Identity & credentials
No bearer secrets on agents
Agents never hold payment credentials; identity payloads are KMS-signed at registration; the responsible party is always the verified session user, never a client-supplied value.
How we defend the control layer — and exactly which assurances exist today versus which are on the roadmap. No certificate theater.
Agents never hold payment credentials; identity payloads are KMS-signed at registration; the responsible party is always the verified session user, never a client-supplied value.
If the control layer cannot decide — identity unreachable, proof unmintable — the money action is refused, and the refusal is recorded.
Hashes on receipt, Merkle batching, on-chain commitments — altering a record after the fact breaks the math, not a policy.
Multi-sig on program upgrades; per-IP rate limiting on every endpoint; org-scoped authorization on every route.
| Item | Status | What that means |
|---|---|---|
| Independent security audit | PLANNED | Will be stated here only when the report is public |
| SOC 2 | ROADMAP | No compliance claim before completion |
| Responsible disclosure | OPEN | Security reports: info@regentprotocol.org |
No bug-bounty program exists yet; we don't promise one until it does.