Third-party proxy
Agents call FlockTab. FlockTab calls the provider. We see the provider key in RAM for that hop only. Ciphertext at rest cannot be decrypted without your unlock secret. Keys do not stay in your VPC on SaaS v1.
Security
We sit in front of spend. Caps, risk, and the ledger run here, not in the agent. Ciphertext at rest; unlock is on the request. This is the public threat model, not a compliance brochure.
Agents call FlockTab. FlockTab calls the provider. We see the provider key in RAM for that hop only. Ciphertext at rest cannot be decrypted without your unlock secret. Keys do not stay in your VPC on SaaS v1.
AES-256-GCM ciphertext at rest. Unlock secret is never stored. Decrypt only in the proxy, only for the upstream call. Raw keys are not logged.
ft_live_ and ft_test_. SHA-256 hash at rest. Secret shown once at issue. Revoke is instant: every request checks revoked_at.
The ledger is integer cents in Postgres. If Postgres is down, the proxy returns 503 and does not call the provider.
Each row is agent, tool, cents, allow or deny. Prompt and completion bodies are not stored by default.
Close the tab. New reserves stop. A stolen virtual key's blast radius is the remaining cap on that tab.
Payments, email send, delete, prod deploy default deny unless allowlisted and remaining ≥ $25.00. Unknown tools are write, not read.
Retry the same request against an open hold: 503 ledger_unavailable. No second upstream call against one hold.
No SOC2, no VPC, no customer-managed keys, no prompt redaction suite, no live Stripe checkout, no prepaid wallets. Do not infer them.