Security is the foundation of agent-native commerce. If an AI agent can spend on your behalf, the spending boundary has to be unbreakable. Here is how we protect you.
1. Wallet isolation
Your agent never touches your payment card. It spends only from a wallet balance you fund. An agent that is compromised or misbehaves cannot drain your bank account — it can only spend what is in the wallet, within your limits.
2. Authorization & limits
- You set per-transaction or policy-based authorization before any purchase.
- Spending limits cap exposure; you can lower or revoke them at any time.
- Every transaction is logged and auditable from your account.
3. Escrow & fulfillment
Funds are held in escrow and released only against verified fulfillment, so you are not charged for items that never ship. Refunds return to your wallet balance.
4. Account protection
- Passwords are hashed with scrypt; we never store plaintext credentials.
- Email verification and password recovery flows are enforced.
- Rate limiting and bot defense (Turnstile) protect sign-in and checkout.
5. Infrastructure
XBuyer runs on Cloudflare's global edge (Workers, D1, R2) with encryption in transit and at rest. We follow least-privilege access for internal systems.
6. Vulnerability reporting
If you find a security issue, email security@xbuyer.com. We acknowledge reports promptly and work with researchers in good faith.