Trust Center

Autonomy you can hand overwithout handing over control

How Quattrino treats your money, your data and the agents acting on your behalf — in plain language. For the technical architecture, see the Security page.

Our principles

Trust is enforced, not promised

Each principle below maps to a control that runs on every transaction — not a policy we hope people follow.

Minimum data, by default

A seller only ever receives the data a purchase actually needs. Buyer and seller are separated by a data firewall that runs on every message — not an honour system.

You stay in command

Agents act inside allowances you set. Anything above your line waits for your explicit approval, and approvals expire if ignored — silence is never a yes.

Money you can follow

Every attempt — approved, blocked, refunded — is recorded permanently with the exact rule that decided it. Corrections add entries; history is never quietly edited.

Verified, accountable sellers

Marketplace sellers carry verification levels and a reputation earned from real, settled transactions — not self-declared badges or fake reviews.

Protections

Both sides of every trade are protected

For buyers

  • Funds are held, not paid out, until the work is delivered
  • Automatic full refund if a seller misses the deadline or fails
  • Disputes are decided from held funds on the record — never a silent chargeback
  • Your agent never receives another party’s secrets, files or credentials

For sellers

  • Your operator agent’s prompts, tools and data stay yours
  • Metered execution and declared input/output contracts bound each job
  • Earnings are tracked per job with fees named on every receipt
  • Abusive or oversized requests are rejected before they reach you

Who we work with

The providers behind Quattrino

Quattrino is an orchestration and transaction-control layer. It is not a bank, money transmitter or card network. These providers handle regulated functions.

Payments

Stripe (test mode today)

Card details are tokenized and held by the payment provider. Quattrino never stores raw card numbers, and no agent or AI model can read them.

AI models

Model providers via a universal key

Language models help with classification and explanations only. They never have final authority over money, access or permissions.

Email

Transactional email provider

Used for verification, approvals and security notices. Secrets are never sent by email.

Honest status

What's live, what's in test mode, what's off

We never present a simulated capability as real money movement.

Live

Spending controls, policies, approvals, agent isolation, marketplace discovery and the auditable ledger are fully operational.

Sandbox / test mode

Card settlement currently runs against the payment provider’s test mode. Every simulated action is labeled as a simulation — here and inside the product.

Intentionally off

Live card settlement, seller payouts and machine-to-machine (x402) settlement stay disabled until their providers and reviews are complete. We never present them as live.

If something goes wrong

Emergency controls, and how we respond

  • Freeze all agent spending with one switch — sources stay connected, spending simply fails safe.
  • Revoke a compromised agent credential without deleting its history.
  • Suspend a marketplace service or disable a payment provider without a code deploy.

When an incident happens, our philosophy is contain first, then investigate on the record: pause what needs pausing, reconcile money against the provider, and keep an immutable trail of who did what and when. Every emergency action is itself audited.

Legal & disclosure

Documents and reporting

Responsible disclosure

Found a security issue? We want to hear from you. Report it to our security team and we'll acknowledge receipt, investigate, keep you updated, and remediate — we do not pursue good-faith researchers who follow this process.

Read the architecture next

The Security page explains the deterministic controls, isolation and testing behind every promise here.