Security & trust
A marketplace asks buyers to trust an operator with money and sellers with traffic. This page separates what the escrow contract is designed to enforce from what is policy, and lists what we do not verify yet. The contracts are unaudited testnet software.
Custody bounds
The MarketEscrow contract on Whitechain, not our database, limits what the operator can do with buyer funds. It is designed so that:
- The operator can settle at most each buyer's remaining cap, counted cumulatively, and nothing after the cap expires.
- A per-window circuit breaker (
settleLimit) caps what the operator can settle in total across all buyers, so a leaked operator key is bounded twice: per buyer by the cap, and overall by the window limit. - A new operator only takes effect after a timelock (24h on the hosted deployment).
- The owner is a 2-of-3 Safe. A separate guardian can pause in an emergency but cannot unpause or move funds.
- Settlement can only pay registered sellers.
- The fee on each line is bounded by an immutable maximum of 10% of the seller amount (the default fee is 5%).
- Settlement batches are idempotent: replaying a batch id is rejected.
- Buyer withdrawals wait a fixed delay and keep working while deposits and settlement are paused.
- Seller payout addresses are set by the seller's own wallet, never by an API key or the operator.
- x402 payments (
depositWithAuthorization) and relayed permit deposits are credited only to the wallet that signed them. The facilitator key that submits them has no role in the escrow and pays gas only. An x402 payment raises the payer's cap by exactly the amount paid, so the operator can settle no more than the payer authorised. - An x402 authorization that someone submits straight to the token still pays the escrow. Only the operator or the owner can then credit it, only to its signer, and never more than the escrow's unattributed balance.
The live values (the owner Safe and its signers, the guardian, the operator, the timelock and the window limit) are read from the contract on the Whitechain escrow page.
What the bound does not cover: within your cap, the operator decides what to charge you based on its metering. Keep caps sized to what you are willing to spend before you next check your usage. The buy flow suggests a cap of at most 25 ITC for that reason.
What the API and order book publish
Public endpoints publish aggregated price levels only: price, number of offers, number of healthy offers and remaining daily capacity. The API and the order book never publish seller wallets, endpoint URLs, upstream providers or per-offer volume, and the x-inferit-offer header is an opaque hash. One known exception: if the escrow does not know a seller as registered (only after a chain reset or redeploy), the reason shown on that failed usage row names the seller's Whitechain address. These promises cover what Inferit itself publishes. The chain publishes its own data, described next.
On-chain visibility
Whitechain settlement is public. MarketEscrow is an ordinary contract on a public chain, so anyone can read its events and views:
- Every settlement line:
LineSettled(batchId, buyer, seller, sellerAmount, fee), with buyer and seller as indexed topics. Who paid which seller, and how much per line, is public. - Each seller's address and payout address (
SellerRegistered), unwithdrawn earnings (sellerState(seller)) and withdrawals (EarningsWithdrawn). SummingLineSettledgives a seller's total volume. - Each buyer's deposit, cap, spent and expiry (
buyerState(buyer)and the deposit, cap and withdrawal events).
A buyer can therefore filter LineSettled by its own address and match the amounts against its usage log to find the wallet of the seller behind its requests. Buyers and sellers who prefer to keep marketplace activity separate from their other on-chain activity can use a dedicated wallet for it. Public settlement is also what makes the market auditable: the on-chain metrics are computed from these same events.
Data handling
- Prompts and completions are relayed to the seller, never stored by Inferit. Usage records hold token counts, costs, latency and status.
- Request and response bodies are not logged; logs redact credentials.
- API keys are stored as peppered SHA-256 hashes and shown once.
- Seller endpoint tokens and upstream keys are encrypted with AES-256-GCM. Deleting an offer destroys the ciphertext.
- The operator and facilitator keys are read only from the environment and never committed. x402 signatures are never logged.
The full list, including retention, is in the privacy notice.
What we do not verify yet
Be clear-eyed about these before routing anything sensitive:
- Model authenticity. Nothing proves a seller runs the model they list, at the precision they imply. A seller could serve a smaller or more aggressively quantized model. There is no TEE attestation or output fingerprinting yet.
- Token counts. Usage comes from the seller server's reported
usage. The market does not re-tokenize to check it. Your cap limits the damage; it does not prevent over-reporting. - Confidentiality from sellers. The seller's server sees your prompts in plain text, as any inference provider does. Do not send data you would not give an unknown host.
- Self-hosting. Nothing proves an endpoint offer is self-hosted. The API rejects endpoint URLs on known hosted providers, but that list is incomplete, and a seller can put a proxy to a hosted API behind their own domain. Such a listing is key resale and is not allowed, but the API cannot detect it.
- Seller accountability. There are no seller bonds or slashing yet. A bad seller is handled by health checks and delisting, not by losing stake.
- Operator key. The owner is a 2-of-3 Safe, but the operator is a single hot key held by the API. It is bounded by the caps, the circuit breaker and the timelock, not by a multisig.
- The x402 facilitator is ours. No independent x402 facilitator exists for Whitechain, so the API verifies and settles x402 payments itself. The party that sells you the request is also the one that submits your payment. The contract limits what that can do (the credit goes to your own escrow balance), but no third party checks the quote you are shown: cap what your client will sign.
- Audits. The contracts are tested (unit, fuzz and invariant tests) but not externally audited. Treat every statement on this page as the design intent of unaudited testnet code.
- Finality. The API marks usage settled once the settle transaction is included. On an OP Stack chain only finalized blocks are irreversible; the site shows settlements as pending finality until then.
- Licence compliance. Licence classes and summaries are our reading of the model cards; sellers remain responsible for meeting the terms.
Reporting a problem
This is testnet software. If you find a way to move funds outside the bounds above, or to learn anything the API promises not to publish (beyond what the chain itself shows, described under On-chain visibility), please follow the security policy and do not disclose it publicly before it is fixed.