The cryptography that keeps payments trustworthy.
Plain-English explainers on payment security, key management, and the trust layer of agentic commerce — for the people who build, secure, and lead in payments.
Featured writing
Coming Soon
A new whitepaper on payment security and AI agents
I'm finishing up a deep dive on how cryptographic trust frameworks govern AI agents in card transactions. Subscribe to the newsletter below to be the first to read it.
Recent posts
-
What's Actually Inside a Key Block?
Key Usage, Algorithm, Mode of Use, and the other header fields inside a TR-31 key block — and why binding the header to the key is the real innovation.
-
HSM vs. Software-Based Key Management
When do you actually need a dedicated hardware security module, and when is a software vault good enough? A practical framework for making the call.
-
How HSMs Organize Keys: The Key Hierarchy
LMK, ZMK, TMK, BDK, DUKPT and the rest of the HSM key hierarchy — how one master key born inside the hardware quietly protects every other key in a payment.
Newsletter
Monthly insights on payment security, cryptography, and what changes as AI agents start to pay.
About
Why "The Root Of Trust"
In cryptography, a root of trust is the anchor everything else chains back to — the one thing you have to trust for the rest to hold. Payments run on exactly that idea: keys, signatures, and scoped credentials that let strangers transact safely.
This is where I break that machinery down in plain English — EMV and HSMs, key management and tokenization, PCI and PIN security, and now the cryptographic trust layer that will decide whether AI agents can be trusted to pay.
Read my story