Security Architecture & Trust Model

Transparent architectural guarantees, non-custodial operations, and cryptographic defense-in-depth on Base Mainnet.

🛡️
100% Non-Custodial
M2M Sentinel never accepts, stores, or handles private keys, mnemonic seed phrases, or transaction custody. Subscriptions and free tier challenges use standard cryptographic EIP-191 message signatures.
🔒
One-Way SHA-256 Hashing
API keys (sk_free_..., sk_live_...) use a server-keyed HMAC-SHA-256 lookup index and a separate randomly salted SHA-256 verifier. Plaintext credentials are not persisted.
⚡
Fail-Closed Isolation
All state validation and credit metering execute atomically in Redis Lua scripts. If primary persistence or RPC trust quorum becomes degraded, the engine fails closed with structured HTTP 503 errors.

Shared Responsibility Security Model

M2M Sentinel operates on a clear separation of security responsibilities across cloud infrastructure, application logic, and upstream blockchain nodes:

Security Layer Provider / Owner Enforced Controls
Platform & Edge Infra Vercel Edge Network TLS 1.3 edge termination, global DDoS mitigation, isolated ephemeral serverless container runtime (IAD1), encrypted edge environment variables.
Application Security M2M Sentinel Engine Zero-plaintext API key storage (SHA-256 salted hash), atomic Redis Lua state machine, PUSH-aware bytecode AST walker (preventing opcode spoofing), fail-closed payment state machine, URL credential refusal.
Blockchain Data & Consensus Base RPC & Nodes Multi-provider quorum consensus (≥ 2 independent Base mainnet nodes), Chain ID 8453 enforcement, bytecode hash integrity checks, fail-closed 503 on consensus mismatch.

Cryptographic Key Protection & In-Transit Security

M2M Sentinel enforces strict defensive boundaries across all network boundaries:

RPC Trust Model & Provenance Levels

To eliminate reliance on single centralized RPC nodes, M2M Sentinel tracks multi-provider provenance for every observation:

On-Chain EAS Project Metadata Attestation & Superchain Registry

M2M Sentinel’s verified project identity, repository lineage, and Base payout configuration are attested on the Optimism Superchain using the Ethereum Attestation Service (EAS):

🔴 Optimism EAS Verified Project Metadata Attestation Schema #472 Verified
Base EAS Contract:
0x4200...0021 ↗
EAS Attestation UID:
0x3fcc74a0...24b05bf2 ↗
Schema UID:
0x6ab544f8...02c385
Attester / Payout Address:
0x6d6c398390cfb88f1cd42715b84906a0bd6652aa
Optimism Atlas Project ID:
0xae56394c...46dd52dac ↗

Responsible Vulnerability Disclosure

We welcome security researchers and developers to audit our platform, verify our open-source SDKs, and inspect our detection engines.

Reporting a Vulnerability

If you identify a security vulnerability, please disclose it responsibly by contacting our security team directly:

Security Contact: [email protected]

We acknowledge all legitimate reports within 24 hours and coordinate patches prior to public disclosure.