Skip to main content
Flomisma

Real-time relay · agent settlement proof

Real-time relay +
agent settlement proof
for developers.

Zero-persistence WebSocket relay, four-call agent settlement, and a public pipeline verifier — buy templates or start free on the Developer relay tier. No custody, no message storage.

Live proof · Pipeline verifier

Paste-free demo: verify a sample agent settlement hash chain — no API key, no evidence payloads.

Sample root hash

a3f2c8910e4b7d6c5a9081726354b3c2d1e0f9a8b7c6d5e4f3a2b1c0d9e8f7a6

Open full verifier →

1,000

free sessions/mo

< 1ms

relay latency

0 bytes

stored server-side

Products

Three pillars. One funnel.

Start on relay, add settlement proof when agents handle money, or buy templates if you want the full stack in your repo. Everything else lives in the full catalog.

Relay

Zero-persistence WebSocket

HMAC-authenticated pub/sub with no disk and no database in the relay path. Free Developer tier — 1,000 sessions/month.

  • Usage-metered tiers, no overage penalties
  • Agent-to-agent channels on every tier
  • Sub-ms regional latency

Agent settlement & verify

Four-call flow + public proof

Off-chain escrow on the settlement ledger, HITL release gates, and a public pipeline verifier — prove what happened without exposing evidence.

  • POST task → submit proof → verify → release
  • Public /verifier — no API key
  • Settlement ledger API + agent settlement spec

Templates

Buy once, own the code

Production Next.js starters for escrow, relay, MCP, and multi-tenant SaaS — Stripe checkout on flomisma.com, MIT or BSL licenses.

  • Settlement & Ledger Starter — $299
  • Relay starter — $199
  • 11+ templates, documentation-complete

17 additional SKUs — credentials API, compliance, marketplace-in-a-box, hosting, Trust Stack, and more.

Relay

Deep dive

The relay only forwards frames. Quotas live in memory for the billing window, then roll up to the portal ledger — never the message body.

  • ✓ ESLint rule bans fs, Prisma, Redis imports in relay binary
  • ✓ GitHub Actions strace CI — fails if write syscalls detected
  • ✓ readonlyRootFilesystem on ECS Fargate container
  • ✓ Separate deployable — relay has no database connection
Read relay architecture →

Relay tiers

TierPriceSessions/moConcurrent
DeveloperFree1,000100Start free →
Startup$49/mo25,000500Get started →
Growth$199/mo150,0002,500Choose Growth →
Scale$499/moUnlimited10,000Choose Scale →
EnterpriseCustomDedicatedSLATalk to us →

Agent commerce

Payment layer for agent-to-agent work

Parent agent creates a task, worker submits structured proof, verification policies decide auto-release or human review. Off-chain escrow on the settlement ledger — not on-chain as system of record. Prove outcomes at /verifier.

Reference deployments

Named integration patterns — not portfolio lore.

Flomisma LLC ships the Trust Stack and protocol SDKs. Pemabu and JStonewall are separate operating entities that license field-of-use deploys — these are the integration shapes enterprise buyers ask about in diligence.

Pemabu

Financial systems operator

Settlement ledger anchor + vault execution plane

Anchors Flomisma protocol settlement on Pemabu’s Postgres ledger. Vault credentials stay encrypted; batch settlement and drift detection run in Pemabu’s sovereign watcher — not on flomisma.com custody APIs.

  • Licensee escrow via @flomisma/escrow-fsm + portal M2M
  • Encrypted exchange credentials in field-of-use vault
  • TLH / portfolio watcher cron (Docker) for drift + backup
Licensee SDK →

JStonewall

HITL command center

Private mesh + settlement exception queue

JStonewall is the portfolio CmdCenter above Pemabu and Flomisma portal. HITL exceptions, mesh health, and treasury sign-off route here — not to a public dashboard.

  • Settlement hitl.exception bridge consumer
  • Live mesh status for portal, relay, and Pemabu
  • Hardware-key MFA with zero local session persistence
Trust stack →

Evaluator memo and SOC2 control index: /memo · /trust

Enterprise · Protocol Integrity

Tamper-evident dispute lifecycle proof.

Flomisma provides zero-persistence cryptographic infrastructure. The Pipeline Integrity Protocol links evidence submission, encrypted storage, AI consumption, and verdict sealing into a single verifiable lifecycle record — available on enterprise and licensed deployments.

  • ✓ Four-stage hash-linked pipeline across heterogeneous trust boundaries
  • ✓ Compact lifecycle proof output for audit and downstream attestation
  • ✓ Streaming dispute paths with rolling validation (enterprise licensees)
  • ✓ Daily attestation reports for compliance consumers

Enterprise vault operations deploy inside isolated client runtimes or licensed financial operators (e.g. Pemabu) — not as a public hosted custody API on flomisma.com.

Protocol Integrity overview →

Stage 1

Evidence submitted

Authenticated dispute evidence enters the pipeline anchor.

Stage 2

Vault stored

Encrypted storage link verified before persistence.

Stage 3

AI consumed

PII-redacted context with auditable redaction manifest.

Stage 4

Verdict sealed

Output cryptographically coupled to evidence chain.

Templates

Templates that save 4–6 weeks.

Each template is documentation-complete. No support obligation. Buy once, own forever.

infrastructureNewTier 1 · MIT / Apache 2.0

AI Agency Directory Starter

Launch a Clutch-style B2B directory in a weekend.

Full Next.js 15 directory SaaS with Stripe tiered submissions, Resend transactional emails, statically generated SEO pages with Schema.org markup, category-filtered browse UI, featured listing tier, and pre-seeded data. TypeScript + Tailwind.

Tier 1 open-core — MIT or Apache 2.0. Community improvement flywheel; no proprietary pipeline logic included. Pipeline integrity protocol excluded (Tier 3).

financeTier 2 · BSL 1.1

Settlement & Ledger Starter

Double-entry ledger, escrow, and audit trail. Production-ready.

Immutable double-entry ledger with escrow workflows, batch settlement, audit trail, and reconciliation. Prisma + Postgres. Drop into any Next.js app. Includes SOC2-adjacent compliance helpers, USD fiat settlement workflows, and integrity snapshots for audit evidence.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

relayinfrastructureTier 1 · MIT / Apache 2.0

Zero-Persistence Relay Starter

WebSocket relay that never touches disk. Stateless by design.

The complete relay service from apps/relay/ — standalone, documented, and ready to deploy. Includes quota manager, room manager, API key rotation with zero-downtime grace slots, and metrics server. ESLint rules, strace CI, and readonlyRootFS config enforce zero persistence.

Tier 1 open-core — MIT or Apache 2.0. Community improvement flywheel; no proprietary pipeline logic included. Pipeline integrity protocol excluded (Tier 3).

infrastructuremonitoringTier 2 · BSL 1.1

Protocol Integrity Integration Kit

Wire attestation, verifier SDK, and pipeline hash hooks.

Drop-in integration kit for Flomisma protocol integrity: verifier SDK wiring, attestation consumer, pipeline root hash hooks, and public verify page patterns. Pairs with Settlement Ledger and Relay.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

infrastructureTier 2 · BSL 1.1

Next.js Multi-Tenant SaaS Starter

Multi-tenant architecture foundation. You bring your own billing.

Architecture foundation for a multi-tenant Next.js 15 SaaS. Includes Supabase auth, Prisma, Row-Level Security, per-tenant branding, and admin dashboard. No Stripe or deployment script included — bring your own payment stack. The foundation that took 6 months of sprints to build — yours in one purchase.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

aiTier 2 · BSL 1.1

AI Concierge Matching

Claude-powered brief parsing and provider matching

Natural language concierge that parses client briefs, matches providers via AI semantic matching, and orchestrates booking packages. Extracted from a production marketplace — works for any vertical.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

infrastructureTier 2 · BSL 1.1

Credential Badge System

HMAC-signed verifiable credentials with SVG badges

Cryptographically signed credential verification system. Generates public credential JSON endpoints and tamper-proof SVG badge images. Verifiable without a central database — signature is the proof.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

monitoringinfrastructureTier 2 · BSL 1.1

Marketplace Automation Suite

SLA monitoring, rate limiting, and incident detection

Production-grade automation infrastructure: SLA uptime monitoring with status escalation, token-bucket rate limiting per endpoint, security incident detection and logging, and health metrics collection. Grab-and-go for any marketplace backend.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

aiinfrastructureTier 2 · BSL 1.1

MCP Server — AI Agent Integration

Model Context Protocol for LLM tool execution

Expose your platform to AI agents via the Model Context Protocol (MCP). Includes agent-key authentication, typed tool definitions, and recommendation engine. Agents discover and invoke your APIs as tools — no custom integration code needed.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

financeaiTier 2 · BSL 1.1

Agent Risk Scoring Engine

7-factor risk scoring. Block HIGH/CRITICAL agents pre-transaction.

Real-time agent risk assessment for AI marketplace governance. Evaluates 7 factors — dispute rate, slash rate, cancel rate, audit failure rate, SLA breach rate, governance alert rate, and arbitration favorability — producing a 0–100 composite score mapped to 5 risk bands (LOW, MODERATE, ELEVATED, HIGH, CRITICAL). Includes immutable evidence log, SOC2-ready risk snapshots, and pre-transaction blocking. Drop into any Next.js + Prisma escrow marketplace.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

infrastructureTier 2 · BSL 1.1

Multi-Tenant SaaS Launchpad

Same architecture + Stripe billing + one-command deploy.

Everything in the Multi-Tenant SaaS Starter, plus Stripe checkout and webhooks, subscription management, custom domain setup, and a one-command deployment script. Deploy a production-ready B2B SaaS in 10 minutes — not 6 months.

License: Business Source License (BSL 1.1) — non-commercial use free; commercial use requires a Flomisma license. Converts to Apache 2.0 after 4 years. Pipeline integrity protocol excluded (Tier 3).

Settlement Ledger API

Double-entry ledger as a service.

Immutable ledger entries, escrow lock/release, batch settlement, and SOC2-adjacent audit trail — exposed as typed HTTP calls. No templates to install, no servers to manage.

  • ✓ Idempotent writes with integrity hash chain
  • ✓ Escrow lock / release / split with signature verification
  • ✓ USD fiat settlement fee preview and batch settlement
  • ✓ Redacted audit logging with SOC2 evidence collection
View API reference →
ledger-api
1// Record a settlement entry via the ledger API
2const portal = process.env.NEXT_PUBLIC_PORTAL_URL ?? 'https://portal.flomisma.com'
3const entry = await fetch(`${portal}/api/v1/ledger/entries`, {
4 method: 'POST',
5 headers: {
6 'x-ledger-api-key': 'fmr_your_key',
7 'Content-Type': 'application/json',
8 },
9 body: JSON.stringify({
10 tenantId: 'tenant_abc',
11 debit_account: 'platform_receivable',
12 credit_account: 'tenant_balance',
13 transaction_type: 'SETTLEMENT',
14 amount: 5000,
15 reference_id: 'order_abc123',
16 }),
17})
18
19const { success, data } = await entry.json()

Managed Hosting

We run the relay and ledger. You own your data.

Relay + settlement ledger, provisioned and operated. Single-region for solo projects, multi-region for teams, dedicated for enterprises. Your Postgres stays under your control; we operate the application and observability paths you approve.

  • ✓ Relay tier provisioned and scaled automatically
  • ✓ Settlement ledger with SOC2-adjacent audit trail
  • ✓ SLA-backed uptime with incident response
  • ✓ Multi-region and PITR backup options
Compare hosting plans →

Hosting plans

TierPriceRelay tierLedgerRegionsAuditSLASupport
Solo$99/moDeveloper (free)Single99.0%Email
Team$299/moStartupMulti-region99.5%Email + SLA
EnterpriseCustomCustomDedicated99.95%Dedicated

Settlement ledger column — managed portal ledger API (escrow FSM + double-entry). Flomisma does not hold customer funds; ledger records settlement events in your Postgres. Solo includes basic entry quota; Team adds batch settlement and SOC2 export; Enterprise is unlimited with dedicated cluster.