Saifuro
SECURITY

How Saifuro keeps agent money safe

Agent payments run through Saifuro without Saifuro ever holding the money. Keys exist only as split shares, every payment clears policy before it settles, and the record cannot be edited after the fact. This page describes the model.

CUSTODY
None
Funds stay in your accounts and wallets.
SIGNING
MPC
No machine ever holds a whole key.
LEDGER
Append-only
Written at settlement, never rewritten.

What can go wrong, and what stops it

Autonomous spend fails in predictable ways. Each one here is paired with the control built for it.

failure 01

An agent overspends

Every payment is checked against its agent's budget and caps while it is still a request. Saifuro refuses it at that point instead of flagging it afterwards.

failure 02

A credential leaks

Signing runs on MPC. A key exists only as shares held on separate machines, and a stolen share on its own moves nothing.

failure 03

An agent is compromised

You revoke its spending power with one call. The cutoff is immediate, and no cached credentials keep working in the meantime.

failure 04

An agent pays the wrong party

Allowlists, category rules and geo rules pin each agent to counterparties you approved. Anything outside the list is refused by default.

failure 05

A deal falls through

Escrow releases funds only on the conditions written into the deal. When delivery fails, the money returns to the buyer without a dispute ticket.

failure 06

An auditor asks for the record

Identity, policy decision and settlement land in the ledger at the moment they happen. Reports come from the same records the system runs on.

Data handling

Encryption

TLS 1.3 on every connection, AES-256 on every store. There is no unencrypted path through the system.

Key handling

Key shares are generated in hardware-backed enclaves and rotated on a schedule. No single server, laptop or person ever holds a complete key.

Card data

Saifuro stores no card numbers. Card-rail payments use network tokens issued through the Visa and Mastercard agent programs.

Personal data

We keep the minimum needed to run policy and audit. Deletion requests are honored, and nothing is shared for advertising.

Compliance

Where the paperwork stands today. Statuses change as audits close.

SOC 2 Type II

IN AUDIT

An independent firm is running the Type II observation window now. The report will be available under NDA once issued.

GDPR

IN EFFECT

Data minimization, encryption and deletion within the required timeframes apply to every account we run.

ISO 27001

PLANNED

Controls are being built to the standard now. Certification is scoped to follow the SOC 2 report.

Running a vendor review? Write to [email protected] for the current documentation set under NDA.

Report a vulnerability

If you find a weakness in anything we run, tell us before anyone else. Reports go to [email protected] and a person answers within two business days.

We do not take legal action against good-faith research. Give us reasonable time to fix the issue before you publish, and we will credit you if you want the credit.

[email protected]

Bring your security team to the demo

The first call covers custody, key handling and the ledger in as much depth as they want.