Skip to content
Machine Outcome
Proof How it works Integrate Work with us Trust boundary
Run locally
Explore MOVNavigation
  • Overview
  • Why MOV
  • Decisions
  • How it works
  • Proof
  • Integrate
  • Trust
  • FAQ
  • Work with us
← Back to MOV

Trust boundary

Security

MOV's local Runtime Acceptance path is designed to minimize the authority and secrets it needs. Security reports are welcome and should be sent privately.

Last updated: 17 August 2026Public disclosure route available

Report a vulnerability

Email sarmad@machineoutcome.com with the subject “MOV security report”. Include the affected surface/version, reproduction steps, impact and any safe supporting evidence.

Please do not include private keys, seed phrases, wallet secrets, API keys, customer data, or other unnecessary secrets in a report.

Current security boundary

  • The public local acceptance path performs no purchase, signer invocation or runtime-secret read.
  • MOV does not take custody of buyer funds.
  • Live payment/signing is a separate explicit authorization boundary.
  • Required but missing, contradictory or non-final evidence must resolve to UNKNOWN, not acceptance.
  • Version-pinned deterministic verifiers and exact evidence binding are part of the current kernel design.

Coordinated handling

Give us a reasonable opportunity to investigate and fix a material issue before public disclosure. Do not intentionally access unrelated accounts/data, degrade service, or create financial side effects while testing.

Security.txt

A machine-readable disclosure contact is published at /.well-known/security.txt.

No badge theater: this page states the current product boundary. It does not claim certifications, audits or controls that have not been independently obtained.
Machine Outcome

The acceptance layer between machine payment and machine action.

sarmad@machineoutcome.com

Built and operated by Sarmad Tawfeek · Sweden.

Personal site LinkedIn GitHub

Product

Why MOV Failure proof How it works Try locally One real flow

Concepts & resources

x402 vs acceptance AI agent payments API contracts vs acceptance README llms.txt

Trust & legal

Security License Privacy Terms Contact
© 2026 Machine Outcome Verification Runtime Acceptance · x402-first · Local-first Back to MOV ↑