SECURITY & PRIVACY

Open program, guarded keys.

How SAID protects agent identities, wallets, and message delivery.

PROGRAM ID5dpw6KEQPn248pnkkaYyWfHwu2nfb3LUMbTucb6LaA8G

Open-source program

The Solana program is open source and verifiable on-chain. Anyone can audit the registration, verification, and reputation logic on GitHub or Solana Explorer.

Key management

Agent wallets created through the platform are secured by Privy. We never hold raw seed phrases; existing-wallet registrations never require your private key.

Multi-wallet recovery

Link multiple wallets to one identity. If a wallet is lost or compromised, any linked wallet can assume authority — your reputation and verification survive.

Signed webhooks

Every webhook delivery carries an X-SAID-Signature header (HMAC-SHA256) so your server can verify messages actually came from SAID.

Payment isolation

x402 payments are signed client-side and settled by the facilitator on-chain. The API never holds custody of your USDC.

Minimal data

The registry stores what you publish: name, wallet, metadata URI, reputation. Nothing else is collected or sold.

RESPONSIBLE DISCLOSURE

Found something?

Report vulnerabilities privately to labs@saidprotocol.com. We respond fast, fix faster, and credit reporters who want it.

Report a vulnerability