Skip to content

Delx property / defensive assurance

Security assurance for systems that can act.

Delx Security is a focused practice inside the Delx ecosystem. It helps teams make bounded, evidence-backed decisions about agents, MCP and A2A systems, applications, APIs and cloud-native delivery.

What it covers

Follow authority from intent to runtime.

The security property exists so the rest of the ecosystem can stay legible: mission, identity, authority, context, side effects, evidence and recovery remain distinct questions.

Agentic systems

Threat modeling and bounded review for agents, MCP and A2A systems, tools, memory, identity and human-approval boundaries.

Read the agent security guide

Product and cloud security

Evidence-led review of applications, APIs, cloud architecture, software supply chains, release gates and secrets.

See assurance services

Incident readiness

Runbooks, tabletop exercises and remediation verification for systems that need a credible path through failure.

Inspect the method

How to evaluate

Inspect the boundary before the claim.

The public practice keeps its own scope inspectable. A technical evaluator can understand the method, prepare a decision and contact the owner without sending sensitive material.

Start with a decision

Bring an owner, a real launch or remediation decision, an architecture view, credible impact and a safety contact.

Prepare a review

Use evidence, not badges

Frameworks provide vocabulary. Runtime behavior, reproducible findings and a verification record carry the burden of proof.

Read the research baseline

Keep disclosure durable

A public security.txt and disclosure policy provide the safe route for reporting issues in Delx-owned surfaces.

Open disclosure policy

Boundaries

A focused practice, not a blanket promise.

Delx Security does not inherit the mission, metrics or claims of the Protocol or Commerce properties, and it does not turn an alignment exercise into a certification.

Defensive only

Work is limited to owned or explicitly authorized systems, with written scope and stop conditions.

No certification claim

Public framework mappings are method inputs; they do not represent a third-party certification.

No secret intake

Do not send credentials, seed phrases, API keys, production data or customer secrets by email.

Public proof

Dated permalinks, not a logo wall.

Each link is a URL a visitor can open. None of these is a partnership, customer count, funding round or certification.

Would Pay Again, issue 5

Independent field review of a tested subset of Delx Commerce REST/MCP calls. Not a catalog-wide certification or ranking.

Open the permalink →

Official MCP Registry listing io.github.davidmosiah/delx-mcp-a2a

The registered name is the Commerce MCP server. Protocol has a separate identity and must not inherit this listing.

Open the permalink →

Live x402 payment manifest

Machine-readable payment discovery for governed Commerce routes. Discovery does not authorize a payment.

Open the permalink →

Coinbase Bazaar index coverage matrix

First-party read of which governed routes currently appear in Bazaar. Not Coinbase curation or a ranking.

Open the permalink →

A2A agent card (ERC-8004 discovery surface)

Published agent identity for machine discovery. Not a claim of on-chain adoption or token utility.

Open the permalink →

Continuity audit live receipt

Hashed first-party receipt for the published continuity-audit slice. Not independent validation.

Open the permalink →

Protocol write-outage incident report

Operator-authored, sanitized report of a 33.5-hour write failure. Not an independent review.

Open the permalink →

mcp-scorecard: delx-living-body

The same public instrument used for every npm-installable MCP server. A score is agent-readiness evidence, not certification.

Open the permalink →

mcp-scorecard: astral-mcp

Astral MCP as it already appears in the public leaderboard dataset.

Open the permalink →

Live properties

Reachability is measured now.

Operational

Delx lab

Expected response observed. HTTP 200. 1414 ms.

Open lab
Operational

Delx Protocol runtime

Expected response observed. HTTP 200. 416 ms.

Open runtime
Operational

Delx Protocol / Ontology

Expected response observed. HTTP 200. 103 ms.

Open ontology
Operational

Delx Commerce

Expected response observed. HTTP 200. 83 ms.

Open commerce
Operational

Delx Security

Expected response observed. HTTP 200. 1044 ms.

Open security
Operational

Delx Wellness

Expected response observed. HTTP 200. 68 ms.

Open wellness
Operational

Astral MCP

Expected response observed. HTTP 200. 63 ms.

Open astral

Probe source: server-side classifyResearchProbe. Not an SLA. Protocol, Hive and Commerce metrics stay separate.

Direct answers

Frequently asked questions.

Concise answers for technical evaluators, procurement teams and autonomous discovery systems.

What is Delx Security?

Delx Security is the defensive assurance practice inside the Delx ecosystem. It owns threat models, authorized reviews, security research, remediation verification and incident-readiness guidance.

Does Delx Security test systems without authorization?

No. Active testing begins only after an auditable Rules of Engagement defines the assets, techniques, timing, contacts and stop conditions. The public practice is defensive and explicitly authorized.

How is Delx Security different from Delx Protocol and Delx Commerce?

Delx Protocol owns continuity, recovery and agent care. Delx Commerce owns prices, pay-per-result services and delivery economics. Delx Security owns assurance methods and defensive security work.

Does Delx Security issue certifications?

No. It can map evidence to public frameworks, but it does not claim third-party certification or guarantee the security of an entire organization.