Security

Security and verification.

What you can check yourself, independent of anything stated here, and what has not been done.

01

The token contract

No custom code

USDF is built from OpenZeppelin's contract library (v5.6.1) with a constructor and nothing else: no owner, no roles, no pause, no upgrade path. The deployed bytecode matches that source exactly on Sourcify.

Redemption

Redemption is permissionless and 1:1: burn USDF, receive the same amount of USDG. The token contract cannot pause it, charge a fee for it, or cap it.

USDG itself

Redemption depends on USDG transfers succeeding: USDG is issued by a regulated issuer that retains pause and freeze powers over its own token.
02

What you can check live

Reserve and custody

Supply, reserve, custody and settlements, read from the chain.

Daily reserve attestation

A signed snapshot every day, plus the read-only ReserveView contract anyone can call directly.

Usage log

Every request, key-paid or x402, is a leaf in an append-only log. A request's receipt links to its own proof.

Signed catalog

The price sheet every model is served from is signed, with the signer's address published alongside it.

Run the checks yourself

A page that recomputes the reserve, a receipt, and the settlement chain directly from the chain, in your own browser.

Data handling

What's stored per request, what never is, and how a key's no-logs mode changes it.
03

Keys and privacy

API keys

A key is shown once and stored only as its hash. The gateway cannot show you a key you already created again, and cannot recover one that is lost.

No-logs mode

Set a key to no-logs and prompt text, completion text and tool arguments are never written anywhere: not the database, not a log line, not an error path. Token counts, cost, model and status are still recorded, because that is what makes a charge checkable against the usage log.

Full detail

What's stored, what's never stored, and how long each is kept.
04

Private tier

Attested hardware only

A request can ask to run only on attested hardware, with the model suffix :private or a Private-tier key. It is served only by an attested-hardware provider, and refused rather than quietly served elsewhere when none can take it.
05

What has not been done

Audits

The gateway and this deployment have not had a third-party audit. The token contract has no custom logic to audit: it is unmodified OpenZeppelin code. Neither of those is a claim that nothing can go wrong.
06

Responsible disclosure

Report first

Found a problem in the token contract, the gateway, or this site? Report it before writing about it publicly. Test against your own funds and your own account only.