Skip to content

COMPLIANCE · POSTURE

Compliance, stated honestly.

If your security or procurement team is evaluating HYVE Ether OS, this is where every framework stands — written plainly, with no certification claimed that we don't hold. For the full cryptographic posture, the five principles, and our responsible- disclosure policy, see the Security page.

Note: "HIPAA certified" and "SOC 2 certified" badges from vendors who haven't completed the work are a red flag. We'd rather show you exactly where we are.

SHARED RESPONSIBILITY

Yours vs. ours.

Because HYVE Ether OS runs on your hardware with zero vendor access, the line is unusually clean: you remain the data controller; we are responsible for the software, not your data.

You

DATA CONTROLLER · COVERED ENTITY

  • All data created, stored, and processed inside the OS — it lives on your hardware, encrypted with your keys
  • Operator access control, provisioning, and authentication policy
  • Your regulatory duties — HIPAA Covered Entity, GDPR controller, and breach determination for your data
  • Physical security of the devices running HYVE
  • What you choose to connect to, download, or share off-device

HYVE

SOFTWARE VENDOR · VIBE SOFTWARE SOLUTIONS

  • Secure development (SDLC), code review, and supply-chain integrity
  • Signed, tamper-evident updates — Ed25519 via the Depot
  • Vulnerability management, responsible disclosure, and patch SLAs
  • The cryptographic architecture — post-quantum, local-first, zero-access by design
  • Processing of commercial data only — purchase, license, support — under a DPA
  • Control mappings, security questionnaires, and SOC 2 (in progress)

By default there is no shared data plane: the OS never phones home, so the data you'd normally split responsibility for in a cloud/SaaS model never reaches us in the first place.

COMPLIANCE · FRAMEWORKS

Compliance & frameworks.

Honest status, stated plainly — we list where each framework actually stands, never a badge we haven't earned. The throughline: because HYVE Ether OS runs on your hardware and never phones home, most regulated data never reaches us in the first place, which shrinks the scope of every framework below.

SOC 2 Type II

Audit readiness in progress

SOC 2 Type II audit readiness is actively underway. Our controls are mapped to the AICPA Trust Services Criteria (Security, Availability, Confidentiality), with a formal independent CPA audit scheduled. We are not yet certified — the report and bridge letters will be published here the moment they are issued. Under NDA, prospects can request our current control mapping and security package today.

HIPAA

Aligned · BAA available

HIPAA has no 'certification' — what's real is the architecture and a signed Business Associate Agreement. HYVE's local-first design keeps Protected Health Information on your own hardware; it never transits our servers, which structurally shrinks HIPAA risk. The OS is built to support the HIPAA Security Rule safeguards — access control, audit controls, integrity, and transmission security. We will execute a BAA with qualifying customers.

GDPR & CCPA

Aligned · DPA available

Data minimization and residency are the default: your data stays on your device, so for most deployments HYVE processes no personal data at all. For customers who require it, a Data Processing Agreement (DPA) is available and our sub-processor list is provided on request.

ISO/IEC 27001

Controls mapped · on roadmap

Our information-security controls map to the ISO/IEC 27001 Annex A control families. Formal certification through an accredited body is on our roadmap, pursued in parallel with SOC 2 based on customer demand.

FedRAMP · CMMC · NIST 800-53

Control mappings available

For public-sector and defense procurement, HYVE provides read-only control mappings (NIST 800-53 / CMMC families) and ships a phased federal-hardening installer in the OS. We do not claim an authorization we don't hold — engage us for a controls package and the path that fits your ATO.

FOR PROCUREMENT & SECURITY TEAMS

Request our security package

We provide our control mapping, a completed security questionnaire (SIG / CAIQ), our sub-processor list, and a BAA or DPA for qualifying customers. HYVE Ether OS also ships an in-product Compliance module that maps live OS controls to framework requirements on your own deployment.

Email majixx@vibesoftwaresolutions.com with your framework and timeline.