Product · Trust & Security

Custody, bounded by design

Nustro’s reach is scoped to one thing: the escrow that backs accountability. Your agents’ operating funds sit in wallets whose keys Nustro does not hold and cannot use. Escrow balances sit in dedicated per-agent wallets under Nustro’s custody, movable only through protocol events — contributions in, dispute outcomes and releases out — every movement on-chain and auditable.

01 · Custody model

Who holds what

Every agent operates two wallets on public networks. The operational wallet holds its working funds and revenue — keys with the principal, managed through your platform, outside Nustro’s reach. The escrow wallet holds its liability balance — custodied by Nustro as the Operator, because executing a dispute outcome requires it. That custody is scoped: bounded to the escrow balance, exercised only on protocol events, visible on-chain.

Principal, via your platform
Operational wallet
Principal’s keys
Holdsworking funds & revenue
Nustro’s reachnone — cannot sign
Visibilitypublic, auditable
Operator custody · scoped
Escrow wallet
Nustro’s keys · protocol-bounded
Holdsliability balance only
Moves onsettlement contributions, dispute outcomes, releases
Visibilityper-agent, on-chain, auditable
Nustro
The Operator
Decisions & records
Certificatesissued & revoked
Ratingscomputed from settlements
Disputesdecided, executed from escrow

One consequence worth stating plainly: Nustro cannot issue refunds. A payment settles into the provider’s operational wallet, and Nustro cannot sign a transfer out of it. Recourse flows through disputes instead — filed through your platform, decided by the Operator, paid from the counterparty’s escrow. The funds that back accountability are the only funds Nustro can reach.

02 · Boundaries

What Nustro can and cannot do

Constraints are the product. Every “cannot” below is structural — enforced by where the keys are, not by a policy that could change.

Nustro canNustro cannot
Custody escrow balances and execute dispute outcomes from themTouch any operational wallet — hold, move, or freeze working funds
Issue, suspend, and revoke agent certificatesIssue refunds or reverse settlements
Compute ratings from settlement historyMove escrow outside protocol events — no discretionary transfers
Define escrow terms and verify escrow stateTransact on behalf of a platform, principal, or agent
Relay dispute filings your platform authenticatesAlter settled history — settlements are on-chain
03 · Business continuity

Continuity, in the architecture

Answers to the questions a risk review asks — grounded in how the system is built and what the Platform Operator Agreement commits to, not in assurances.

Operational resilience
Service status is published and monitored. Settled history is on-chain and remains verifiable by any party during a service interruption; certificate verification is designed to degrade safely rather than silently.
Segregated balances
Escrow is held per agent in dedicated on-chain wallets — never commingled, never pooled. Every movement is a public transaction attributable to a protocol event.
Portability
Agent identities, ratings and escrow semantics are defined by an open specification — not rows in a proprietary database. Any other operator implementing that specification can verify and serve them, which is what makes portability real rather than promised.
Wind-down commitments
On any service termination: open disputes are resolved or returned to a defined state, escrow balances are released to their principals, and affected platforms receive contractual notice — commitments of the Platform Operator Agreement, not courtesies.
04 · Security practices

How the system is engineered

Stated concretely, because “bank-grade security” is a phrase, not a practice.

Management keys are hashed
Your Nustro-Api-Key is stored as a hash and shown once at issue. Nustro cannot recover it — rotation is the only path, and revocation is immediate.
Agent keys are never seen
Agent operational keys are generated for one-time delivery and never stored. Certificates bind to the public key; per-request, timestamp-bound proofs mean the private key never travels.
Escrow key isolation
Escrow signing keys are held separately from the application tier and exercised only by the settlement and dispute engines on protocol events — no operator console, no manual transfer path.
Tenant isolation
Every management credential is scoped to one platform and one environment. Sandbox and production are separate keys, separate data, separate networks.
Signed webhooks
Every delivery carries an HMAC over the timestamp and raw body, with per-endpoint secrets you can read and rotate. Endpoint URLs are validated against private ranges; destination changes are written to your activity log.
Auditable management surface
Every consequential management action — key rotations, webhook changes, promotions, verification events — lands in an activity log your admins can read.
Encryption & transport
TLS everywhere; secrets encrypted at rest; agent authentication is per-request, certificate-bound, and replay-protected by timestamp.
Responsible disclosure
Security reports go to security@nustro.com. We acknowledge, we fix, and we credit — the disclosure policy is published and versioned.
05 · Data & compliance

Data minimization, by architecture

The protocol is designed so trust flows from signatures and on-chain settlements — not from data accumulation. Nustro’s data footprint is the narrow set required to operate the trust layer, and no more.

No PII on transacting parties
Nustro does not collect personal data about your principals’ customers or about the parties transacting through agents. Agents are identified by DID and certificate; counterparties verify signatures, not identities-behind-identities. What the protocol never needs, Nustro never stores.
Held
Your company profile and KYB documents — collected at the platform level, where the accountable legal relationship is. Principals and agents you register, as registration records and identity documents. Transaction and dispute records. The management credentials and webhook configuration described above.
Not held
Operational wallet keys. Personal data of your end-customers. Payment credentials — settlement is on-chain, and the only funds path Nustro touches is escrow.
Agreements
The Platform Operator Agreement, Terms of Service, Privacy Policy and DPA are published and linked in the footer — reviewable before you register, because your legal team reads them before your engineers do.
Standards work
AEAP Labs participates in the OWASP GenAI agentic-security initiative and Cloud Security Alliance AI safety working groups, and AEA/P is developed as an open specification with a public changelog.
Questions your risk team wants answered directly — security@nustro.comPatent pendingOWASP GenAICloud Security AllianceOpen specification

Put a trust layer under your platform

Walk your risk team through the custody model with us — or verify it yourself in sandbox, free.

Contact salesStart in sandbox

The trust layer for transacting AI agents. Verified identity, escrowed liability, and binding recourse — Nustro never holds your agents’ keys.

Patent pending OWASP GenAI Cloud Security Alliance Open specification
Product
Agent IdentityProof of PerformanceLiability EscrowDispute ResolutionHow settlement worksTrust & SecurityPricing
Developers
Nustro docsAPI referenceWebhooks & eventsReference apps ↗Changelog Status
Protocol
What is AEA/P ↗Framework ↗Specification ↗AEA/P docs ↗AEA/P reference ↗AEA/P certified ↗
Company
AboutContactLegalPrivacy
© 2026 Nustro, LLC nustro.com