{
  "title": "Security Policy Evidence and Change Log",
  "version": "2026-09-05",
  "review_date": "2026-09-05",
  "review_type": "Source and read-only hosting review; local editorial corrections",
  "production_website_baseline": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
  "publication_status": "Prepared for parent review; this asset does not claim deployment",
  "scope_pages": [
    "/security/",
    "/privacy",
    "/security/founder-risk/",
    "/security/iso-27001-self-attested/",
    "/security/soc2-self-attested/"
  ],
  "scope_limits": [
    "No production configuration, key, migration or environment changes.",
    "No live visitor data, secret values or logs retrieved.",
    "No destructive restart, restoration or founder-unavailability test.",
    "Local source correction is not production acceptance or legal approval."
  ],
  "deployments": [
    {
      "service": "Typed API",
      "service_id": "srv-d9r39fe417fc73babs1g",
      "region": "oregon",
      "country": "United States",
      "runtime": "Node",
      "source_repository": "thehiveryiq-site",
      "source_revision": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
      "deployed_revision": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
      "storage_observation": "No declared persistent disk in reviewed configuration; that does not inventory external stores.",
      "observed_date": "2026-09-05",
      "evidence_type": "Read-only Render get_service and deployed-lineage source review",
      "evidence_url": "https://dashboard.render.com/web/srv-d9r39fe417fc73babs1g",
      "limitations": "Configuration observation is not a recovery, retention, key-rotation or tenant-isolation acceptance test."
    },
    {
      "service": "Countersigner and briefing",
      "service_id": "srv-da470gf10e5c73aus5v0",
      "region": "oregon",
      "country": "United States",
      "runtime": "Python",
      "source_repository": "hive-countersigner",
      "source_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "storage_observation": "One worker; 1 GB persistent disk mounted at /var/hive. Recovery and backup restoration not tested.",
      "observed_date": "2026-09-05",
      "evidence_type": "Read-only Render get_service and deployed-lineage source review",
      "evidence_url": "https://dashboard.render.com/web/srv-da470gf10e5c73aus5v0",
      "limitations": "Configuration observation is not a recovery, retention, key-rotation or tenant-isolation acceptance test."
    },
    {
      "service": "Receipt and Carnac",
      "service_id": "srv-d7out8km0tmc73ddn71g",
      "region": "oregon",
      "country": "United States",
      "runtime": "Node",
      "source_repository": "hive-receipt",
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "storage_observation": "No declared persistent disk; source includes memory storage and conditional external persistence.",
      "observed_date": "2026-09-05",
      "evidence_type": "Read-only Render get_service and deployed-lineage source review",
      "evidence_url": "https://dashboard.render.com/web/srv-d7out8km0tmc73ddn71g",
      "limitations": "Configuration observation is not a recovery, retention, key-rotation or tenant-isolation acceptance test."
    },
    {
      "service": "ML-DSA signer",
      "service_id": "srv-d8o0t53sq97s73bub3qg",
      "region": "oregon",
      "country": "United States",
      "runtime": "Node",
      "source_repository": "hive-typed-signer",
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "storage_observation": "Disk and backup configuration not established by the supplied signer summary. Source has local seed-file persistence.",
      "observed_date": "2026-09-05",
      "evidence_type": "Read-only Render get_service and deployed-lineage source review",
      "evidence_url": "https://dashboard.render.com/web/srv-d8o0t53sq97s73bub3qg",
      "limitations": "Configuration observation is not a recovery, retention, key-rotation or tenant-isolation acceptance test."
    }
  ],
  "signing_custody_matrix": [
    {
      "id": "KEY-01",
      "service": "Typed API",
      "algorithm": "Ed25519",
      "observed_boundary": "Environment seed is passed into the Node process and @noble/ed25519 signAsync.",
      "key_source_or_mode": "Environment configuration; missing mint/signer configuration fails closed.",
      "status": "Source boundary reviewed; operational evidence open",
      "evidence": [
        "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/signer.js",
        "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/canon.js"
      ],
      "source_revision": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
      "deployed_revision": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
      "verification_date": "2026-09-05",
      "owner": "Accountable key owner not supplied",
      "limitations": "No HSM/KMS boundary or operational key-rotation test established."
    },
    {
      "id": "KEY-02",
      "service": "Receipt / Carnac",
      "algorithm": "Ed25519",
      "observed_boundary": "Node crypto signs with an in-process private key.",
      "key_source_or_mode": "Source supports environment restoration or local key generation.",
      "status": "Source boundary reviewed; operational evidence open",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/spectral.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/server.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "deployed_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "owner": "Accountable key owner not supplied",
      "limitations": "Actual deployed seed branch and log handling require privileged review without disclosing secrets."
    },
    {
      "id": "KEY-03",
      "service": "Countersigner",
      "algorithm": "Ed25519",
      "observed_boundary": "Python cryptography key held in application memory; KEY.sign signs the countersignature.",
      "key_source_or_mode": "Environment seed or local PEM file; file mode 0600 is not hardware custody.",
      "status": "Source boundary reviewed; operational evidence open",
      "evidence": [
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/countersigner.py"
      ],
      "source_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "deployed_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "verification_date": "2026-09-05",
      "owner": "Accountable key owner not supplied",
      "limitations": "Hive-operated second key/log, not an independent organization. Persistent disk does not establish backup or recovery."
    },
    {
      "id": "KEY-04",
      "service": "ML-DSA base signer / public typed demo",
      "algorithm": "ML-DSA-65",
      "observed_boundary": "@noble/post-quantum keypair and secretKey held in Node application memory.",
      "key_source_or_mode": "Environment seed or local seed file, generated when needed; source labels issuer did:hive:typed-demo.",
      "status": "Source boundary reviewed; operational evidence open",
      "evidence": [
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/key.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/server.js"
      ],
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "verification_date": "2026-09-05",
      "owner": "Accountable key owner not supplied",
      "limitations": "Key stability across redeploys depends on actual configuration. No universal hybrid receipt format."
    },
    {
      "id": "KEY-05",
      "service": "ML-DSA QPuF path",
      "algorithm": "ML-DSA-65",
      "observed_boundary": "Derived seed is used to create an application-memory keypair; sign calls the software library.",
      "key_source_or_mode": "Separate /sign-qpuf path attempts boot initialization and can be unavailable.",
      "status": "Source boundary reviewed; operational evidence open",
      "evidence": [
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/qpuf/index.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/server.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/hwsign.js"
      ],
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "verification_date": "2026-09-05",
      "owner": "Accountable key owner not supplied",
      "limitations": "No hardware key custody, entropy provenance or certificate inferred from an attestation label. Selected backend configuration requires confirmation."
    },
    {
      "id": "KEY-06",
      "service": "Signer backend catalog",
      "algorithm": "ML-DSA-65 backend selection",
      "observed_boundary": "Executable SOFTWARE path; inspected FPGA/ASIC adapters are unavailable stubs that fail closed.",
      "key_source_or_mode": "Vendor catalog capability fields are not evidence of a deployed Hive hardware boundary.",
      "status": "Source boundary reviewed; operational evidence open",
      "evidence": [
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/hwsign.js"
      ],
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "deployed_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "verification_date": "2026-09-05",
      "owner": "Accountable key owner not supplied",
      "limitations": "No applicable CAVP or CMVP certificate supplied for Hive. Self-tests are a different evidence category."
    }
  ],
  "retention_inventory": [
    {
      "id": "RET-01",
      "service": "Typed API",
      "data_class": "Typed receipts and request metadata",
      "observed_handling": "API signs caller-supplied fields; no declared disk in reviewed service configuration.",
      "candidate_start_event_for_approval": "Receipt issuance; customer copy creation",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/signer.js",
        "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/canon.js"
      ],
      "source_revision": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
      "verification_date": "2026-09-05",
      "limitations": "No claim that all payloads are stored, or that absence of a disk prevents logs or external copies."
    },
    {
      "id": "RET-02",
      "service": "Receipt service",
      "data_class": "Legacy receipt envelopes and payment metadata",
      "observed_handling": "Legacy signing path places envelopes in an in-process Map.",
      "candidate_start_event_for_approval": "Receipt issuance / transaction completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/server.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Process-memory loss is not scheduled deletion or a durable receipt archive."
    },
    {
      "id": "RET-03",
      "service": "Carnac",
      "data_class": "Readable classification inputs",
      "observed_handling": "Server receives request/output text; optional semantic reader sends text to configured compute endpoint.",
      "candidate_start_event_for_approval": "Classification completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/engine.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/compute.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Judgment schema omission of raw fields is not evidence that logs or downstream processors never retain text."
    },
    {
      "id": "RET-04",
      "service": "Carnac",
      "data_class": "Judgments, trajectories and derived metadata",
      "observed_handling": "In-memory authoritative store with conditional best-effort Supabase mirror; durable:false can accompany successful processing.",
      "candidate_start_event_for_approval": "Judgment creation / trajectory closure",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/engine.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/ledger.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Persistence, approved duration, hold rules and deletion tests need deployment-specific evidence."
    },
    {
      "id": "RET-05",
      "service": "Carnac public sandbox",
      "data_class": "Sandbox inputs and outputs",
      "observed_handling": "Readable processing still occurs; sandbox skips durable judgment ledger and Howler writes.",
      "candidate_start_event_for_approval": "Sandbox request completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/engine.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/ledger.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/compute.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Does not imply absence of platform logs, error details or semantic-processor copies."
    },
    {
      "id": "RET-06",
      "service": "Countersigner / briefing",
      "data_class": "Countersigned log entries and briefing records",
      "observed_handling": "Append-only JSONL plus briefing record files; configured persistent disk at /var/hive.",
      "candidate_start_event_for_approval": "Log append / briefing completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/countersigner.py",
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/briefing.py"
      ],
      "source_revision": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
      "verification_date": "2026-09-05",
      "limitations": "Crash recovery, backup restoration, complete exports and retention enforcement not tested."
    },
    {
      "id": "RET-07",
      "service": "ML-DSA signer",
      "data_class": "Submitted text, fragments and signed responses",
      "observed_handling": "Public text/fragment signing paths process readable content; digest-binding path is narrower.",
      "candidate_start_event_for_approval": "Signing response / inspection completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/server.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/key.js"
      ],
      "source_revision": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3",
      "verification_date": "2026-09-05",
      "limitations": "No broad claim of encrypted inspection storage, no-plaintext disk or universal payload exclusion."
    },
    {
      "id": "RET-08",
      "service": "Static site / receipt telemetry",
      "data_class": "Browsing metadata, IP and location fields",
      "observed_handling": "Shared beacon sends path/query, referrer, UA and time zone; legacy receipt telemetry stores IP/location and other fields in Supabase.",
      "candidate_start_event_for_approval": "Telemetry collection / log creation",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/thehiveryiq-site/blob/d07903aa2aa55e3f2ff4d9a6e2df11098921303f/assets/hive-beacon.js",
        "https://github.com/srotzin/thehiveryiq-site/blob/d07903aa2aa55e3f2ff4d9a6e2df11098921303f/assets/hive-nav.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/site_store.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/server.js"
      ],
      "source_revision": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f; d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Active processor mapping, consent assessment, retention and field-level redaction remain open."
    },
    {
      "id": "RET-09",
      "service": "All reviewed services / hosting and edge",
      "data_class": "Operational logs and error telemetry",
      "observed_handling": "Field inventory and log-drain configuration not fully established; Carnac upstream errors may include excerpts.",
      "candidate_start_event_for_approval": "Log creation / incident closure",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/compute.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/server.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/server.js"
      ],
      "source_revision": "Multiple revisions listed in deployment inventory",
      "verification_date": "2026-09-05",
      "limitations": "No universal PII-free or payload-free logs assertion; platform/vendor copies need review."
    },
    {
      "id": "RET-10",
      "service": "Contact, account and billing workflows",
      "data_class": "Account/contact records, support messages and billing data",
      "observed_handling": "Existing workflows may receive identifiers and messages; complete stores and agreements not established.",
      "candidate_start_event_for_approval": "Account closure / purpose completion / transaction completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [],
      "source_revision": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "verification_date": "2026-09-05",
      "limitations": "Proposed events are not approved periods. Legal applicability and hold rules need fact-specific review."
    },
    {
      "id": "RET-11",
      "service": "All reviewed services and processors",
      "data_class": "Backups, snapshots and disaster-recovery copies",
      "observed_handling": "Persistent disk and optional external stores do not prove backup coverage or restoration capability.",
      "candidate_start_event_for_approval": "Backup creation / supersession / contract termination",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/ledger.js",
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/countersigner.py",
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/briefing.py"
      ],
      "source_revision": "Multiple revisions listed in deployment inventory",
      "verification_date": "2026-09-05",
      "limitations": "Backup expiry, hold overrides, deletions and sample restoration/deletion evidence were not supplied."
    },
    {
      "id": "RET-12",
      "service": "Carnac and customer-held records",
      "data_class": "Exports and downloaded receipts",
      "observed_handling": "Carnac export code is tenant-scoped JSON/CSV, capped at 1,000 rows and may use degraded memory storage.",
      "candidate_start_event_for_approval": "Export generation / recipient purpose completion",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/export.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Not evidence of an all-record portable manifest; recipient-held copies are separate custody."
    },
    {
      "id": "RET-13",
      "service": "Configured compute / storage / edge providers",
      "data_class": "Processor-held copies and onward disclosures",
      "observed_handling": "Source identifies optional semantic compute and Supabase paths; complete active recipient inventory and regions not supplied.",
      "candidate_start_event_for_approval": "Processor completion / service termination",
      "approved_start_event": null,
      "approved_duration": null,
      "legal_hold_rule": null,
      "deletion_process": null,
      "deletion_verification_method": null,
      "approval_status": "No approved schedule supplied",
      "owner": "Business, privacy/legal and service owners to be assigned",
      "evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/compute.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/ledger.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/site_store.js"
      ],
      "source_revision": "d012630a8ed8b062691027c88532638a48ed9d81",
      "verification_date": "2026-09-05",
      "limitations": "Model name alone does not identify the deployed provider. Verify contracts, regions, downstream retention and deletion evidence."
    }
  ],
  "claims_registry": [
    {
      "claim_id": "SEC-REGION",
      "approved_wording": "Four reviewed Render services run in Oregon, United States. Static distribution is global, with no single region verified.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy"
      ],
      "scope": "Hosting configuration, not all storage or processor locations",
      "status": "FIXED AND VERIFIED",
      "supporting_evidence": [
        "https://dashboard.render.com/web/srv-d9r39fe417fc73babs1g",
        "https://dashboard.render.com/web/srv-da470gf10e5c73aus5v0",
        "https://dashboard.render.com/web/srv-d7out8km0tmc73ddn71g",
        "https://dashboard.render.com/web/srv-d8o0t53sq97s73bub3qg"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "Does not establish EU-only routing, origin controls or external database regions."
    },
    {
      "claim_id": "SEC-PLAINTEXT",
      "approved_wording": "Client-side hashing can keep content local. Carnac and text-signing paths receive readable inputs; transit encryption does not change that boundary.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "Input-processing paths",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/engine.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/compute.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/server.js"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "No universal no-payload-storage claim; raw fields omitted from judgments may still occur in metadata, errors or downstream processing."
    },
    {
      "claim_id": "SEC-TELEMETRY",
      "approved_wording": "The shared beacon collects browsing metadata; legacy receipt telemetry includes IP and location data.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "Current source path",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://github.com/srotzin/thehiveryiq-site/blob/d07903aa2aa55e3f2ff4d9a6e2df11098921303f/assets/hive-beacon.js",
        "https://github.com/srotzin/thehiveryiq-site/blob/d07903aa2aa55e3f2ff4d9a6e2df11098921303f/assets/hive-nav.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/site_store.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/server.js"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "Live visitor records were not accessed. Complete consent/processor/retention controls remain to be reviewed."
    },
    {
      "claim_id": "SEC-RETENTION",
      "approved_wording": "Approved retention events, durations, holds, deletion steps and verification remain open by data class.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "RET-01 through RET-13",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
        "https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/ledger.js",
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/countersigner.py"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "Neither AI Act Article 12 nor storage type creates a universal seven-year schedule. ICE third-party published terms are not replaced by this Hive schedule review."
    },
    {
      "claim_id": "SEC-CUSTODY",
      "approved_wording": "Inspected Ed25519 and ML-DSA-65 signing paths use application-memory keys, not a verified KMS boundary.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "KEY-01 through KEY-06",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/canon.js",
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/spectral.js",
        "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/countersigner.py",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/key.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/qpuf/index.js",
        "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/hwsign.js"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "Actual key configuration, secret logging review and historical verification after rotation remain operational work."
    },
    {
      "claim_id": "SEC-VALIDATION",
      "approved_wording": "Self-tests, CAVP algorithm validation and CMVP module validation are distinct. No applicable Hive validation certificate was supplied.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "Certification evidence",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program",
        "https://csrc.nist.gov/projects/cryptographic-module-validation-program"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "No inference of validation from FIPS names, vendor catalogs or attestation fields."
    },
    {
      "claim_id": "SEC-ERASURE",
      "approved_wording": "A signed deletion statement authenticates its stated scope; it does not prove removal of every copy or legal compliance.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "Deletion-statement limits",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "No universal endpoint, 72-hour all-copy removal or dual-signature format promised."
    },
    {
      "claim_id": "SEC-ENTITY",
      "approved_wording": "Hive Civilization is the brand. Registered entity and jurisdiction require charter verification.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "Corporate identity reconciliation",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "Wyoming and Delaware references conflict; no charter supplied. No corporation identity invented."
    },
    {
      "claim_id": "SEC-AUDIT",
      "approved_wording": "No executed SOC 2 engagement, independent report, ISO certificate or approved audit date was supplied in the review.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/",
        "/privacy",
        "/security/founder-risk/",
        "/security/iso-27001-self-attested/",
        "/security/soc2-self-attested/"
      ],
      "scope": "Evidence availability, not a claim that no agreement can exist",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "No control is marked operational solely from a public self-attestation page."
    },
    {
      "claim_id": "SEC-CONTINUITY",
      "approved_wording": "Single-founder dependence remains open; second-admin recovery, escrow, succession, independent treasury authority and insurance require records and tests.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/security/founder-risk/",
        "/security/"
      ],
      "scope": "Continuity disclosure",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "No insurance limits, accepted co-signers, active escrow, completed legal succession or recovery drill was established."
    },
    {
      "claim_id": "SEC-EXPORT",
      "approved_wording": "Carnac export code is tenant-scoped, capped at 1,000 rows and may use process-memory fallback.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/privacy",
        "/security/founder-risk/"
      ],
      "scope": "Carnac export only",
      "status": "WORDING FIXED; OPERATIONAL EVIDENCE OPEN",
      "supporting_evidence": [
        "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/export.js"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "Not a universal all-data export or verified complete portable manifest."
    },
    {
      "claim_id": "SEC-GDPR-TIMING",
      "approved_wording": "Where GDPR applies, Article 12(3) provides a response without undue delay and within one month, with a possible two-month extension and timely notice.",
      "approval_meaning": "Editorial wording supported for this source review; not business/legal policy approval.",
      "affected_pages_products": [
        "/privacy#rights"
      ],
      "scope": "Applicable-law response timing",
      "status": "FIXED AND VERIFIED",
      "supporting_evidence": [
        "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
      ],
      "source_version": "d07903aa2aa55e3f2ff4d9a6e2df11098921303f",
      "deployed_versions": {
        "typed": "9aa407c47c0e6c7e93a3542d99c70ab3ef54c330",
        "receipt_carnac": "d012630a8ed8b062691027c88532638a48ed9d81",
        "countersigner": "eccc931a395eec9b181f1b02b9f31e5e32dcdb87",
        "signer": "1fd71fbd3d789d0e90345dc0e88316bc560db9c3"
      },
      "last_verification_date": "2026-09-05",
      "owner": "Accountable owner not supplied",
      "limitations": "No universal 30-day promise or invented legal default."
    }
  ],
  "primary_references": {
    "typed_signer": "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/signer.js",
    "typed_canon": "https://github.com/srotzin/thehiveryiq-site/blob/9aa407c47c0e6c7e93a3542d99c70ab3ef54c330/hive-verifier-api/src/typed/canon.js",
    "receipt_signer": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/spectral.js",
    "receipt_server": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/server.js",
    "carnac_engine": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/engine.js",
    "carnac_compute": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/compute.js",
    "carnac_ledger": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/ledger.js",
    "carnac_export": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/carnac/export.js",
    "site_store": "https://github.com/srotzin/hive-receipt/blob/d012630a8ed8b062691027c88532638a48ed9d81/lib/site_store.js",
    "beacon": "https://github.com/srotzin/thehiveryiq-site/blob/d07903aa2aa55e3f2ff4d9a6e2df11098921303f/assets/hive-beacon.js",
    "nav": "https://github.com/srotzin/thehiveryiq-site/blob/d07903aa2aa55e3f2ff4d9a6e2df11098921303f/assets/hive-nav.js",
    "countersigner": "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/countersigner.py",
    "briefing": "https://github.com/srotzin/hive-countersigner/blob/eccc931a395eec9b181f1b02b9f31e5e32dcdb87/briefing.py",
    "signer_key": "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/key.js",
    "signer_server": "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/server.js",
    "signer_backend": "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/hwsign.js",
    "signer_qpuf": "https://github.com/srotzin/hive-typed-signer/blob/1fd71fbd3d789d0e90345dc0e88316bc560db9c3/src/qpuf/index.js",
    "nist_cavp": "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program",
    "nist_cmvp": "https://csrc.nist.gov/projects/cryptographic-module-validation-program",
    "gdpr": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
    "ai_act_12": "https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12"
  },
  "change_log": [
    {
      "date": "2026-09-05",
      "change": "Replaced incorrect US East (Oregon), platform-wide KMS, universal no-plaintext and no-tracking claims with service-specific evidence."
    },
    {
      "date": "2026-09-05",
      "change": "Preserved deletion-statement limits and earlier removal of the Article 12 seven-year default; added unapproved retention inventory."
    },
    {
      "date": "2026-09-05",
      "change": "Removed unsupported audit/certification dates, active continuity arrangements, insurance limits and universal complete-export promises."
    },
    {
      "date": "2026-09-05",
      "change": "Reconciled linked ISO/SOC inventories, including contrary KMS, PII, deletion, hybrid-signature and audit-completion assertions."
    },
    {
      "date": "2026-09-05",
      "change": "Preserved layout styles, artwork, fonts and scripts; updated in-scope footer and metadata wording."
    }
  ]
}
