Technical Documentation

Security and compliance

API controls, on-chain custody, and the limit of what we promise.

Controls

  • Encrypted transit and security headers on the API
  • Authenticated session; staff do not see fiscal setup or the plan charge
  • Secrets (Stripe, providers) from the environment, not the client
  • Printing on the floor network: Nodo does not forward the ticket to a third party to “analyze” it
  • Wallet keys are not on Nodo servers. Users sign with Privy or an external wallet. The API stores the bound address and indexes Base activity
  • P2P USDC sits in a per-trade escrow clone on Base. The API records tx hashes and reads chain state; it does not sign user or arbiter keys
  • Wallet USDC and P2P escrow USDC sit at an address or in that trade’s contract. Nodo verifies the public receipt

What that does not mean

  • Nodo does not warrant that a third-party printer always prints, or that Base includes a transaction when you expect.
  • Nodo is not the tax office or the floor’s bank, and it is not holding user USDC in a platform wallet.
  • P2P escrow is role-based (seller, buyer, arbiter), not a multisig. Fiat in a P2P trade is off-chain between the parties.
  • Merchant cash-out is a request to Nodo as counterparty. Automated payout is not live.
  • Account login and the marketplace “Verified” badge are not document KYC for wallet or P2P. See AML, KYC, and verification.

The formal text is under Legal, Wallet and custody, and AML, KYC, and verification.