Security

Built to be verifiable.

Security is not a feature you have to manage. These are the guarantees MARCO enforces for every Passport, every payment and every application.

Live verification

Security, checked now.

Checking public endpoints
Portal API
Checking
Public health endpoint
Trust controls
Checking
Verification endpoint
MARCO Connect
Checking
Production bundle reachable
MARCO Pay
Checking
Production bundle reachable

Widget checks confirm production delivery of the published application bundles; payment and identity transactions are verified separately at runtime.

Canonical contracts

One MARCO identity. 6 registered networks, 5 publicly operational.

Bridge health map

Certified routes stay fail-closed.

Checking
Basecertified
BNB hubroute authority
Robinhoodcertified
Solanapaused
bnb → baseExecutable
Route available.
base → bnbExecutable
Route available.
bnb → solanaPaused
Solana bridging is paused. It will open with public activation.
solana → bnbPaused
Solana bridging is paused. It will open with public activation.
bnb → robinhoodClosed
Certified route. Public bridge activation has not been opened yet.
robinhood → bnbClosed
Certified route. Public bridge activation has not been opened yet.
bnb → arcExecutable
Route available.
arc → bnbExecutable
Route available.

A certified route is not automatically public or executable. The map reads the canonical MMN route-state endpoint and never turns a closed route green.

Your wallet stays yours.

  • MARCO never holds your private keys.
  • Connecting a wallet only proves who you are.
  • You can disconnect at any time from your Passport.

A payment completes only with on-chain proof.

  • Every MARCO payment requires a wallet signature and a transaction hash.
  • Settlement is verified on-chain before a payment is marked completed.
  • Payments settle to the merchant's configured wallet, never a placeholder.

One wallet, one active identity.

  • Each application receives its own isolated identity context.
  • Changing wallet ends the session and requires a new confirmation.
  • No application can ever receive one wallet paired with another Passport.

Only what is needed.

  • M-Credits balances and history are recorded by the MARCO ledger.
  • Businesses see aggregated, identity-free performance — never your profile.
  • Sign-in methods and recovery live inside Passport security settings.