Funds move from payer to merchant in the same transaction. No balances, no withdrawals, nothing waiting in our wallets.
No upgrades, no proxies, no admin who can move funds. The code on chain is the code you can read.
Every contract's source is published and verified on Sourcify and BaseScan.
Every payment needs the payer's own signature over the exact recipient and amount. Our servers submit transactions; they cannot change them.
What we run, and where to see the results.
Our contracts have not yet had a paid third-party audit. Until they do, this is what we run, and every result is public.
Static analysis
Slither and Aderyn, the industry's standard open-source analysers, on every change. Every finding is reviewed and explained publicly; none is a vulnerability.
Fuzzing and invariant tests
157 Foundry tests drive thousands of random payments, signatures, timings and attack sequences through the contracts and check that no money appears, disappears or goes anywhere it was not signed for. A 20,000-run deep soak before every release.
Real-network tests
The same payments replayed against the real USDC, Permit2 and x402 contracts on copies of Base Mainnet and Base Sepolia.
Tests that test the tests
We deliberately break guards in the code and confirm the tests catch every change.
Independent review
Next. An independent review of the subscription contract comes first.
157 Foundry + 159 deployment
In one line each.
Check them yourself.
Found something?
Email contact@p2flux.com privately. Please don't disclose it publicly or test against real users' funds. We reply within five business days. We don't run a paid bug bounty at the moment; with your permission, we credit you publicly for a confirmed report.
Last reviewed 8 October 2026. This page describes our own testing and analysis; it is not a third-party audit.