Security
In one sentence: IronBridge sits between your AI and your money and checks every payment before it goes out. It is separate software the AI cannot see, trick, or switch off.
Even a fully jailbroken AI can only ask to spend. The checkpoint runs outside the AI, decides what clears, and serves nothing on a forged or unpaid request. New to this? Read the plain-English docs.
Reporting a vulnerability
We welcome responsible disclosure. Report security issues via the contact in our security.txt (RFC 9116) or through Contact. Please give us a reasonable chance to respond before public disclosure.
Design
- The gate is “off-LLM” — separate software the model cannot reach — and it cannot move funds on its own; refusing unpaid calls is proven live on the public network.
- Every gate decision lands in a hash-chain — a public log where each entry is locked to the one before it, so past records cannot be quietly edited. Re-check it yourself:
/api/law25/verify. - Keys and rules live outside the model's reach.
Custody
Pay-per-call revenue settles to a shared multi-signature vault (a Gnosis Safe, 0x5Bb0…1680) rather than any one person’s wallet — moving funds out needs more than one sign-off. Migration of the Dog Tag contract owner from a single operator key to the Safe is in progress.
Self-hosted
When you run IronBridge in your own Cloudflare account, you control the deployment, the keys, and the funds. IronBridge custodies nothing on your behalf.
IronBridge · self-hosted off-LLM gate · lab deployment. Updated 2026-08-12. Terms · Privacy · Disclaimer · Security · Legal