based claims and dismissing RICO claims, as reported by trade press and postdating the 10-Q. Event contract consumer class actions were filed April 22, 2026 in Massachusetts state court and the Northern District of California. Separately, the CFTC sued New York on April 24, 2026, following similar suits against Arizona, Connecticut, and Illinois, and sued Wisconsin on April 28, 2026.

Sources: Robinhood 10-Q legal note, GeekWire on the Washington suit, Wisconsin Law Journal, CFTC release 9218-26, CFTC release 9220-26.

For this customer and this contract at this moment: which state or location signal was used, which contract category applied, which rule version was in force, which restriction applied, what disclosure was shown, what authorization existed, and what the order result was.

Each of those facts as they stood at order time, in sequence, signed, and checkable by someone with no access to Robinhood systems. It would also make a missing receipt visible, which is often the harder thing to demonstrate.

A record cannot decideWhether an instrument is lawful, whether federal law preempts a state, whether something is gaming, what tribal compact rights require, or make any contract lawful. It carries facts. It does not resolve the legal question.

Execution quality and order collaring

Robinhood has disclosed a New York Attorney General investigation into brokerage execution, and states that it is cooperating.

Sources: Robinhood 10-Q legal note, Compliance Week.

What instruction was authorized, what order was submitted, which collar or routing rule version applied at that moment, what the venue acknowledged, what was filled or refused, and what price and time facts came back.

The whole chain from instruction to acknowledgment, each link signed and ordered, so the sequence can be reconstructed without relying on the party being questioned.

A record cannot decideWhether execution was best execution. That is a legal and analytical standard applied to market data, not a fact a receipt carries. A record also does not route, price, or improve any order.

Overnight disruptions and complaint supervision

Robinhood has disclosed an ongoing Massachusetts Securities Division examination covering customer complaint supervision, the August 4 to 5, 2024 overnight disruptions, and presidential election and sports event contracts, and a separate ongoing FINRA Enforcement and Examinations investigation into the same August 2024 disruptions. Robinhood has stated the failure originated at a third party venue supporting its 24 Hour Market.

Sources: Robinhood 10-Q legal note, CNBC.

What each customer attempted, what Robinhood accepted or refused, what the third party venue acknowledged, where the sequence stopped, what message the customer was shown, and when each of those happened.

An acknowledgment gap made explicit: the last step that was acknowledged, the step that never was, and the clock on each. That converts a reconstruction exercise into a reading exercise.

A record cannot decideIt cannot prevent an outage, restore service, or establish whether supervision was reasonable. Robinhood already publishes a control and monitoring program; this is additive, not a substitute.

Electronic Fund Transfer Act compliance

Robinhood has disclosed an ongoing FDIC investigation into Electronic Fund Transfer Act compliance.

Source: Robinhood 10-Q legal note.

What the customer authorized, when the transfer was initiated, what the sending side acknowledged, what the receiving side acknowledged, whether it was pending or failed, what fees applied, and the timing of any provisional credit or dispute step.

Two sided acknowledgments with independent clocks, so a one sided claim that money moved is visible as one sided rather than assumed to be complete. This is the third preset in the demonstration below.

A record cannot decideIt does not move money, resolve liability, establish that a statutory timing requirement was met, or substitute for the dispute process itself.

Cash sweep program and product mechanics

The consolidated Dey and Deeney cash sweep matter in the Northern District of California had a motion to dismiss granted in part and is in discovery.

Sources: Robinhood 10-Q legal note, ClassAction.org summary.

Which disclosure version was shown, what the customer elected or consented to, what the program, rate, and fee state were at the time, what transfer instructions were issued, what the receiving bank acknowledged, and what the balance state was.

The sequence and the versions: which disclosure text was in force, what the customer confirmed, and what each institution acknowledged, in order.

A record cannot decideWhether a disclosure was adequate, whether a product was fair, or whether any best interest or fiduciary standard was met. Those are assessments of the content, not of the sequence.

Historical reporting and recordkeeping findings, as context

A 2025 FINRA letter of acceptance, waiver and consent covering earlier periods included findings on order handling disclosure accuracy, account takeover detection, clearing supervision under load, and reporting integrity, specifically more than 17,200 inaccurate or incomplete blue sheets affecting more than 216.4 million transactions, together with CAT, TRF, and large options position reporting failures, some persisting until April 2024. Two Robinhood broker dealers separately resolved SEC recordkeeping and related charges in January 2025. Under the FINRA matter Robinhood agreed to an undertaking that senior management certify remediation in writing within 180 days, and represented in its Corrective Action Statement that it had addressed the blue sheet, TRF, large options position, and CAT reporting issues going forward. FINRA states that a Corrective Action Statement is not a factual or legal finding by FINRA.

Sources: FINRA AWC, FINRA release, SEC press release 2025-5.

For a selected event, can the exact control state and report state be reconstructed later: which version of which control ran, on which record, and what it produced.

Going forward, a per event record of which control version ran and what it returned, so reconstruction is a lookup rather than a rebuild. Reporting integrity at very large transaction counts is precisely where after the fact reconstruction gets expensive.

A record cannot decideIt cannot fix a past record, and it should not be read as a claim that it would have prevented these findings, because it would not necessarily have prevented them. Remediation here is the subject of an agreed certification undertaking under the FINRA matter. This row is context for the reconstruction cost, not a criticism.

Agentic trading, a forward looking evidence questionNo matter filed

This row is not a dispute. Robinhood opened its platform to third party AI agents in May 2026. Announcing it, Robinhood stated that "Robinhood does not control, supervise, monitor, recommend, or audit these AI agents," and that, as a fraud detection measure, "Robinhood's support team can review exactly what you asked the agent to do, see what it actually did, and help you quickly resolve any disputes." Separately, in the Robinhood Gold Card disclosure block accompanying its July 2026 announcement, Robinhood states that transactions initiated by the AI assistant in accordance with the customer's active settings and authorizations "will be considered authorized by you." Agentic Trading launched in beta for equities, with options, crypto, event contracts, and futures described by Robinhood as coming soon and therefore not confirmed live.

Sources: Robinhood is now open to agents, Agentic Trading overview, July 2026 newsroom disclosures.

If a customer later contests an agent initiated action: who or what was authorized, under which limits and which disclosure version, what the customer asked, what was submitted, and what arrived.

The authority grant and the instruction to action linkage, held in a form that a reviewer with no access to Robinhood systems and no access to the agent provider can still read. That is exactly the comparison Robinhood already promises to perform, made portable.

A record cannot decideIt does not supervise, audit, certify, or vouch for any third party agent or model, and it does not block or approve anything an agent does. Robinhood already publishes per trade notifications, an activity feed, limits, approvals, and a disconnect control.
The honest scope of the claim

What an independent record changes, and what it does not

An independently checkable record would not have prevented any of these disputes. In several of them, it could have narrowed the part of the argument that is only about what actually happened.

That is a deliberately small claim. The list on the left is the whole of it. The list on the right is everything a record leaves exactly where it was.

Could have helped avoid

  • Evidence that has to be rebuilt or cannot be found. A record that exists at the moment of the action does not need to be reassembled from systems afterward.
  • Ambiguity about which control version actually ran. The rule identifier and version travel inside the record, so there is no later argument about which one was in force.
  • One sided claims that money moved. Where only the sending party acknowledged, the record shows one acknowledgment and one gap, rather than an assumption of arrival.
  • Inability to demonstrate that a restriction applied to a specific customer in a specific state. The state signal, category, rule version, and result sit together in one signed record per order.
  • Expensive after the fact reconstruction. Answering a narrow factual question becomes a lookup against records rather than a project against logs.

Could not have avoided

  • Disagreement about what the law is. Whether an event contract is lawful is not a fact a record carries.
  • Federal preemption questions. Whether federal law displaces a state's enforcement is decided by courts, not by evidence quality.
  • Legal standards such as best execution or disclosure sufficiency. These are assessments of content and analysis, not of sequence.
  • Outages themselves. A record can show where a sequence stopped. It cannot keep a venue running.
  • Conduct that was wrong. If a control was misconfigured or a decision was wrong, a faithful record of it does not make it right. It records it accurately.
The demonstration, run against matter cluster one

One request, run end to end through the state event contract question

A customer types: "I want to place $25 on Spain to win." This demonstration treats that sentence as a request to place an order for a prediction market contract. It is not a legal conclusion about betting, and it is not a statement about what any product is or is not.

The first row of the map above turns on a narrow factual question: for this customer and this contract, which state signal, category, and rule version applied, and what was the result. Run the journey below and every stage will name, in plain English, what Robinhood could later produce to a court or regulator. If a gate refuses, you will see the signed reason and no downstream order receipt. If every gate passes, you will see the complete chain through submission, venue acknowledgment, execution, settlement, and both ends of the payout.

Demonstration signing key ready
Change the facts of the journey
Receipt rail No journey run yet
Each consequential step adds one receipt here, linked to the one before it.
    Journey record
    StageWhat was checked or acknowledgedResultTime (UTC)Receipt
    Run the journey to fill in this record. It is written to be read without any technical background: one row per stage, with what was checked, what happened, when, and which receipt holds it.
    Checking the record

    Verify the journey

    This re-reads every receipt the journey produced and reports, in plain English, whether the record holds together: whether each receipt is valid, whether the chain is complete, whether both sides of each money movement acknowledged it, and exactly where the journey stopped.

    What this shows
    • Which facts and which rule version produced each result, in the order they happened.
    • That each record was signed and has not been changed since.
    • That each record links to the one before it, so a missing or reordered step shows up.
    • Where both sides of a money movement acknowledged it, and where only one side did.
    • That anyone can re-check all of it later with only the records and the public key.
    What this does not show
    • That the demo policy is correct, lawful, or the same as Robinhood's actual policy.
    • That the underlying facts are true. A record captures the inputs it was given.
    • Any real world identity. The signer is a temporary demonstration key, not a production issuer.
    • That money actually moved. Only that a party acknowledged sending or receiving it.
    • Any compliance, regulatory, or legal conclusion.
    Do not take our word for it

    Independent verification

    Everything below works without this page, without Hive, and without a network connection. That is the point: a record is only useful as evidence if someone who distrusts the producer can still check it.

    Take the records with you

    Download the journey as a single evidence bundle, or download the offline checker, a single HTML file that opens from your desktop with no network and re-runs every check on its own.

    Check a record you were handed

    Paste a single receipt or a whole evidence bundle, or upload the file. The same checks run here as run in the offline checker, using the public key carried inside the record itself.

    How Hive does it, for the technically inclined

    Each receipt is a small structured record. Before it is signed, it is serialized deterministically using an RFC 8785 style canonical form, so that two identical records always produce identical bytes and any independent implementation can reproduce the hash. Hive Canonical bytes are hashed with SHA-256, and that digest is signed twice: once with Ed25519, and once with ML-DSA-65, the post quantum lattice signature standardised as FIPS 204. Each receipt carries the hash of the receipt before it, so a removed or reordered step breaks the link.

    The signing key on this page is generated in your browser when the page loads and is destroyed when you close the tab. No private key is shipped in these files, and no independent production issuance is claimed. In production, key custody would move to a hardware root of trust and the signer would have a resolvable, certified identity.

    The Hive primitives, in the order they run

    These names and their dependency order are Hive internal proof architecture. They are not an industry standard and not a Robinhood design. They are listed here only so a technical reader can map the plain English stages above onto the internal pieces.

    1Carnac Live Ink 2Imprimatur 3InkFrame v1 4Carnac 5HiveGate 6R3Pv 7Hive Settlement Feed 8MiR where used 9Hive Ledger
    Just filed · USPTO 64/119,279 · Jul 26, 2026

    Seven upstream receipts, before the eligibility decision commits

    Here is how Robinhood could use Hive receipts to prove which state rule applied to a given account and that surveillance ran on a given session. Those receipts would prove what the decision was. The seven upstream primitives below could prove the environment, the policy state, and the constraint state that produced the decision before it ever commits. Every name below is real, has a live public route, and is not a Robinhood commitment or a deployed integration.

    Upstream 01
    PBS™ · Provenance-Bonded Sandbox

    Was the eligibility-decision model itself running on an unaltered machine at the moment it decided?

    Provenance-Bonded Sandbox

    Proves the model that produced a state-eligibility decision was running in a sandbox whose kernel, packages, and firmware were on the signed heartbeat chain when it decided.

    Upstream 02
    Refusal Ledger™

    Were the compliance thresholds that blocked a trade the same ones on file, at that exact moment?

    Refusal Ledger

    Proves Robinhood's own compliance-refusal thresholds were inside the disclosed envelope at the instant the state-eligibility rejection fired.

    Upstream 03
    Howler™ (SAE-triggered)

    If a routing model starts reasoning toward manipulation-adjacent behavior, is that moment sealed?

    Howler

    Produces a signed freeze receipt the instant a Reg BI probe detects manipulation-adjacent reasoning inside an execution-routing model.

    Upstream 04
    Perimeter Bond™

    Is the code that blocks customer data from leaving actually the code that was filed with the regulator?

    Perimeter Bond

    Binds the DLP bytecode that blocks outbound customer PII to model providers to a hash that is byte-identical to the version on file with FINRA.

    Upstream 05
    Diurnal Bond™

    Who has to sign off before an autonomous system rebalances accounts over a weekend?

    Diurnal Bond

    Requires k-of-n countersign from operations, compliance, and a geographically distinct attestor before weekend or after-hours autonomous rebalancing runs.

    Upstream 06
    Egress Bond™

    Can an SSN and a public ticker symbol leave the trading systems under the same cap?

    Egress Bond

    Meters the cap on PII bytes leaving trading systems by semantic class, so an SSN and a public ticker are classified and capped separately.

    Upstream 07
    Forensic Rail™

    After a market disruption, can a regulator independently rerun the incident response and get the same answer?

    Forensic Rail

    Runs post-disruption incident response under a threshold-signed consortium credential that a regulator or exchange can deterministically replay.

    Filed. July 26, 2026. USPTO application 64/119,279. See upstream group in Hive Proof Architecture → · Read the essay →

    Matter by matter, primitive by primitive

    Where Robinhood can use Hive Proof Architecture

    The walkthrough above exercises one matter cluster. This is the crosswalk for all seven, naming the specific Hive primitive that answers each evidence question and linking to its canonical page. Every name below is a real Hive primitive with a live canonical route. Nothing here is a Robinhood commitment, a Robinhood design, or a deployed integration.

    Cluster 01
    Prediction markets and state gambling enforcement

    Can you prove which state rule was in force at the moment a specific contract was offered to a specific account, without relying on a reconstructed log?

    Imprimatur

    Signed pre-clearance. Proves the eligibility policy fired before the contract was offered, rather than being reconstructed afterwards.

    Carnac Live Ink

    Captures the eligibility decision as it happens, at the moment of the offer.

    InkFrame v1

    The non-mutating substrate underneath. Change one byte and the content address changes, which breaks the signature.

    Hive Settlement Feed

    Independently signed settlement values as the payout basis, so the "who set the number" question has a signed answer.

    Cluster 02
    Execution quality and order collaring

    Can you show that a pre-trade control was enforced on a given order, and rank which orders carry the weakest evidence?

    HiveBound

    Input-side pre-commitment. Identity, intent, and limit are signed before the order is routed, so the control is provable at the door.

    SiGR

    Signed Inference Guarantee Receipt. Turns "trust our routing logs" into a signed exhibit that stands up in a dispute.

    R3Pv

    One signed score per event flags the thinnest evidentiary boundary, so a risk team can triage instead of investigating every order.

    Cluster 03
    Overnight disruptions and complaint supervision

    When a customer disputes what support told them during an outage, can you produce what was actually said, including on a live call?

    AFiR

    Signs only the fragments of an answer that matter, so audit cost stays flat across a high volume complaint queue.

    AFiR-Stream

    Makes a voice call or streamed answer receiptable segment by segment, so consent, disclosure, and wording survive a dispute.

    Hive Ledger

    Searchable receipt index, so a supervision team can pull every receipt touching one account and one window.

    Cluster 04
    Electronic Fund Transfer Act compliance

    Can you prove which disclosure document a specific customer was shown, and defend each extracted figure back to its exact place on the page?

    AFiR-OCR DocProof

    Signs the extracted value, the page region it came from, and the confidence, so an extraction error is traceable rather than deniable.

    Carnac Live Ink

    Records the disclosure presentation itself at the moment it is shown.

    Cluster 05
    Cash sweep program and product mechanics

    For a given balance on a given day, which program terms and which participating bank were in force, and can that be shown without trusting an internal spreadsheet?

    Imprimatur

    Pins the program terms version that was in force before the sweep ran.

    Carnac

    Signs the resulting allocation record so the terms and the outcome are bound together.

    Hive Ledger

    Indexes those records so a per account, per day question is a query rather than a reconstruction project.

    Cluster 06
    Historical reporting and recordkeeping findings, as context

    Can a regulatory record be produced on demand as a signed, schema-bound export instead of a quarter long evidence hunt?

    Hive Typed Signer

    One FIPS 204 sign and verify interface for regulatory records, so reporting is signed at the point of production.

    Hive Customer Console

    Self-serve export of receipts, keys, and evidence bundles as an audit ready pack.

    Cluster 07
    Agentic trading, a forward looking evidence question

    If an agent places an order, can you prove which agent instance acted, under which model version, through an identity the venue can check?

    Agent Trip and SPIRE

    SPIRE attested instance identity plus trajectory receipts, so a rogue or spoofed agent cannot act unattributed.

    MiR

    Pins each output to the exact model version and eval, so a bad output cannot be blamed on an unidentified model.

    HiveGate

    One portable signed agent identity at the gateway, so the counterparty can check the agent before it transacts.

    Runs underneath all seven
    The signing layer itself

    These are not matter specific. They are what makes every receipt above verifiable, and they are the two pieces this demonstration deliberately does not run in production form.

    Hive Typed Signer

    The ML-DSA-65 engine. This page really does use it. Every receipt on this page is signed with hybrid Ed25519 plus ML-DSA-65 and verified in your browser.

    HiveSeal, QPuF

    Hardware root of trust. This page does not use it. The signing key here is generated in your browser and destroyed on reload. In production the key would be born in silicon and never leave the device.

    Named in the proof architecture, deliberately not claimed here
    Primitives with no defensible Robinhood use case in these seven matters

    These are real Hive primitives, but stretching them to fit a brokerage evidence question would be an overclaim, so they are listed by name only and not mapped to a matter above. They are reachable through the proof architecture index rather than pitched here.

    Media Origin Receipt, MoR MoRSo, Segments of Origin OriginProof Protected Flow and Protected Flow Fleets Proof Credit Structural Lateration
    Read this before drawing conclusions

    What this demonstration is, and is not

    This is a concept demonstration built to make one idea concrete. It is not a Robinhood system, it does not connect to any Robinhood account or data, and it is not legal advice.

    The policy is invented

    The state and category rules used here were written for this page and are labelled illustrative demo policy. They are not Robinhood's actual policy and they are not a statement of law.

    The signer is temporary

    The signing key is ephemeral. It is generated in your browser when the page loads and discarded on reload. A signature from it shows a record has not changed. It does not establish who signed it in any externally attributable sense, and no production key is present anywhere on this page.

    Records do not prove facts

    A receipt captures the inputs it was given. It does not confirm those inputs were true, and it does not confirm that money physically moved.

    The chain is session scoped

    Receipts link to each other within one browser session. This is not a shared ledger and it detects nothing across sessions or between parties.

    Hive never touches money or orders

    Every acknowledgment shown here is described as coming from the party that made it. Hive records acknowledgments. It does not move funds, route orders, price anything, or execute.

    No approval of any kind

    No regulator has reviewed or approved this concept. Nothing here is a compliance, regulatory, or legal conclusion, and Robinhood is not represented as a Hive customer, partner, or pilot.

    Nine panel proof map reference sheet prepared by Hive
    Nine panel reference sheet, click to open full size Download reference sheet (PNG)
    new in the canon ยท runnable on this page

    Bound agent actions and shared exposure

    These newer receipts add checkable boundaries around a delegated action and the shared exposure it may create. They answer in production right now, and the runs below prove it end to end.

    mandate.conformance · Deployed in production

    Check one agent action against its delegated mandate

    Before an agent action is carried out, this receipt compares its amount, currency, timing, and scope with one delegated mandate that was signed beforehand. It recalculates the result instead of accepting a claimed result from the caller. For brokerage, money movement, or trading workflows, it gives compliance, legal, and risk a record of the limits applied to that one action. It leaves control of accounts, orders, funds, and execution with the systems that already hold it.

    What it does not do. It does not show that a customer granted the mandate, that the named agent is genuine, that a broker, payment network, or market authorized, settled, or delivered anything, or that any displayed terms were read, and it carries no customer or cardholder credential. It is not payment authorization, and no payment network, issuer, or regulator currently recognizes it as authentication data, compelling evidence, or a liability shift; it does not resolve a dispute, change consumer rights, assess total spend, transaction pace, or any aggregate limit across the mandate, or confirm that the mandate was unrevoked.

    POST /verify/mandate-conformance · case pass, a clean record

    Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

    POST /verify/mandate-conformance · case fail, a forged record

    Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

    portfolio.exposure · Deployed in production

    Measure shared exposure without opening individual holdings

    This receipt recalculates concentration counts and share ratios for one book at a stated time from opaque fingerprints. It will not report a group smaller than five members. That lets risk and compliance inspect a shared exposure while keeping member identities, dependency names, and policy terms out of the service. In a retail investing or agentic trading program, it gives the team a bounded concentration signal without opening individual records.

    What it does not do. It does not establish that the fingerprints are correct, honestly computed, complete, or that any member is insured, and it cannot detect a missing, repeated, or wrongly committed member. It does not measure, price, or judge risk, serve as actuarial, capital, or reinsurance analysis, or show that a reported concentration will cause a correlated loss.

    POST /verify/portfolio-exposure · case pass, a clean record

    Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

    POST /verify/portfolio-exposure · case fail, a forged record

    Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

    Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.