Caller-supplied audit output requires successful x402 settlement.
TRUST / REVENUE INTEGRITY
A payment is not revenue
until every record agrees.
Andromalius treats HTTP output, facilitator settlement, durable accounting, privacy-minimized telemetry, encrypted backup, and the finalized Base transfer as one evidence chain. A missing or contradictory link fails closed.
01 / SETTLEMENT CHAIN
Six links. One recognized sale.
A successful HTTP response alone is insufficient. Each paid report must follow the same bounded sequence, and the operator reconciles any first outside settlement without copying buyer identity into funnel analytics.
- 01Expose one exact requirement
An unsigned x402 v2 challenge names the canonical resource, Base network, native USDC asset, public payee, fixed atomic amount, and timeout before a wallet is involved.
- 02Verify before reading caller input
The merchant verifies the payment credential and binds it to the exact product before it reads or validates the bounded caller-supplied JSON.
- 03Build—but withhold—the report
The deterministic report is constructed in memory. It is not released while verification, binding, settlement, or accounting remains incomplete.
- 04Settle once
The facilitator settles the one reviewed native Base-USDC authorization. Ambiguity opens the paid circuit and never triggers a blind retry.
- 05Write durable accounting
A transaction-idempotent, hash-chained sale record binds the product, amount, settlement state, and release without storing the submitted artifact or payer identity.
- 06Reconcile the complete evidence chain
Privacy-minimized telemetry, a sale-triggered encrypted backup, facilitator evidence, and the finalized Base transfer must agree before revenue is treated as reconciled.
02 / FAIL-CLOSED BEHAVIOR
Uncertain means stop.
Andromalius does not optimize conversion by weakening payment or accounting controls. It withholds the report, prevents an unsafe retry, and requires reconciliation when the payment outcome cannot be proved.
- Wrong network, asset, payee, amount, resource, scheme, timeout, or settlement binding withholds output.
- Settlement uncertainty stops paid admission and is treated as spent until independently reconciled.
- Missing durable accounting after settlement opens the accounting circuit instead of recognizing revenue.
- Backup, telemetry, beta-budget, or admission degradation remains visible in health and can stop paid traffic.
- A repeated request bound to the same transaction cannot inflate sale count or gross revenue.
03 / DATA BOUNDARY
Enough evidence to operate. No buyer dossier.
Application evidence is deliberately aggregate or transaction-bound. Infrastructure providers may still process ordinary security and request metadata under their own operational controls and the published Privacy Notice.
- Submitted audit artifact
- Processed in memory and not retained by default
- Payer identity
- Not stored in the merchant sale ledger or application telemetry
- Wallet and transaction analytics
- Not used to build caller profiles or conversion attribution
- Application telemetry
- Fixed-cardinality route, status, latency, payment, and risk counters
- Durable sale record
- Product, amount, network, asset, payee, settlement, and accounting evidence
- Infrastructure metadata
- May be processed by providers as described in the Privacy Notice
04 / CURRENT PROOF BOUNDARY
Paid beta live. First outside sale reconciled.
Operational proof only. It is not a customer, demand, or outside-revenue claim.
One non-owner Challenge Audit passed the complete settlement, accounting, telemetry, backup, restore, and finalized Base-transfer reconciliation chain. It proves one delivery—not repeat demand.
Settled calls, gross native USDC, and concurrent paid requests.
The deployment is deliberately single-node and is not represented as highly available or qualified for one million monthly calls. Live state may change; inspect the health, catalog, OpenAPI, and unsigned x402 challenge before purchase.
05 / REPORT A PROBLEM
Payment ambiguity is an incident—not a reason to pay twice.
If a payment appears to settle without delivering the report, do not retry. Contact support with the public Base transaction reference and product route. Never send a private key, recovery phrase, payment authorization, or identity document.
Terms · Privacy · Acceptable use · Refunds