Solutions

Three products for compliance evidence that can be verified: Attest for signing and records, the Hubz platform for compliance programs, and Rubro for security assessments. Hubz VCE anchors their evidence on public blockchains, and the CSE Registry gives it a shared vocabulary.

01 / 03

Signing and verifiable evidence

Attest

Attest signs documents and records evidence so that anyone can verify it without trusting DataHubz. Signers use a passkey, documents are encrypted in the browser, and every completed record is anchored on Horizen, with zero-knowledge proofs verified on zkVerify.

  • Document signing

    Passkey signatures with Face ID or a fingerprint. Signers need no account and no password.

  • End-to-end encryption

    Documents are encrypted in the browser before upload. Attest stores only data it cannot read.

  • Signed copies that prove themselves

    Each party receives the same sealed copy, with a certificate, an audit trail and an embedded verifier.

  • Receipts, certificates and Proof Cards

    Timestamped receipts for any record, and credentials issued as W3C Verifiable Credentials.

  • Zero-knowledge proofs

    Prove that a party signed an agreement on a date without revealing the document. Verified on zkVerify.

  • Integrations API and SDK

    Platforms register organizations, record events and receive webhooks. The SDK is open source.

02 / 03

Compliance platform

Hubz platform

Hubz is where compliance work is done and documented: frameworks, controls, roadmaps, documents, evidence, reviews and monitoring in one workspace. Each compliance activity is recorded through Attest, and only its SHA-256 fingerprint leaves the platform.

  • Any compliance framework

    NIST CSF, HIPAA, CMMC, SOC 2, ISO 27001, HITRUST and more. Each organization activates the frameworks it needs, with controls, roadmaps and template documents.

  • Evidence management

    Collect, review and approve evidence per control, with audit reports generated from the same data.

  • Auditor workspace

    Invite assessors with access limited to the frameworks in scope, for control and evidence reviews.

  • Continuous monitoring

    Microsoft 365, Entra, Intune and Google Workspace connections, plus email security checks.

  • Verifiable activity

    Fourteen activity types, such as evidence reviewed or control audited, are each anchored on Horizen.

  • Daily posture proofs

    Each day's compliance state is proven in zero knowledge and verified on zkVerify.

03 / 03

Security assessments

Rubro

Rubro runs authorized penetration tests and security assessments from the legal paperwork to the final report. Scope and authorization are enforced by the platform, and the evidence it produces can be recomputed by an auditor.

  • Authorization enforced in code

    Statement of work, rules of engagement and authorization letter come first. No tool runs outside the signed scope or window.

  • Client-controlled stop

    The client can halt all testing at once. Resuming requires both parties to sign.

  • Findings mapped to controls

    CVSS 3.1 and MITRE ATT&CK, with recommendations mapped to NIST CSF 2.0, NIST 800-53 r5, CIS v8.1 and ISO 27001:2022.

  • Protected evidence

    Encrypted, write-once, object-locked storage, with a hash-chained audit log and Merkle inclusion proofs.

  • Client portal

    Scope, findings, coverage, retests and deliverables, in English and Spanish.

  • Completion certificates

    Issued on Attest, with a zero-knowledge proof that no findings remain open.

Hubz VCE

The engine underneath

Hubz VCE is the verifiable compliance engine behind Attest, the Hubz platform and Rubro. It anchors evidence on Horizen and proves it with zero-knowledge proofs verified on zkVerify. Anyone can check the results on the public explorers, with no account and no API key.

vce.datahubz.com
CSE Registry

An open standard for compliance signals

The Compliance Signal Enumeration (CSE) Registry defines stable identifiers for technical signals that matter in compliance, and maps them to framework controls. It is published under the Apache 2.0 license, maintained in the open, and free for any tool to use.

1,100+

Signals

2,062

Mappings

12

Frameworks

More solutions, available on request

DataHubz has built more than what is listed above. These solutions are available for specific needs; talk to us to see whether one fits yours.

GuardGit

A Git platform that scans repositories against compliance frameworks and records the results on chain.

Contact sales
VeraComply

A compliance assistant that runs inside your own environment, with answers linked to their sources.

Contact sales
VeriCode

An attestation engine that anchors evidence on Horizen and proves it with Groth16 proofs.

Contact sales

Step into the future of compliance.

Prove what you're doing, not just claim it. Build on infrastructure designed for clarity, confidence, and verifiable trust.