About Bidda Sovereign Intelligence ================================== JS-free text mirror for AI crawlers. Canonical page: https://bidda.com/about Last updated: 2026-07-11 10,000-NODE MAINNET REACHED: 10,085 VERIFIED NODES ACROSS 39 PILLARS BUILT FOR THE AGENTIC ECONOMY The world's first source-verified, cryptographically-signed compliance intelligence registry - where regulatory law becomes deterministic, auditable, machine-executable logic. Used by compliance officers to verify regulatory positions and by AI development teams to reduce hallucination risk in automated workflows. Same verified data - two interfaces. 10,085 VERIFIED NODES 39 SOVEREIGN PILLARS $0.01 PER NODE ACCESS 4ms AVG LATENCY WHO BUILDS BIDDA About the Architect: Patrick Nel A small team of operators. Direct Contact: patrick@bidda.com Bidda Intelligence is sovereign compliance infrastructure built for the age of autonomous agents. It is backed by nearly two decades of systems engineering and cybersecurity experience. My engineering foundation is rooted in Industrial Control Systems (ICS) and physical telemetry. For 10 years, I architected and maintained SCADA grids and overfill safety systems for major petrochemical companies. When securing physical infrastructure, safety and compliance cannot rely on probability. They require deterministic, hardcoded rules. Over the past seven years, my focus has shifted to deep-level cybersecurity, infrastructure hardening, and vulnerable system testing. Today, I operate Bidda Intelligence alongside a small, highly specialized team of developers who share this zero-tolerance engineering philosophy. We built Bidda Intelligence to bridge the gap between deterministic physical security and AI software. As developers rapidly deploy autonomous agents, relying on probabilistic LLM memory to handle strict legal compliance is a systemic risk. We apply the rigor of SCADA systems to AI orchestration. Bidda Intelligence provides a cryptographic fail-safe, operating as a headless MCP server designed to help enterprise teams deploy AI confidently, without relying on probabilistic model memory. INSTITUTIONAL TRUST SIGNALS › Registered: BIDDA INTELLIGENCE (PTY) LTD › CIPC enterprise number: 2026/363776/07 › Registered office: Cape Town, Republic of South Africa › Operating jurisdiction: International, governed by SA law › Public legal trio: Terms, Privacy, Disclaimer › Live integrity endpoint: /api/v1/registry-health.json › Methodology: /methodology › Verify a node: /verify › Contact: info@bidda.com The Cost of Getting Compliance Wrong A single incorrect compliance assumption - in healthcare, finance, or data privacy - can trigger regulatory fines in the millions, enforcement action, or personal liability for directors. AI systems that summarise regulations without citing primary sources make this risk worse, not better. Bidda eliminates the guesswork: every node traces directly to its authoritative legal source, so your team and your AI systems are working from the same verified, primary-source traceable foundation. 📋 For Compliance Officers Each node is a regulation or standard distilled into plain-English guidance - what it requires, what it applies to, and how it connects to related frameworks. Browse by sector, search by regulation name, or follow the dependency chain to understand your full compliance picture. Every claim cites the exact clause it comes from. 🔐 Source-Verified Data Integrity Every node is cryptographically signed. When a framework is updated by its issuing authority - ISO, NIST, WIPO, the EU, or a national regulator - our pipeline is re-triggered, the node is re-verified against the new source, and re-published. Your compliance team and your AI systems are always working from current law, not last year's version. 🏛️ Primary Sources Only No commentary. No interpretation. No paraphrasing. Every node cites the original regulatory text - legislation.gov, EUR-Lex, Federal Register, NIST, ISO, WIPO. If you need to defend a compliance position in an audit or legal proceeding, the citation is right there, with the section reference. ⚡ Agent-Native by Design For AI development teams: the same verified data powers a machine-executable logic graph that autonomous agents can query, verify, and chain - via REST API with $0.01 micropayment settlement per node. Reduced hallucination risk. No stale training data. Compliance intelligence delivered at inference speed. What is a Compliance Node? For compliance teams and AI engineers new to the registry. A compliance node is a single regulation, standard, or enforcement framework (for example, GDPR Article 32 (Security of Processing) or NIST AI RMF Govern 1.1), distilled into a 13-key machine-readable JSON object that both humans and AI agents can query. › Plain-English Summary What the regulation requires in one paragraph. No legal jargon. › Step-by-Step Logic A compliance workflow your team or AI agent can execute, with decision branches. › Automated Checklist Machine-executable checklist items mapped directly to the regulation text. › Primary Legal Citations Avg 7 citations per node: exact clause references to the original instrument. › Framework Crosswalks How this regulation maps to NIST, ISO, EU AI Act, GDPR, and 150+ other standards. › Prerequisite Nodes Which other nodes you must comply with first: your full compliance chain. Each node also carries a SHA-256 integrity hash and a verified source URL, so any claim can be traced back to the original regulatory text by your team, your auditors, or an independent reviewer. ⚠ ALWAYS VERIFY BEFORE YOU IMPLEMENT Bidda nodes are reference intelligence, not legal advice. Every node must be reviewed and confirmed by a qualified compliance professional, legal counsel, or regulatory specialist before it is implemented in any enterprise workflow, regulated system, or compliance programme. BEFORE IMPLEMENTING ANY NODE, CONFIRM: › The node covers the correct jurisdiction for your business › No superseding amendment has been issued since the node's last_updated date › Your specific business activity falls within the regulation's scope › Any dependent nodes in the chain have also been reviewed WHY THIS MATTERS NOW: › EU GDPR fines exceeded €1.6 billion in 2023 alone › EU AI Act penalties reach €35M or 7% of global turnover › DORA (EU financial resilience) became enforceable January 2025 › Regulators globally have increased enforcement frequency and fine sizes Bidda provides the verified data layer. Your qualified team is responsible for how that intelligence is applied to your specific business context. See our full Legal Disclaimer for complete terms. The Full Roadmap From Foundation to the 10,000-Node Global Intelligence Standard: every phase, every goal, every milestone. PHASE 1 COMPLETE FOUNDATION Q1 2026 100% COMPLETE 502 NODES PUBLISHED 16 SOVEREIGN PILLARS 7+ AVG CITATIONS / NODE Launched the Intelligence Forest with 502 verified nodes spanning 16 sovereign sectors. Every node cryptographically signed, source-verified against primary legal instruments, and structured with a deterministic step-by-step compliance workflow ready for agentic consumption at $0.01 per unlock. PHASE GOALS ✓ Design and finalise the 13-key Bidda node schema, the machine-executable compliance standard ✓ Build the two-tier API: Discovery (free, 6 fields) + Vault (gated, full 13 keys) ✓ Integrate Skyfire JWT bearer tokens for autonomous AI agent settlement at $0.01/node ✓ Deploy the edge payment gateway at bidda.com/api/v1/vault/* ✓ Publish first 502 nodes with zero critical schema violations across 16 sovereign pillars KEY ACHIEVEMENTS › 13-key node schema finalised: node_id, title, domain, bluf, deterministic_workflow, actionable_schema, primary_citations, crosswalks, dependencies, verification, paywall, version, last_updated › Skyfire micropayment integration, now listed on the Skyfire Directory for enterprise agent payments › L402/x402 USDC payment path on Base network at $0.01 per node, settled onchain › Pre-commit git hook blocking any node with critical schema violations from reaching production › 13-point automated validation gate with zero tolerance for malformed or incomplete nodes PHASE 1.5 COMPLETE AI REGULATION SPRINT April 2026 100% COMPLETE +493 NODES ADDED 995 TOTAL AT SPRINT END 39 SOVEREIGN PILLARS April 2026 brought the largest single regulatory intelligence update in Bidda's history, spanning every major pillar from AI Governance and Cybersecurity to Banking, Healthcare, ESG, and beyond. Every node source-verified and citation-audited before publishing. No invented content. Reduced hallucination risk. PHASE GOALS ✓ Expand to all 39 sovereign pillars with no pillar left empty ✓ Achieve full AI Governance coverage: EU AI Act, NIST AI RMF, ISO/IEC 42001, Anthropic RSP ✓ Complete the dependency graph with every prerequisite node chain fully resolved ✓ Reach the 1,000-node milestone with zero critical violations ✓ Confirm Skyfire Directory listing for real enterprise agent payment authorisation KEY ACHIEVEMENTS › AI Governance & Law: EU AI Act enforcement wave, NIST AI RMF full coverage, ISO/IEC 42001 AIMS, Anthropic RSP › Banking & Finance: APRA CPS 230, Basel operational risk, FATF AML/CFT, DORA enforcement provisions › Cybersecurity: NIST CSF 2.0, FIPS Post-Quantum Cryptography, CIS Controls v8, NIS2 Directive › Medical & Healthcare: FDA SaMD guidance, HIPAA Security Rule, HL7 FHIR interoperability standard › Legal & IP Sovereignty: WIPO copyright frameworks, cross-border data transfer regimes, Brussels I Recast › Full pillar coverage: Logistics, ESG, Workplace, Aviation Defense, Crypto, Industrial IoT, Operations, Telecoms ↯ 10,085 nodes live. Every one traceable to a primary source. Reduced hallucination risk. No invented content. PHASE 2 COMPLETE GLOBAL SCALE Q1-Q2 2026 100% COMPLETE 10,085 TOTAL NODES 39 ACTIVE PILLARS 0 BROKEN DEP LINKS 10,085 verified nodes live across 39 sovereign pillars. The 1,500-node milestone was exceeded by more than 2x. Every node passed 13-key validation, primary citation audit, and dependency-graph verification before publication. Three payment paths live. Zero placeholder content remaining. PHASE GOALS ✓ Scale beyond 1,500 nodes. Target exceeded: 10,085 verified nodes now live ✓ Expand into LatAm, India, MENA, and multilateral AI governance frameworks (Sprint K) ✓ Fill thin pillars: Industrial IoT, Workflow Automation, Maritime, Biotech, Mining, Space Law (Sprint M) ✓ Eliminate all placeholder content for 100% primary-source verified coverage at every node ✓ Remove all vendor and secondary-source nodes, keeping only sovereign primary-law sources ✓ Confirm all three payment paths live: Skyfire + L402/USDC on Base + Direct Base USDC KEY ACHIEVEMENTS › Sprint K: AI supply chain, LatAm/MENA data protection, India regulatory depth. 74 nodes accepted after full Layer 1 + Layer 2 review › Sprint M: thin pillar depth fill across Industrial IoT, Maritime, Biotech, Mining, Space Law. 33 nodes accepted › All 6,959 placeholder instances across 837 nodes eliminated (2026-04-30): every workflow step now reflects real regulatory procedure › 15 vendor/secondary nodes quarantined. Registry now entirely sovereign primary-law sourced › Three payment paths confirmed live: Skyfire pay+jwt, L402/USDC on Base, and Direct Base USDC › 39 active pillars, zero empty. Dependency graph: zero broken links across all nodes. PHASE 3 ACTIVE SOURCE INTEGRITY WATCHER April 2026 → 85% COMPLETE 3,687 URLS FINGERPRINTED Weekly (Mon 02:00 UTC) WATCHER CADENCE 99.9% VERIFICATION COVERAGE Weekly TLS SPKI fingerprint and content SHA-256 hash of every primary source URL across the registry. The tamper-evident manifest is committed to git on every run, building a tamper-evident audit chain that stands up to independent scrutiny. Verification block schema enriched with jurisdiction, instrument_type, and effective date fields. PHASE GOALS › Weekly automated source integrity watcher to catch regulatory amendments within 7 days › Fingerprint every primary source URL by TLS certificate (SPKI hash) and content (SHA-256) › Build a tamper-evident git Merkle chain: each Monday commit is an immutable, timestamped record › Publish a live health endpoint so compliance officers can verify registry integrity in real-time › Enrich verification blocks with jurisdiction (ISO 3166), instrument_type, effective_date, and enactment_date › v2: amendment detection triggers automated diff PR, human review, and node update workflow IN PROGRESS › TLS SPKI hash silently detects certificate replacement or domain hijacking before your compliance team notices › Content SHA-256 detects regulatory amendments before most compliance teams receive formal notification › Git Merkle chain: every Monday commit is a timestamped, immutable record in the audit history › Live health endpoint at bidda.com/api/v1/registry-health.json, zero-config for compliance officers › Path B verification enrichment: 2,328 nodes enriched with ISO 3166 jurisdiction, 1,742 with instrument_type › v2 roadmap: amendment diff → automated PR with source comparison → human review → node update PHASE 4 (UNPLANNED) ACTIVE AGENT INTELLIGENCE LAYER May 2026 → 90% COMPLETE 111 ATLAS TECHNIQUES 8 MCP TOOLS LIVE 1 FREE SAMPLE NODE High-leverage platform layer shipped May-June 2026: the MITRE ATLAS adversarial AI crosswalk (111 techniques across 16 attack tactics mapped to compliance coverage), an MCP server exposing 8 free tools to any Claude- or watsonx-orchestrated agent, the /scan endpoint for real-time agentic compliance mapping, a free full-access sample vault node for buyer trust, and the public /verify hash-lookup endpoint that returns timestamp, source URL, SHA-256 hash and TLS fingerprint for any node. PHASE GOALS › Crosswalk all 111 MITRE ATLAS adversarial AI techniques against Bidda sovereign compliance coverage › Release a free, zero-config GitHub Action for automated compliance gap detection in CI/CD pipelines › Publish one full vault-tier node publicly with no payment required, to demonstrate tangible buyer value › Launch /verify: node_id input, timestamp, SHA-256, TLS fingerprint, and integrity match status › Establish Bidda as a platform and tooling layer, not just a data registry, for enterprise compliance teams IN PROGRESS › MITRE ATLAS × Bidda: 111 adversarial AI techniques across 16 attack tactics mapped to sovereign compliance nodes › MCP server live with 9 free tools (list_pillars, search_nodes, get_node, get_dependency_chain, get_crosswalk, get_latest_changes, get_jurisdiction_bundle, get_mitre_mapping, check_action_compliance). The Model Context Protocol is an open standard reachable from Claude, IBM watsonx Code Assistant, and other MCP-enabled clients. › /scan endpoint: real-time agentic compliance mapping for LangChain, MCP, biometric, and credit-decisioning patterns › Free sample node: full EU AI Act Article 10 vault node publicly accessible without payment gate › /verify endpoint live: input any node_id, get timestamp, source URL, SHA-256 hash, TLS fingerprint, and tamper-evident match status › Agent-to-agent payment flow validated at production scale: Skyfire JWT + L402 USDC confirmed ↯ Every Phase 4 item was unplanned. All shipped because they were the highest-leverage platform signals available at this stage of the build. PHASE 4.5 ACTIVE ENTERPRISE TIER, PAYSTACK SUBSCRIPTIONS & SELF-SERVE ACCOUNT May-June 2026 → 80% COMPLETE Live PAYSTACK ZAR SUBS Live SELF-SERVE ACCOUNT bidda-shield 0.3.0 PYPI SDK Recurring revenue infrastructure shipped. Paystack-backed ZAR subscription billing is live in production through the edge payment gateway. A full /account self-serve surface with magic-link recovery, per-call audit logging, and API key rotation is live for paying customers. The bidda-shield Python SDK is published on PyPI with full MCP parity. Enterprise contact intake captures Fortune-500 leads through a form-handling sub-processor. The remaining 20% is final Paystack PLN activation, first enterprise contracts, and the auto-updater scheduled cron going to v1. PHASE GOALS › Ship recurring subscription billing for non-crypto buyers via Paystack ZAR plans (Starter, Pro, Enterprise) › Build /account self-serve: subscription state, API key, magic-link recovery, audit-log download, plan upgrade › Publish bidda-shield Python SDK on PyPI with full MCP-server parity for LangChain, AutoGen, CrewAI › Add enterprise contact intake on /pricing and /contact for direct buyer conversations › Launch /verify endpoint: node_id input returns timestamp, source URL, SHA-256 hash, and TLS fingerprint › Ship the Node Auto-Updater Tuesday cron: amendment detection → pending_nodes staging → PR review → merge IN PROGRESS › Paystack live: ZAR recurring subscriptions running through the edge payment gateway against api.paystack.co with webhook handler and persisted subscription state › /account self-serve surface: subscription view, API key display and rotation, per-call audit log, magic-link recovery via an email-delivery sub-processor › bidda-shield 0.3.0 on PyPI: 9 MCP-parity methods + api_key auth + LangChain, AutoGen, CrewAI wrappers, installable with pip install bidda-shield › /verify page live: cryptographic proof of node integrity visible to compliance officers without requiring API access › Enterprise contact intake on /pricing and /contact: form-handling captures company, use case, and email › Auto-updater v1 wiring: scheduled weekly cron with material-change filter and cascading verifier pipeline, ~$10-20/mo budget › Target: first $20M ARR run-rate, the inflection point for enterprise SaaS pricing and seat-based licensing PHASE 5 COMPLETE 10,000 NODE MAINNET: REACHED July 2026 100% COMPLETE 10,000 MILESTONE 10,085 NODES LIVE None PILLAR LIMIT The full-coverage milestone for global regulatory intelligence, reached in July 2026. 10,085 verified nodes are live across 39 sovereign pillars, every one generated with mandatory human review and traceable to a primary legal source. The registry keeps growing under the same verification gates, with the weekly source watcher and the human-reviewed auto-updater holding every node current against its source. PHASE GOALS ✓ Scale to 10,000 verified nodes with no upper pillar limit. New pillars are added as regulatory coverage demands ✓ Generation pipeline with a constrained frontier-tier extraction model + mandatory human PR review at every step ✓ Broad jurisdictional coverage: G20 nations, EU member states, and active multilateral frameworks ✓ Node Auto-Updater live at scale, with source amendments detected within 7 days ✓ Verification block enrichment: jurisdiction + instrument_type + effective_date coverage ✓ Enterprise-ready state with full schema integrity and source-verified accuracy at scale KEY ACHIEVEMENTS › 10,085 nodes across 39 sovereign pillars. Every major regulated industry globally covered at primary-source depth › Node generation pipeline with mandatory Layer 1 accuracy gate + Layer 2 human review against primary source › Source-verified accuracy maintained at scale: zero placeholder markers in production, zero broken dependency links › Weekly source watcher checks every node against its primary source within 7 days of any regulatory amendment › Dependency graph integrity at 10,085 nodes: complete chain traceability across every sovereign pillar › Revenue thesis: predictable enterprise SaaS recurring revenue at scale, anchored to subscription licensing and per-node API volume PHASE 6 ACTIVE GOVERNED AI EVIDENCE LAYER + ENTERPRISE SCALE H2 2026 70% COMPLETE 25 MCP + SDK TOOLS 4 SIGNED RECORD TYPES Public VERIFICATION The evidence layer auditors ask AI operators for. Signed decision attestations, point-in-time records, governed runs that pin the exact version and fingerprint of every rule an agent consulted, sealed run receipts, control attestations, and a public append-only transparency log built the same way as Certificate Transparency. Evidence exports as a NIST OSCAL assessment-results document so it drops into existing GRC tooling. Everything verifies against Bidda's published keys with no Bidda account. These support an audit trail and are never a determination that an obligation was met. PHASE GOALS › Enterprise contracts on the subscription and enterprise API tiers › Deeper GRC and audit-tooling integrations on top of the OSCAL export › Registry growth beyond 10,000 nodes under the same 4-gate verification pipeline › Distribution: MCP marketplaces, agent-framework integrations, and the bidda-shield SDK line IN PROGRESS › Governed runs live: one-call consult fetches a rule and records a verified, hash-pinned run entry; sealed receipts verify against the published keyset › Public transparency log live: RFC 6962-style inclusion and consistency proofs over every signed record Bidda issues › Control attestations, coverage gap check, obligation-delta feed, drift check and OSCAL export live across the API, MCP server and SDK (25 tools) › Offline verifiers published: browser page, Node and Python CLIs, and a frozen public spec at /.well-known/bidda-attestation-spec.md 39 Active Sovereign Pillars From Space & Satellite Law to Banking & Global Finance. Every major regulated industry with active enforcement. AI GOVERNANCE & LAW CYBERSECURITY BANKING & GLOBAL FINANCE MEDICAL & HEALTHCARE LEGAL & IP SOVEREIGNTY LOGISTICS & SUPPLY CHAIN SUSTAINABILITY & ESG WORKPLACE AVIATION, DEFENSE & QUANTUM CRYPTO & SOVEREIGN FINANCE CLOUD & SAAS INDUSTRIAL IOT & ENERGY WORKFLOW AUTOMATION OPERATIONS & CX SALES, MARKETING & PR FOOD & HOSPITALITY CREATIVE, CONTENT & MEDIA IP ENERGY & UTILITIES CONSTRUCTION & REAL ESTATE TELECOMS & DIGITAL INFRASTRUCTURE TAX & TRANSFER PRICING PHARMACEUTICALS & LIFE SCIENCES INSURANCE & RISK COMPETITION & ANTITRUST AUTOMOTIVE & MOBILITY EDUCATION & RESEARCH BIOTECH & GENOMICS MARITIME & SHIPPING MINING & NATURAL RESOURCES SPACE & SATELLITE LAW GAMING & GAMBLING Join the Sovereign Network Questions about integration, enterprise licensing, or node coverage? Our trust registry team responds within one business day. CONTACT TRUST REGISTRY →