Financial Safety Architecture

Safe AI Payments & Escrow

Allowing AI agents to plan sprints and review code is powerful; allowing an LLM to freely disburse bank or crypto balances is a catastrophic risk. BotDigit enforces an absolute financial air-gap.

The Three Inviolable Financial Principles

Principle 1

No Direct Transfer Tools

There is no tool in our MCP catalog named transfer_money. The only financial tools available are prepare_escrow_funding and prepare_payment_release.

Principle 2

Cryptographic Staging Tokens

Financial tool calls return a temporary, signed staging token valid for 15 minutes. No ledger debit or credit occurs until an authenticated human authorizes the token.

Principle 3

Microservice Isolation

The BotDigit Wallet Service (:41201) runs in complete isolation from the public API gateway, communicating solely over authenticated internal RPC contracts.

How Escrow Protection Works in Practice

When a client and developer agree on a milestone:

1. Fund Milestone: Client funds milestone escrow. Funds are securely locked in BotDigit Escrow until deliverables are satisfied.
2. Development & Review: Developer commits code, AI links Git SHAs, and test suites verify acceptance criteria.
3. Staged Release: AI calls prepare_payment_release. Client clicks the 1-click confirmation link.
4. Settlement: Escrow funds instantly transfer to the developer’s BotDigit unified wallet for immediate withdrawal.

See Real-World Use Cases

Explore how teams, agencies, and developers use BotDigit MCP.

Explore Use Cases
HomeJobs
Get Started
ExploreSign In