Deep First Search ·

Safe rails for the agent economy.

AI agents are starting to pay for things, and anyone can talk them into paying the wrong party. We keep every payment inside limits you signed, and expose less of your business.

The problem

Your agent reads untrusted content all day, and it can move money. One poisoned page is enough to make it pay the wrong party. And every payment it makes is public: who, how much, when. Attackers read your balance. Competitors read your suppliers.

18M+

x402 payments audited on-chain. Payer, payee, amount and timing are public for every one.

$150K+

drained from one AI agent's wallet by a single prompt injection. The same trick worked again a year later.

77%

of employees paste company data into AI tools that keep logs.

Exposure control

What third parties can link to you today. Same payment.
Less to link.

Each merchant sees a fresh payer with no history, and what your agent bought is shared with that merchant only, never with facilitators or the chain. Amounts and payees remain on-chain. Funding payers through a regulated exchange breaks the public link to you, while you can still prove any payment to an auditor.

x402 · payment LINKABLE

The product

Three layers. One SDK.

01

Agent Safe

An on-chain vault that assumes your agent will be tricked. You sign a budget per merchant; the agent's key can spend inside it and never widen it. Revoke or pause instantly.

  • Per-merchant budgets enforced on-chain
  • Increases need your signature and a timelock
  • You can always withdraw, even while paused

02

Policy gate

An x402 client that treats every payment request as hostile. Payee, asset, network and price must match what you approved before anything is signed. The model proposes; code decides.

  • Pinned USDC, networks and prices
  • Plans sealed before reading untrusted content
  • Sanctions screening that fails closed

03

Exposure control

Expose less of your business. Each merchant sees its own payer, nothing extra leaves your machine, and payers can be funded through a regulated exchange so the public can't trace them back to you.

  • A fresh payer address per merchant
  • Exchange-funded payers via an owner-side service
  • A tamper-evident log to prove any payment

Built to survive

Discreet. Never hidden from the law.

Non-custodial

We never hold funds or run relayers. Immutable contracts with no admin keys, open source.

Records you control

A tamper-evident payment log lets owners prove any payment to an auditor or tax authority, on their terms. Sanctioned addresses are screened before any payment.

A transparent token

Privacy lives in the app, not in the token. stays exchange-listable after EU AMLR 2027.

No single secret

No master key, no admin, no upgrade path. Enclaves are defense in depth, never the only lock.

Token allocation

1,000,000,000

total supply, minted once

Tokenomics

A supply that only goes down.

One billion , minted once at genesis. The contract has no mint function at all, so the number can only shrink.

    View as table
    AllocationShareTerms

    Usage burns supply

    Fees fill the jar. Burning empties it.

    Agent Safe

    0.1% fee in USDC

    Fee jar

    50% of fees, immutable

    Anyone

    burns to claim the jar

    Burned

    supply goes down

    No swaps, no oracle, no admin, nothing to front-run. The price to claim the jar doubles after every claim and halves every three days. Only Agent Safe, SDK and inference fees feed the jar. No transfer taxes, no reflections, no hidden market-maker deals.

    0%

    to venture capital

    0

    new tokens, ever

    0%

    of fees to the burn jar

    0y

    founder lock, on-chain

    No token until there is revenue to burn.

    Roadmap

    Product first. Token last.

    1. Phase 0 · Done

      Research

      Market pain, 30+ launches and failures studied, legal and security assessments, tokenomics.

    2. Phase 1 · Live on testnet

      Open-source SDK on Base Sepolia

      x402 client with a policy engine outside the model, Agent Safe vaults, per-merchant payers. Verified contracts and the first live x402 payment.

    3. Phase 2

      Mainnet on Base, audited

      Capped beta, independent review, bug bounty, real USDC fees. Exchange-funded payers.

    4. Phase 3

      Fair launch

      Wallet-only airdrop to real users, one-price public auction, liquidity burned, no mint function at all.

    5. Phase 4

      Deeper privacy

      Integration with a compliant, third-party privacy pool. Later: private inference paid through the same rails.

    Your agent will be tricked.
    Make sure it can't spend.

    npm install @deepfirstsearch/agent-pay