generated: '2026-09-19' method: searched probe: true source: https://thehiveryiq.com/security/ url: https://thehiveryiq.com/security/ pages: - https://thehiveryiq.com/security/ - https://thehiveryiq.com/security/soc2-self-attested/ - https://thehiveryiq.com/security/iso-27001-self-attested/ - https://thehiveryiq.com/security/founder-risk/ - https://thehiveryiq.com/compliance/ - https://thehiveryiq.com/trust - https://thehiveryiq.com/security/policy-evidence-2026-09-05.json certifications: [] self_attestations: - framework: SOC 2 (AICPA TSC 2017) url: https://thehiveryiq.com/security/soc2-self-attested/ status: self-attested review inventory; "No independent SOC 2 report or executed engagement letter was supplied in this review." - framework: ISO/IEC 27001:2022 url: https://thehiveryiq.com/security/iso-27001-self-attested/ status: self-attested review inventory of 93 Annex A control topics; "not an ISO certificate or independent audit". - framework: HIVECOMPLY control dashboard url: https://thehiveryiq.com/compliance/ status: self-scored 96.2/100 across 158 controls and 12 frameworks (SOC 2, ISO 27001/27017/27018/27701/27036/42001, GDPR, eIDAS 2.0, NIS2, DORA; EU AI Act pending), "Machine = automated; Self = operator-attested". Last scanned 2026-05-08. correction: 'The automated probe (probe-security-programs.py) keyword-matched ''SOC 2'', ''ISO 27001'', ''FedRAMP'' and ''GDPR'' on /security and wrote them as certifications. Read in context, the page says the opposite: ''No executed SOC 2 engagement letter, independent audit report or ISO certificate was supplied for this review''; ''Audit Engagement: Not verified. AICPA SOC 2 Report: Not supplied. ISO 27001: Date unapproved''; ''No independent penetration-test agreement or report was supplied''. FedRAMP appears only as a framework name in the HiveComply product list. certifications is therefore EMPTY. What Hive does publish, unusually, is a dated, source-referenced evidence review of its own posture, including the gaps.' posture_highlights: review_date: '2026-09-05' hosting: Four Render services in Oregon, United States; Cloudflare edge; static distribution global cryptography: Ed25519 in application processes (no verified KMS boundary); ML-DSA-65 signer service; algorithm labels are not validation certificates key_person_risk: Single-founder operation disclosed at /security/founder-risk/; treasury 0x15184Bf5...436E on Base; proposed 2-of-3 Safe not deployed penetration_testing: No independent test report supplied subprocessors: Render, Cloudflare, Stripe (not verified active), Mercury (not verified), GitHub, Supabase/other storage (not verified) machine_readable_evidence: https://thehiveryiq.com/security/policy-evidence-2026-09-05.json (deployments, signing_custody_matrix, retention_inventory, claims_registry, change_log) evidence: - source: https://thehiveryiq.com/security/ http_status: 200 fetched: '2026-09-19' quote: No executed SOC 2 engagement letter, independent audit report or ISO certificate was supplied for this review. - source: https://thehiveryiq.com/security/soc2-self-attested/ http_status: 200 fetched: '2026-09-19' quote: 'Self-attestation notice: not a SOC 2 report.' - source: https://thehiveryiq.com/security/iso-27001-self-attested/ http_status: 200 fetched: '2026-09-19' quote: This is a self-maintained review inventory, not an ISO certificate or independent audit. - source: https://thehiveryiq.com/compliance/ http_status: 200 fetched: '2026-09-19' quote: 96.2 / 100 Overall compliance score ... Machine = automated; Self = operator-attested.