Transparency

Trust & data.

Exactly what Verge stores, what it is architecturally incapable of seeing, and what happens if we receive a legal request.

What Verge stores

Wallet session tokens
Issued on wallet signature, expiry-bound, stored as a hash. Used to authenticate /app actions.
API key hashes
SHA-256 of the raw key only. The plaintext is shown once at creation and never stored.
Endpoint metadata
Name, URL, price, network, health status. Needed to serve the marketplace and hosted endpoints.
payments_log rows
wallet (recipient), payer_address, amount_usdg, endpoint_id, settled_at. Revenue accounting.
Reputation scores
Derived from settled payment counts and volume per address. Sourced entirely from on-chain tx hashes.
Vault entries
AES-256-GCM encrypted blobs — we store ciphertext, IV and tag only. Plaintext is never written.
Agent wallet addresses
Public address + label + vault reference. Private keys are stored encrypted in the vault above.
Webhook registrations
URL, event subscriptions, HMAC secret hash. Used to deliver payment callbacks.
Invoice records
Description, amount, network, status, payer address after settlement. Needed to detect double-pay.
Audit log
Append-only log of security-sensitive actions (key created/revoked, session created, endpoint published). Never raw keys.
RPC and API request logs
Standard access logs retained for 30 days for abuse prevention. IP, timestamp, status code — no body content.

What Verge is built never to see

✓Wallet private keys
Never transmitted to Verge. Agent wallet private keys are encrypted client-side before vaulting.
✓API key plaintext after creation
Shown once on creation, then dropped. We store only the SHA-256 hash.
✓Vault secret plaintext
AES-256-GCM encrypted before storage. The decryption key (VERGE_VAULT_KEY) is an env secret we don't log.
✓x402 payment content
On-chain tx hashes are recorded; we do not store what data was returned by paid endpoints.
✓Full transaction history
We scan on-chain Transfer events on-demand for your address; we don't maintain a shadow ledger.
✓User identity / KYC
Verge has no identity layer. Wallet address is the only identifier.
✓Cross-wallet linkage
Each wallet session is isolated. We don't correlate addresses or build profiles.

Legal requests

Verge complies with valid legal process. Because private keys, secret values, and vault plaintext are never held in recoverable form, we cannot produce them under compulsion. What we can produce is limited to the data in the "What Verge stores" table above: session records, hashed keys, endpoint metadata, payment logs, and access logs. We cannot reconstruct vault secrets, API key values, or private keys — not because of policy, but because they don't exist on our servers in recoverable form.

Security practices

Vault encryption

AES-256-GCM with a server-side key (VERGE_VAULT_KEY). Each entry has a unique IV.

API keys

SHA-256 hashed before storage. Atomic daily quota via single-UPDATE to prevent races.

Replay protection

Nonce + tx-hash replay guard in Postgres (x402_settlements, x402_nonces tables).

Rate limits

Per-IP rate limiting on all mutating endpoints. 60/min workbench, 30/min key verification.

Webhook signatures

HMAC-SHA256 with per-webhook secret. X-Verge-Signature: sha256=<hex> header.

SSRF protection

Private IP ranges blocked on all URL-accepting endpoints (marketplace, workbench, webhooks).

Questions or security disclosures? Open an issue on GitHub.