Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

About Bidda — 10,085 Verified Compliance Nodes

World's first cryptographically-verified compliance intelligence registry. 10,085 nodes across 39 regulatory domains. Primary sources only.

10,000-NODE MAINNET REACHED: 10,085 VERIFIED NODES ACROSS 39 PILLARS
BUILT FOR THE
AGENTIC ECONOMY

The world's first source-verified, cryptographically-signed compliance intelligence registry - where regulatory law becomes deterministic, auditable, machine-executable logic.

Used by compliance officers to verify regulatory positions and by AI development teams to reduce hallucination risk in automated workflows. Same verified data - two interfaces.

10,085
VERIFIED NODES
39
SOVEREIGN PILLARS
$0.01
PER NODE ACCESS
4ms
AVG LATENCY
WHO BUILDS BIDDA
About the Architect: Patrick Nel

A small team of operators.
Direct Contact: [email protected]

Bidda Intelligence is sovereign compliance infrastructure built for the age of autonomous agents. It is backed by nearly two decades of systems engineering and cybersecurity experience.

My engineering foundation is rooted in Industrial Control Systems (ICS) and physical telemetry. For 10 years, I architected and maintained SCADA grids and overfill safety systems for major petrochemical companies. When securing physical infrastructure, safety and compliance cannot rely on probability. They require deterministic, hardcoded rules.

Over the past seven years, my focus has shifted to deep-level cybersecurity, infrastructure hardening, and vulnerable system testing. Today, I operate Bidda Intelligence alongside a small, highly specialized team of developers who share this zero-tolerance engineering philosophy.

We built Bidda Intelligence to bridge the gap between deterministic physical security and AI software. As developers rapidly deploy autonomous agents, relying on probabilistic LLM memory to handle strict legal compliance is a systemic risk. We apply the rigor of SCADA systems to AI orchestration. Bidda Intelligence provides a cryptographic fail-safe, operating as a headless MCP server designed to help enterprise teams deploy AI confidently, without relying on probabilistic model memory.

INSTITUTIONAL TRUST SIGNALS


Registered: BIDDA INTELLIGENCE (PTY) LTD

CIPC enterprise number: 2026/363776/07

Registered office: Cape Town, Republic of South Africa

Operating jurisdiction: International, governed by SA law

Public legal trio: Terms, Privacy, Disclaimer

Live integrity endpoint: /api/v1/registry-health.json

Methodology: /methodology

Verify a node: /verify

Contact: [email protected]
The Cost of Getting Compliance Wrong

A single incorrect compliance assumption - in healthcare, finance, or data privacy - can trigger regulatory fines in the millions, enforcement action, or personal liability for directors. AI systems that summarise regulations without citing primary sources make this risk worse, not better. Bidda eliminates the guesswork: every node traces directly to its authoritative legal source, so your team and your AI systems are working from the same verified, primary-source traceable foundation.

📋
For Compliance Officers

Each node is a regulation or standard distilled into plain-English guidance - what it requires, what it applies to, and how it connects to related frameworks. Browse by sector, search by regulation name, or follow the dependency chain to understand your full compliance picture. Every claim cites the exact clause it comes from.

🔐
Source-Verified Data Integrity

Every node is cryptographically signed. When a framework is updated by its issuing authority - ISO, NIST, WIPO, the EU, or a national regulator - our pipeline is re-triggered, the node is re-verified against the new source, and re-published. Your compliance team and your AI systems are always working from current law, not last year's version.

🏛️
Primary Sources Only

No commentary. No interpretation. No paraphrasing. Every node cites the original regulatory text - legislation.gov, EUR-Lex, Federal Register, NIST, ISO, WIPO. If you need to defend a compliance position in an audit or legal proceeding, the citation is right there, with the section reference.


Agent-Native by Design

For AI development teams: the same verified data powers a machine-executable logic graph that autonomous agents can query, verify, and chain - via REST API with $0.01 micropayment settlement per node. Reduced hallucination risk. No stale training data. Compliance intelligence delivered at inference speed.

What is a Compliance Node?

For compliance teams and AI engineers new to the registry.

A compliance node is a single regulation, standard, or enforcement framework (for example, GDPR Article 32 (Security of Processing) or NIST AI RMF Govern 1.1), distilled into a 13-key machine-readable JSON object that both humans and AI agents can query.


Plain-English Summary

What the regulation requires in one paragraph. No legal jargon.


Step-by-Step Logic

A compliance workflow your team or AI agent can execute, with decision branches.


Automated Checklist

Machine-executable checklist items mapped directly to the regulation text.


Primary Legal Citations

Avg 7 citations per node: exact clause references to the original instrument.


Framework Crosswalks

How this regulation maps to NIST, ISO, EU AI Act, GDPR, and 150+ other standards.


Prerequisite Nodes

Which other nodes you must comply with first: your full compliance chain.

Each node also carries a SHA-256 integrity hash and a verified source URL, so any claim can be traced back to the original regulatory text by your team, your auditors, or an independent reviewer.


ALWAYS VERIFY BEFORE YOU IMPLEMENT

Bidda nodes are reference intelligence, not legal advice. Every node must be reviewed and confirmed by a qualified compliance professional, legal counsel, or regulatory specialist before it is implemented in any enterprise workflow, regulated system, or compliance programme.

BEFORE IMPLEMENTING ANY NODE, CONFIRM:


The node covers the correct jurisdiction for your business

No superseding amendment has been issued since the node's last_updated date

Your specific business activity falls within the regulation's scope

Any dependent nodes in the chain have also been reviewed

WHY THIS MATTERS NOW:


EU GDPR fines exceeded €1.6 billion in 2023 alone

EU AI Act penalties reach €35M or 7% of global turnover

DORA (EU financial resilience) became enforceable January 2025

Regulators globally have increased enforcement frequency and fine sizes

Bidda provides the verified data layer. Your qualified team is responsible for how that intelligence is applied to your specific business context. See our full Legal Disclaimer for complete terms.

The Full Roadmap

From Foundation to the 10,000-Node Global Intelligence Standard: every phase, every goal, every milestone.

PHASE 1
COMPLETE
FOUNDATION

Q1 2026

100%
COMPLETE
502
NODES PUBLISHED
16
SOVEREIGN PILLARS
7+
AVG CITATIONS / NODE

Launched the Intelligence Forest with 502 verified nodes spanning 16 sovereign sectors. Every node cryptographically signed, source-verified against primary legal instruments, and structured with a deterministic step-by-step compliance workflow ready for agentic consumption at $0.01 per unlock.

PHASE GOALS

Design and finalise the 13-key Bidda node schema, the machine-executable compliance standard

Build the two-tier API: Discovery (free, 6 fields) + Vault (gated, full 13 keys)

Integrate Skyfire JWT bearer tokens for autonomous AI agent settlement at $0.01/node

Deploy the edge payment gateway at bidda.com/api/v1/vault/*

Publish first 502 nodes with zero critical schema violations across 16 sovereign pillars
KEY ACHIEVEMENTS

13-key node schema finalised: node_id, title, domain, bluf, deterministic_workflow, actionable_schema, primary_citations, crosswalks, dependencies, verification, paywall, version, last_updated

Skyfire micropayment integration, now listed on the Skyfire Directory for enterprise agent payments

L402/x402 USDC payment path on Base network at $0.01 per node, settled onchain

Pre-commit git hook blocking any node with critical schema violations from reaching production

13-point automated validation gate with zero tolerance for malformed or incomplete nodes
PHASE 1.5
COMPLETE
AI REGULATION SPRINT

April 2026

100%
COMPLETE
+493
NODES ADDED
995
TOTAL AT SPRINT END
39
SOVEREIGN PILLARS

April 2026 brought the largest single regulatory intelligence update in Bidda's history, spanning every major pillar from AI Governance and Cybersecurity to Banking, Healthcare, ESG, and beyond. Every node source-verified and citation-audited before publishing. No invented content. Reduced hallucination risk.

PHASE GOALS

Expand to all 39 sovereign pillars with no pillar left empty

Achieve full AI Governance coverage: EU AI Act, NIST AI RMF, ISO/IEC 42001, Anthropic RSP

Complete the dependency graph with every prerequisite node chain fully resolved

Reach the 1,000-node milestone with zero critical violations

Confirm Skyfire Directory listing for real enterprise agent payment authorisation
KEY ACHIEVEMENTS

AI Governance & Law: EU AI Act enforcement wave, NIST AI RMF full coverage, ISO/IEC 42001 AIMS, Anthropic RSP

Banking & Finance: APRA CPS 230, Basel operational risk, FATF AML/CFT, DORA enforcement provisions

Cybersecurity: NIST CSF 2.0, FIPS Post-Quantum Cryptography, CIS Controls v8, NIS2 Directive

Medical & Healthcare: FDA SaMD guidance, HIPAA Security Rule, HL7 FHIR interoperability standard

Legal & IP Sovereignty: WIPO copyright frameworks, cross-border data transfer regimes, Brussels I Recast

Full pillar coverage: Logistics, ESG, Workplace, Aviation Defense, Crypto, Industrial IoT, Operations, Telecoms

10,085 nodes live. Every one traceable to a primary source. Reduced hallucination risk. No invented content.

PHASE 2
COMPLETE
GLOBAL SCALE

Q1-Q2 2026

100%
COMPLETE
10,085
TOTAL NODES
39
ACTIVE PILLARS
0
BROKEN DEP LINKS

10,085 verified nodes live across 39 sovereign pillars. The 1,500-node milestone was exceeded by more than 2x. Every node passed 13-key validation, primary citation audit, and dependency-graph verification before publication. Three payment paths live. Zero placeholder content remaining.

PHASE GOALS

Scale beyond 1,500 nodes. Target exceeded: 10,085 verified nodes now live

Expand into LatAm, India, MENA, and multilateral AI governance frameworks (Sprint K)

Fill thin pillars: Industrial IoT, Workflow Automation, Maritime, Biotech, Mining, Space Law (Sprint M)

Eliminate all placeholder content for 100% primary-source verified coverage at every node

Remove all vendor and secondary-source nodes, keeping only sovereign primary-law sources

Confirm all three payment paths live: Skyfire + L402/USDC on Base + Direct Base USDC
KEY ACHIEVEMENTS

Sprint K: AI supply chain, LatAm/MENA data protection, India regulatory depth. 74 nodes accepted after full Layer 1 + Layer 2 review

Sprint M: thin pillar depth fill across Industrial IoT, Maritime, Biotech, Mining, Space Law. 33 nodes accepted

All 6,959 placeholder instances across 837 nodes eliminated (2026-04-30): every workflow step now reflects real regulatory procedure

15 vendor/secondary nodes quarantined. Registry now entirely sovereign primary-law sourced

Three payment paths confirmed live: Skyfire pay+jwt, L402/USDC on Base, and Direct Base USDC

39 active pillars, zero empty. Dependency graph: zero broken links across all nodes.
PHASE 3
ACTIVE
SOURCE INTEGRITY WATCHER

April 2026 →

85%
COMPLETE
3,687
URLS FINGERPRINTED
Weekly (Mon 02:00 UTC)
WATCHER CADENCE
99.9%
VERIFICATION COVERAGE

Weekly TLS SPKI fingerprint and content SHA-256 hash of every primary source URL across the registry. The tamper-evident manifest is committed to git on every run, building a tamper-evident audit chain that stands up to independent scrutiny. Verification block schema enriched with jurisdiction, instrument_type, and effective date fields.

PHASE GOALS

Weekly automated source integrity watcher to catch regulatory amendments within 7 days

Fingerprint every primary source URL by TLS certificate (SPKI hash) and content (SHA-256)

Build a tamper-evident git Merkle chain: each Monday commit is an immutable, timestamped record

Publish a live health endpoint so compliance officers can verify registry integrity in real-time

Enrich verification blocks with jurisdiction (ISO 3166), instrument_type, effective_date, and enactment_date

v2: amendment detection triggers automated diff PR, human review, and node update workflow
IN PROGRESS

TLS SPKI hash silently detects certificate replacement or domain hijacking before your compliance team notices

Content SHA-256 detects regulatory amendments before most compliance teams receive formal notification

Git Merkle chain: every Monday commit is a timestamped, immutable record in the audit history

Live health endpoint at bidda.com/api/v1/registry-health.json, zero-config for compliance officers

Path B verification enrichment: 2,328 nodes enriched with ISO 3166 jurisdiction, 1,742 with instrument_type

v2 roadmap: amendment diff → automated PR with source comparison → human review → node update
PHASE 4 (UNPLANNED)
ACTIVE
AGENT INTELLIGENCE LAYER

May 2026 →

90%
COMPLETE
111
ATLAS TECHNIQUES
8
MCP TOOLS LIVE
1
FREE SAMPLE NODE

High-leverage platform layer shipped May-June 2026: the MITRE ATLAS adversarial AI crosswalk (111 techniques across 16 attack tactics mapped to compliance coverage), an MCP server exposing 8 free tools to any Claude- or watsonx-orchestrated agent, the /scan endpoint for real-time agentic compliance mapping, a free full-access sample vault node for buyer trust, and the public /verify hash-lookup endpoint that returns timestamp, source URL, SHA-256 hash and TLS fingerprint for any node.

PHASE GOALS

Crosswalk all 111 MITRE ATLAS adversarial AI techniques against Bidda sovereign compliance coverage

Release a free, zero-config GitHub Action for automated compliance gap detection in CI/CD pipelines

Publish one full vault-tier node publicly with no payment required, to demonstrate tangible buyer value

Launch /verify: node_id input, timestamp, SHA-256, TLS fingerprint, and integrity match status

Establish Bidda as a platform and tooling layer, not just a data registry, for enterprise compliance teams
IN PROGRESS

MITRE ATLAS × Bidda: 111 adversarial AI techniques across 16 attack tactics mapped to sovereign compliance nodes

MCP server live with 9 free tools (list_pillars, search_nodes, get_node, get_dependency_chain, get_crosswalk, get_latest_changes, get_jurisdiction_bundle, get_mitre_mapping, check_action_compliance). The Model Context Protocol is an open standard reachable from Claude, IBM watsonx Code Assistant, and other MCP-enabled clients.

/scan endpoint: real-time agentic compliance mapping for LangChain, MCP, biometric, and credit-decisioning patterns

Free sample node: full EU AI Act Article 10 vault node publicly accessible without payment gate

/verify endpoint live: input any node_id, get timestamp, source URL, SHA-256 hash, TLS fingerprint, and tamper-evident match status

Agent-to-agent payment flow validated at production scale: Skyfire JWT + L402 USDC confirmed

Every Phase 4 item was unplanned. All shipped because they were the highest-leverage platform signals available at this stage of the build.

PHASE 4.5
ACTIVE
ENTERPRISE TIER, PAYSTACK SUBSCRIPTIONS & SELF-SERVE ACCOUNT

May-June 2026 →

80%
COMPLETE
Live
PAYSTACK ZAR SUBS
Live
SELF-SERVE ACCOUNT
bidda-shield 0.3.0
PYPI SDK

Recurring revenue infrastructure shipped. Paystack-backed ZAR subscription billing is live in production through the edge payment gateway. A full /account self-serve surface with magic-link recovery, per-call audit logging, and API key rotation is live for paying customers. The bidda-shield Python SDK is published on PyPI with full MCP parity. Enterprise contact intake captures Fortune-500 leads through a form-handling sub-processor. The remaining 20% is final Paystack PLN activation, first enterprise contracts, and the auto-updater scheduled cron going to v1.

PHASE GOALS

Ship recurring subscription billing for non-crypto buyers via Paystack ZAR plans (Starter, Pro, Enterprise)

Build /account self-serve: subscription state, API key, magic-link recovery, audit-log download, plan upgrade

Publish bidda-shield Python SDK on PyPI with full MCP-server parity for LangChain, AutoGen, CrewAI

Add enterprise contact intake on /pricing and /contact for direct buyer conversations

Launch /verify endpoint: node_id input returns timestamp, source URL, SHA-256 hash, and TLS fingerprint

Ship the Node Auto-Updater Tuesday cron: amendment detection → pending_nodes staging → PR review → merge
IN PROGRESS

Paystack live: ZAR recurring subscriptions running through the edge payment gateway against api.paystack.co with webhook handler and persisted subscription state

/account self-serve surface: subscription view, API key display and rotation, per-call audit log, magic-link recovery via an email-delivery sub-processor

bidda-shield 0.3.0 on PyPI: 9 MCP-parity methods + api_key auth + LangChain, AutoGen, CrewAI wrappers, installable with pip install bidda-shield

/verify page live: cryptographic proof of node integrity visible to compliance officers without requiring API access

Enterprise contact intake on /pricing and /contact: form-handling captures company, use case, and email

Auto-updater v1 wiring: scheduled weekly cron with material-change filter and cascading verifier pipeline, ~$10-20/mo budget

Target: first $20M ARR run-rate, the inflection point for enterprise SaaS pricing and seat-based licensing
PHASE 5
COMPLETE
10,000 NODE MAINNET: REACHED

July 2026

100%
COMPLETE
10,000
MILESTONE
10,085
NODES LIVE
None
PILLAR LIMIT

The full-coverage milestone for global regulatory intelligence, reached in July 2026. 10,085 verified nodes are live across 39 sovereign pillars, every one generated with mandatory human review and traceable to a primary legal source. The registry keeps growing under the same verification gates, with the weekly source watcher and the human-reviewed auto-updater holding every node current against its source.

PHASE GOALS

Scale to 10,000 verified nodes with no upper pillar limit. New pillars are added as regulatory coverage demands

Generation pipeline with a constrained frontier-tier extraction model + mandatory human PR review at every step

Broad jurisdictional coverage: G20 nations, EU member states, and active multilateral frameworks

Node Auto-Updater live at scale, with source amendments detected within 7 days

Verification block enrichment: jurisdiction + instrument_type + effective_date coverage

Enterprise-ready state with full schema integrity and source-verified accuracy at scale
KEY ACHIEVEMENTS

10,085 nodes across 39 sovereign pillars. Every major regulated industry globally covered at primary-source depth

Node generation pipeline with mandatory Layer 1 accuracy gate + Layer 2 human review against primary source

Source-verified accuracy maintained at scale: zero placeholder markers in production, zero broken dependency links

Weekly source watcher checks every node against its primary source within 7 days of any regulatory amendment

Dependency graph integrity at 10,085 nodes: complete chain traceability across every sovereign pillar

Revenue thesis: predictable enterprise SaaS recurring revenue at scale, anchored to subscription licensing and per-node API volume
PHASE 6
ACTIVE
GOVERNED AI EVIDENCE LAYER + ENTERPRISE SCALE

H2 2026

70%
COMPLETE
25
MCP + SDK TOOLS
4
SIGNED RECORD TYPES
Public
VERIFICATION

The evidence layer auditors ask AI operators for. Signed decision attestations, point-in-time records, governed runs that pin the exact version and fingerprint of every rule an agent consulted, sealed run receipts, control attestations, and a public append-only transparency log built the same way as Certificate Transparency. Evidence exports as a NIST OSCAL assessment-results document so it drops into existing GRC tooling. Everything verifies against Bidda's published keys with no Bidda account. These support an audit trail and are never a determination that an obligation was met.

PHASE GOALS

Enterprise contracts on the subscription and enterprise API tiers

Deeper GRC and audit-tooling integrations on top of the OSCAL export

Registry growth beyond 10,000 nodes under the same 4-gate verification pipeline

Distribution: MCP marketplaces, agent-framework integrations, and the bidda-shield SDK line
IN PROGRESS

Governed runs live: one-call consult fetches a rule and records a verified, hash-pinned run entry; sealed receipts verify against the published keyset

Public transparency log live: RFC 6962-style inclusion and consistency proofs over every signed record Bidda issues

Control attestations, coverage gap check, obligation-delta feed, drift check and OSCAL export live across the API, MCP server and SDK (25 tools)

Offline verifiers published: browser page, Node and Python CLIs, and a frozen public spec at /.well-known/bidda-attestation-spec.md
39 Active Sovereign Pillars

From Space & Satellite Law to Banking & Global Finance. Every major regulated industry with active enforcement.

AI GOVERNANCE & LAW
CYBERSECURITY
BANKING & GLOBAL FINANCE
MEDICAL & HEALTHCARE
LEGAL & IP SOVEREIGNTY
LOGISTICS & SUPPLY CHAIN
SUSTAINABILITY & ESG
WORKPLACE
AVIATION, DEFENSE & QUANTUM
CRYPTO & SOVEREIGN FINANCE
CLOUD & SAAS
INDUSTRIAL IOT & ENERGY
WORKFLOW AUTOMATION
OPERATIONS & CX
SALES, MARKETING & PR
FOOD & HOSPITALITY
CREATIVE, CONTENT & MEDIA IP
ENERGY & UTILITIES
CONSTRUCTION & REAL ESTATE
TELECOMS & DIGITAL INFRASTRUCTURE
TAX & TRANSFER PRICING
PHARMACEUTICALS & LIFE SCIENCES
INSURANCE & RISK
COMPETITION & ANTITRUST
AUTOMOTIVE & MOBILITY
EDUCATION & RESEARCH
BIOTECH & GENOMICS
MARITIME & SHIPPING
MINING & NATURAL RESOURCES
SPACE & SATELLITE LAW
GAMING & GAMBLING
Join the Sovereign Network

Questions about integration, enterprise licensing, or node coverage? Our trust registry team responds within one business day.

CONTACT TRUST REGISTRY →

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.