Fixes, defects, and disclosures. A verification service that hides its own defects is not worth paying for — we publish ours. ← fairseal.io
2026-10-07
Pricing update across paid endpoints pricing
Effective 2026-10-07, per-call prices changed: VEO verify $0.002 → $0.02; notarize $0.02 → $0.05; anchor $0.001 → $0.02; rng/latest $0.005 → $0.01. PII detect stays at $0.001, and /v1/rng/commit + reveal remain free during beta. Prices were below the x402 ecosystem median; this aligns them with the value of signed, independently verifiable receipts. All discovery documents (.well-known/x402, llms.txt, docs) were updated the same day. Requests paid at the old price before the cutover were honored at the old price.
Found during an internal paid self-audit of POST /v1/pii/detect (we buy our own endpoints with real USDC to check what customers actually receive). Two defects:
Overlap resolution was not longest-match-first. When a shorter pattern match (e.g. a NANP phone match) sat inside a longer one (a 16-digit card number), the shorter match could win the redaction. Result: sanitized text like 41111[REDACTED:PHONE] — the leading 5 card digits exposed and the finding mislabeled.
Spaced/dashed card formats were not detected (e.g. 4111 1111 1111 1111, the most common human formatting), and this limitation was not disclosed in the service description.
Impact:hasPII verdicts and findings for non-overlapping PII were unaffected. Sanitized output was affected only when PII patterns overlapped. This endpoint received its first external paid request earlier the same day, before the fix was deployed; that buyer may have received output from the flawed version.
Fix (F9): longest-match-first overlap resolution in sanitized output; added spaced/dashed card patterns (4-4-4-4 and 4-6-5) with Luhn validation to limit false positives; service description updated to disclose coverage limits.
Verification: 5/5 unit tests plus a paid end-to-end re-purchase of the live endpoint — both card formats now fully redacted as CREDIT_CARD; prior-fix (F4) regression passed.
2026-09-30
RNG: /v1/rng/latest served pre-computed pool output without per-request commitment; non-verifiable fallback removed defect fix
Found during an internal claim-level review of the RNG serving path. Two defects in the paid demo endpoint GET /v1/rng/latest ($0.005):
Pre-computed pool output could be stale and was not bound to the request. The endpoint served genuine VDF outputs drawn from a pre-computed pool, but a served value was computed before the request and was not committed to the individual caller. The same epoch output could in principle be observed by more than one party before serving. This is acceptable for the listed demo/testing use cases but was not fully disclosed, and the endpoint carried no per-request cryptographic receipt.
A configuration default allowed a silent non-verifiable fallback. If the pre-computed pool was exhausted, the service could fall back to non-VDF randomness without a verifiable proof, instead of refusing to serve.
Impact: exposure window 2026-08-30 to 2026-09-30. External paid requests in the window: one confirmed and one suspected (~$0.01 total). Served values were genuine VDF outputs in all observed cases; responses already carried a demo/sandbox warning. Commit/reveal (/v1/rng/commit) was never affected.
Fix (F6, deployed 2026-09-30): pool outputs are now Merkle-committed at fill time with the root anchored on Base; every paid response includes a single-use pool token with Merkle proof, root, and anchor status; the non-verifiable fallback path was removed entirely — if the pool is unavailable the endpoint fails closed with HTTP 503 rather than serving unverifiable output; the service description now states this endpoint is demo/sandbox and directs production use to commit/reveal.
Verification: 87/87 unit tests; two paid end-to-end purchases of the live endpoint with Merkle proofs recomputed and roots matched against the on-chain anchor; fail-closed 503 behavior exercised against the live service; full 16-check endpoint matrix passed.