Skip to content

Security

Operations

Security

Non-custodial, post-settlement, signed receipts, JWKS, ingest authentication. Precise claims only.

Trust claims we make

  • Non-custodial — no merchant or buyer funds held.
  • Post-settlement observation.
  • Signed receipts (Ed25519) with JWKS-published keys.
  • Artifact-bound UBL via SHA-256 of exact bytes.
  • Offline verification without a Fiscal402 “trust me” API.
  • Ingest authenticated with X-Fiscal402-Key when configured.

Claims we do not make

  • Tax compliant, legally certified, or government approved.
  • Guaranteed audit proof in every jurisdiction.
  • Wallet address equals legal identity or VAT identity.

When on-chain settlement checks are enabled, Fiscal402 looks for an ERC-20 USDC Transfer matching payer, payee and amount on the supported EVM networks. That check can fail the ingest; it is not a substitute for receipt verification.