Trust & data.
Exactly what Verge stores, what it is architecturally incapable of seeing, and what happens if we receive a legal request.
What Verge stores
What Verge is built never to see
Legal requests
Verge complies with valid legal process. Because private keys, secret values, and vault plaintext are never held in recoverable form, we cannot produce them under compulsion. What we can produce is limited to the data in the "What Verge stores" table above: session records, hashed keys, endpoint metadata, payment logs, and access logs. We cannot reconstruct vault secrets, API key values, or private keys — not because of policy, but because they don't exist on our servers in recoverable form.
Security practices
AES-256-GCM with a server-side key (VERGE_VAULT_KEY). Each entry has a unique IV.
SHA-256 hashed before storage. Atomic daily quota via single-UPDATE to prevent races.
Nonce + tx-hash replay guard in Postgres (x402_settlements, x402_nonces tables).
Per-IP rate limiting on all mutating endpoints. 60/min workbench, 30/min key verification.
HMAC-SHA256 with per-webhook secret. X-Verge-Signature: sha256=<hex> header.
Private IP ranges blocked on all URL-accepting endpoints (marketplace, workbench, webhooks).