TRUST / REVENUE INTEGRITY

A payment is not revenue
until every record agrees.

Andromalius treats HTTP output, facilitator settlement, durable accounting, privacy-minimized telemetry, encrypted backup, and the finalized Base transfer as one evidence chain. A missing or contradictory link fails closed.

01 / SETTLEMENT CHAIN

Six links. One recognized sale.

A successful HTTP response alone is insufficient. Each paid report must follow the same bounded sequence, and the operator reconciles any first outside settlement without copying buyer identity into funnel analytics.

  1. 01
    Expose one exact requirement

    An unsigned x402 v2 challenge names the canonical resource, Base network, native USDC asset, public payee, fixed atomic amount, and timeout before a wallet is involved.

  2. 02
    Verify before reading caller input

    The merchant verifies the payment credential and binds it to the exact product before it reads or validates the bounded caller-supplied JSON.

  3. 03
    Build—but withhold—the report

    The deterministic report is constructed in memory. It is not released while verification, binding, settlement, or accounting remains incomplete.

  4. 04
    Settle once

    The facilitator settles the one reviewed native Base-USDC authorization. Ambiguity opens the paid circuit and never triggers a blind retry.

  5. 05
    Write durable accounting

    A transaction-idempotent, hash-chained sale record binds the product, amount, settlement state, and release without storing the submitted artifact or payer identity.

  6. 06
    Reconcile the complete evidence chain

    Privacy-minimized telemetry, a sale-triggered encrypted backup, facilitator evidence, and the finalized Base transfer must agree before revenue is treated as reconciled.

02 / FAIL-CLOSED BEHAVIOR

Uncertain means stop.

Andromalius does not optimize conversion by weakening payment or accounting controls. It withholds the report, prevents an unsafe retry, and requires reconciliation when the payment outcome cannot be proved.

03 / DATA BOUNDARY

Enough evidence to operate. No buyer dossier.

Application evidence is deliberately aggregate or transaction-bound. Infrastructure providers may still process ordinary security and request metadata under their own operational controls and the published Privacy Notice.

Submitted audit artifact
Processed in memory and not retained by default
Payer identity
Not stored in the merchant sale ledger or application telemetry
Wallet and transaction analytics
Not used to build caller profiles or conversion attribution
Application telemetry
Fixed-cardinality route, status, latency, payment, and risk counters
Durable sale record
Product, amount, network, asset, payee, settlement, and accounting evidence
Infrastructure metadata
May be processed by providers as described in the Privacy Notice

04 / CURRENT PROOF BOUNDARY

Paid beta live. First outside sale reconciled.

LIVE COMMERCIAL MODEEnabled

Caller-supplied audit output requires successful x402 settlement.

RECONCILED OWNER CANARY1 × $0.01

Operational proof only. It is not a customer, demand, or outside-revenue claim.

VERIFIED OUTSIDE SALES1 × $0.01

One non-owner Challenge Audit passed the complete settlement, accounting, telemetry, backup, restore, and finalized Base-transfer reconciliation chain. It proves one delivery—not repeat demand.

FOUNDING-BETA CEILINGS1,000 / $20 / 32

Settled calls, gross native USDC, and concurrent paid requests.

The deployment is deliberately single-node and is not represented as highly available or qualified for one million monthly calls. Live state may change; inspect the health, catalog, OpenAPI, and unsigned x402 challenge before purchase.

05 / REPORT A PROBLEM

Payment ambiguity is an incident—not a reason to pay twice.

If a payment appears to settle without delivering the report, do not retry. Contact support with the public Base transaction reference and product route. Never send a private key, recovery phrase, payment authorization, or identity document.

Terms · Privacy · Acceptable use · Refunds