{"service":"SolMachina","release":"0.1.9","generatedAtUtc":"2026-09-09T16:11:04.155Z","legend":{"verified":"implemented and tested by SolMachina","inherited":"enforced by the official @x402/svm exact-SVM scheme we run","roadmap":"planned, not yet in production"},"controls":[{"control":"x402 v2 protocol","status":"verified","note":"Static discovery terms use v2 amount, asset, recipient and timeout; request-specific SVM blockhashes come from the live 402. External indexing is not asserted."},{"control":"exact-SVM scheme (Solana)","status":"inherited","note":"registerExactSvmScheme(@x402/svm) performs payment verification + settlement"},{"control":"fee-payer isolation","status":"inherited","note":"the exact-SVM scheme rejects a tx that uses the fee payer as source/authority/delegate"},{"control":"exactly-one valid transfer (asset/payTo/amount)","status":"inherited"},{"control":"signer-set integrity (client + fee payer only)","status":"inherited"},{"control":"address-lookup-table resolution","status":"inherited","note":"resolved by the SVM scheme before verification"},{"control":"on-chain post-settlement (real transfer, not just simulation)","status":"inherited","note":"facilitator.settle() submits + returns the signature"},{"control":"replay protection","status":"inherited","note":"each payment payload binds a recentBlockhash with ~60s validity (see /.well-known/x402 maxTimeoutSeconds)"},{"control":"SHA-256-chained payment ledger (tamper-evident)","status":"verified","note":"public window at /ledger; head at /health; verify client-side"},{"control":"Ed25519-signed release manifest","status":"verified","note":"/.well-known/solmachina-manifest, signed by the facilitator identity"},{"control":"signed intelligence receipts (proof-of-delivery)","status":"verified","note":"every paid response carries an Ed25519-signed X-SolMachina-Receipt binding response SHA-256 + resource + price + versions + ledger head to our public identity; verify at /trust/verify or fully offline (see /trust/pubkey)"},{"control":"Merkle transparency log + inclusion proofs","status":"verified","note":"Merkle root over the WAL at /trust/log; compact inclusion proofs at /trust/proof?index=N — prove a paid call is in the public log without revealing it. Leaves are hashes only (privacy-safe)"},{"control":"kill-switch (halt all paid traffic)","status":"verified","note":"single file; every toggle audited in the WAL; /uptime.killFilePresent"},{"control":"RPC fail-closed + multi-provider","status":"verified","note":"unresolvable data returns 'unknown', never a guess; /health.dataProviders"},{"control":"standard 402 for machine clients","status":"verified","note":"free preview is gated to same-origin storefront; agents/validators always get the 402 challenge"},{"control":"duplicate-settlement in-flight lock + idempotent cached retries","status":"roadmap","note":"the exact-SVM scheme's blockhash binding limits replay; a store-level in-flight dedup is planned for higher concurrent volume"},{"control":"independent facilitator security audit","status":"roadmap","note":"planned as the first meaningful reinvestment once revenue supports it"}],"spec":"https://x402.org","scheme":"exact / solana-mainnet","note":"This matrix is self-reported. Everything marked 'verified' is checkable on this domain (/ledger, /health, /uptime, /.well-known/*); 'inherited' means we run the official scheme rather than a custom one."}