Trust for AI spend
accountability.
P402 records the economic facts of AI work, not the private content behind it.
Metadata-only by default. No prompt storage required.
Meter economics, not content.
P402 records the economic facts of each AI call. Prompts, responses, files, documents, and source code stay inside the customer environment by default.
- Prompts
- Responses
- Messages
- Raw traces
- Files
- Documents
- Source code
- Transcripts
- Chat history
Per-event economic facts.
tenantworkflow_idcustomer_idfeature_idmodelprovidertokenscostbudget resultpolicy resultoutcome statusreceipt or evidence statusFive modes. Metadata-only is the default. full_trace is opt-in and requires explicit tenant policy.
metadata_onlyDefault+
- request_id
- tenant_id
- api_key_id
- department_id
- employee_id
- customer_id
- feature_id
- workflow_id
- task_type
- action_type
- model
- provider
- input_tokens
- output_tokens
- cost_usd
- latency_ms
- cache_hit
- budget_id
- policy_id
- governance_decision
- deny_code
- output_status
- quality_score
- evidence_status
- prompt text
- response text
- files
- documents
- chat history
- PHI
- PII
- secrets
- source code
- Meter
- Monitor
- Control
- budget enforcement
- department, employee, feature, customer margin
- forecasting
- basic optimization
- evidence exports
- Semantic cache is off in P402 cloud for metadata_only
- Limited prompt-level optimization
- Limited context-bloat analysis
- Limited duplicate-work detection
fingerprint_only+
- metadata above, plus:
- HMAC prompt fingerprint, tenant-secret HMAC, not plain SHA-256
- HMAC response fingerprint
- token shape
- optional prompt length bands
- optional document hash
- raw prompt or response content
- embeddings, treated as sensitive, opt-in only
- Duplicate request detection
- Retry loop detection
- Repeated task detection
- Cache opportunity estimates
- Same-input cost analysis
- Semantic cache is off in P402 cloud for fingerprint_only
- No prompt-level rewrite suggestions
- No semantic similarity grouping unless embeddings explicitly enabled
redacted_trace+
- redacted prompt sample
- redacted response sample
- trace summary
- tool-call summary
- retrieval summary
- policy summary
- unredacted PII, PHI, secrets, API keys, emails, phone numbers, addresses, or custom-regex-matched content, redacted client-side before send
- Context waste detection
- Prompt compression recommendations
- Retry-loop diagnosis
- Tool-call waste analysis
- Quality review
- Better model selection by action
- Redaction is the tenant responsibility before send
- Opt-in per tenant, project, key, or workflow
- Semantic cache is off unless the tenant explicitly opts in
private_gateway+
- economic events
- recommendation summaries
- savings proofs
- policy results
- evidence hashes
- aggregate analytics
- raw prompts, planned to stay in customer VPC
- raw responses, planned to stay in customer VPC
- embeddings unless explicitly exported
- Customer-controlled routing path
- Deeper optimization scope
- Tenant-scoped trace inspection
- Tenant-scoped redaction
- Tenant-scoped policy enforcement
- Enterprise evidence export
- Enterprise deployment path, availability subject to agreement and deployment scope
- Operational responsibilities defined per engagement
- No P402-cloud semantic cache for private_gateway
full_trace+
- prompt
- response
- tool calls
- trace
- retrieval context
- output status
- quality score
- data the customer does not send
- Deepest optimization
- Full trace replay
- Per-request quality review
- Never the default, must be explicitly enabled
- Short retention required
- Semantic cache is off unless the tenant explicitly opts in
- Project-level enablement, planned for enterprise deployment
- Role-gated access, planned for enterprise deployment
- Audit log of access, planned for enterprise deployment
Settlement and identity contracts on Base Mainnet, chain ID 8453. Verify independently on Basescan.
ERC-20 asset used for settlements. Circle-issued.
Receives USDC from settled payments. Platform fee destination.
Marketplace settlement contract. Applies a platform fee on settlement.
Recurring subscription billing via EIP-2612 permit. Month 1 sets allowance, months 2+ draw without new signatures.
On-chain agent identity registration and DID resolution.
On-chain agent reputation scoring. Read by the routing engine for trust-weighted decisions.
P402 never holds user funds. The facilitator executes signed authorizations, it does not custody assets.
Signs the EIP-3009 authorization. Controls validAfter, validBefore, nonce, and value. The user never submits a transaction, the facilitator does.
User sets authorization bounds. Once signed, the facilitator can execute within those bounds before validBefore.
Hot wallet that executes transferWithAuthorization on USDC. Pays gas on behalf of the user. Does not hold user funds.
If compromised, could execute valid but not-yet-settled authorizations. Mitigated by short validBefore windows and replay protection.
Receives settled USDC. Read-only from the protocol perspective, receives only, never sends.
Separate from the facilitator wallet. Compromise of the facilitator does not affect treasury funds.
Defines paymentRequirements: amount, payTo, asset, resource URL. Calls verify then settle through the P402 facilitator API.
Must validate the verify response before serving content. Failure to check valid: true results in serving without confirmed payment.
Enterprise review paths.
- available on requestSecurity review pathWalkthrough of the data boundary, privacy modes, on-chain contracts, and custody model.
- available on requestDPA pathData processing agreement covering subprocessor list, retention, and tenant-level deletion.
- available after security and contracting reviewBAA pathBusiness associate agreement scoped to metadata-only or private-gateway mode.
- available for enterpriseMSA pathMaster services agreement for enterprise deployment, including support and SLA terms.
- availableAudit export pathEvidence bundles, finance reports, and per-event proof exports for audit and dispute review.
- availableData retention reviewReview and configuration of retention windows for economic events and any opt-in trace data.
- available for regulated buyersPrivate deployment reviewCustomer-hosted inference path. Economic events recorded over a signed channel.
Proof without prompt storage.
- Receiptsx402 settlement records on Base. See /receipts for the surface.
- Outcome recordsAccepted, revised, escalated, or failed status tied to the event. See /prove for the surface.
- Audit exportsStructured exports of events and decisions for finance, audit, and legal review.
- Proof bundlesPer-event evidence bundle linking attribution, cost, policy, and settlement when applicable.
Evidence does not require prompt storage.
Billing state is separate from prompt content.
Billing state and plan state are stored separately from any AI event content. Payment providers are used only for subscription and invoice operations. Build checkout is controlled by the billing rollout. Enterprise billing remains sales-assisted.
Do you store prompts?+
No prompt storage is required. Metadata-only mode is the default.
Do you store responses?+
No response storage is required. Metadata-only mode is the default.
Can we use metadata-only mode?+
Yes. It is the default. The economic event lands in the ledger without prompt or response content.
Can we complete a security review?+
Yes. Request a security review through the access route. DPA path is available on request.
Is settlement required?+
No. Meter works without settlement. Receipts are added when AI work is payable.
Is P402 SOC 2 certified?+
SOC 2 is a roadmap item until an audit report exists. P402 does not claim certification before audit.
Does P402 support HIPAA workloads?+
BAA path is available after security and contracting review. Healthcare buyers should request the path before production use.
Can we use P402 in healthcare or finance?+
Yes. Use metadata-only or private-gateway mode. Request the regulated-buyer review path.
Can we export audit evidence?+
Yes. Evidence bundles, finance reports, and per-event proof are exportable. See /prove for the surface.