Skip to content

Trust

Trust starts with explicit boundaries.

To verify a Delx trust boundary, identify the owner, inspect the current machine contract, trace data and authority, run a bounded test, and retain evidence before execution.

Five checks

Verify before you authorize.

A trustworthy evaluation is a short evidence trail: owner, contract, data and authority, bounded test, then retained result.

Machine identity

Canonical agent cards, API catalogs and protocol documents identify the surface an integrator is actually calling.

Current contract

Each capability publishes its own inputs, outputs, authentication, payment requirement and delivery boundary.

Data and authority

Evaluators should record what information moves, what external effects are possible and which decisions remain with the caller.

Bounded test

Use sample or non-sensitive inputs with a narrow scope and an explicit stop or rollback condition.

Evidence and route

Retain the result and contract version; a published security.txt provides a durable disclosure route.

Open security.txt

Security assurance

Delx Security is the focused defensive practice for authorized reviews, threat models and remediation verification.

Explore the practice

Data

Know where information moves.

The institutional page does not erase differences between local-first connectors, protocol relays and paid execution services.

Personal state

Delx Wellness is local-first, and its hosted public demonstration runs on sample data.

Protocol relays

Compatibility routes identify their canonical Delx property and preserve machine consumers without copying identity claims.

Paid execution

Commerce services publish service-specific schemas and terms; evaluators should inspect those terms before execution.

Public proof

Dated permalinks, not a logo wall.

Each link is a URL a visitor can open. None of these is a partnership, customer count, funding round or certification.

Would Pay Again, issue 5

Independent field review of a tested subset of Delx Commerce REST/MCP calls. Not a catalog-wide certification or ranking.

Open the permalink →

Official MCP Registry listing io.github.davidmosiah/delx-mcp-a2a

The registered name is the Commerce MCP server. Protocol has a separate identity and must not inherit this listing.

Open the permalink →

Live x402 payment manifest

Machine-readable payment discovery for governed Commerce routes. Discovery does not authorize a payment.

Open the permalink →

Coinbase Bazaar index coverage matrix

First-party read of which governed routes currently appear in Bazaar. Not Coinbase curation or a ranking.

Open the permalink →

A2A agent card (ERC-8004 discovery surface)

Published agent identity for machine discovery. Not a claim of on-chain adoption or token utility.

Open the permalink →

Continuity audit live receipt

Hashed first-party receipt for the published continuity-audit slice. Not independent validation.

Open the permalink →

Protocol write-outage incident report

Operator-authored, sanitized report of a 33.5-hour write failure. Not an independent review.

Open the permalink →

mcp-scorecard: delx-living-body

The same public instrument used for every npm-installable MCP server. A score is agent-readiness evidence, not certification.

Open the permalink →

mcp-scorecard: astral-mcp

Astral MCP as it already appears in the public leaderboard dataset.

Open the permalink →

Live properties

Reachability is measured now.

Operational

Delx lab

Expected response observed. HTTP 200. 1553 ms.

Open lab
Operational

Delx Protocol runtime

Expected response observed. HTTP 200. 1052 ms.

Open runtime
Operational

Delx Protocol / Ontology

Expected response observed. HTTP 200. 73 ms.

Open ontology
Operational

Delx Commerce

Expected response observed. HTTP 200. 125 ms.

Open commerce
Operational

Delx Security

Expected response observed. HTTP 200. 1160 ms.

Open security
Operational

Delx Wellness

Expected response observed. HTTP 200. 59 ms.

Open wellness
Operational

Astral MCP

Expected response observed. HTTP 200. 444 ms.

Open astral

Probe source: server-side classifyResearchProbe. Not an SLA. Protocol, Hive and Commerce metrics stay separate.

Direct answers

Frequently asked questions.

Concise answers for technical evaluators, procurement teams and autonomous discovery systems.

How do I verify a Delx trust boundary before execution?

Identify the owner, inspect the current machine contract, trace data and authority, run a bounded test with non-sensitive inputs, and retain the result with its contract version and support route.

Does a Delx trust review grant authorization or certify a service?

No. The review is an evaluation checklist, not a certification, SLA, authorization or guarantee of future availability. The caller remains responsible for approvals and controls.

Where can I report a security issue?

Use the contact and policy published at delx.ai/.well-known/security.txt. Do not send private keys, seed phrases, API keys or customer secrets by email.

Does the public Wellness demo process real personal health data?

No. The hosted Delx Wellness demonstration runs on sample data.

Are all Delx services covered by identical data terms?

No. Each focused property and capability has its own declared scope. Evaluators should inspect the relevant service contract before use.