How Saifuro keeps agent money safe
Agent payments run through Saifuro without Saifuro ever holding the money. Keys exist only as split shares, every payment clears policy before it settles, and the record cannot be edited after the fact. This page describes the model.
What can go wrong, and what stops it
Autonomous spend fails in predictable ways. Each one here is paired with the control built for it.
An agent overspends
Every payment is checked against its agent's budget and caps while it is still a request. Saifuro refuses it at that point instead of flagging it afterwards.
A credential leaks
Signing runs on MPC. A key exists only as shares held on separate machines, and a stolen share on its own moves nothing.
An agent is compromised
You revoke its spending power with one call. The cutoff is immediate, and no cached credentials keep working in the meantime.
An agent pays the wrong party
Allowlists, category rules and geo rules pin each agent to counterparties you approved. Anything outside the list is refused by default.
A deal falls through
Escrow releases funds only on the conditions written into the deal. When delivery fails, the money returns to the buyer without a dispute ticket.
An auditor asks for the record
Identity, policy decision and settlement land in the ledger at the moment they happen. Reports come from the same records the system runs on.
Data handling
Encryption
TLS 1.3 on every connection, AES-256 on every store. There is no unencrypted path through the system.
Key handling
Key shares are generated in hardware-backed enclaves and rotated on a schedule. No single server, laptop or person ever holds a complete key.
Card data
Saifuro stores no card numbers. Card-rail payments use network tokens issued through the Visa and Mastercard agent programs.
Personal data
We keep the minimum needed to run policy and audit. Deletion requests are honored, and nothing is shared for advertising.
Compliance
Where the paperwork stands today. Statuses change as audits close.
SOC 2 Type II
IN AUDITAn independent firm is running the Type II observation window now. The report will be available under NDA once issued.
GDPR
IN EFFECTData minimization, encryption and deletion within the required timeframes apply to every account we run.
ISO 27001
PLANNEDControls are being built to the standard now. Certification is scoped to follow the SOC 2 report.
Running a vendor review? Write to [email protected] for the current documentation set under NDA.
Report a vulnerability
If you find a weakness in anything we run, tell us before anyone else. Reports go to [email protected] and a person answers within two business days.
We do not take legal action against good-faith research. Give us reasonable time to fix the issue before you publish, and we will credit you if you want the credit.
[email protected]Bring your security team to the demo
The first call covers custody, key handling and the ledger in as much depth as they want.