§ FAQ
Common questions, grounded answers.
If your question is not here, use the public contact address to reach Charles directly.
- Q.01Is SecHive safe to run against production?Research is limited to owned systems, purpose-built targets, or systems with explicit authorization. External actions and exploit execution require human approval. Production testing must follow the written authorization and the target owner's change and safety procedures.
- Q.02What does SecHive actually do that a scanner does not?SecHive routes recon signals into specialist skills, builds a hypothesis graph, validates candidates against the live target, and bundles a proof pack with hashed artifacts and a deterministic replay script. A scanner gives you a list. SecHive gives you a chain.
- Q.03Does SecHive replace a human operator?No. SecHive accelerates the human review path by producing artifacts the reviewer can defend. Novel research, edge-case judgement and final disposition stay with the operator.
- Q.04Can SecHive run offline / locally?The research workflow is local-first, and restricted or sensitive artifacts are handled locally unless they must be shared deliberately for coordinated disclosure, authorized collaboration, or backup.
- Q.05Does SecHive produce compliance certification?No. SecHive produces technical evidence aligned to framework articles. Certification is an organizational outcome that depends on a qualified auditor or assessor. Read the boundary in the compliance hub.
- Q.06How are findings priced into a report?Each promoted finding ships with severity (CVSS:4.0), business impact, runtime evidence, source references when available, remediation guidance and a retest record. Reports are mode-specific (pentest, bug bounty, internal source review).
- Q.07Does SecHive retain my data?The public site has no account registration or contact form. Sensitive research artifacts are handled locally first; email and hosting providers may retain correspondence or request logs under their own documented policies. See the privacy page.
- Q.08Will SecHive submit to my bug bounty platform automatically?No. Submission is a human action. SecHive produces a HackerOne-shaped report, redaction manifest and replay script — the operator decides what is submitted, when, and to which program.
- Q.09How do you handle false positives?Source candidates and runtime findings are different objects in the proof pack. A source candidate that fails runtime validation is recorded as refuted and stays in the negative-evidence set — never promoted to the report.
- Q.10Can my consultancy white-label the report?Public packaging and collaboration options are still being defined. Contact SecHive with the authorized use case; the site does not promise a white-label, licensing, or CI/API offering.
- Q.11Does SecHive provide customer access to advanced AI accounts?No. SecHive does not provide customers or third parties with access to operator AI accounts or credentials. Any advanced model access used for internal research remains under the sole operator's control and is not proxied, resold, or embedded as downstream model access.
- Q.12How is SecHive different from XBOW, Shannon, PentAGI or Strix?All four are interesting projects. SecHive's distinguishing point is the per-finding chain of evidence, the policy-gated benign-PoC validation, the proof pack format, and the operator UI. I do not claim unique capability; I focus on making the work survivable in review.
- Q.13What targets is SecHive designed for?Web applications, APIs, mobile (Android / APK), cloud configuration, source repositories, and binary targets at the triage level. Active Directory and on-prem network are scoped via the GOAD benchmark framework, with public scorecards in 2026.Q3.