Security
Security and verification.
What you can check yourself, independent of anything stated here, and what has not been done.
01
The token contract
No custom code
USDF is built from OpenZeppelin's contract library (v5.6.1) with a constructor and nothing else: no owner, no roles, no pause, no upgrade path. The deployed bytecode matches that source exactly on Sourcify.
Redemption
Redemption is permissionless and 1:1: burn USDF, receive the same amount of USDG. The token contract cannot pause it, charge a fee for it, or cap it.
USDG itself
Redemption depends on USDG transfers succeeding: USDG is issued by a regulated issuer that retains pause and freeze powers over its own token.
02
What you can check live
Daily reserve attestation
A signed snapshot every day, plus the read-only ReserveView contract anyone can call directly.
Usage log
Every request, key-paid or x402, is a leaf in an append-only log. A request's receipt links to its own proof.
Signed catalog
The price sheet every model is served from is signed, with the signer's address published alongside it.
Run the checks yourself
A page that recomputes the reserve, a receipt, and the settlement chain directly from the chain, in your own browser.
Data handling
What's stored per request, what never is, and how a key's no-logs mode changes it.
03
Keys and privacy
API keys
A key is shown once and stored only as its hash. The gateway cannot show you a key you already created again, and cannot recover one that is lost.
No-logs mode
Set a key to no-logs and prompt text, completion text and tool arguments are never written anywhere: not the database, not a log line, not an error path. Token counts, cost, model and status are still recorded, because that is what makes a charge checkable against the usage log.
Full detail
What's stored, what's never stored, and how long each is kept.
04
Private tier
Attested hardware only
A request can ask to run only on attested hardware, with the model suffix
:private or a Private-tier key. It is served only by an attested-hardware provider, and refused rather than quietly served elsewhere when none can take it.05
What has not been done
Audits
The gateway and this deployment have not had a third-party audit. The token contract has no custom logic to audit: it is unmodified OpenZeppelin code. Neither of those is a claim that nothing can go wrong.
06
Responsible disclosure
Report first
Found a problem in the token contract, the gateway, or this site? Report it before writing about it publicly. Test against your own funds and your own account only.