Veyline Enterprise: security, architecture, and procurement brief
This page is the enterprise evaluation packet for Veyline: what it does for an organization, how the production system is built, what security and governance evidence exists, how it is deployed and supported, and how to start a 14-day pilot. Everything here is stated plainly, and anything not claimed is marked as not claimed.
Contents: Enterprise use cases Production architecture Security and governance What we do not claim Deployment Support and commercial terms Procurement checklist Start a pilot
Enterprise use cases
Agent fleet spend governance
Put machine-enforced policy between your agents and your money. Org-level authorization with spend caps, action allow and deny lists, and custom rate limits runs before every operation. The economic governor compiles natural-language spending policy into enforced mandates with human-approval thresholds that fail closed; each step is decided ALLOW, DENY, or ESCALATE_HUMAN, and spend commits against a durable budget.
Finance-grade audit trail
Every operation records payment, execution, delivery, and outcome as separate, independently proven stages in a hash-chained evidence ledger with deterministic replay. Enterprise orgs can pull org-level usage reporting and export the audit and evidence trail through a dedicated endpoint.
API provider monetization at scale
Charge per call with x402 and keep the hard parts in the platform: payment verification, settlement certainty, duplicate protection, and auditable evidence for every paid call.
Marketplace and machine-to-machine settlement
Run autonomous commerce flows where no human watches the economics: intent checked against policy, settlement classified with certainty instead of assumed, failures recovered to a known terminal state, and the full trail preserved as evidence.
Production architecture
Concise summary an evaluator can verify against the live system:
- Hosted REST API. The production service runs at
https://payload-rail.fly.dev(the OpenAPI server URL). 47 paths, 51 operations, published athttps://payload-rail.fly.dev/openapi.json. All traffic is over HTTPS. - Stack. Express with TypeScript, SQLite persistence, hosted on Fly.io. The production architecture is frozen and the service is the same one all plans use.
- Authentication. API-key auth with per-account namespacing, sent as a Bearer token (
Authorization: Bearer <key>). Keys are high-entropy, stored hashed, shown once at creation, scoped and product-bound so a key cannot exceed its entitlement, and revocable and rotatable at any time. Enterprise org admin operations additionally require an active enterprise entitlement plus theveyline:adminkey scope: non-admin enterprise keys and non-enterprise tiers receive 403, unauthenticated requests receive 401. - Settlement chain. At launch: USDC on Base. Payments are verified independently on-chain and classified as confirmed, unconfirmed, or unknown. Ambiguity is reported, never silently treated as paid.
- Exactly-once execution. Atomic transaction-hash reservation prevents double claims; idempotency keys make retries safe; concurrent submissions resolve to a single outcome; crash-interrupted operations resume or roll back cleanly to a known state.
- Operation lifecycle. Intent, policy check, preflight, routing, authorization, payment, settlement, execution, delivery, outcome, reconciliation, recovery, evidence. Each stage is verified before the next begins.
- Non-custodial. Veyline never holds funds, private keys, or seed phrases. It verifies payments on-chain and controls what agents are authorized to do. It is not a wallet and not a payment facilitator.
Security and governance evidence
- Server-side enforcement. Policy checks, budgets, and approval thresholds are enforced by the platform before money moves. Client assertions are never trusted; approval thresholds fail closed.
- Evidence integrity. Every operation is recorded in a hash-chained ledger. Payment, execution, delivery, and outcome are proven separately. Deterministic replay reconstructs any operation for audit.
- Settlement certainty. Unknown settlement never silently becomes "paid." No retry after unknown settlement without explicit review.
- Org administration (Enterprise). Dedicated endpoints for listing, creating, and revoking scoped org keys; reading and updating org governance policy; org-level usage reporting; and exporting the audit and evidence trail. All gated on enterprise entitlement plus
veyline:adminscope. - Metering honesty. Operations are metered against the plan's included allocation in real time; requests beyond it are throttled (429), not silently billed. Usage overages and basis-point fees on protected volume are disabled by design today.
What we do not claim
Stated explicitly so a procurement review has no ambiguity:
- We do not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or any other compliance certification. None is held or implied.
- We do not publish a penetration-test attestation. The MCP Launch Readiness Audit is a security scanner with fixes, not a certification or penetration test.
- We do not publish a formal SLA or uptime figure for self-serve tiers. Enterprise availability and response terms are negotiated per contract.
- Veyline is not a wallet, money transmitter, or payment facilitator, and takes no custody of funds or keys.
- Public pages carry illustrative example hostnames only; production API details are provided with issued credentials.
Deployment
- Veyline is a hosted service. There is no self-hosted Veyline. The platform is operated by Payload on Fly.io and reached over HTTPS at
https://payload-rail.fly.dev. - Separate self-hosted option. The Veyline Developer Primer ($79) is a different product: downloadable Node.js middleware you run yourself to add per-call x402 payments to your own server. It is not the hosted Veyline platform.
Support and commercial terms
- Support channel. kyler.simmons.partners@gmail.com. Inquiries are answered within one business day.
- Enterprise pricing. $5,000+/month with custom terms and a negotiated operations allocation, enforced in real time. Full safety foundation included on every plan.
- Pilot. Approved inquiries are provisioned as a 14-day Enterprise pilot with a negotiated operations allocation, after inquiry review.
- Payment. Self-serve plans check out through Stripe. USDC on Base checkout is available for any plan where Stripe is unavailable or unwanted; start with the inquiry form and mention the plan.
- Legal. Subscription is governed by the Terms of Service and Privacy Policy. Enterprise custom agreements, DPAs, and vendor-security questionnaires are handled per deal on request.
Procurement checklist
Materials a procurement or security team can review right now:
- This brief (print or save as PDF from your browser).
- Live API contract: openapi.json (47 paths, 51 operations).
- Terms of Service and Privacy Policy.
- Product page with pricing: veyline.html.
- Machine-readable product record: agents.json.
Start a pilot
Send an enterprise inquiry. We reply within one business day, and approved inquiries are provisioned as a 14-day Enterprise pilot with a negotiated operations allocation.
Prefer email? kyler.simmons.partners@gmail.com