Security belongs in the system design.

The verified controls around identity, tenant isolation, agent access, contracts, receipts, ledger truth, and provider boundaries.

The security page explains forced row-level isolation, scoped keys, passkey-only platform access, idempotent MCP mutations, immutable receipts, and the separation of Postgres business truth from TigerBeetle money truth. Nothing described there makes either test estate production.

Hyperscale is an agent-native fintech infrastructure control plane above partner financial institutions. A founder or agent composes published catalog bricks in HSX, and the compiler freezes that Product contract into OpenAPI, eight SDKs, MCP metadata, and docs. The hyperscale CLI and portal expose the same build. Named operations record receipts and audit entries against TigerBeetle money truth. Hyperscale is not a bank or money handler and never holds tenant funds under its own name.

Every Product starts in the sandbox with fixture identities, deterministic provider simulators, and play money. No tenant is live. Neither estate is production. Nothing on this public estate connects to real bank infrastructure. Product Activation is the explicit future gate for live access, and partner financial institutions would perform every regulated money movement.