Skip to content

Bee TrustHub

Security, compliance and verification in one place.

The central assurance centre for Bee: security controls, privacy and data protection, compliance status, AI governance, signed evidence, live verification, legal documents, and responsible-disclosure channels.

Standards-backed cryptography

Bee's PQC stack is not a custom protocol. Every algorithm we ship is a NIST-finalized standard with a published reference, an effective date, and a test-vector suite.

Operational evidence

Bee's six governed production tiers publish live service status, model specifications and capability evidence separately from roadmap intent.

Verifiable corporate identity

Bee is a Singapore product built and operated by HEOSSI (Pte.) Ltd., a Singapore-incorporated entity with published legal, security and corporate contact information.

Model assurance

Bee is a stable, governed model family with controlled releases.

Bee Cell, Brood, Comb, Buzz, Hive and Swarm are HEOSSI product and release names. Cell through Hive are controlled model releases with immutable release identities; Swarm is a versioned routing fabric across eligible lanes. Release lineage, technical specifications, capability probes and release approval are related—but they are not the same claim. TrustHub keeps those evidence layers separate.

Bee Cell

Free, fast multimodal entry tier

Active

Governed production model with capability evidence and release controls.

Bee Brood

Cost-efficient multimodal reasoning

Active

Governed production model with capability evidence and release controls.

Bee Comb

Structured multimodal workhorse

Active

Governed production model with capability evidence and release controls.

Bee Buzz

Agent and builder workhorse

Active

Governed production model with capability evidence and release controls.

Bee Hive

High-capability specialist intelligence

Active

Governed production model with capability evidence and release controls.

Bee Swarm

Premium distributed intelligence

Active

Governed production model with capability evidence and release controls.

1 · Foundation evidence

Controlled lineage records bind architecture, licensing and the exact foundation revision used by a Bee release.

2 · Bee capability evidence

Live probes verify what Bee actually serves. Current register: 2026-07-14.

3 · Immutable release

Each Bee alias resolves to a dated release binding the base revision and complete adapter-set digest.

4 · Governed promotion

Candidates require held-out evaluation, release checks and rollback readiness before activation.

Security centre

Controls, boundaries and disclosure—stated at their real scope.

Shared public tiers and contracted Enclave deployments do not have identical security boundaries. Public Bee uses standard TLS 1.3 today. Enclave Sovereign adds the NIST-finalized post-quantum transport stack. The formal control descriptions, response commitments, and vendor-risk detail remain in the Security Practices document.

Encryption boundaries

Public Bee uses TLS 1.3 in transit and AES-256-GCM at rest. NIST post-quantum transport is default-on for separately contracted Enclave Sovereign deployments; we do not claim it for public-tier transport today.

Identity & least privilege

Customer authentication supports password and social sign-in paths. Operator production access is time-bounded and audited; privileged access and customer SSO controls follow the published Security Practices and contracted tier scope.

Secrets & tenant isolation

Production secrets are separated by environment and excluded from source control. Customer data and retrieval indexes are tenant-scoped; customer-controlled keys require an Enclave engagement.

Vulnerability & incident response

Dependency, static-analysis, secret, and release checks run in the delivery pipeline. Security reports use the published RFC 9116 channel; breach notification obligations are stated in the DPA and Security Practices.

Infrastructure governance

HEOSSI governs Bee's application, inference, data and external-capability boundaries. Named sub-processors and their processing purposes remain documented in the DPA schedule for customer due diligence.

Verifiable releases

Product facts are dual-signed with ML-DSA-65 and Ed25519. Capability claims are gated by live probes, and adapter releases require governed evaluation before activation.

NIST post-quantum standards used by Bee
StandardAlgorithmRoleBee scope
FIPS 203 ML-KEMKey encapsulationEnclave Sovereign customer transport
FIPS 204 ML-DSADigital signaturesSigned registers, attestations, and release artefacts
FIPS 205 SLH-DSAHash-based signaturesLong-lived and offline attestation paths

Post-Quantum Coverage Register

Our PQC claims, as signed code you can verify

Every claim about how Bee protects data with post-quantum cryptography lives in a machine-readable register — hash-chained across versions and signed with ML-DSA-65 (NIST FIPS 204). Download the signed envelope and the public key below and verify the signature yourself; nothing here asks you to take our word.

v0.9.9 · signed

21

Coverage rows

11 / 4 / 6

Covered / partial / excluded

10

Continuous probes

ML-DSA-65

Signature

Register hash (v0.9.9, 2026-07-07)

sha384:52d3e76d287fea787aaa51be7cb45c9eb080e489096b2d9efe8dbb748cb518a8648a7553656b03ff596e96670ce8366e

Verify it yourself

  1. Download the signed envelope and the verification key above.
  2. Canonicalise the register JSON (UTF-8, lexicographically sorted keys, compact separators) and hash it with SHA-384 — it must equal the envelope’s register hash.
  3. Verify the ML-DSA-65 signature over that canonical byte stream against the published public key.

Verified citations

Every fact, linked.

Each row links to the authoritative source. Right column is the date of the most recent re-verification.

machine-readable: /llms.txt
ClaimSourceVerified

FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard

ML-KEM (Kyber) standardised by NIST as the post-quantum KEM. Effective August 14, 2024.

csrc.nist.gov2026-07-19

FIPS 204 — Module-Lattice-Based Digital Signature Standard

ML-DSA (Dilithium) standardised by NIST as the post-quantum digital signature. Effective August 14, 2024.

csrc.nist.gov2026-07-19

FIPS 205 — Stateless Hash-Based Digital Signature Standard

SLH-DSA (SPHINCS+) standardised by NIST for hash-based signatures. Effective August 14, 2024.

csrc.nist.gov2026-07-19

Federal Register — Issuance of FIPS 203, 204, and 205

Official US government issuance of all three post-quantum cryptography standards.

www.federalregister.gov2026-07-19

OpenQuantum — unified real-QPU access and transparent pricing

Public and Private Compute pricing, provider-credit terms, and current hardware providers across Rigetti, IQM, IonQ, and AQT.

www.openquantum.com2026-07-19

Bee Cell production inference — serverless

Bee Cell production inference runs serverless; the public status page publishes live backend liveness (shown as 'Live — serverless production inference').

bee.heossi.com2026-07-19

Parent company — HEOSSI (Pte.) Ltd.

Singapore-incorporated parent. Tagline: 'Verifiable Trust · Continuous Resilience'. Compliance: CSA STAR Level 1, ISO track in progress.

www.heossi.com2026-07-19

Quantum Inspire 2.0 (TU Delft / QuTech)

Free access (via registration) to QuTech's superconducting transmon backends — Tuna-5, Tuna-9, and Tuna-17 — plus simulators. (Starmon-7 and Spin-2+ are now legacy/retired.)

www.quantum-inspire.com2026-07-19

D-Wave Leap — free-trial QPU access

The D-Wave Leap cloud platform offers free-trial access to quantum-annealing QPUs (apply via the Leap free trial).

www.dwavequantum.com2026-07-19

Xanadu Borealis — photonic quantum computing research

Xanadu's public photonic quantum-computing research and platform information.

www.xanadu.ai2026-07-19

Microsoft Azure Quantum — IonQ, Pasqal, Quantinuum, Rigetti

Pay-as-you-go access to IonQ, Pasqal, Quantinuum, and Rigetti quantum hardware through Azure Quantum.

learn.microsoft.com2026-07-19

Quantum hardware claims

Real backends. Verifiable backend names.

These are Bee's reviewed OpenQuantum targets, not a claim that every provider backend is always online. Availability and job quotes come from the provider at request time; the local simulator is explicitly labelled and never presented as physical hardware.

rigetti:cepheus-1-108q

Superconducting

108qubits

OpenQuantum Docs

iqm:emerald

Superconducting

54qubits

OpenQuantum Docs

iqm:garnet

Superconducting

20qubits

OpenQuantum Docs

Local statevector

Simulator

28qubits

Live service evidence

Bee publishes operational status.

Cell through Hive inference is served behind HEOSSI’s Bee gateway. The health badge probes the configured operational backend and reports its measured round-trip; it is not a per-tier latency benchmark or an SLA. Model capabilities, assurance boundaries and current limitations are published through Bee’s own Models, TrustHub and status surfaces.

Live

Unavailable

Bee operational backend

api · api.bee.heossi.com/bee

Latency above is measured server-side to the configured backend and refreshed every 10 seconds. It does not measure token generation. Customer inference lanes scale to zero and may incur a cold start; response latency varies by tier, prompt length and generated output.

View Bee models

Compliance posture

Where we are, where we're going.

Certifications, ongoing assurance programmes and implemented controls are labelled separately.

Achieved

CSA STAR Level 1

Cloud Security Alliance Self-Assessment listing for the parent HEOSSI (Pte.) Ltd.

In progress

ISO 27001

Information Security Management track in progress at the parent level.

Operational

GDPR / UK GDPR / PDPA

Operational privacy programme with published Privacy Policy and DPA, rights-request channels, retention and deletion controls, transfer terms, and breach procedures.

Implemented

RFC 9116

Canonical security.txt and vulnerability-disclosure contacts are published at /.well-known/security.txt.

Privacy & data protection

Rights, processing roles and data boundaries.

Bee's Privacy Policy describes account and website data. The DPA governs customer data processed for business customers, including sub-processors and international transfer terms. Model-improvement use is off by default and requires the published opt-in path.

AI governance

Capability truth, release gates and human oversight.

Bee separates live capability evidence from roadmap intent, identifies AI-generated outputs, publishes model and training-source governance, restricts high-impact uses, and requires governed evaluation before a domain adapter enters production.

Assurance library

Documents for users, security teams and procurement.

TrustHub is the index; the linked policies and machine-readable artefacts remain the canonical, versioned records. Counter-signed agreements and procurement evidence are available on request where applicable.

Found something we got wrong?

Tell us — we'd rather correct it than defend it.

Inaccuracies on this page get fixed within one business day. Anything material gets a changelog entry too.