Support · Security & data

Security overview

FeeGuard observes your event stream and never intermediates payments. Three properties back that claim everywhere it appears: restricted read-only scopes, AES-256-GCM key encryption, and an append-only audit trail.

Observe, never intermediates

FeeGuard sits nowhere in your payment path. Buyers, sellers and Stripe interact exactly as before; detection reads events after the fact, so a FeeGuard outage changes nothing about money movement.

Read-only posture

Detection requires five read scopes only. Write scopes exist solely for opt-in automation, are requested explicitly at enablement, and remain revocable by you instantly.

The three properties in practice

Scopes limit blast radius. Envelope encryption isolates tenants cryptographically. The append-only trail makes every action examinable forever — including our own system actions, labelled as such.

What we ask you to trust, and what you can verify

Trust nothing silently: the detector math is published, the scanner runs it without an account, and the self-test corpus asserts false positives as hard as positives. Security review packets are available under Enterprise agreements.