Skip to main content
Trust · Security · Compliance

Security & Compliance

HYVE OVERLORD is built for defense, regulated, and enterprise environments. This page summarizes how the platform protects your data and where we stand on the frameworks your security team will ask about. For procurement or vendor due diligence, our full security package is available on request.

Compliance Posture

SOC 2 Type IIPLANNED

We operate under SOC 2-aligned controls (security, availability, confidentiality) today. A formal SOC 2 Type II examination has not yet been completed; when we engage an independent auditor and the examination concludes, the report will be made available to qualified customers under NDA. We do not claim a current SOC 2 certification.

HIPAAAVAILABLE

HIPAA-ready architecture. HYVE OVERLORD runs inside your environment and we do not collect or store your operational data or PHI. One configuration exception you must control: if you enable the MaXXIe AI assistant against a cloud LLM provider, prompts and a security-context summary are sent to that provider, which for a covered entity is a disclosure to a third party with no BAA in place. For HIPAA deployments, run MaXXIe against a local model (Ollama) or leave it disabled. A Business Associate Agreement (BAA) is available for qualified healthcare deployments.

CMMC Level 2 · NIST 800-171POSTURE MONITORING

Built-in control mapping and continuous posture monitoring against CMMC Level 2 and NIST SP 800-171, with reporting that supports your assessment evidence. This is posture monitoring and control alignment — not a certification of your environment.

US Data ResidencyAVAILABLE

US-only product. Customer data resides in the United States and, for the desktop platform, within your own environment. International interest is routed to an export-compliance review (EAR / ITAR) before any engagement.

How We Protect Your Data

Your data stays in your environment

The OVERLORD + Raptor desktop platform runs on your machines and activates offline (Ed25519, verified locally). Nothing phones home; we do not collect or store your operational data, telemetry, or PHI.

Post-quantum encrypted control channel

The Shield-to-Command channel is encrypted at the application layer with NIST ML-KEM-768 (FIPS 203) and a forward-secret double-ratchet cell protocol, protecting threat intelligence against the “harvest now, decrypt later” threat model. ML-KEM is the transport encryption on this link — it is not layered on top of TLS, and the key exchange is ephemeral-to-ephemeral with no certificate or static-key binding. It therefore defends against a passive recorder, not an active on-path attacker: run Shield-to-Command links inside your own network segment or an existing VPN/mTLS tunnel.

Encryption at rest

Local secrets and key material are sealed with OS-native key stores (Windows DPAPI / platform secure storage), never written in plaintext.

Tenant isolation

Multi-tenant data is isolated at the database layer with row-level security; cross-tenant access is denied by default. Privileged operations run server-side under least privilege.

Least privilege & audit trail

Role-based access control with an immutable audit trail across administrative and security actions. Control-plane writes require explicit authorization and fail closed.

Proof the agent was actually watching

OVERLORD writes an Ed25519-signed, hash-chained heartbeat every 30 seconds and a clean-shutdown marker on a normal exit. On the next start it compares the last proof-of-life to now and names any window it cannot prove it was watching — a kill, a crash or a power loss appears as an unexplained absence with both timestamps, and that finding is itself signed into the chain. Monitoring runs while the OVERLORD window is open, and this ledger is what makes any period it was closed appear in the record instead of vanishing. It is tamper-EVIDENT, not tamper-proof: the signing key lives on the monitored host, so someone who owns that host can forge a clean ledger, and deleting the whole ledger leaves an empty one rather than a detectable edit. It makes the hole visible; it does not prevent it.

Offline-first, no lock-in

Licenses are offline-verifiable and perpetual-capable — no license server, nothing to phone home, no dependency on us to keep your deployment running.

Need our security package?

For vendor security reviews we provide a control overview, architecture summary, data-flow description, and a BAA on request. SOC 2 Type II report shared under NDA on completion.

Request the security packageDownload the Security Overview (PDF)

This page describes our security architecture and the control frameworks we engineer to. Each framework’s status is stated explicitly above. Engineering to a framework’s controls is not the same as a third-party certification of your environment; formal attestations (the SOC 2 Type II report) and executed agreements (BAA) are provided directly to qualified customers under NDA as part of procurement. HYVE OVERLORD and Raptor are US-only, export-controlled products (EAR / ITAR).