Demo Tenant — Netskope One Agentic Broker
◈ Wave-Lattice · 16-axis entropy ribbon
◈ Live receipt ticker · last 14
- collecting first receipt…
◈ Spend & meter
◈ Evidence room
◈ Workflow · service state
- Workflow
- MCP-Agentic-Broker
- Archetype
- PQ-Identity-Receipt-Layer
- Concern
- EU AI Act Article 50, NIST IR 8547, FIPS 204 compliance
- Endpoints
- /v1/provebirth/cert/issue · /v1/provebirth/cert/verify · /v1/sign · /v1/ia/passport · /v1/zone · /v1/evidence · /v1/receipts/bundle
- Tenant DID
- did:hive:tenant:demo-netskope-001
- Model pin
- claude-3-5-sonnet@20241022
- Deployment
- netskope-agentic-broker
◈ Compliance posture · frameworks satisfied via Hive
◈ Where Hive fits · Netskope One AI Security
Netskope sees & controls
Netskope One AI Security · GA Mar 2026
- Decodes MCP traffic in real time, scores servers via Cloud Confidence Index
- Secures non-human identities across agentic workflows
- Enforces DLP and AI Guardrails on every agent call
- Maintains searchable logs through the AI Gateway
- Discovers and risk-assesses AI from the AI Command Center
Hive proves & signs
Signed inference Guarantee Receipt™ · live
- Signs the exact state the agent saw, before it acted — ML-DSA-65, 7ms
- Portable receipt anchored on Base Mainnet via USDC, offline-verifiable
- Turns a DLP or CCI decision into a cryptographic record, not just a log line
- Survives outside the tenant — proof a third party can check independently
- Reconstructs what happened in seconds, not weeks
Netskope adjudicates and logs every agent decision. None of those decisions are cryptographically signed today. Hive is the provenance substrate beneath all four Netskope One AI Security products — the only way to prove what an agent saw when it acted.
◈ Stack map · provenance under every product
Netskope One AI Security
Agentic Broker
Decodes MCP traffic, CCI risk-scoring, default-block public MCP
AI Guardrails
Policy enforcement on agent input and output
AI Gateway
Single API to Claude, ChatGPT, Gemini with searchable logs
AI Red Teaming
Adversarial testing of agentic surfaces
Hive provenance layer
SiGR™ receipt
Every decision signed ML-DSA-65 in 7ms, anchored on Base via USDC
Offline verifier
Any party checks the receipt without calling Hive
Evidence bundle
Court-ready record mapped to EU AI Act, NIST IR 8547, FIPS 204
◈ SiGR™ · Signed inference Guarantee Receipt
One signed receipt per agent decision. Verification is always free, forever — anyone can check a receipt at no cost. You pay only to sign.
| Tier | Volume / month | Price per receipt |
|---|---|---|
| Build | First 1M | Free |
| Scale | 1M – 50M | $0.0008 |
| Platform | 50M – 1B | $0.0004 |
| Hyperscale | 1B+ | $0.0002 |
Verify is always free. Pricing settles in USDC on Base Mainnet. No seat licenses, no exclusivity. A pilot can start on the Build tier at zero cost.
◈ Signed agent memory
The gap
Every memory write in an agent is an unsigned mutation of persistent state. When the agent recalls a fact later and acts on it, there is no record of where that fact came from or whether it was tampered with between write and read.
With Hive
Each memory write is signed at the moment it is committed. The recall path verifies the receipt before the fact is used, so the agent only acts on memory whose provenance can be proven — and an auditor can replay exactly what was stored, when, and by whom.
◈ Sign it yourself · live signer
Type any text and sign it against the live Hive signer. Real ML-DSA-65 (NIST FIPS 204) — no mock, no simulation.
◈ Start a pilot · three steps
Pick one agent path
Choose a single Netskope One flow — Agentic Broker MCP decisions or an AI Gateway route. We sign every decision on that one path.
Sign & anchor live
Receipts generate in 7ms and anchor on Base Mainnet. Your audit team verifies them offline, with no call back to Hive.
Show the evidence
Reconstruct an incident in seconds and hand auditors a court-ready bundle mapped to EU AI Act and FIPS 204. Then decide on rollout.
◈ Team & access
◈ API keys & webhooks
Want to run one yourself?
Issue a real cert against the production endpoint. Returns Ed25519 + ML-DSA-65 signatures, federated block hash, and three validator DIDs in roughly 160ms.
Ready to move beyond demo?
Production tenants go through KYB and IA registration. No real production data is in this demo; receipts shown are real but issued against an ungated test deployment.