Nustro’s reach is scoped to one thing: the escrow that backs accountability. Your agents’ operating funds sit in wallets whose keys Nustro does not hold and cannot use. Escrow balances sit in dedicated per-agent wallets under Nustro’s custody, movable only through protocol events — contributions in, dispute outcomes and releases out — every movement on-chain and auditable.
Every agent operates two wallets on public networks. The operational wallet holds its working funds and revenue — keys with the principal, managed through your platform, outside Nustro’s reach. The escrow wallet holds its liability balance — custodied by Nustro as the Operator, because executing a dispute outcome requires it. That custody is scoped: bounded to the escrow balance, exercised only on protocol events, visible on-chain.
One consequence worth stating plainly: Nustro cannot issue refunds. A payment settles into the provider’s operational wallet, and Nustro cannot sign a transfer out of it. Recourse flows through disputes instead — filed through your platform, decided by the Operator, paid from the counterparty’s escrow. The funds that back accountability are the only funds Nustro can reach.
Constraints are the product. Every “cannot” below is structural — enforced by where the keys are, not by a policy that could change.
| Nustro can | Nustro cannot |
|---|---|
| ✓Custody escrow balances and execute dispute outcomes from them | ✕Touch any operational wallet — hold, move, or freeze working funds |
| ✓Issue, suspend, and revoke agent certificates | ✕Issue refunds or reverse settlements |
| ✓Compute ratings from settlement history | ✕Move escrow outside protocol events — no discretionary transfers |
| ✓Define escrow terms and verify escrow state | ✕Transact on behalf of a platform, principal, or agent |
| ✓Relay dispute filings your platform authenticates | ✕Alter settled history — settlements are on-chain |
Answers to the questions a risk review asks — grounded in how the system is built and what the Platform Operator Agreement commits to, not in assurances.
Stated concretely, because “bank-grade security” is a phrase, not a practice.
The protocol is designed so trust flows from signatures and on-chain settlements — not from data accumulation. Nustro’s data footprint is the narrow set required to operate the trust layer, and no more.
Walk your risk team through the custody model with us — or verify it yourself in sandbox, free.
The trust layer for transacting AI agents. Verified identity, escrowed liability, and binding recourse — Nustro never holds your agents’ keys.