Compliance Posture
We operate under SOC 2-aligned controls (security, availability, confidentiality) today. A formal SOC 2 Type II examination has not yet been completed; when we engage an independent auditor and the examination concludes, the report will be made available to qualified customers under NDA. We do not claim a current SOC 2 certification.
HIPAA-ready architecture. HYVE OVERLORD runs inside your environment and we do not collect or store your operational data or PHI. One configuration exception you must control: if you enable the MaXXIe AI assistant against a cloud LLM provider, prompts and a security-context summary are sent to that provider, which for a covered entity is a disclosure to a third party with no BAA in place. For HIPAA deployments, run MaXXIe against a local model (Ollama) or leave it disabled. A Business Associate Agreement (BAA) is available for qualified healthcare deployments.
Built-in control mapping and continuous posture monitoring against CMMC Level 2 and NIST SP 800-171, with reporting that supports your assessment evidence. This is posture monitoring and control alignment — not a certification of your environment.
US-only product. Customer data resides in the United States and, for the desktop platform, within your own environment. International interest is routed to an export-compliance review (EAR / ITAR) before any engagement.
How We Protect Your Data
The OVERLORD + Raptor desktop platform runs on your machines and activates offline (Ed25519, verified locally). Nothing phones home; we do not collect or store your operational data, telemetry, or PHI.
The Shield-to-Command channel is encrypted at the application layer with NIST ML-KEM-768 (FIPS 203) and a forward-secret double-ratchet cell protocol, protecting threat intelligence against the “harvest now, decrypt later” threat model. ML-KEM is the transport encryption on this link — it is not layered on top of TLS, and the key exchange is ephemeral-to-ephemeral with no certificate or static-key binding. It therefore defends against a passive recorder, not an active on-path attacker: run Shield-to-Command links inside your own network segment or an existing VPN/mTLS tunnel.
Local secrets and key material are sealed with OS-native key stores (Windows DPAPI / platform secure storage), never written in plaintext.
Multi-tenant data is isolated at the database layer with row-level security; cross-tenant access is denied by default. Privileged operations run server-side under least privilege.
Role-based access control with an immutable audit trail across administrative and security actions. Control-plane writes require explicit authorization and fail closed.
OVERLORD writes an Ed25519-signed, hash-chained heartbeat every 30 seconds and a clean-shutdown marker on a normal exit. On the next start it compares the last proof-of-life to now and names any window it cannot prove it was watching — a kill, a crash or a power loss appears as an unexplained absence with both timestamps, and that finding is itself signed into the chain. Monitoring runs while the OVERLORD window is open, and this ledger is what makes any period it was closed appear in the record instead of vanishing. It is tamper-EVIDENT, not tamper-proof: the signing key lives on the monitored host, so someone who owns that host can forge a clean ledger, and deleting the whole ledger leaves an empty one rather than a detectable edit. It makes the hole visible; it does not prevent it.
Licenses are offline-verifiable and perpetual-capable — no license server, nothing to phone home, no dependency on us to keep your deployment running.
This page describes our security architecture and the control frameworks we engineer to. Each framework’s status is stated explicitly above. Engineering to a framework’s controls is not the same as a third-party certification of your environment; formal attestations (the SOC 2 Type II report) and executed agreements (BAA) are provided directly to qualified customers under NDA as part of procurement. HYVE OVERLORD and Raptor are US-only, export-controlled products (EAR / ITAR).