PolicyVault Documentation

Non-custodial delegated-spending vaults on Kaspa L1 — for people and AI agents.

PolicyVault lets a vault owner hand a spending key to an agent — an employee, a service, a bot, or an AI agent — without handing over control of the funds. The spending policy is enforced by Kaspa L1 consensus through a covenant: even an agent who bypasses this entire application and talks directly to a Kaspa node cannot exceed the owner's policy.

AI MAY REQUEST. POLICYVAULT DETERMINISTICALLY DECIDES. THE COVENANT ENFORCES. SIGNERS RETAIN CUSTODY.

New here? Start with PolicyVault in 5 Minutes for the complete mental model, or jump straight to Create your first vault.

Production status (honest labels)

SurfaceStatus
Web / Agent platformPRODUCTION — LIVE at https://app.policy-vault.org (you can also fully self-host)
Current production sourcePUBLIC — https://github.com/zapsoblige-hash/PolicyVault, v1.0.0
Covenant protocol v0.4.1Mainnet-operational (real mainnet lifecycle evidence; see Covenant enforcement)
Native mobile (iOS/Android)DEVELOPMENT — NOT YET PRODUCTION-CAPABLE. Source and architecture are published, honestly labeled
External professional security auditHas NOT occurred. Planned. Nothing in this documentation claims otherwise

PolicyVault does not claim to be "FULL-SCALE POLICYVAULT — COMPLETE." The web/agent platform above is a production release; native mobile is a separate, later, honestly-labeled effort.

Find your way around

Product policy (permanent)

PolicyVault is free forever, including commercial use — no subscriptions, no transaction fees, no paid security, no usage caps. No patents on the protocol or its mechanisms. Apache-2.0 license. Voluntary support only, via KAS donations: kaspa:qyppakv5y7kmeynffldl9zshwgkjrl3fy9jjj8wf24v7f64v0gnuragz7ehdqhn (public receiving address; nothing in PolicyVault ever asks for or handles donation-wallet keys).