Trust & Operations
This page states the controls and contractual boundaries of the ColabHive offer. ColabHive does not claim enterprise certification where evidence has not been published.
Last reviewed: 8 September 2026 Public summary: colabhive.com/trust
Security posture
Available today:
- TLS for public API and web traffic;
- hashed API-key storage, expiration and revocation;
- versioned runtime images, request correlation IDs and model lineage;
- account-fenced datasets, trained models, endpoints, training runs, inference tasks and their artifacts. Account scoping controls visibility and invocation; public models remain global;
- enforced node-eligibility policy at account, workload and task level, with a downloadable placement attestation. See Data Protection & Placement.
Not a published guarantee today:
- granular API-key scope enforcement;
- project/environment RBAC and service accounts;
- workload mTLS and tenant-specific KMS;
- third-party pentest evidence, SOC 2 or ISO 27001.
Report a security issue to security@colabhive.com.
Capability contract map
This table is the short answer to “what behavior does the install provide?”. Shipped means the
named contract exists in the referenced service version; it does not widen the limitation column.
| Capability | State / minimum contract | Important limitation | Reproducible proof |
|---|---|---|---|
| Account-scoped datasets, endpoints and runs | Shipped / Builder 1.1.6+ for the complete dataset read/write surface | Visibility and invocation are not a universal physical-isolation claim | Builder/OpenAPI account context, dataset account-fence regressions and endpoint/training cross-account tests |
| Trained-model registry ownership | Shipped / Builder 1.1.7+ and Model Registry 0.1.1+ | models.account_id is the durable private-resource authority; owner_user_id records the creator and public models remain globally readable | models.account_id NOT NULL + FK, account-fence regressions and live cross-account denial |
| Account/workload/task node eligibility | Shipped / data-protection schema 20260905+ | Values select node classes, not country, provider or legal jurisdiction | Orchestrator OpenAPI data-protection routes, preflight and placement attestation |
| Cohort restrictive-key scope | Shipped / Cohort v1 | inference:execute is enforced only on the documented Cohort run/cancel/health surface; most Builder scopes remain account-wide | Cohort OpenAPI plus flags-scopes-errors contract tests |
| Typed stable JSON responses | Shipped / Builder 1.1.5+ | Proxy envelopes allow additive fields so older clients can preserve forward compatibility | Builder OpenAPI; contract test rejects {} on every stable JSON success response and rejects legacy validation schemas |
| Architecture/backend recognition | Registry snapshot, not validation | 393 active rows are routing candidates; 14 pairs are tested and 10 have numeric throughput in the published snapshot | Compatibility matrix and live HF compatibility check |
| Backup/restore | Internal operational evidence | No public recovery SLO or third-party-operated drill yet | Backup/restore runbook, scheduled isolated restore drill and artifact hashes |
| Node failure and reconnect | Implementation plus automated CockroachDB transition coverage | CI proves stale-heartbeat fencing, durable no-capacity requeue, idempotent replay, heartbeat recovery and sticky maintenance state against an isolated real database; an independent physical disconnect/reconnect drill is not yet published | G3d failover integration gate plus Orchestrator unit suite |
| Model Flywheel lifecycle | Merge/retrain shipped | candidate → ready is explicit operator action; no mandatory automated quality gate or automatic rollback | Merge/retrain API and lineage; lifecycle boundary in Flywheel docs |
The service reports its exact version in health and OpenAPI. If an installed version predates the minimum above, use that version's schema rather than this table.
Privacy and deployment boundary
Private Cluster is the default topology for customer-controlled nodes in a scoped deployment. Cloud Burst is an Enterprise add-on using the customer's DigitalOcean account and credential; the customer pays the provider directly, and ColabHive adds no fee on those charges. Share Hive is account-controlled, requires explicit opt-in and starts unselected. These operating paths do not create a universal residency or isolation guarantee.
Retention, deletion timing, subprocessors and DPA requirements are deployment-specific until a public enterprise policy is published. See the Privacy Notice and Private Agentic Infrastructure.
Operational status
status.colabhive.com is currently a health-entry and maturity page, not a historical uptime dashboard. Public component SLOs, incident history and availability percentages have not been published.
Live, read-only checks:
- Builder API health
- Capabilities
- Builder OpenAPI
- Orchestrator OpenAPI, including the data-protection and placement-attestation routes
Service levels
There is no general public uptime SLA. Availability, latency, throughput and recovery targets apply only when written into a customer agreement. Product labels are not substitutes for an SLA. The standard Enterprise support boundary is:
| Commitment | Standard Enterprise term |
|---|---|
| Coverage | 8x5 for two authorized contacts |
| P1/P2 response | Within four business hours |
| P3 response | Within one business day |
| P4 response | Within two business days |
| Advisory | Up to two hours per month |
| Uptime | No general uptime SLA |
Public API-contract limits
The API is versioned and publishes separate Builder and Orchestrator OpenAPI 3.1 contracts. Runtime
errors use the stable error.code/message/details/request_id envelope. Every stable JSON success
response in Builder 1.1.5+ has a schema; proxy envelopes deliberately permit additive fields for
forward compatibility. API-key scopes are not enforced generally, with Cohort
inference:execute as the documented exception. The exact boundaries are in the
API Reference.