09 / TEAM CONTROL PLANE

One payment policy.
Every agent still holds the line.

The proposed design-partner pilot combines bounded catalog-scale seller-health audits with centrally reviewed policy, signed bundles, entitlement controls, and aggregate operational evidence—while per-payment allowlists, signing, and wallet custody stay with the buyer.

COMMERCIAL STATUS

Team design-partner pilot

$299 / month

Proposed founding-pilot price for one organization and one manually provisioned tenant. Final scope and written pilot terms must be agreed before invoicing.

MANUAL PILOT · NO SELF-SERVE CHECKOUT

WHO IT IS FOR

  • A marketplace, index, or team needs to audit many caller-supplied x402 catalog records before buyers see them.
  • A team operates multiple x402-aware agents or services under one reviewed payment policy.
  • Security or operations needs proof that clients received the intended policy bundle.
  • The buyer accepts a manual founding pilot while product fit and support load are measured.

SCOPE / TRUST BOUNDARY

Centralize policy. Keep wallet authority local.

The service may distribute reviewed policy and receive privacy-minimized operational summaries. It does not receive a recovery phrase, private key, raw payment authorization, or unrestricted authority to spend.

Included in scope

  • One tenant with a time-bounded entitlement and a reviewed catalog-audit cadence.
  • Bounded no-fetch batch analysis with versioned finding codes, deterministic scoring, and aggregate severity/code counts.
  • Short-lived Ed25519-signed policy bundles with tenant and digest binding.
  • Sanitized, idempotent usage events and aggregate amount, gas, commission, and status totals.
  • Manual onboarding and best-effort pilot support within the agreed scope.

Not promised

  • Wallet custody, remote signing, payment authorization, or raw paid-response storage.
  • Self-serve billing, public SaaS availability, or automatic entitlement renewal.
  • An unbounded crawler, arbitrary target fetching, or a claim of full-catalog coverage without reconciled item IDs.
  • High availability, SSO, SCIM, per-user RBAC, or a contractual SLA.
  • A claim that the current single-writer pilot is million-call qualified.

MANUAL COMMERCIAL PATH

Agree on the boundary before anything is provisioned.

There is no automatic enrollment or billing flow. Each engagement starts with a fit review and requires an agreed written scope before credentials, an invoice, or a deployment is created.

  1. 01
    Fit and risk review

    Confirm the organization, use case, jurisdiction, desired controls, data boundary, and accountable owner.

  2. 02
    Written pilot scope

    Agree on tenant scope, price, term, retention, support, security, offboarding, and success criteria.

  3. 03
    Manual provisioning

    Issue an isolated tenant credential and pinned signing public key through an authenticated channel after invoicing is reconciled.

  4. 04
    Evidence-based review

    Measure policy fetches, sanitized usage, support load, and renewal fit without collecting wallet or customer payload analytics.

Founding-beta boundary

Andromalius currently serves United States business users age 18 or older. The public service is bounded and single-node. Any customer-specific service level, retention, support, security, or refund term must be written into the applicable pilot or deployment agreement.

Contacting us does not create a subscription, deployment, payment authorization, or service-level commitment. Terms · Privacy · Acceptable use · Refunds