OceanAltOceanAlt

PROOF · FROM NARRATIVE TO RUNNING CODE

Not a deck.
Click anything — verify it live.

Most early-stage projects sell a vision on slides. OceanAlt is different: every item below can be verified right now — in your browser or with one line of curl. Protocol, blocks, settlement, audit — all real. A tiny team reaching this in weeks is itself proof of capital efficiency.

78

over-reach payments blocked before settlement

9

always-on compliance gates (11 total, 2 optional)

6

Attack Lab episodes, breaking ourselves in public

1035

sanctions-list + our own risk addresses (our set grows with use)

★ Wedge · live demo

KYA: an ID card for the agent

One click: register → pay with credential → impersonation blocked → revoke → blocked even with a valid credential.

Try it →

★ Killer demo

AI hijacked → firewall blocks it

Prompt-inject an agent that pays: firewall off → wallet drained; on → real 403 block (not an animation).

Attack it →

Live · callable

11-gate compliance gateway

KYA → proof → revocation → per-tx → daily → allowlist → intent → AML → anti-replay. A public endpoint any agent can curl now.

See how to integrate →

Sellable data

Risk query API

A buyer agent asks “is this counterparty safe?” before paying: sanctions/mixers + our own list + on-chain heuristics.

Query a mixer address →

Real on-chain

Base Sepolia settlement

The authenticated tier settles real test-USDC on Base Sepolia, verifiable on BaseScan; past the daily testnet cap or on an on-chain failure it falls back to simulated (noted). The public gateway always simulates.

See the real-settlement tier →

★ Tamper-evident · Bitcoin

Audit log → hash chain → Bitcoin

The audit tip is anchored to Bitcoin via OpenTimestamps (pending). Rewriting history means rewriting our DB, GitHub, and Bitcoin.

See the fingerprint + Bitcoin proof →

★ Publicly checkable · GitHub witness

Audit fingerprints → public GitHub witness

The same fingerprint is committed every few hours to a public GitHub repo (fingerprints only — no code, no data). Anyone can inspect the unbroken chain and verify it against Bitcoin independently — no trust in us required.

See the public witness →

★ Costly signal

Attack Lab: 6 episodes, self-broken 5×

We keep attacking our own product and publish every failure: missed limits, empty attribution, erasable logs, replay, deniable evidence — all patched.

Read all 6 →

Standard + funnel

RAP · Responsible Agentic Payments

A citable 7-pillar standard (with compliance ratings + a trusted-service registry), bilingual for humans and agents.

Read the standard →

We'll state it fully

Everything above is a real, running research-grade implementation — not a production-grade financial component. We wrote that sentence into our BP rather than waiting to be asked in diligence. But that's exactly the point: in a field where anyone can claim “we're secure” at zero cost, the only signal with information is publishing the process of breaking yourself. We've done it 6 episodes running. Credibility doesn't come from claiming completeness — it comes from publishing the result when your own team breaks it.

Want to be an early design partner — or talk investment?

If you're building agents that spend autonomously, or looking at the trust layer for agentic payments, leave your contact and let's talk.