Bee Cell
Free, fast multimodal entry tier
Governed production model with capability evidence and release controls.
Bee TrustHub
The central assurance centre for Bee: security controls, privacy and data protection, compliance status, AI governance, signed evidence, live verification, legal documents, and responsible-disclosure channels.
Bee's PQC stack is not a custom protocol. Every algorithm we ship is a NIST-finalized standard with a published reference, an effective date, and a test-vector suite.
Bee's six governed production tiers publish live service status, model specifications and capability evidence separately from roadmap intent.
Bee is a Singapore product built and operated by HEOSSI (Pte.) Ltd., a Singapore-incorporated entity with published legal, security and corporate contact information.
Model assurance
Bee Cell, Brood, Comb, Buzz, Hive and Swarm are HEOSSI product and release names. Cell through Hive are controlled model releases with immutable release identities; Swarm is a versioned routing fabric across eligible lanes. Release lineage, technical specifications, capability probes and release approval are related—but they are not the same claim. TrustHub keeps those evidence layers separate.
Free, fast multimodal entry tier
Governed production model with capability evidence and release controls.
Cost-efficient multimodal reasoning
Governed production model with capability evidence and release controls.
Structured multimodal workhorse
Governed production model with capability evidence and release controls.
Agent and builder workhorse
Governed production model with capability evidence and release controls.
High-capability specialist intelligence
Governed production model with capability evidence and release controls.
Premium distributed intelligence
Governed production model with capability evidence and release controls.
Controlled lineage records bind architecture, licensing and the exact foundation revision used by a Bee release.
Live probes verify what Bee actually serves. Current register: 2026-07-14.
Each Bee alias resolves to a dated release binding the base revision and complete adapter-set digest.
Candidates require held-out evaluation, release checks and rollback readiness before activation.
Security centre
Shared public tiers and contracted Enclave deployments do not have identical security boundaries. Public Bee uses standard TLS 1.3 today. Enclave Sovereign adds the NIST-finalized post-quantum transport stack. The formal control descriptions, response commitments, and vendor-risk detail remain in the Security Practices document.
Public Bee uses TLS 1.3 in transit and AES-256-GCM at rest. NIST post-quantum transport is default-on for separately contracted Enclave Sovereign deployments; we do not claim it for public-tier transport today.
Customer authentication supports password and social sign-in paths. Operator production access is time-bounded and audited; privileged access and customer SSO controls follow the published Security Practices and contracted tier scope.
Production secrets are separated by environment and excluded from source control. Customer data and retrieval indexes are tenant-scoped; customer-controlled keys require an Enclave engagement.
Dependency, static-analysis, secret, and release checks run in the delivery pipeline. Security reports use the published RFC 9116 channel; breach notification obligations are stated in the DPA and Security Practices.
HEOSSI governs Bee's application, inference, data and external-capability boundaries. Named sub-processors and their processing purposes remain documented in the DPA schedule for customer due diligence.
Product facts are dual-signed with ML-DSA-65 and Ed25519. Capability claims are gated by live probes, and adapter releases require governed evaluation before activation.
| Standard | Algorithm | Role | Bee scope |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key encapsulation | Enclave Sovereign customer transport |
| FIPS 204 | ML-DSA | Digital signatures | Signed registers, attestations, and release artefacts |
| FIPS 205 | SLH-DSA | Hash-based signatures | Long-lived and offline attestation paths |
Post-Quantum Coverage Register
Every claim about how Bee protects data with post-quantum cryptography lives in a machine-readable register — hash-chained across versions and signed with ML-DSA-65 (NIST FIPS 204). Download the signed envelope and the public key below and verify the signature yourself; nothing here asks you to take our word.
21
Coverage rows
11 / 4 / 6
Covered / partial / excluded
10
Continuous probes
ML-DSA-65
Signature
Register hash (v0.9.9, 2026-07-07)
sha384:52d3e76d287fea787aaa51be7cb45c9eb080e489096b2d9efe8dbb748cb518a8648a7553656b03ff596e96670ce8366e
Signed envelope
ML-DSA-65 signature + public key + register hash
Register (JSON)
The canonical claims register — every row, probe, and gate
Coverage matrix
Human-readable rendering of the register
Verification key
Public key for the ML-DSA-65 signature
Verify it yourself
Verified citations
Each row links to the authoritative source. Right column is the date of the most recent re-verification.
| Claim | Source | Verified |
|---|---|---|
FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard ML-KEM (Kyber) standardised by NIST as the post-quantum KEM. Effective August 14, 2024. | csrc.nist.gov | 2026-07-19 |
FIPS 204 — Module-Lattice-Based Digital Signature Standard ML-DSA (Dilithium) standardised by NIST as the post-quantum digital signature. Effective August 14, 2024. | csrc.nist.gov | 2026-07-19 |
FIPS 205 — Stateless Hash-Based Digital Signature Standard SLH-DSA (SPHINCS+) standardised by NIST for hash-based signatures. Effective August 14, 2024. | csrc.nist.gov | 2026-07-19 |
Federal Register — Issuance of FIPS 203, 204, and 205 Official US government issuance of all three post-quantum cryptography standards. | www.federalregister.gov | 2026-07-19 |
OpenQuantum — unified real-QPU access and transparent pricing Public and Private Compute pricing, provider-credit terms, and current hardware providers across Rigetti, IQM, IonQ, and AQT. | www.openquantum.com | 2026-07-19 |
Bee Cell production inference — serverless Bee Cell production inference runs serverless; the public status page publishes live backend liveness (shown as 'Live — serverless production inference'). | bee.heossi.com | 2026-07-19 |
Parent company — HEOSSI (Pte.) Ltd. Singapore-incorporated parent. Tagline: 'Verifiable Trust · Continuous Resilience'. Compliance: CSA STAR Level 1, ISO track in progress. | www.heossi.com | 2026-07-19 |
Quantum Inspire 2.0 (TU Delft / QuTech) Free access (via registration) to QuTech's superconducting transmon backends — Tuna-5, Tuna-9, and Tuna-17 — plus simulators. (Starmon-7 and Spin-2+ are now legacy/retired.) | www.quantum-inspire.com | 2026-07-19 |
D-Wave Leap — free-trial QPU access The D-Wave Leap cloud platform offers free-trial access to quantum-annealing QPUs (apply via the Leap free trial). | www.dwavequantum.com | 2026-07-19 |
Xanadu Borealis — photonic quantum computing research Xanadu's public photonic quantum-computing research and platform information. | www.xanadu.ai | 2026-07-19 |
Microsoft Azure Quantum — IonQ, Pasqal, Quantinuum, Rigetti Pay-as-you-go access to IonQ, Pasqal, Quantinuum, and Rigetti quantum hardware through Azure Quantum. | learn.microsoft.com | 2026-07-19 |
Quantum hardware claims
These are Bee's reviewed OpenQuantum targets, not a claim that every provider backend is always online. Availability and job quotes come from the provider at request time; the local simulator is explicitly labelled and never presented as physical hardware.
Local statevector
Simulator
28qubits
Live service evidence
Cell through Hive inference is served behind HEOSSI’s Bee gateway. The health badge probes the configured operational backend and reports its measured round-trip; it is not a per-tier latency benchmark or an SLA. Model capabilities, assurance boundaries and current limitations are published through Bee’s own Models, TrustHub and status surfaces.
Live
Bee operational backend
api · api.bee.heossi.com/bee
Latency above is measured server-side to the configured backend and refreshed every 10 seconds. It does not measure token generation. Customer inference lanes scale to zero and may incur a cold start; response latency varies by tier, prompt length and generated output.
View Bee modelsCompliance posture
Certifications, ongoing assurance programmes and implemented controls are labelled separately.
CSA STAR Level 1
Cloud Security Alliance Self-Assessment listing for the parent HEOSSI (Pte.) Ltd.
ISO 27001
Information Security Management track in progress at the parent level.
GDPR / UK GDPR / PDPA
Operational privacy programme with published Privacy Policy and DPA, rights-request channels, retention and deletion controls, transfer terms, and breach procedures.
RFC 9116
Canonical security.txt and vulnerability-disclosure contacts are published at /.well-known/security.txt.
Privacy & data protection
Bee's Privacy Policy describes account and website data. The DPA governs customer data processed for business customers, including sub-processors and international transfer terms. Model-improvement use is off by default and requires the published opt-in path.
AI governance
Bee separates live capability evidence from roadmap intent, identifies AI-generated outputs, publishes model and training-source governance, restricts high-impact uses, and requires governed evaluation before a domain adapter enters production.
Assurance library
TrustHub is the index; the linked policies and machine-readable artefacts remain the canonical, versioned records. Counter-signed agreements and procurement evidence are available on request where applicable.
Found something we got wrong?
Inaccuracies on this page get fixed within one business day. Anything material gets a changelog entry too.