Trust and security

Trust infrastructure for agent transactions.

Receipt combines scoped authorization before execution with traceable settlement state and portable signed evidence afterward. Current controls and roadmap work are separated below.

Current controls

Implemented today

  • Server-enforced authorization tied to exact connected-app identity
  • Per-connection authority, daily SpendCaps, and per-purchase limits
  • Hosted human approvals, pause, and revoke controls
  • Signed quotes bound to transaction terms and expiry
  • Delivery Contracts that distinguish delivered from validated assurance
  • Signed Open Receipts, verification links, and evidence hashes
  • Idempotent reservation, release, settlement, and remedy commands
  • Provider credentials decrypted only within the selected adapter path

Roadmap

Planned—not current certification

  • SOC 2 readiness work
  • Independent penetration testing
  • Enhanced incident-response practices
  • Institutional deployment controls
  • Additional data-residency options

Funds and settlement

Receipt does not replace or operate the settlement rail. It supplies authorization, policy enforcement, and portable evidence around transactions handled through payment and infrastructure providers.

The Receipt product includes funded wallets, reservations, wallet debits, seller credits, and settlement records. This description makes no regulatory or custody conclusion.