Skip to main content

Data Protection & Placement

ColabHive enforces a node-eligibility policy at account, workload, and task level. The most restrictive declared value wins. This controls which nodes may execute a task; it does not select a country, provider, or legal jurisdiction.

Policy values​

ValueEligible capacity
own_hardware_onlyNon-rented hardware owned by your account. A task under this policy does not run on public-cloud capacity. Nodes whose rental status is unknown are excluded.
own_account_onlyHardware assigned to your account, including rented capacity assigned to it. During the current Cloud Burst transition, the account's enrolled burst nodes are included.
any_nodeAny otherwise eligible ColabHive node, including shared or burst capacity.

The account value is a ceiling. A workload or task may choose a more restrictive value, but it cannot choose a more permissive one. Attempts to relax past the ceiling return policy_exceeds_account_ceiling; ColabHive never silently relaxes a request.

Check before dispatch​

Use the placement preflight before creating or invoking a workload. It returns the effective value, the eligible-node count, excluded nodes with machine-readable reasons, and—when one exists—the least-permissive relaxation that would currently have capacity.

curl -X POST https://api.colabhive.com/api/v1/data-protection/placement-preflight \
-H "X-API-Key: $COLABHIVE_API_KEY" \
-H "X-Account-ID: $COLABHIVE_ACCOUNT_ID" \
-H "Content-Type: application/json" \
-d '{
"workload_type": "inference_endpoint",
"workload_id": "<endpoint-uuid>",
"node_eligibility": "own_hardware_only",
"explain": true
}'

The hypothetical node_eligibility does not change stored policy. A response with policy_no_eligible_node is a hard stop unless an authorized operator explicitly chooses one of the returned relaxation options.

Override one task​

For inference, send the policy as a header. It can only restrict the account ceiling:

curl -X POST https://api.colabhive.com/api/builder/v1/endpoints/<endpoint-uuid>/infer \
-H "X-API-Key: $COLABHIVE_API_KEY" \
-H "X-Node-Eligibility: own_hardware_only" \
-H "Content-Type: application/json" \
-d '{"input":{"messages":[{"role":"user","content":"Hello"}]}}'

For training, use node_eligibility in POST /api/builder/v1/training/runs.

Evidence and observed destinations​

The placement attestation is a read-only JSON report over a past time window. It records the policy stamped on each task, whether the observed placement conformed, and the destination labels recorded by the nodes that actually ran tasks. It also reports nodes whose destination label was absent.

curl -G https://api.colabhive.com/api/v1/compliance/placement-attestation \
-H "X-API-Key: $COLABHIVE_API_KEY" \
-H "X-Account-ID: $COLABHIVE_ACCOUNT_ID" \
--data-urlencode "from=2026-09-08T00:00:00Z" \
--data-urlencode "to=2026-09-09T00:00:00Z"

Destination labels in this report document what happened. They are not a placement selector or a guarantee about future tasks. The report includes a deterministic evidence_digest: two reads of the same unchanged window produce the same digest.

See the Data Protection API for every route and stable error code.