Documentation / Security Model
LIVE

Security Model

Permission to spend is not unrestricted control of money.

Agent → credential → Financial Intent → Policy → human or execution → Agent Wallet → Circle

Paymod is not the wallet infrastructure - Circle's Developer-Controlled Wallets hold and execute for each Agent Wallet, using an entity authority Paymod controls. The agent itself receives only a revocable wallet credential, never that entity authority or any direct signing power.

Policy enforcement, reservation accounting, idempotency and audit events protect the application boundary in front of Circle's own custody. Paymod does not protect a compromised Paymod entity credential, an approved but undesirable payment or an insecure third-party agent runtime.