System scope & data boundary
The entity, product, production environment, regions, processing path, and explicit exclusions these statements apply to — and where the customer boundary begins.
Every public claim below carries its exact scope, date, source authority, and limitations — and the ones that can be checked cryptographically link to the record, not the marketing. Protected diligence materials are available to authorized reviewers under NDA.
Operational evidence updates are supplemental and are not a continuous independent audit or a CPA-issued opinion. See each card for the exact source and its limits.
Selecting a role reorders the nine canonical cards below. It never changes a fact, status, scope, date, source, or limitation — and it is never sent to any system. order-only · local-only
The entity, product, production environment, regions, processing path, and explicit exclusions these statements apply to — and where the customer boundary begins.
All 20tracked frameworks with their honest state, evidence class, and last-updated date. Filter by tier — fixed-value buttons only, no free-text input. Nothing self-scores, and in-progress or roadmap items never borrow a “certified” look.
| Framework | Status | Evidence class | Updated |
|---|---|---|---|
| 01Signed Evidence Room | Live | Signed daily | — |
| 02SOC 2 Type I | In Progress — Engaged | Third-party issued | — |
| 03SOC 2 Type II | In Progress — Engaged | Third-party issued | — |
| 04CSA STAR Level 1 CAIQ | Listed | Public self-assessment | — |
| 05CSA STAR Level 2 | Roadmap 2027 | Third-party issued | — |
| 06EU-US / UK / Swiss DPF | Not Applicable | Public self-assessment | — |
| 07NIST Cybersecurity Framework | Self-Attested | Self-attested | — |
| 08ISO 27001 | Mapped | Third-party issued | — |
| 09ISO 27701 | Roadmap 2027 | Third-party issued | — |
| 10ISO 27018 | Roadmap 2027 | Third-party issued | — |
| 11GDPR / UK GDPR Privacy Pack | Mapped | Self-attested program | — |
| 12NIST SSDF / SP 800-218 | Self-Attested | Self-attested | — |
| 13CISA Secure Software Attestation Form | Self-Attested | Self-attested | — |
| 14Cyber & Tech E&O Insurance | Self-Attested | Self-attested | — |
| 15Business Continuity Management | Mapped | Control mapping | — |
| 16ISO 22301 | Roadmap 2026 | Third-party issued | — |
| 17NIST AI Risk Management Framework | Self-Attested | Self-attested | — |
| 18ISO/IEC 42001 | Roadmap 2026 | Third-party issued | — |
| 19Independent Penetration Test | Roadmap 2026 | Third-party issued | — |
| 20OWASP ASVS Level 2 | Self-Attested | Self-attested | — |
Every certificate status on this page traces to a daily-signed manifest. Verify it right here in your browser, or with nothing but this page’s public key and a stock Node.js install.
Each daily manifest is signed and hash-linked to the previous one, back to the chain’s first entry — reviewers who keep prior entries can detect any later change to the published chain.
The daily root is independently timestamped and witnessed in the public Sigstore Rekor transparency log — verifiable by a first-time visitor with no prior entry saved.
Continuous control evidence is verified and countersigned daily by a separate trust domain — a dedicated identity with no production access, its own operator-held signing key, an append-only hash-chained ledger, and dead-man paging that alerts if a day is missed. Operational since July 22, 2026. This is organizational separation, not a third-party audit; countersignature materials (ledger and tier-2 public key) are available to customers and auditors on request.
2026-08-01 UTC (Jul 31, 2026, EDT) ·
This button fetches the real signed manifest and the real published keys, canonicalizes, and checks the Ed25519 signature — in your browser, via WebCrypto. This server never sees the verdict.
Everything above is written for a human reviewer. This is for the software doing diligence on their behalf — schema, endpoints, and verification contract, so an agent can check HiveSilo’s claims without asking HiveSilo to vouch for itself.
All three are rate-limited, unauthenticated, and return the same data a human sees on this page — no separate, softer “bot” version.
Canonicalization: hs-canonical-json-v1
Certificate membership uses sha256-merkle-v2(RFC 6962 domain-separated) — verify a single certificate’s inclusion without downloading or trusting the full manifest.
The public site holds no credential and grants no automatic access. Protected evidence is delivered through the secure review process — never by this page.
A plain-language overview, mapped to the NIST AI Risk Management Framework (govern → map → measure → manage).
A public-safe excerpt of the shared-responsibility model. Full detail (including the merchant-CVM boundary and cryptographic mechanism) is reviewer-only.
| Area | HiveSilo | Customer |
|---|---|---|
| Customer identities, roles, privileges | Platform auth infrastructure | Grants, revokes, and audits who holds each role |
| Data governance | Retention tooling and enforcement | Sets retention policy and classification |
| CRM & ad-platform integrations | Connector reliability | Credentials, field mapping, downstream use |
| Endpoint security | — | Devices used to access the dashboard |
| Content & messaging strategy | — | What’s sent, to whom, and why |
| Enclave (TEE) verification | Cryptographically attested by hardware | Independently verifiable by the customer |
Objective status per workstream — no self-scoring.
STAR Level 2 is a third-party attestation/certification built on the Cloud Controls Matrix and an accredited ISO 27001 audit — a step above the Level 1 self-assessment already listed. It is scoped after ISO 27001 readiness; no Level 2 assessment is engaged and no certificate is claimed before an accredited assessor issues it.
International transfers are designed around Standard Contractual Clauses with a UK IDTA addendum; the executed enterprise DPA embedding them is in legal review, not yet finalized for general availability. DPF self-certification is not currently pursued and no listing is claimed.
Privacy-management extension is scoped after ISO 27001 readiness; no certificate is claimed before issuance.
Cloud-privacy control coverage is tracked for the certification roadmap without presenting an issued certificate.
Business-continuity-management-system certification (ISO 22301) is scoped on the certification roadmap; the BC/DR program mapping already listed provides the control basis, but no certificate is claimed before an accredited body issues one.
AI-management-system certification is scoped for later pursuit; no certificate is claimed before an accredited body issues one.
Every public artifact this page’s claims trace to, in one place. Each is deterministic, versioned, and safe to automate against — no auth, no scraping.
Each protected item lists its honest availability — nothing is promised before it exists.
The registered identity behind every statement on this page — with the direct routes for security, privacy, and diligence contact.
Each independent program listed separately, dated, with its evidence class. SOC 2 Type I & II examinations are engaged with a licensed CPA firm; no report or opinion is issued yet.
Controller/processor roles, purpose limitation, retention, transfer mechanism (SCCs + UK IDTA), current subprocessor list, and contract routes for legal and privacy reviewers.
Public-safe encryption, identity & privileged-access governance, tenant isolation, secure SDLC, dependency/vuln remediation, and responsible disclosure. Independent penetration test on the roadmap.
The daily Ed25519-signed public snapshot, signing-key history, canonical-JSON verification, per-certificate endpoints, Merkle membership proofs, hash-linked continuity, and offline-verifier recipe.
Measured availability against the independent monitor, current incident state, BC/DR scope, RTO/RPO targets stated separately from observed drills, and the customer incident route.
A plain index of public and protected enterprise-review materials — corporate identity, SLA/support, insurance, DPA/SCC, security questionnaire, continuity — and how an authorized buyer requests each.
The scoped AI/agent boundary, input/output use restrictions, model-training position, human oversight, evaluation & change controls, and the confidential-compute role — with its attestation limits stated plainly.
Which controls depend on HiveSilo, the customer, an integration, or a subprocessor — plus current subprocessor categories, change-notification approach, and the security/privacy/vulnerability contacts.
Roadmap years are targets, not commitments. The independent-evidence tier is reserved for evidence issued or verified by a party other than HiveSilo — until a third party has looked, entries stay exactly where they are.
Save today’s signed manifest — one JSON file, no account needed.
Come back any day and re-fetch. Every future manifest must hash-link back to the one you kept; any rewrite of history breaks the chain against your copy.
Cross-check the daily root in the public Sigstore Rekor log — an independent witness we cannot edit, even in principle.
A single broken link would be permanent, public evidence — that is the point.
The offline variant never talks to this server at verification time — it checks two previously downloaded files with the Node.js crypto stdlib only, so the result cannot depend on anything HiveSilo says in the moment.
No. HiveSilo’s bot-detection and decision-core scoring are deterministic, explainable algorithms — not trained models — and never ingest visitor PII. Where generative AI is used (internal tooling, analytics copilots), it operates on de-identified data with PII excluded by design, not filtered after the fact.
A named third-party inference vendor is disclosed to approved reviewers under NDA, governed under the same vendor-review program as every other subprocessor — no carve-out for AI.
Prompts sent to generative-AI tooling are constructed from de-identified data by design; no raw customer PII is included in any prompt.
Model and vendor changes follow the standard subprocessor change-notice process (30-day advance notice), not an ad hoc path.
Internal AI tooling is limited to a fixed, code-owned allowlist of read-only tools — no arbitrary command execution, no unbounded data access, and no ability for the model to grant itself new capabilities.
Yes. AI-assisted tooling operates as an advisory layer for a human operator or the merchant’s own team — it does not autonomously execute high-impact actions.
Real structural controls exist today (fixed tool allowlists, read-only execution, PII-excluded data access) and are validated by internal adversarial CI tests. An independent third-party penetration test is not yet on record — that is a disclosed gap, not an implied one, tracked on the assurance roadmap rather than glossed over.
| Data boundary | Status |
|---|---|
| Controller vs. processor status | Documented per-tenant, available on request |
| Sub-processor disclosure list | Published, updated on change |
| Data retention policy | Public summary; full policy under NDA |
| PII scope & handling | Scoped to the merchant CVM boundary |
No independent penetration test is on record; isolation and application controls are validated today by internal adversarial CI tests only. A comparative quote process with accredited third-party firms is underway, and an engagement will be commissioned before the first regulated-sector (banking/healthcare) signature, per CAP-03.
Independent uptime from t.hivesilo.com over the last 90 days — the same monitor the public status page reads from. Tracked continuously, not asserted.
Historical availability does not guarantee future availability. Recovery targets are commitments, not observed results.
No curated pull-quote can survive this page’s own standard of evidence — so instead, your team talks directly with a current HiveSilo customer. Your questions, no script, always with the customer’s consent.
Authorized reviewers can request reports, testing summaries, architecture material, continuity evidence, and legal documents through the secure review process. The public site holds no credential and grants no automatic access.