How Saifuro keeps agent money safe
Agent payments run through Saifuro without Saifuro ever holding the money. The keys that move funds stay in your custody and never reach us, every payment clears policy before it settles, and the record cannot be edited after the fact. This page describes the model.
What can go wrong, and what stops it
Autonomous spend fails in predictable ways. Each one here is paired with the control built for it.
An agent overspends
Every payment is checked against its agent's budget and caps while it is still a request. Saifuro refuses it at that point instead of flagging it afterwards.
A credential leaks
An API credential authorizes requests to Saifuro and nothing else. It cannot move money, because Saifuro cannot move money: the keys that sign transactions stay in your custody and never reach us. Rotate the credential and the access is gone.
An agent is compromised
You revoke its spending power with one call. The cutoff is immediate, and no cached credentials keep working in the meantime.
An agent pays the wrong party
Allowlists, category rules and geo rules pin each agent to counterparties you approved. Anything outside the list is refused by default.
A deal falls through
Escrow releases funds only on the conditions written into the deal. When delivery fails, the money returns to the buyer without a dispute ticket.
An auditor asks for the record
Identity, policy decision and settlement land in the ledger at the moment they happen. Reports come from the same records the system runs on.
Data handling
Encryption
TLS 1.3 on every connection, AES-256 on every store. There is no unencrypted path through the system.
Key handling
Saifuro holds one signing key per environment, and it signs authorization verdicts only. It cannot move money, sign a transaction or release funds. The keys that do move money are generated and held by you, and never reach us. Your own organization and agent credentials rotate on demand, and a rotation takes effect immediately.
Card data
Card data is captured and tokenized by VGS, a PCI DSS Level 1 service provider, before it reaches Saifuro. Primary account numbers never enter our systems. Card-rail payments use network tokens issued through the Visa and Mastercard agent programs.
Personal data
We keep the minimum needed to run policy and audit. Deletion requests are honored, and nothing is shared for advertising.
Compliance
Where the paperwork stands today. Statuses change as audits close.
SOC 2 Type I
Controls are documented and the Type I audit is being scoped with an independent firm. The auditor and the report date appear here when the report is issued.
GDPR
Data minimization, encryption and deletion within the required timeframes apply to every account we run.
ISO 27001
Controls are being built to the standard now. Certification is scoped to follow the SOC 2 report.
Insurance
Technology errors and omissions and cyber liability policies are active. The certificate of insurance goes out with the vendor pack on request.
Running a vendor review? Write to contact@saifuro.com for the current documentation set under NDA.
Report a vulnerability
If you find a weakness in anything we run, tell us before anyone else. Reports go to security@saifuro.com and a person answers within two business days.
We do not take legal action against good-faith research. Give us reasonable time to fix the issue before you publish, and we will credit you if you want the credit.
security@saifuro.comBring your security team to the demo
The first call covers custody, key handling and the ledger in as much depth as they want.