Security questionnaire

BMM buyer security facts

A compact review sheet for developers, buyer agents, and marketplaces evaluating Blockchain Money Map x402 paid APIs. This page is factual product documentation, not a certification claim.

Vendor identity

Service name
Blockchain Money Map
Primary public site
https://blockchainmoneymap.com
Agent API base
https://api.blockchainmoneymap.com
Support contact
support@blockchainmoneymap.com

Data accepted

  • Public EVM wallet addresses
  • Public EVM contract addresses
  • Public transaction hashes
  • Caller-supplied public x402 endpoint, payee, receiver, and receipt facts

Data not accepted

  • Private keys
  • Seed phrases
  • Wallet passwords
  • Admin tokens
  • Supabase keys
  • Raw secrets or private wallet material

Payment boundary

  • Public paid endpoints use x402 payment challenges before paid execution.
  • The buyer agent signs payment in its own runtime; BMM does not request or store buyer private keys.
  • A valid x402 payment proves payment for a resource; it does not prove agent authority, seller identity, compliance status, or transaction safety.

Storage and logging notes

  • Public-chain inputs may be processed to generate research summaries and operational request records.
  • Saved report endpoints may create unlisted saved-report artifacts when the buyer calls those endpoints.
  • Raw signed payment header values should not be logged, pasted into support, or shared publicly.

Scope and boundaries

  • No SOC 2, ISO 27001, PCI, HIPAA, AML, sanctions-screening, or regulatory approval claim is made on this page.
  • Outputs are research and educational summaries, not financial, legal, tax, investment, trading, or compliance advice.
  • Blockchain Money Map depends on upstream blockchain data providers, facilitator availability, and public-chain data quality.