DropEngine · Financial Layer
SECURITY BOUNDARIES

What the layer protects — and what it never touches.

Every agent payment preparation step is made visible and bounded. The layer is not a wallet, custodian or transaction relay: it never holds keys or sends money itself.

Tenant isolation

Every financial record — agents, intents, policies, approvals, ledger and reconciliation data — is scoped to a customer account (tenant). Cross-tenant access is rejected even if an internal ID is guessed.

Hashed API credentials

Customer API keys are stored only as SHA-256 hashes. The plaintext secret is shown exactly once at creation or rotation and never appears in logs, listings or audit records.

Key revocation

API keys can be revoked instantly from the dashboard or API. Revoked keys are rejected with 401 on the next request.

Rotation support

Keys can be rotated with a configurable grace period so the old key keeps working while the new secret is deployed — or rotated immediately when compromised.

No key custody

The service does not collect or store a wallet private key.

No signing or broadcast

Intent, preflight and route APIs do not request a signature or submit a blockchain transaction.

Pseudonymized records

Agent, wallet and token identities are represented by HMAC-derived hashes where a stable identifier is needed.

Approval controls

Policy evaluation can require an authenticated operator to approve or reject a pending authorization. Review actions are replay-safe.

Append-only ledger

Financial events are recorded as append-only ledger entries; production operations should include regular backup and retention review.

Environment isolation

The staging deployment uses an isolated database volume and Base Sepolia configuration, separate from production mainnet configuration.

Idempotency

Intent creation requires an opaque Idempotency-Key; preflight, route and reconciliation records also guard against incompatible replay.

Rate limiting

Application-level customer rate limits are not yet enforced in this staging MVP. Configure an edge or gateway limit before exposing production credentials.

OPERATOR RESPONSIBILITIES

Keep administrator credentials in a secret manager, rotate agent tokens, review policy limits, restrict staging access, and independently verify all x402 payment requirements before any user signs a transaction.